---
updatedAt: 2026-10-01T08:19:56.000Z
agentTools:
  projectIndex: https://developer.spendesk.com/llms.txt
---

# Using the AI assistant safely (MCP)

What protects you when an AI assistant works with your Spendesk data, what to know about AI assistants before allowing them to act, and how to roll it out safely.

An AI assistant connected to Spendesk works **as you**: with your account, your role, your companies and the permissions you chose — never more. This page explains what protects you, what every team should know about AI assistants before letting one act, and how to roll it out safely.

# What protects you

**It acts as you.** You connect by signing in to Spendesk yourself, with your usual second factor; the assistant never sees your password. Every call is checked against your Spendesk role in the company it works on — only Controllers and Account Owners can use the assistant — and, on an organisation-level connection, company by company: it only reaches companies where you hold that role, and never mixes one company's access into another's. Each action applies to one company at a time.

**Only what you allow.** When you connect, you choose what the assistant may do. Read permissions are ticked by default; **write permissions are not** — each kind of action (purchase orders, payables, suppliers, chart of accounts, accounting exports, analytical fields, expense categories) is a separate permission you tick yourself. A tool you did not allow is not even shown to the assistant, and a call to it is refused. Above that, an Admin or Account Owner sets the permissions the connector may ask for, and changing them needs a second-factor check. Write actions are in **Beta**: their permissions are off by default on every connection until an Admin or Account Owner turns them on.

**You decide before it acts.** Spendesk instructs the assistant to act only when you ask for a change, to check the current state first, and to tell you what it is about to do — for a purchase-order cancellation, the order, its supplier and its amount — and wait for your go-ahead. Bank details are only set when you gave them exactly. To make approval mandatory rather than expected, turn it on in your assistant: in Claude, allow Spendesk actions **once** rather than always; in ChatGPT Enterprise, an admin chooses which Spendesk actions the app may use.

**Everything it does is logged.** Every call the assistant makes — reads and actions alike — is recorded in the connection's **Action log**, in Spendesk: the date, the tool, whether it succeeded, the user, the company and the duration. Admins and Account Owners find it under **Settings → Integrations → MCP** (or the **MCP** tab of the multi-entity hub): open the connection, then **Action log**. The same page shows who connected, which companies each person shared, and the permissions of the connection with their sensitivity. The log names the tool, not its details: to see exactly what changed — which purchase order, which supplier field — open the object in Spendesk.

**You can switch it off.** An Admin or Account Owner can remove a connection from its page in Spendesk (**Remove**): this cuts access for everyone using it. Each person can also narrow their own permissions by reconnecting.

**If a client secret is exposed.** Remove the connection and create a new one — a secret is shown once and cannot be regenerated. Send the new details through a secure channel; users then connect again.

Every action, what it changes and whether it can be undone is listed in [Assistant actions and safety](https://developer.spendesk.com/reference/mcp-actions-and-safety).

# What to know about AI assistants before allowing them to act

The protections above decide **what** the assistant can do. Within those limits, it is still an AI model, and a few things are worth knowing before you tick a write permission:

* **It can misunderstand you.** Name the object precisely — the supplier, the purchase-order number, the amount — and read the assistant's summary before you confirm. "Cancel the Acme order" is ambiguous if there are two.
* **It can be wrong about what it read.** Figures come from Spendesk's own tools, and totals from its analysis tools, but the assistant can still misread a date range or a currency. Check the figures that drive a decision — a payment run, a close — in Spendesk.
* **Content can try to steer it.** A supplier name, an invoice line or a document can contain text written to give the assistant instructions ("prompt injection"). With read-only permissions, the worst case is a wrong answer; with write permissions and actions allowed *always*, it could be an unwanted change. This is why write permissions are opt-in, and why approving each action matters.
* **Your data goes to the AI provider.** What the assistant reads from Spendesk is sent to the provider of your assistant (Anthropic, OpenAI, Dust, Langdock…) as part of the conversation, and handled under your agreement with them. Check your workspace's data settings — retention, training — before connecting.
* **A batch can partly succeed.** Creating several suppliers or updating several accounts in one request can work for some items and fail for others. Read the result item by item before asking again.
* **Actions are real.** There is no sandbox mode in production: a purchase order created by the assistant is a real purchase order, an export it commits marks real entries as exported. Try actions on a demo account first.

# Rolling it out safely

1. **Start read-only.** Analysis, month-end checks and invoice follow-up need no write permission.
2. **Try actions on the demo** server listed in [Connect an AI assistant (MCP)](https://developer.spendesk.com/reference/connect-an-ai-assistant-mcp) before production.
3. **Pilot with a few Controllers**, on the jobs you expect — for example purchase orders only.
4. **Enable and tick only the write permission the job needs.** An Admin or Account Owner turns it on for the connection; each user then disconnects, connects again and ticks it (refreshing the tool list is not enough). Keep approving actions one by one.
5. **Review the Action log** regularly during the pilot — which tools are used, by whom, and whether any fail.
6. **Revisit permissions** when a job is done: reconnect and untick what is no longer needed; an Admin or Account Owner can narrow what the connector may ask for, or remove the connection.

# For security reviews

* **Sign-in**: OAuth 2.0 authorization code with PKCE; each user signs in to Spendesk and approves their own access. Spendesk public API keys are refused by the MCP server.
* **Tokens**: access tokens last one hour; refresh tokens rotate on each use and expire after 30 days without use.
* **Clients**: the connection for Claude, ChatGPT or Dust is created in Spendesk by an Admin or Account Owner, with a second-factor check; assistants that register themselves (Dust's automatic set-up, Langdock) get the same default permissions, and an Admin or Account Owner manages them the same way, from the connection's **Permissions** tab. The client secret is shown once and cannot be regenerated: if it is exposed, remove the connection and create a new one.
* **Permissions**: each permission has a sensitivity level (low, medium, high) shown on the approval screen; write permissions are all *high*. See the [MCP tool reference](https://developer.spendesk.com/reference/mcp-tool-reference) for which permission each tool needs.
* **Audit**: every tool call is recorded per connection — date, tool, status, user, company, duration and a correlation ID — and shown in the connection's **Action log** in Spendesk. Tool arguments are not stored in the log.
* **Hosting**: the MCP server is part of the Spendesk public API (`https://public-api.spendesk.com/v1/mcp`) and works with Spendesk's own services; it has the same [rate limits](https://developer.spendesk.com/reference/rate-limiting), plus a limit on simultaneous requests — see [MCP errors and limits](https://developer.spendesk.com/reference/mcp-errors-and-limits).

See also [Set up Claude, ChatGPT or Dust](https://developer.spendesk.com/reference/mcp-set-up-claude-chatgpt-dust) and [Scopes](https://developer.spendesk.com/reference/scopes).