booksguard · QuickBooks and Xero · updated
Stop AI from changing your books without asking
There are three ways, from bluntest to most useful. Remove the write tools: Intuit's QUICKBOOKS_DISABLE_WRITE, _UPDATE and _DELETE, or Xero's read-only connector. Make the agent ask before named tools: each client's own approval setting, such as Claude Code's permissions.ask rules, with no record. Or hold every write for your yes, with a diff and a per-client log: booksguard, free, for Claude Code, Cowork, Codex and Gemini CLI.
The three ways, side by side
| Remove write tools | Ask before named tools | booksguard | |
|---|---|---|---|
| The AI can still write after you look | No | Yes | Yes |
| Shows what would change, with totals | — | The raw arguments | A diff, totals, journal balance |
| Flags a duplicate of a posted write | — | No | Yes |
| Claude Code, Cowork, Codex, Gemini CLI | Per server | Each in its own settings | All four (approval by message in Claude Code and Cowork) |
| How a ledger tool is found | — | By the server and tool names you list | By server name, or by the tool name alone |
| A per-client record of who approved what | No | No | Yes, hash-chained, on your machine |
Set it up
$ npx --allow-git=root github:agentwares/booksguard installWrites the hook into Claude Code, Codex and Gemini CLI where they are installed (user level), and ~/.booksguard/rules.json. No account, no signup. uninstall removes only booksguard's entries. For Cowork, add the booksguard plugin instead.
agent mcp__quickbooks__create_invoice
hook deny: held until a person approves
+ customer_ref: "58"
+ doc_number: "1042"
+ line 1: 1,250.00 · item_ref "12" · qty 10 · unit_price 125
= total 1,250.00 across 2 lines
person types: yes, post it
agent mcp__quickbooks__create_invoice (same arguments)
hook released, approved by your message at 14:05 UTC (“yes, post it”)What it does not do
- It never calls QuickBooks or Xero, and sends nothing anywhere: the hook reads the call it is shown, the rulebook and the log on your machine.
- It cannot see inside a script the agent writes and then runs, unless the command line names the QuickBooks or Xero API host. A local hook is a seatbelt, not a vault.
- An update shows the fields it would set, not the values they replace: reading those would mean calling the ledger.
- The log records what was held, released and refused, and who approved each; the ledger's own answer to a released write is not recorded.
For a bookkeeping firm
The free log stays on one machine. One firm-wide record of every client's AI changes, with a monthly sign-off, is not built yet. It would keep every client's held and approved writes across your staff in one place, with a reviewer sign-off per client per month. I want that record