AI Agents & Security

Letting AI Agents Work Your Books Safely: Permissions, Review Pages and Audit

Per-user, per-feature and per-company permissions for AI agents, review-and-approve pages for bulk changes, and bulk data kept out of the chat. How ERP Sync keeps agents in bounds.

Jose R. Gonzalez, CPA

Jose R. Gonzalez, CPA

Updated · 2 min read

Short answer

ERP Sync controls AI agents at three levels: which companies a user can see (read or read-write), which features each user’s agent may use (off, read or read-write, per feature and per tool), and whether a connection exists at all. Bulk changes can be staged as a review page with control totals that a person approves and runs under their own login.

Letting AI Agents Work Your Books Safely: Permissions, Review Pages and Audit

Three layers of permission

  • Company access: each user is an owner or invited user per company, with read or read-write access. Write tools refuse companies where the user only has read.
  • Feature modes: for invited users, each of ERP Sync’s 16 feature areas (general ledger, QuickBooks direct, NetSuite, bank feeds, files, Google, Microsoft 365 and more) is off, read or read-write, with per-tool overrides.
  • Availability: a tool only appears when the connection or module behind it exists. Settings can restrict what’s available but never grant more.

Review before posting

For bulk work, the agent stages a review page with a summary, control totals and per-row exceptions. A person clicks Approve & Run under their own login; the agent never posts that batch itself.

Large reads land in server-side datasets that the agent queries with SQL, so thousands of rows don’t pass through the chat — cheaper, and less exposure.

Workbooks built by the agent recompute declared control totals and stamp PASS or MISMATCH on the sheet.

The ERP Sync tools behind it

These are the MCP tools an agent calls. Each one is switched on or off per user, and read-only versus read-write is set per feature.

ToolWhat it does
erp_workflow_stage / erp_workflow_resultStages a review-and-approve page and reads its outcome.
erp_dataset_querySandboxed SQL over server-side datasets.
erp_sheet_writeRenders a real .xlsx with verified control totals.

Limits and requirements

  • Owners bypass feature modes on their own companies; set invited users’ modes deliberately.

Frequently asked questions

Where does my data go when the agent reads it?

Reads return to the agent you connected. Bulk results stay in ERP Sync as datasets unless the agent asks for specific rows.

Can I turn off writes entirely?

Yes. Give users read access to companies, or set features to read-only; write tools then refuse.

See it on your own books

A 30-minute call is enough to know whether ERP Sync fits. Bring the task you're tired of doing by hand.