What an AI assistant connected to Spendesk can change, what cannot be undone, and what keeps it in check — to read before you tick a write permission.
An AI assistant connected through the Spendesk MCP server can do more than read: with your permission, it can create a purchase order, update a supplier, mark a payable as exported or commit an accounting export. This page lists every action, says which ones cannot be undone, and explains what keeps the assistant in check. Read it before you tick a write permission.
What keeps the assistant in check
Three checks apply to every action. The first two are enforced by Spendesk on each call; the third is guidance the assistant follows.
- Your permissions. Each kind of action is a separate write permission on the approval screen, unticked by default. A tool whose permission you did not tick is not even shown to the assistant, and a call to it is refused.
- Your Spendesk role. Every call checks your role in the company it acts on: only Controllers and Account Owners can use the assistant, for reading as for acting.
- Confirmation before acting. The server tells the assistant to act only when you asked for that change, and each action tells it what to check and confirm first — see How the assistant confirms. This is an instruction to the assistant, not a lock: the enforced safeguards are 1 and 2.
Some actions carry their own protection: updates to a payable are refused if the payable changed since the assistant read it (the payable's version), and chart-of-accounts changes are refused when your accounting integration manages the chart of accounts — make them in your accounting software instead.
Actions that cannot be undone
No assistant action can reverse these. Check the target before you confirm.
| Action | What happens | Why it matters |
|---|---|---|
| Cancel a purchase order | The purchase order is cancelled; no invoice can be attached to it any more | Only possible while it is open with no invoice attached |
| Close a purchase order | The purchase order is closed, and its amount is rewritten to what was billed | The originally approved budget is no longer shown on it |
Commit an accounting export (markEntriesAsExported) | The payables and settlements in the export are marked as exported | Previews are the default: an export only commits when you ask for it explicitly |
| Mark a payable as exported | The payable moves to exported | For a payable you entered in your accounting outside Spendesk |
| Mark a settlement as exported | The settlement's accounting entry is recorded as exported | The assistant does not check the current state: a settlement already exported can be marked again |
| Delete an analytical field, or one of its values | Archived; the field's values stay active | No tool restores them |
| Delete the expense category field | Removes expense categories for the whole company | A new field starts empty |
| Delete an expense category | Archived, even if existing spend uses it | No tool restores it |
A purchase order also cannot be deleted: if one is created by mistake, the only clean-up is to cancel it while it is still open with no invoice attached.
Every action, by permission
| Permission (sensitivity: high for all) | Actions | Can the assistant undo it? |
|---|---|---|
| Manage purchase orders | Create a purchase order | Only by cancelling it (see above); a repeated request creates a second one |
| Cancel, close a purchase order | No | |
| Manage payables | Update a payable's accounting fields (account payable, accounting date, line items, amortisation dates) | Yes, by updating it again |
| Mark a payable as ready for export | No tool moves it back | |
| Mark a payable as exported, mark a settlement as exported | No | |
| Manage suppliers | Create suppliers | By archiving them, if they have no payment, request or subscription |
| Update a supplier, including its bank details | Yes, by updating it again | |
| Archive or unarchive a supplier | Yes: archiving only works for a supplier with no payment, request or subscription, and can be reversed | |
| Manage chart of accounts | Create or update accounts | Yes, by updating them |
| Archive an account | Yes, by unarchiving it | |
| Manage accounting exports | Generate a journal export (preview by default) | A preview changes nothing; a commit cannot be undone |
| Download an export, list journal templates | Read only — they need this permission today | |
| Manage analytical fields | Create or update a field or a value | Yes, by updating or deleting it |
| Delete a field or a value | No | |
| Manage expense categories | Create or update the expense category field, or a category | Yes, by updating or deleting it |
| Delete the field or a category | No |
Every call the assistant makes is listed in the connection's Action log in Spendesk (date, tool, status, user, company) — see Using the AI assistant safely. Changes made by the assistant are ordinary Spendesk changes: a cancelled purchase order shows as cancelled, an exported payable as exported, an archived supplier as archived — in Spendesk and through the API alike.
How the assistant confirms
The Spendesk server gives the assistant these rules:
- Act only on request. A write action is used only when you asked for that change — never as a side effect of a question.
- Check, then ask. Before an action, the assistant reads the current state (is the purchase order open? is the payable ready?) and tells you what it is about to change. For a cancellation or a closure, it names the purchase order, its supplier and its amount, and waits for your explicit go-ahead. Checking the data is not your approval.
- Bank details verbatim. When creating or updating a supplier, the assistant only sets bank details that you gave exactly and confirmed; it never infers or completes them.
- One at a time. After a broad instruction such as "clean up unused suppliers", it confirms each supplier instead of archiving several unprompted.
- No blind retries. When a result is unclear, it reads the state again instead of repeating the action — creating a purchase order or a supplier twice would create two.
- Say what happened. After an export, it tells you whether it was a preview (nothing changed) or a commit (entries marked as exported).
Your assistant may add its own step: Claude, for example, asks the first time it uses each tool whether to allow it once, always, or not. For write actions, allow once keeps a human decision on each one.
Choosing permissions
- Start read-only. Leave write permissions unticked until you have a use for them: reading is enough for analysis, month-end checks and invoice follow-up.
- Tick only what the job needs. Someone who manages purchase orders needs Manage purchase orders, not Manage accounting exports.
- Company or organisation. An organisation-level connection can act in every company where you are a Controller or Account Owner; a company-level connection only in that company. See Several companies in Connect an AI assistant.
- Try it on the demo first. Actions can be tried safely against a demo account, on the demo server URL given in Connect an AI assistant.
Changing or removing permissions
- You: reconnect the assistant and untick the permissions you no longer want. Your connection only carries the permissions you left ticked.
- Your Admin: can change the permissions the connector may request, from its detail page in Spendesk (Settings → Integrations → MCP, Permissions tab, with a second-factor check), or remove the connection (Remove).
- A connection that is not used for 30 days expires, and you have to sign in again.
See also the MCP tool reference (every tool, with its permission), Connect an AI assistant (MCP) and Scopes.