booksguard · QuickBooks and Xero · updated
Xero MCP: approve before the AI posts
Xero's own connector in Claude is read-only at launch, so it cannot change your books. The writes come from Xero's open-source MCP server (XeroAPI/xero-mcp-server, npm @xeroapi/xero-mcp-server), whose 24 write tools create and update invoices and bills, payments, manual journals, bank transactions, contacts, credit notes, quotes, items and payroll timesheets, and from scripts that call Xero's API (each read on 9 October 2026). booksguard holds every one of those writes until you approve it, and logs it per Xero organisation.
The 24 write tools of Xero's MCP server
- Invoices and bills:
create-invoice(a bill istype: ACCPAY, and booksguard names it a bill),update-invoice - Money:
create-payment,create-bank-transaction,update-bank-transaction,create-credit-note,update-credit-note - Journals:
create-manual-journal(booksguard checks that the signed lines sum to zero) - Contacts, items and quotes:
create-contact,update-contact,create-item,update-item,create-quote,update-quote - Tracking:
create-tracking-category,update-tracking-category,create-tracking-options,update-tracking-options - Payroll timesheets:
create-timesheet,add-timesheet-line,update-timesheet-line,approve-timesheet,revert-timesheet,delete-timesheet
Its 26 list- and get- tools pass untouched. A curl or HTTPie call to api.xero.com with PUT, POST or DELETE is held as well, with the xero-tenant-id it names.
Approve it where you work
| Where the agent runs | How you approve a held write |
|---|---|
| Claude Code | In your own next message (“yes, post it”), read from the session transcript; or in a terminal |
| Cowork | The same, through the booksguard plugin's hook (plugin hooks load in Cowork) |
| Codex | In a terminal: npx --allow-git=root github:agentwares/booksguard approve <id>. Trust the hook once in Codex's /hooks |
| Gemini CLI | In a terminal: npx --allow-git=root github:agentwares/booksguard approve <id> (written to Gemini CLI's hook docs) |
| Claude chat (web, desktop, mobile) | Not covered: chat ignores plugin hooks |
$ npx --allow-git=root github:agentwares/booksguard installWrites the hook into Claude Code, Codex and Gemini CLI where they are installed (user level), and ~/.booksguard/rules.json. No account, no signup. uninstall removes only booksguard's entries. For Cowork, add the booksguard plugin instead.
Limits
- It never calls QuickBooks or Xero, and sends nothing anywhere: the hook reads the call it is shown, the rulebook and the log on your machine.
- It cannot see inside a script the agent writes and then runs, unless the command line names the QuickBooks or Xero API host. A local hook is a seatbelt, not a vault.
- An update shows the fields it would set, not the values they replace: reading those would mean calling the ledger.
- The log records what was held, released and refused, and who approved each; the ledger's own answer to a released write is not recorded.
For a bookkeeping firm
The free log stays on one machine. One firm-wide record of every client's AI changes, with a monthly sign-off, is not built yet. It would keep every client's held and approved writes across your staff in one place, with a reviewer sign-off per client per month. I want that record