User Guide

Bank reconciliation

Read-only Plaid sync, 5-rule auto-matcher, categorization rules, QuickBooks IIF export.

Read-only by design
TimeTrack Pro never moves money via this connection — only transactions and balance Plaid products are enabled at the integration layer (defense-in-depth enforcement before any Plaid API call, not just config).
Bank transactions list with match status pills (screenshot pending — Bank Sync is shipped, ready to capture)
Screenshot to be added

Connecting a bank

Super_admin only. Settings → Bank Sync → "Connect Bank Account" launches Plaid Link. User signs in through Plaid's hosted modal; we receive an access token which we encrypt at rest (AES-256-GCM with tenant-derived key) + store under bank_connections. Token never leaves the service layer in plaintext.

Per-account opt-in
Each connection exposes every account under the Plaid Item. Toggle individual accounts on/off — disabled accounts have their transactions dropped at the sync boundary. Useful for excluding personal accounts that came along with a business login.

5 auto-match rules

Evaluated in priority order; first match ≥ 0.70 confidence auto-applies.

🎯

R1 · 0.98

Invoice number in transaction name AND amount matches invoice balance. Highest confidence — pretty much always right.
🏷️

R2 · 0.85

Amount + client name in transaction name or merchant. Common for ACH labeled with the payor.
📅

R3 · 0.75

Amount matches a payments row within ±7 days. Catches payments where the memo doesn't carry the invoice #.
🏭

R4 · 0.80

Outflow + vendor name in transaction name, ±5 days. Used for AP-side vendor payments.
🔁

R5 · 0.70

Paired internal transfer — same connection, opposite signs, near-equal amounts. Catches the most common false-positive shape.

Admin can confirm, reject, or manually rebind any auto-matched row. Manual matches always win over rule-based labels.

Match kinds — 6 entity bindings + 2 special

  • ✓ar_payment — inflow → invoices (auto + manual)
  • ✓retainer_deposit — inflow → active retainers (manual only in v1)
  • ✓ap_payment — outflow → vendor payments (auto + manual)
  • ✓expense_reimbursement — outflow → approved expenses (manual only)
  • ✓retainer_refund — outflow → closed retainers with refund disposition
  • ✓direct_user_payment — outflow → users (employee / vendor_member); foundation for year-end 1099-NEC reporting via GROUP BY targetEntityId
  • ✓transfer — paired internal transfer via R5 (detection only, no auto-apply)
  • ✓manual_category — free-text, no entity (categorize path for bank-only flows like payroll / fees)

Categorization rules

For recurring transactions the auto-matcher can't bind (payroll, Stripe deposits, bank fees, tax payments), define pattern-based rules in Banking → Categorization rules. Each rule matches merchant name or description against a substring or regex pattern and stamps a category. Rules fire DURING sync AND via the "Auto-categorize" sweep button on the transactions list.

Manual categorization is sacred
Rules never overwrite a transaction already manually categorized. The sweep targets only ttp_category IS NULL rows. Once a category is set by hand, only an admin can change it.

Reconciliation + QuickBooks export

📊

Reconciliation

Month-end: visit Banking → Reconciliation, pick account + period, verify all transactions are matched or categorized, click Close period. Closed periods are immutable.
💼

IIF export

Banking → Export to QuickBooks → pick date range → download IIF file your CPA can import into QuickBooks Desktop. Uses your ttp_category per line.
Tip
IIF files import into QuickBooks Desktop directly. For QBO, use a conversion tool like Transaction Pro.

Security posture

  • ✓Read-only Plaid products only — enforced before any API call
  • ✓AES-256-GCM tenant-scoped encryption on access tokens
  • ✓Tampered ciphertext rejected by GCM auth tag
  • ✓Webhook signature verification via Plaid's ES256-signed JWT
  • ✓Atomic disconnect — Plaid /item/remove BEFORE local wipe
  • ✓Audit log on every state change