booksguard · QuickBooks and Xero · updated

Is the QuickBooks MCP server safe to let write?

As safe as your review of each write. Intuit's open-source QuickBooks Online MCP server has 71 tools that create, update or delete records across 29 entities, and runs each one as soon as it is called (its only switch removes the write tools altogether). Intuit's hosted connector in Claude has 27 tools that create, change, delete or send invoices, estimates, payment links, customers and employees, and Meridian's connector has 32, including delete_transaction and void_invoice (each read from its public source on 9 October 2026). booksguard holds every one of those writes until you approve it, whichever server makes it.

What each QuickBooks server can change

ServerWhere it runsTools that writeExamples
Intuit QuickBooks connector (Claude directory)ai-inc.quickbooks.intuit.com/v1/mcp27 of 74qbo_sales_create_invoice, qbo_sales_send_invoice, qbo_sales_delete_invoice, qbo_contact_create_customer, qbo_payroll_create_employee, quickbooks-transaction-import
Intuit's open-source QuickBooks Online MCP serveryour machine (stdio)71 of 142create_invoice, update_invoice, delete_invoice, create_journal_entry, create-bill, create_payment, create_bill_payment, create_deposit, create_transfer
Meridian Connector for QuickBooks (Pilot)qbo-connector.meridian.pilot.com/mcp32 of 63create_journal_entry, create_bill, delete_transaction, delete_entity, void_invoice, batch_entity_operations
Xero connector (Claude directory)mcp.xero.com/mcpnone (read-only at launch)—
Xero's open-source MCP serveryour machine (npx @xeroapi/xero-mcp-server)24 of 50create-invoice (bills are type ACCPAY), create-payment, create-manual-journal, create-bank-transaction, update-contact, approve-timesheet

What goes wrong without a review

The built-in switches, and why they are not enough for a bookkeeper

Intuit's open-source server can drop whole categories of tools with QUICKBOOKS_DISABLE_WRITE, QUICKBOOKS_DISABLE_UPDATE and QUICKBOOKS_DISABLE_DELETE. That makes it read-only, which is right when the AI should never write. When you want it to write after you look, the write tools must stay, and something has to hold each call. Claude Code's own permissions.ask rules can prompt for named tools, in Claude Code only, with no record kept of what was approved.

Hold every write instead

$ npx --allow-git=root github:agentwares/booksguard install

Writes the hook into Claude Code, Codex and Gemini CLI where they are installed (user level), and ~/.booksguard/rules.json. No account, no signup. uninstall removes only booksguard's entries. For Cowork, add the booksguard plugin instead.

agent   mcp__quickbooks__create_invoice
hook    deny: held until a person approves
          + customer_ref: "58"
          + doc_number: "1042"
          + line 1: 1,250.00 · item_ref "12" · qty 10 · unit_price 125
          = total 1,250.00 across 2 lines
person  types: yes, post it
agent   mcp__quickbooks__create_invoice (same arguments)
hook    released, approved by your message at 14:05 UTC (“yes, post it”)

Limits

For a bookkeeping firm

The free log stays on one machine. One firm-wide record of every client's AI changes, with a monthly sign-off, is not built yet. It would keep every client's held and approved writes across your staff in one place, with a reviewer sign-off per client per month. I want that record

Sources, each read on 9 October 2026