Skip to main content

Use AI assistants with Spendesk safely

What protects your data when an AI assistant works with Spendesk, what AI can get wrong, and good practices before you let it act.

When you connect Claude, ChatGPT, Dust or Langdock to Spendesk through Spendesk MCP, the assistant works as you: with your Spendesk account, your role, your entities and the permissions you chose — never more. Spendesk MCP is not an AI model; it is a controlled bridge between your assistant and Spendesk.

This article explains what protects you, what an AI assistant can still get wrong, and good habits before you let it act. To set up Spendesk MCP, see the MCP Getting Started Guide.

Note: The screenshots show Claude as an example. The same steps apply to ChatGPT, Dust and Langdock, with their own screens.

What protects you

It acts as you. Each person connects with their own Spendesk login; the assistant never sees your password. Only Account Owners and Controllers can use Spendesk MCP, and your role is checked on every call, entity by entity: the assistant only reaches the entities where you hold that role.

Only what you allow. When you connect, read permissions are ticked by default; write permissions are not. Each kind of action — suppliers, payables, purchase orders, chart of accounts, analytical fields, expense categories, accounting exports — is a separate permission that an Account Owner or Admin first enables on the connection, and that you then tick yourself. The assistant cannot use a tool you did not allow, and cannot give itself more access.

The Permissions tab of an MCP connection in Spendesk, with the Access column
On the Spendesk approval screen, write access is unticked by default
With read access and Manage suppliers only, Claude sees 37 Spendesk tools instead of 62

One entity per action. With a connection that covers several entities, every action targets a single entity, which the assistant has to name.

Everything is logged. Every call — reads and actions — is recorded in the connection's Action log in Spendesk (Settings → Integrations → MCP, or Multi-entity Hub → MCP, then Manage → Action log): date, tool, status, user and entity. Account Owners and Admins can open it. The Action log does not list the values that were changed: to see what changed on an object, open it in Spendesk.

The Action log records the Archive Supplier call with its date, status, user, entity and correlation ID

You can switch it off. An Account Owner or Admin can remove a connection from its page in Spendesk (Manage → Remove, confirmed with their second factor). This ends the access of every user connected through it at once. Each user can also disconnect Spendesk in their AI assistant.

What an AI assistant can still get wrong

The protections above decide what the assistant can do. Within those limits, it is still an AI model:

  • It can misunderstand you. "Cancel the Acme order" is ambiguous if there are two. Name the object precisely — the supplier, the purchase-order number, the amount, the entity — and read the assistant's summary before you confirm.

  • It can misread what it found. Figures come from Spendesk, but the assistant can still get a date range or a currency wrong. Check in Spendesk the figures that drive a decision, such as a payment run or a month-end close.

  • Content can try to steer it. A supplier name, an invoice line or a document can contain text written to give the assistant instructions ("prompt injection"). With read permissions only, the worst case is a wrong answer; with write permissions and actions always allowed, it could be an unwanted change. This is why write permissions are off by default, and why you should approve each action.

  • Actions are real. There is no test mode: a purchase order created by the assistant is a real purchase order, and a committed accounting export marks real entries as exported. Some actions cannot be undone — the MCP Write Tools guide lists each action and whether it can be reversed.

Your data and your AI provider

What the assistant reads from Spendesk becomes part of your conversation, which is processed by the provider of your assistant — Anthropic for Claude, OpenAI for ChatGPT, Dust or Langdock — under your agreement with them. Before connecting Spendesk, review your workspace's settings with that provider for privacy, data retention, sharing and model training.

Good habits when the assistant acts

  • Keep approval on for actions. In Claude, choose Allow once when asked, and keep Write Tools on Needs approval; use Always allow for read tools only.

  • Ask for a preview first: "Show me what would change, but do not do it yet."

  • Check before you confirm: the entity, the object, the fields and values, and whether the action can be undone.

  • Review the results of actions on several items. Some tools, such as creating suppliers or updating accounts, handle several items in one call: some items can succeed while others fail.

  • Never paste passwords, OAuth credentials or tokens into a conversation with an AI assistant.

  • Check the result in Spendesk after an important action.

Claude asks for approval before the Archive supplier action: choose Allow once
Claude connector settings: approval setting for each Spendesk tool (Always allow, Needs approval, Blocked)

Roll it out step by step

  1. Start read-only. Reporting, month-end checks and invoice follow-up need no write permission.

  2. Pilot with a few Controllers on one job you expect — for example purchase orders only.

  3. Enable only the write permissions that job needs, on the connection and when each user connects.

  4. Review the Action log during the pilot: which tools are used, by whom, and whether any fail.

  5. Narrow permissions when the job is done. Users reconnect and untick what they no longer need; an Account Owner or Admin can turn permissions off on the connection, or remove it.

If something goes wrong

  • An action was made by mistake: contact Spendesk Support with the tool name, the object, the approximate time and the correlation ID shown in the Action log. The MCP Write Tools guide shows which actions can be undone, and how.

  • Credentials were exposed (pasted into a chat, sent by email): delete the connection (Manage → Remove) and create a new one; its users then reconnect. The OAuth Client Secret cannot be displayed again or regenerated.

For your security team

The technical details — OAuth 2.0 with PKCE, token lifetimes, permission sensitivity levels, audit and hosting — are in the developer documentation: Using the AI assistant safely.

Did this answer your question?