Mozap — Embedded Engineering for FinanceHow it works · Vol. 01 · 2026
Mozap
How it works

A six-week ramp, then a retainer.

One 60-minute kickoff. Read-only credentials. The first deliverable lands within fourteen days. The cadence locks within thirty. Maintenance is the retainer — there is no change order.

Build calendar · weeks 1 through 6EVERY WEEK · ONE SHIP
  1. W1DISCOVERYKickoffOne 60-minute call with your controller and one Mozap engineer. We leave with the list of systems, the list of read-only credentials we need, and one open question for follow-up.↳ ships: List of credentials needed.
  2. W2BUILDConnectCredentials issued; we test connectors against your specific tenant. Schema diff against your COA. Reporting templates pulled from your shared drive — verbatim.↳ ships: Connection report; schema map.
  3. W3BUILDDraftFirst draft of the workflow runs end-to-end on last close. Mozap engineer reviews against your prior memo. Variance threshold and footnote conventions tuned.↳ ships: Workflow v0 against last close.
  4. W4BUILDDry runWorkflow runs on the current period (mid-close). Internal review with your controller. Edits to tone, citation style, and sign-off chain.↳ ships: Dry-run deliverable, controller-marked.
  5. W5STEADYFirst sendFirst production deliverable lands in your inbox on close day 3. Signed by Mozap; counter-signed by your controller before forwarding.↳ ships: First signed deliverable.
  6. W6STEADYCadence locksSecond cycle runs without intervention. Workflow committed to your engagement repository. On-call rotation in place.↳ ships: Engagement repo + on-call schedule.
  7. W7+RETAINERSteady stateDeliverables ship on cadence. Maintenance runs in the background. Investigations answered as they arrive.↳ ships: every cycle, no exception.
Maintenance · what the retainer coversNO CHANGE ORDER · NO RE-ENGAGEMENT FEE
  1. 01COA changesYou add account 6485 for cloud infra; we update the workflow inside the same week. No change order.
  2. 02New entityYou acquire a sub-ledger or open a foreign subsidiary. We extend the connector and consolidating workflow within fourteen days.
  3. 03Reporting restructureYour VP Finance restructures segment reporting; we re-segment the variance memo and flux page in the next cycle.
  4. 04Software migrationYou move from QuickBooks to NetSuite mid-year. We connect the new system and run both in parallel for one cycle.
  5. 05Threshold or template tuneYou change the variance threshold from $250k to $500k; we update the workflow same-day.
  6. 06New artifactYou ask for a new deliverable mid-engagement. Inside the retainer if recurring; one-off pricing if discrete.
Who does what13 LINES · 5 CLIENT · 8 MOZAP
Client · you
  1. 01Issuing read-only credentials
  2. 02Maintaining those credentials
  3. 03One 60-minute kickoff
  4. 04Reviewing & counter-signing the first cycle
  5. 05NDA execution
Mozap · us
  1. 01Building the workflow
  2. 02Hosting the workflow infrastructure
  3. 03Pulling the snapshot at-time-of-close
  4. 04Drafting the deliverable
  5. 05Citing the source records
  6. 06Maintenance · COA / entity / reporting changes
  7. 07On-call rotation for ad-hoc questions
  8. 08Audit-trail retention for seven years
Security & data posture08 ITEMS · NDA-BACKED
  1. 01AuthenticationOAuth 2.0 to every supported system. API keys (where OAuth is unavailable) are restricted to read-only scopes and IP-pinned to Mozap egress.
  2. 02Scope of accessRead-only. We do not have write credentials to your GL, your HCM, or your CRM.
  3. 03Credential storageMozap-owned secret manager (HashiCorp Vault). Rotation cadence configurable; 90 days by default.
  4. 04Data residencyWorkflow runs on Mozap-owned infrastructure. Snapshots retained for seven years for audit-trail purposes; nothing else is retained.
  5. 05PII postureNo PII is rendered in deliverables. Worker identifiers are replaced with positions in narrative copy.
  6. 06EmailOutbound only, from [email protected]. We do not read your inbox.
  7. 07ComplianceSOC 2 Type II report (Coalfire, FY26). HIPAA BAA available for healthcare clients. NDA executed before kickoff.
  8. 08TerminationOn 30 days notice. Credentials revoked by you; snapshot data retained for the seven-year audit window unless your contract specifies sooner deletion.
Full SOC 2 Type II report, subprocessor list, DPA, and BAA available under NDA.

Thirty days from kickoff, your senior FP&A analyst is back to the work you hired them to do.

← Back to Mozap.io