---
updatedAt: 2026-10-01T13:30:59.000Z
agentTools:
  projectIndex: https://developer.spendesk.com/llms.txt
---

# Assistant actions and safety (MCP)

What an AI assistant connected to Spendesk can change, what cannot be undone, and what keeps it in check — to read before you tick a write permission.

An AI assistant connected through the [Spendesk MCP server](https://developer.spendesk.com/reference/connect-an-ai-assistant-mcp) can do more than read: with your permission, it can create a purchase order, update a supplier, mark a payable as exported or commit an accounting export. This page lists every action, says which ones cannot be undone, and explains what keeps the assistant in check. Read it before you tick a write permission.

> 🚧 Write actions are in Beta
>
> Reading through the MCP server is generally available. Write actions are in **Beta**: their permissions are **off by default** on every connection. An Account Owner or Admin turns on the ones the team needs (the connection's **Permissions** tab), then each user disconnects, connects again and ticks them.

# What keeps the assistant in check

Three checks apply to every action. The first two are enforced by Spendesk on each call; the third is guidance the assistant follows.

1. **Your permissions.** Each kind of action is a separate *write* permission. An Account Owner or Admin first enables it on the connection; on the approval screen it is then unticked by default, and you tick it yourself. A tool whose permission you did not tick is not even shown to the assistant, and a call to it is refused.
2. **Your Spendesk role.** Every call checks your role in the company it acts on: only **Controllers** and **Account Owners** can use the assistant, for reading as for acting.
3. **Confirmation before acting.** The server tells the assistant to act only when you asked for that change, and each action tells it what to check and confirm first — see [How the assistant confirms](#how-the-assistant-confirms). This is an instruction to the assistant, not a lock: the enforced safeguards are 1 and 2.

Some actions carry their own protection: updates to a payable are refused if the payable changed since the assistant read it (the payable's `version`), and chart-of-accounts changes are refused when your accounting integration manages the chart of accounts — make them in your accounting software instead.

**One company per action.** Every action applies to one company. On an organisation-level connection the assistant has to say which one: check that it names the right entity before you confirm.

**A batch can partly succeed.** *Create suppliers* and *Update accounts* take several items in one call, and some can succeed while others fail. The result lists each item: read it before asking again, or suppliers that were already created would be created twice.

# Actions that cannot be undone

No assistant action can reverse these. Check the target before you confirm.

| Action                                                    | What happens                                                                      | Why it matters                                                                                    |
| :-------------------------------------------------------- | :-------------------------------------------------------------------------------- | :------------------------------------------------------------------------------------------------ |
| **Cancel a purchase order**                               | The purchase order is cancelled; no invoice can be attached to it any more        | Only possible while it is open with no invoice attached                                           |
| **Close a purchase order**                                | The purchase order is closed, and its amount is rewritten to what was billed      | The amount originally approved is no longer shown on it                                           |
| **Commit an accounting export** (`markEntriesAsExported`) | The payables and settlements in the export are marked as exported                 | Previews are the default: an export only commits when you ask for it explicitly                   |
| **Mark a payable as ready for export**                    | The payable becomes ready for export. This is a bookkeeping step, not an approval | No assistant tool moves it back; in Spendesk, send it back from **Bookkeep → Export**             |
| **Mark a payable as exported**                            | The payable moves to *exported*                                                   | For a payable you entered in your accounting outside Spendesk                                     |
| **Mark a settlement as exported**                         | The settlement's accounting entry is recorded as exported                         | The assistant does not check the current state: a settlement already exported can be marked again |
| **Delete an analytical field, or one of its values**      | Archived; the field's values stay active                                          | No tool restores them                                                                             |
| **Delete the expense category field**                     | Removes expense categories for the whole company                                  | A new field starts empty                                                                          |
| **Delete an expense category**                            | Archived, even if existing spend uses it                                          | No tool restores it                                                                               |

A purchase order also **cannot be deleted**: if one is created by mistake, the only clean-up is to cancel it while it is still open with no invoice attached.

# Every action, by permission

| Permission (sensitivity: high for all) | Actions                                                                                                 | Can the assistant undo it?                                                                             |
| :------------------------------------- | :------------------------------------------------------------------------------------------------------ | :----------------------------------------------------------------------------------------------------- |
| **Manage purchase orders**             | Create a purchase order                                                                                 | Only by cancelling it (see above); a repeated request creates a second one                             |
|                                        | Cancel, close a purchase order                                                                          | No                                                                                                     |
| **Manage payables**                    | Update a payable's accounting fields (account payable, accounting date, line items, amortisation dates) | Yes, by updating it again                                                                              |
|                                        | Mark a payable as ready for export                                                                      | No tool moves it back                                                                                  |
|                                        | Mark a payable as exported, mark a settlement as exported                                               | No                                                                                                     |
| **Manage suppliers**                   | Create suppliers                                                                                        | By archiving them, if they have no payment, request or subscription                                    |
|                                        | Update a supplier, including its bank details                                                           | Yes, by updating it again                                                                              |
|                                        | Archive or unarchive a supplier                                                                         | Yes: archiving only works for a supplier with no payment, request or subscription, and can be reversed |
| **Manage chart of accounts**           | Create or update accounts                                                                               | Yes, by updating them                                                                                  |
|                                        | Archive an account                                                                                      | Yes, by unarchiving it                                                                                 |
| **Manage accounting exports**          | Generate a journal export (preview by default)                                                          | A preview changes nothing; a commit cannot be undone                                                   |
|                                        | Download an export, list journal templates                                                              | Read only — they need this permission today                                                            |
| **Manage analytical fields**           | Create or update a field or a value                                                                     | Yes, by updating or deleting it                                                                        |
|                                        | Delete a field or a value                                                                               | No                                                                                                     |
| **Manage expense categories**          | Create or update the expense category field, or a category                                              | Yes, by updating or deleting it                                                                        |
|                                        | Delete the field or a category                                                                          | No                                                                                                     |

Every call the assistant makes is listed in the connection's **Action log** in Spendesk (date, tool, status, user, company), which Account Owners and Admins can open. It names the tool, not the values changed — see [Using the AI assistant safely](https://developer.spendesk.com/reference/mcp-using-the-assistant-safely). Changes made by the assistant are ordinary Spendesk changes: a cancelled purchase order shows as cancelled, an exported payable as exported, an archived supplier as archived — in Spendesk and through the API alike.

**Not in this list, not possible.** The assistant cannot approve or reject a request or an invoice, pay or schedule a payment, create or change cards, users or cost centers, or read budgets: see [What the assistant cannot do](https://developer.spendesk.com/reference/connect-an-ai-assistant-mcp#what-the-assistant-cannot-do).

# How the assistant confirms

The Spendesk server gives the assistant these rules:

* **Act only on request.** A write action is used only when you asked for that change — never as a side effect of a question.
* **Check, then ask.** Before an action, the assistant reads the current state (is the purchase order open? is the payable ready?) and tells you what it is about to change. For a cancellation or a closure, it names the purchase order, its supplier and its amount, and waits for your explicit go-ahead. Checking the data is not your approval.
* **Bank details verbatim.** When creating or updating a supplier, the assistant only sets bank details that you gave exactly and confirmed; it never infers or completes them.
* **One at a time.** After a broad instruction such as *"clean up unused suppliers"*, it confirms each supplier instead of archiving several unprompted.
* **No blind retries.** When a result is unclear, it reads the state again instead of repeating the action — creating a purchase order or a supplier twice would create two.
* **Say what happened.** After an export, it tells you whether it was a preview (nothing changed) or a commit (entries marked as exported).

Your assistant may add its own step: Claude, for example, asks the first time it uses each tool whether to allow it once, always, or not. For write actions, *allow once* keeps a human decision on each one.

# Choosing permissions

* **Start read-only.** Leave write permissions unticked until you have a use for them: reading is enough for analysis, month-end checks and invoice follow-up.
* **Tick only what the job needs.** Someone who manages purchase orders needs *Manage purchase orders*, not *Manage accounting exports*.
* **Company or organisation.** An organisation-level connection can act in every company where you are a Controller or Account Owner; a company-level connection only in that company. See *Several companies* in [Connect an AI assistant](https://developer.spendesk.com/reference/connect-an-ai-assistant-mcp).
* **Try it on the demo first.** Actions can be tried safely against a demo account, on the demo server URL given in [Connect an AI assistant](https://developer.spendesk.com/reference/connect-an-ai-assistant-mcp).

# Changing or removing permissions

* **You**: disconnect the assistant, connect again, and tick or untick permissions on the approval screen. Your connection only carries the permissions you left ticked — so after an Admin enables a new permission, refreshing the tool list in the assistant is not enough: reconnect and tick it.
* **Your Admin or Account Owner**: can change the permissions the connector may request, from its detail page in Spendesk (**Settings → Integrations → MCP**, or the **MCP** tab of the multi-entity hub; **Permissions** tab, with a second-factor check), or remove the connection (**Remove**), which cuts access for everyone using it.
* A connection that is not used for 30 days expires, and you have to sign in again.

See also the [MCP tool reference](https://developer.spendesk.com/reference/mcp-tool-reference) (every tool, with its permission), [Connect an AI assistant (MCP)](https://developer.spendesk.com/reference/connect-an-ai-assistant-mcp) and [Scopes](https://developer.spendesk.com/reference/scopes).