# Evidence matching: Every charge keeps its proof.
> Oatmilk reads receipts from your company's inboxes and matches each one to its charge. It asks you when it isn't sure and keeps the original.
[Get started](https://app.getoatmilk.com/sign-up) · [Sign in](https://app.getoatmilk.com/sign-in) · [Docs](https://getoatmilk.com/docs.md) · [llms.txt](https://getoatmilk.com/llms.txt)
## How it works
1. Forward it or connect your inbox
2. Oatmilk reads it and finds the charge
3. You check only the unsure ones
## What it does
- **One forwarding address for the company.** Forward any receipt or invoice to the company's own address and it lands in the right mailbox.
- **Gmail and Outlook, read-only.** Connected mailboxes are read-only: Oatmilk can read receipts but can't send, move or delete mail.
- **Matches only when it's sure.** A receipt is matched on its own only at 98% or more with a clear lead; anything less waits in Match review for a person.
- **GST/HST, PST, QST and VAT as printed.** Taxes are kept exactly as the receipt prints them, and a tax that isn't printed is never treated as zero.
- **Originals kept as received.** Every email and file is kept exactly as it arrived, next to the charge it proves.
- **A polite nudge when one is missing.** Cardholders get a short reminder for missing receipts, more often as GST/HST and year-end deadlines get close.
## Where evidence comes from
Evidence is the receipt, invoice or email that proves what a charge was for. It reaches Oatmilk in any of these ways:
- **The company forwarding address** (`accounting-…@inbound.getoatmilk.com`). Mail is sorted into the company mailboxes: Accounting, Invoices, Signatures, Reminders, Contractors and Notifications.
- **Gmail and Outlook, connected read-only.** Oatmilk asks only for read access (`gmail.readonly` for Gmail, `Mail.Read` for Outlook). It can't send, move or delete mail.
- **"Find receipts in my inbox".** A one-time search of a person's inbox. The access lasts at most 1 hour and is removed as soon as the search is done.
- **Photos and uploads** of paper receipts and PDF files.
- **Wise receipts** from a connected Wise account.
## What happens to each email
Every item goes through the same steps, in this order:
1. **Accept and keep the original** exactly as it was received.
2. **Screen it.** Sign-in and account emails (passwords, "confirm your card") are screened out and never read. Sender checks (SPF, DKIM, DMARC) and fraud checks run too.
3. **Mask secrets.** Passwords, one-time codes, card numbers and tokens are masked before any AI model reads the email.
4. **Read every page twice.** When the two reads disagree, a third read settles it.
5. **Route it** to the right mailbox. Routing is decided by Jev, TypeSafe's decision model, and only when it is at least 95% likely and 90% confident.
6. **Check the money** against the company's charges.
7. **Add it to the books.** Only clear cases from trusted senders go in on their own. Mail from unknown senders becomes a draft for a person to check.
## How a receipt finds its charge
- Oatmilk looks at **up to 8 candidate charges** for each receipt.
- Jev picks one of them, or answers "no match" or "not enough evidence". For every candidate it also answers **"same purchase?"** with a probability.
- A receipt is matched without a person **only when all of these hold**: the chosen charge is at least 98% likely, the answer is at least 95% confident, "same purchase?" is at least 98%, and it leads the next best charge by 20 points.
- **A clear-match rule** also applies without AI: the amount is the same, the bank line names the vendor, and no other line has that amount.
- Anything less waits in **Match review**, where a person accepts or rejects the suggested charge.
- **The database checks the thresholds again** before a match is saved.
- Guards: fraud holds, closed periods and duplicates are never matched over, and a charge in another currency is matched only with proof.
- A receipt can match a charge weeks or months apart, for example a flight booked in September with its receipt in October.
- Admins can make the thresholds stricter, or looser down to fixed floors (90% likely, 85% confident, 90% same purchase, a 10-point lead).
## Staying compliant
- **Every charge keeps its proof**: the original email or file, the lines read from it, its taxes, the match score, who or what matched it, and its History.
- **Taxes are kept as printed**: GST/HST, PST, QST and VAT. A tax that isn't printed is kept as unknown, never treated as zero.
- **Originals are kept exactly as received.** The CRA (Canada Revenue Agency) asks businesses to keep their records for six years.
- Every change shows in History and can be undone.
## Missing receipts
When a charge has no proof, Oatmilk emails the cardholder a short, polite reminder. Reminders come more often as GST/HST, year-end and T2 (corporate tax return) deadlines get close, and never less than 48 hours apart. People can pause or stop them, and they end as soon as the receipt comes in.
## With Ask AI and the receipt investigator
- **Ask AI** finds evidence from a plain question, such as "Find the receipt for Uber on Oct 3", and shows the charge it proves.
- **The receipt investigator** is opt-in. It searches only the inboxes whose owners agreed, and it only proposes matches: finance accepts them.
## More from Oatmilk
- [Classifier](https://getoatmilk.com/classifier.md): Each bank and card line runs through rules, memory, receipts and Jev. Oatmilk sorts it only when it's sure, and asks you one question when it isn't.
- [Bookkeeping](https://getoatmilk.com/bookkeeping.md): Bank, card, Wise and Stripe charges come in and get sorted. Oatmilk asks you only when it isn't sure.
- [Compliance](https://getoatmilk.com/stay-compliant.md): Ask any rules question and get an answer with official sources. Guides, deadlines and rule changes for your company, in one place.
- [Invoices](https://getoatmilk.com/invoices.md): Make an invoice in a minute, send it, and see when it's opened and paid.
- [Agreements](https://getoatmilk.com/agreements.md): Write an agreement, send it to sign on any device, and keep every signed copy with a full record.
- [Contractors](https://getoatmilk.com/contractors.md): Contractors send hours from their own portal. You approve with a tap, pay with Wise and get tax slips at year-end.
- [Tax](https://getoatmilk.com/tax.md): Year-end for Canadian companies, one plain question at a time. T2, GST/HST and T4A work, ready for your accountant.
- [Ask AI](https://getoatmilk.com/ask-ai.md): Ask a question about your company and get a straight answer. Ask AI reads your books and asks before it changes anything.
- [Accountants](https://getoatmilk.com/accountants.md): Invite your accountant to see the books and help with year-end. You pick what they can do and when it ends, and every action is on the record.
- [Run it locally](https://getoatmilk.com/local.md): Run Oatmilk on your own computer with the CLI and the web portal, or choose where each part runs: this computer, the cloud, or off.
- [Local models](https://getoatmilk.com/local-models.md): Run Ask AI, the classifiers and document reading on Ollama, LM Studio or any OpenAI-compatible server. Mix local and cloud by role.
- [CLI](https://getoatmilk.com/cli.md): Oatmilk in your terminal: every page one keypress away, Ask AI built in, and themes that work in light and dark terminals.
- [AI connectors](https://getoatmilk.com/mcp.md): Connect Claude, ChatGPT, Cursor, Codex and more to Oatmilk. Your AI can do what you can do, and nothing more.
Human version: https://getoatmilk.com/evidence