Using the AI assistant safely (MCP)

What protects you when an AI assistant works with your Spendesk data, what to know about AI assistants before allowing them to act, and how to roll it out safely.

An AI assistant connected to Spendesk works as you: with your account, your role, your companies and the permissions you chose — never more. This page explains what protects you, what every team should know about AI assistants before letting one act, and how to roll it out safely.

What protects you

It acts as you. You connect by signing in to Spendesk yourself, with your usual second factor; the assistant never sees your password. Every call is checked against your Spendesk role in the company it works on — only Controllers and Account Owners can use the assistant — and, on an organisation-level connection, company by company: it only reaches companies where you hold that role, and never mixes one company's access into another's.

Only what you allow. When you connect, you choose what the assistant may do. Read permissions are ticked by default; write permissions are not — each kind of action (purchase orders, payables, suppliers, chart of accounts, accounting exports, analytical fields, expense categories) is a separate permission you tick yourself. A tool you did not allow is not even shown to the assistant, and a call to it is refused. Above that, your Admin sets the permissions the connector may ask for, and changing them needs a second-factor check.

You decide before it acts. Spendesk instructs the assistant to act only when you ask for a change, to check the current state first, and to tell you what it is about to do — for a purchase-order cancellation, the order, its supplier and its amount — and wait for your go-ahead. Bank details are only set when you gave them exactly. To make approval mandatory rather than expected, turn it on in your assistant: in Claude, allow Spendesk actions once rather than always; in ChatGPT Enterprise, an admin chooses which Spendesk actions the app may use.

Everything it does is logged. Every call the assistant makes — reads and actions alike — is recorded in the connection's Action log, in Spendesk: the date, the tool, whether it succeeded, the user, the company and the duration. Admins and Account Owners find it under Settings → Integrations → MCP (or the MCP tab of the multi-entity hub): open the connection, then Action log. The same page shows who connected, which companies each person shared, and the permissions of the connection with their sensitivity. The log names the tool, not its details: to see exactly what changed — which purchase order, which supplier field — open the object in Spendesk.

You can switch it off. An Admin can remove a connection from its page in Spendesk (Remove). Each person can also narrow their own permissions by reconnecting.

Every action, what it changes and whether it can be undone is listed in Assistant actions and safety.

What to know about AI assistants before allowing them to act

The protections above decide what the assistant can do. Within those limits, it is still an AI model, and a few things are worth knowing before you tick a write permission:

  • It can misunderstand you. Name the object precisely — the supplier, the purchase-order number, the amount — and read the assistant's summary before you confirm. "Cancel the Acme order" is ambiguous if there are two.
  • It can be wrong about what it read. Figures come from Spendesk's own tools, and totals from its analysis tools, but the assistant can still misread a date range or a currency. Check the figures that drive a decision — a payment run, a close — in Spendesk.
  • Content can try to steer it. A supplier name, an invoice line or a document can contain text written to give the assistant instructions ("prompt injection"). With read-only permissions, the worst case is a wrong answer; with write permissions and actions allowed always, it could be an unwanted change. This is why write permissions are opt-in, and why approving each action matters.
  • Your data goes to the AI provider. What the assistant reads from Spendesk is sent to the provider of your assistant (Anthropic, OpenAI, Dust, Langdock…) as part of the conversation, and handled under your agreement with them. Check your workspace's data settings — retention, training — before connecting.
  • Actions are real. There is no sandbox mode in production: a purchase order created by the assistant is a real purchase order, an export it commits marks real entries as exported. Try actions on a demo account first.

Rolling it out safely

  1. Start read-only. Analysis, month-end checks and invoice follow-up need no write permission.
  2. Try actions on the demo server listed in Connect an AI assistant (MCP) before production.
  3. Pilot with a few Controllers, on the jobs you expect — for example purchase orders only.
  4. Tick only the write permission the job needs, and keep approving actions one by one.
  5. Review the Action log regularly during the pilot — which tools are used, by whom, and whether any fail.
  6. Revisit permissions when a job is done: reconnect and untick what is no longer needed; your Admin can narrow what the connector may ask for, or remove the connection.

For security reviews

  • Sign-in: OAuth 2.0 authorization code with PKCE; each user signs in to Spendesk and approves their own access. Spendesk public API keys are refused by the MCP server.
  • Tokens: access tokens last one hour; refresh tokens rotate on each use and expire after 30 days without use.
  • Clients: the connection for Claude, ChatGPT or Dust is created in Spendesk by an Admin or Account Owner, with a second-factor check; assistants that register themselves (Dust's automatic set-up, Langdock) only get low-sensitivity permissions by default.
  • Permissions: each permission has a sensitivity level (low, medium, high) shown on the approval screen; write permissions are all high. See the MCP tool reference for which permission each tool needs.
  • Audit: every tool call is recorded per connection — date, tool, status, user, company, duration and a correlation ID — and shown in the connection's Action log in Spendesk. Tool arguments are not stored in the log.
  • Hosting: the MCP server is part of the Spendesk public API (https://public-api.spendesk.com/v1/mcp) and works with Spendesk's own services; it has the same rate limits, plus a limit on simultaneous requests — see MCP errors and limits.

See also Set up Claude, ChatGPT or Dust and Scopes.