Assistant actions and safety (MCP)

What an AI assistant connected to Spendesk can change, what cannot be undone, and what keeps it in check — to read before you tick a write permission.

An AI assistant connected through the Spendesk MCP server can do more than read: with your permission, it can create a purchase order, update a supplier, mark a payable as exported or commit an accounting export. This page lists every action, says which ones cannot be undone, and explains what keeps the assistant in check. Read it before you tick a write permission.

What keeps the assistant in check

Three checks apply to every action. The first two are enforced by Spendesk on each call; the third is guidance the assistant follows.

  1. Your permissions. Each kind of action is a separate write permission on the approval screen, unticked by default. A tool whose permission you did not tick is not even shown to the assistant, and a call to it is refused.
  2. Your Spendesk role. Every call checks your role in the company it acts on: only Controllers and Account Owners can use the assistant, for reading as for acting.
  3. Confirmation before acting. The server tells the assistant to act only when you asked for that change, and each action tells it what to check and confirm first — see How the assistant confirms. This is an instruction to the assistant, not a lock: the enforced safeguards are 1 and 2.

Some actions carry their own protection: updates to a payable are refused if the payable changed since the assistant read it (the payable's version), and chart-of-accounts changes are refused when your accounting integration manages the chart of accounts — make them in your accounting software instead.

Actions that cannot be undone

No assistant action can reverse these. Check the target before you confirm.

ActionWhat happensWhy it matters
Cancel a purchase orderThe purchase order is cancelled; no invoice can be attached to it any moreOnly possible while it is open with no invoice attached
Close a purchase orderThe purchase order is closed, and its amount is rewritten to what was billedThe originally approved budget is no longer shown on it
Commit an accounting export (markEntriesAsExported)The payables and settlements in the export are marked as exportedPreviews are the default: an export only commits when you ask for it explicitly
Mark a payable as exportedThe payable moves to exportedFor a payable you entered in your accounting outside Spendesk
Mark a settlement as exportedThe settlement's accounting entry is recorded as exportedThe assistant does not check the current state: a settlement already exported can be marked again
Delete an analytical field, or one of its valuesArchived; the field's values stay activeNo tool restores them
Delete the expense category fieldRemoves expense categories for the whole companyA new field starts empty
Delete an expense categoryArchived, even if existing spend uses itNo tool restores it

A purchase order also cannot be deleted: if one is created by mistake, the only clean-up is to cancel it while it is still open with no invoice attached.

Every action, by permission

Permission (sensitivity: high for all)ActionsCan the assistant undo it?
Manage purchase ordersCreate a purchase orderOnly by cancelling it (see above); a repeated request creates a second one
Cancel, close a purchase orderNo
Manage payablesUpdate a payable's accounting fields (account payable, accounting date, line items, amortisation dates)Yes, by updating it again
Mark a payable as ready for exportNo tool moves it back
Mark a payable as exported, mark a settlement as exportedNo
Manage suppliersCreate suppliersBy archiving them, if they have no payment, request or subscription
Update a supplier, including its bank detailsYes, by updating it again
Archive or unarchive a supplierYes: archiving only works for a supplier with no payment, request or subscription, and can be reversed
Manage chart of accountsCreate or update accountsYes, by updating them
Archive an accountYes, by unarchiving it
Manage accounting exportsGenerate a journal export (preview by default)A preview changes nothing; a commit cannot be undone
Download an export, list journal templatesRead only — they need this permission today
Manage analytical fieldsCreate or update a field or a valueYes, by updating or deleting it
Delete a field or a valueNo
Manage expense categoriesCreate or update the expense category field, or a categoryYes, by updating or deleting it
Delete the field or a categoryNo

Every call the assistant makes is listed in the connection's Action log in Spendesk (date, tool, status, user, company) — see Using the AI assistant safely. Changes made by the assistant are ordinary Spendesk changes: a cancelled purchase order shows as cancelled, an exported payable as exported, an archived supplier as archived — in Spendesk and through the API alike.

How the assistant confirms

The Spendesk server gives the assistant these rules:

  • Act only on request. A write action is used only when you asked for that change — never as a side effect of a question.
  • Check, then ask. Before an action, the assistant reads the current state (is the purchase order open? is the payable ready?) and tells you what it is about to change. For a cancellation or a closure, it names the purchase order, its supplier and its amount, and waits for your explicit go-ahead. Checking the data is not your approval.
  • Bank details verbatim. When creating or updating a supplier, the assistant only sets bank details that you gave exactly and confirmed; it never infers or completes them.
  • One at a time. After a broad instruction such as "clean up unused suppliers", it confirms each supplier instead of archiving several unprompted.
  • No blind retries. When a result is unclear, it reads the state again instead of repeating the action — creating a purchase order or a supplier twice would create two.
  • Say what happened. After an export, it tells you whether it was a preview (nothing changed) or a commit (entries marked as exported).

Your assistant may add its own step: Claude, for example, asks the first time it uses each tool whether to allow it once, always, or not. For write actions, allow once keeps a human decision on each one.

Choosing permissions

  • Start read-only. Leave write permissions unticked until you have a use for them: reading is enough for analysis, month-end checks and invoice follow-up.
  • Tick only what the job needs. Someone who manages purchase orders needs Manage purchase orders, not Manage accounting exports.
  • Company or organisation. An organisation-level connection can act in every company where you are a Controller or Account Owner; a company-level connection only in that company. See Several companies in Connect an AI assistant.
  • Try it on the demo first. Actions can be tried safely against a demo account, on the demo server URL given in Connect an AI assistant.

Changing or removing permissions

  • You: reconnect the assistant and untick the permissions you no longer want. Your connection only carries the permissions you left ticked.
  • Your Admin: can change the permissions the connector may request, from its detail page in Spendesk (Settings → Integrations → MCP, Permissions tab, with a second-factor check), or remove the connection (Remove).
  • A connection that is not used for 30 days expires, and you have to sign in again.

See also the MCP tool reference (every tool, with its permission), Connect an AI assistant (MCP) and Scopes.