Your General Ledger Is Becoming Readable From Tools Your Access Controls Were Never Written For

A ledger shape sitting inside a drawn boundary, with three new doorways opening in the boundary wall from outside it

Your General Ledger Is Becoming Readable From Tools Your Access Controls Were Never Written For

Xero's announcements last week aren't really product news. They're a change to where the boundary around your financial data sits — and most access reviews are still drawn around the old one.

Ask most finance leaders who can see the general ledger and you'll get a confident answer. It comes from the user list in the accounting system: these eight people have access, three of them read-only, one left in June and was removed. That answer has been reliable for twenty years because the ledger only had one front door.

That is the thing which is changing, and it's worth separating the change from the marketing around it.

What was actually announced

At Xerocon US in Denver on 19 August, Xero set out the next stage of what it calls its orchestration hub. Two items matter more than the rest for anyone responsible for financial data.

The first is that the Microsoft 365 Copilot integration announced in July is expanding into Excel, Word, PowerPoint and Copilot Cowork, with live Xero data flowing directly into charts, tables and documents. The second is a Xero plugin for ChatGPT — described as available in coming weeks across Chat, Work and Codex — letting customers query their Xero data from inside ChatGPT. A Claude integration was announced alongside both. Xero also flagged that advisors will soon be able to switch between client organisations while working inside these integrations.

Both are described as coming soon rather than live today, so nobody needs to act this week. But the direction is settled, and it is not unique to Xero — the same pattern is arriving across the accounting platforms. Xero is simply the one with a dated announcement in front of us.

Underneath the announcements sits a number that tells you this has already started without waiting for the official integrations. Xero disclosed that usage of its MCP Server — the gateway that lets AI tools work with live Xero data — grew ten-fold between December 2025 and May 2026, powering more than one million API calls as of June. Separately, one in five connections into the Xero ecosystem is now a custom app built outside the App Store, with new app registrations up four-fold since 2025.

10×
Growth in Xero MCP Server usage between December 2025 and May 2026, passing one million API calls as of June — before any of the announced integrations went live.
1 in 5
Connections into the Xero ecosystem that are now custom apps built outside the App Store, with new app registrations up four-fold since 2025.

Why this isn't just another integration

Finance functions have been connecting things to the ledger for years — payroll, point of sale, expense tools, rostering systems. Those connections share a shape. Each one moves a defined set of records in a defined direction on a defined schedule, and if you want to know what it can see, you read its documentation once and the answer stays true.

A connection into a general-purpose assistant doesn't have that shape. It exposes a set of capabilities that something else decides when and how to use, in response to whatever a person types. Nobody wrote down in advance that a particular question would pull three years of transactions across four accounts; that path got assembled at the moment the question was asked.

The practical consequence is a shift in who the gatekeeper is. Historically, seeing the ledger required a login to the ledger. Increasingly, it requires access to a productivity tool that has been connected to the ledger by somebody else. Those are different populations, governed by different people, reviewed on different cycles — and in many organisations the second population is the larger of the two.

The question your access review stopped answering

Most finance functions run some form of periodic user access review. It typically involves exporting the user list from the finance system, confirming each person still needs their role, and removing leavers. It is a good control and it should continue.

It is also now answering a narrower question than the one it appears to answer. "Who has a Xero login" is not the same question as "who can obtain information from the ledger", and the gap between those two is exactly what the coming integrations widen.

The gap matters in a specific, unglamorous way. Payroll sits in the same platform as the ledger for most small and mid-sized organisations. So does anything you've coded to a project, a program, or a funder. A general-purpose assistant with read access doesn't distinguish between a routine debtors query and a question about what a particular person is paid — it distinguishes only on what the connection was scoped to reach. If the scope was set to "the organisation's accounting data" because that was the simplest option in the setup screen, then the scope is the whole thing. Narrower scoping is usually available — Xero's own connector work, for instance, is opt-in per permission with reports held read-only — but it has to be chosen, and the default rarely is.

None of that is an argument against connecting these tools. The productivity case is real and the sector will adopt them. It is an argument that the connection is an access decision, made once, that quietly outranks every subsequent access review you run against the old list.

Before financial data reaches any AI tool: ledger, payroll and participant or client data are among the most sensitive holdings a finance function has. Confirm in writing whether the vendor retains customer inputs for model training, and prefer a tool where it does not. This applies to the assistant at the far end of the connection as much as to the accounting platform itself — there are now two vendors in the chain, and both need answering for. A no-training term is also a floor rather than a discharge: the OAIC's position is that minimising what personal information reaches the tool, and de-identifying where the task allows it, remains the primary control.

Where the AI work actually pays here

There's an irony worth naming. The same technology creating the visibility question is genuinely good at answering it.

Working out what can currently reach your financial data is a mapping problem, not a judgement problem — enumerate the connected applications, the API tokens issued, the users of each connected platform, and the overlap between them. It is tedious, which is why it is usually done badly or not at all. It is also precisely the kind of structured enumeration where AI does the pass and a person reviews the output. The judgement — what should be reachable, by whom, and what is unacceptable — stays entirely human, because it depends on knowing what the data means to your organisation. The machine can tell you what the doors are. It cannot tell you which ones should be shut.

The exercise worth doing before anyone asks

You don't need a policy this week. You need one page, and it takes about an hour to produce.

List every route by which financial data can currently leave the accounting platform: direct logins, connected apps, API tokens issued to developers or advisors, reporting tools, and any AI connection already in place. Against each, note who controls it, what it can reach, and when it was last reviewed. Most organisations find at least one entry nobody can fully account for — usually a token issued to a former bookkeeper or a trial app that was never disconnected.

That page is the baseline. Once it exists, the request that lands on your desk in a month's time — "can we switch on the ChatGPT connector?" — stops being a yes or no question asked in a vacuum and becomes an amendment to something you can already see.

Can you list every route into your financial data?

If the answer comes from the user list alone, it's now answering the wrong question. PFL provides senior-level outsourced finance, management reporting, and AI automation for Australian NFP, NDIS, and SME organisations.

Talk to PFL →
Timothy, CPA is Managing Director of Professional Financelink (PFL), providing senior-level outsourced finance, management reporting, and AI automation for Australian NFP, NDIS, and SME organisations. 20+ years in finance leadership across NFP, NDIS and SME.

Comments

Popular posts from this blog

Google Gemma 4 Just Launched — And It Might Solve Finance's Biggest AI Privacy Problem

Claude vs Gemini for Australian Finance: An Honest Comparison After 12 Months of Using Both

Why NFP Boards Are Finally Talking About AI — And What the Finance Team Should Do Before They Ask