Using Claude with your accounting data means connecting Claude to the system that holds your invoices, expenses and ledger, so it answers from your real records instead of from whatever you paste into the chat. The connection runs over the Model Context Protocol (MCP): your accounting software publishes a set of tools, you add it to Claude as a custom connector, and you approve exactly what Claude may read or change. This guide covers how the connection works, prompts by job, what to allow and what to keep read-only, a permissions checklist, data-protection points, and the limits you should hold it to.
What is MCP, in plain language?
The Model Context Protocol is an open standard for connecting AI applications to external systems. Anthropic introduced it in November 2024 and later donated it to the Agentic AI Foundation under the Linux Foundation, so it is not tied to one vendor. The official documentation compares it to a USB-C port: one standard plug, many devices.
In practice there are three parts:
| Part | What it is | In an accounting setup |
|---|---|---|
| Client | The AI app you talk to | Claude on the web, Claude Desktop |
| Server | A service that exposes tools | Your accounting platform's MCP endpoint |
| Tools | Named actions with defined inputs | "list invoices", "P&L summary", "create expense" |
When you ask "who owes me money?", Claude does not guess. It calls a tool such as list invoices with a filter for unpaid ones, gets structured data back from your system, and writes the answer from that. The data stays in your accounting system; Claude fetches what a question needs, when it needs it.
How do custom connectors work in Claude?
Anthropic's help center says custom connectors (remote MCP servers) are available on the Free, Pro, Max, Team and Enterprise plans, with Free users limited to one custom connector. On Team and Enterprise plans, only Owners can add a custom connector for the organisation; each member then connects and enables it individually. Plan details change, so check the current help center article before you rely on this.
The setup is the same for most accounting tools:
- In your accounting software, find the Claude or MCP integration page and copy the server URL it gives you.
- In Claude, open Connectors (under Settings or Customize, depending on the app version) and choose Add custom connector.
- Paste the URL. Claude opens a browser window where you sign in to the accounting system and approve permissions (OAuth).
- Back in Claude, enable the connector in the conversation and check which tools are switched on.
Anthropic's own warning is worth repeating: custom connectors connect Claude to services Anthropic has not verified, and a malicious MCP server can include hidden instructions that try to make Claude take unintended actions. Only add servers from vendors you already trust with your books, and only use the URL shown inside that vendor's app.
What should you ask it? Prompts by job
The best prompts name a period, a currency and an output format. Vague questions get vague answers.
Receivables
- "List every unpaid invoice older than 30 days, grouped by customer, with the total in AED. Sort by amount owed."
- "Which customers paid late more than twice this year? Show the invoice numbers and how many days late each was."
- "Draft a polite payment reminder for the three largest overdue invoices. Do not send anything."
For the follow-up process itself, see how to chase late payments in Dubai and the sibling guide on payment terms in the UAE and Saudi Arabia.
Month-end P&L
- "Give me the P&L for August 2026 from the ledger, compared with July. Flag any expense category that moved more than 20%."
- "Which projects made the lowest margin last quarter? Show revenue, direct costs and margin for each."
VAT prep
- "Show output VAT and input VAT for Q3 2026, and list any expenses with no VAT amount recorded."
- "List sales invoices in Q3 where the customer has no tax registration number on file."
Here is what a useful answer looks like, with numbers that add up. A UAE business with net sales of AED 184,000 in the quarter has output VAT of AED 9,200 (5%). Net purchases with recoverable VAT of AED 62,400 carry input VAT of AED 3,120. The net VAT payable is AED 9,200 − AED 3,120 = AED 6,080. Claude can pull and lay out those figures; whether every input VAT line is recoverable is a judgment for you or your accountant.
Deadline: UAE VAT returns and payment are due by the 28th day of the month after the tax period ends. Claude does not file anything; the return is submitted by you or your tax agent on EmaraTax.
Pipeline
- "What is the value of open deals by stage, and which deals have had no activity in 30 days?"
Expenses
- "Top 10 vendors by spend this year, in AED, with the change from last year."
- "List expenses over AED 2,000 in August with no receipt or no category."
- "Record a AED 420 expense for printer ink from Jarir, dated today, category Office supplies. Show me the draft first."
What should you let Claude do, and what should stay read-only?
Reading is low risk. Writing is where mistakes become records, and sending is where they reach customers. A sensible split:
| Action | Recommendation | Why |
|---|---|---|
| Reports, summaries, lists | Allow | Nothing changes; worst case is a wrong answer you can check |
| Drafting invoices, quotes, expenses | Allow, with review | Easy to fix before anything is final |
| Updating deals or projects | Allow for the owner or sales lead | Low financial impact, but visible to the team |
| Recording payments | Allow only for whoever reconciles the bank | A wrong payment marks an invoice paid and changes receivables |
| Deleting records | Keep off, or approve each call | Hard to spot afterwards |
| Sending invoices, quotes, credit notes by email | Keep off, or approve each call | Once a customer has it, it is out |
| Payroll and salary data | Separate permission, owner only | Personal data of employees |
Claude lets you control tool permissions per connector, including requiring approval before a tool runs. For anything that writes or sends, require approval every time. Anthropic's help center also recommends disabling write tools when you use Research with connectors, because a long research run makes many tool calls you do not watch one by one.
A permissions and safety checklist
Run through this when you connect, and again every quarter.
- Least privilege. Approve only the scopes you need. If you want reports, do not grant write access "in case".
- Separate write scopes. Treat read, write, send and sensitive data (salaries) as separate decisions. A tool that only reads cannot create an invoice by mistake.
- Review before anything leaves. Ask for drafts, read the draft in your accounting app, then send. Check the customer, currency, VAT line and total.
- Check the figures. For anything you will act on, open the underlying report once and confirm the total matches.
- Watch the audit trail. Use your accounting system's usage or activity log to see what the connector read and changed.
- Revoke when roles change. When someone leaves or a trial ends, revoke the connection in the accounting system, not only in Claude.
- Mind your Claude data settings. On Free, Pro and Max plans, Anthropic's consumer terms let chats be used for model training unless you opt out in Privacy Settings. Team and Enterprise are covered by commercial terms and are not used for training. Choose accordingly for financial conversations.
From the platform: Staks connects to Claude Desktop and claude.ai as a custom connector. You copy the server URL from Staks → Integrations → Claude, add it in Claude, and approve scoped read and write permissions in a browser; salary and other sensitive data is a separate scope. Read tools cover invoices, quotes, credit notes, expenses, bills, vendors, companies, people, deals, products, projects, payroll, assets, liabilities and taxes, plus revenue, expense, P&L (from the ledger), tax, payroll, pipeline and finance summaries and reports including subscriptions. Write tools can create invoices, quotes, credit notes, expenses, deals, vendors and projects; update expenses, deals and projects; delete expenses; record payments; and send invoices, quotes and credit notes by email. You can revoke access in Staks → Integrations → Configurations, and a usage audit log shows what was called. It is a Scale plan feature. ChatGPT and Cursor are not supported yet. Setup details are on the Staks Claude integration page.
What about data protection in the UAE and Saudi Arabia?
This section is general information, not legal advice. Connecting Claude to your books means personal data (customer contacts, employee names, salaries) can pass to a service outside your accounting system, so both countries' data-protection laws are relevant.
| UAE | Saudi Arabia | |
|---|---|---|
| Law | Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (PDPL) | Personal Data Protection Law, Royal Decree No. M/19 (1443H), amended by Royal Decree No. M/148 (1444H) |
| Status | In force since January 2022; the executive regulations were reported as still unpublished by law firms tracking it | Fully enforceable since 14 September 2024 after a one-year grace period |
| Regulator | UAE Data Office | Saudi Data and Artificial Intelligence Authority (SDAIA) |
| Carve-outs to note | DIFC and ADGM have their own data-protection regimes; banking and health data have sector rules | Applies to processing of data of individuals in the Kingdom, including by entities abroad |
| Cross-border transfers | The law sets transfer requirements; detail depends on the pending regulations | SDAIA's transfer regulation allows transfers with adequate protection or safeguards, and SDAIA has issued standard contractual clauses |
What this means in practice for a small business:
- Keep payroll out unless you need it. Salary data is the most sensitive thing in your books. Do not grant that scope for general finance questions.
- Ask for aggregates. "Total payroll cost by month" does the job without pulling individual salaries into a chat.
- Know where the data goes. Claude is operated by Anthropic outside the Gulf, so queries that return personal data are a cross-border flow. If you are in DIFC or ADGM, check your free zone's rules; if you process data of people in Saudi Arabia, check SDAIA's transfer rules.
- Update your privacy notice if you now use an AI assistant to process customer or employee data, and ask your adviser whether a transfer mechanism is needed.
What are the limits?
Be clear about what you are getting.
It is not a tax adviser. Claude can list VAT figures from your records. It cannot tell you with authority whether an expense is recoverable, whether you should register, or how a zero-rated export should be treated. Those are questions for a registered tax agent or accountant.
It can be wrong. The underlying data comes from your system, but Claude still chooses which tool to call, which filters to apply, and how to summarise. It can pick the wrong date range, miss a currency, or add up a list incorrectly in its own text. Treat its answers as a fast first draft of analysis, and check any number you will act on against the report in your accounting app.
It does not file. No return goes to the FTA or ZATCA through Claude. It also does not make an invoice compliant with Saudi e-invoicing or the UAE's 2027 mandate; that depends on the invoicing system, not the assistant. See the UAE e-invoicing July 2027 checklist.
Writes are only as safe as your permissions. A write tool does what it is asked. Keep approvals on.
Is there an option without setting up Claude?
Yes. If you do not use Claude, or you are not on a plan that includes the connector, the Staks Agent is built into the app on every plan. It answers questions from your books, drafts invoices and expenses, extracts receipts and imports spreadsheets, and every action shows as a confirmation card before anything is saved. It uses the AI credits included in your plan. For a broader view of what AI can and cannot do in bookkeeping, read Can AI do your bookkeeping?.
Frequently asked questions
Do I need a paid Claude plan to connect my accounting software?
According to Anthropic's help center, custom connectors work on Free, Pro, Max, Team and Enterprise, with Free limited to one custom connector. On Team and Enterprise, an Owner has to add the connector first. Your accounting software may also restrict the integration to certain plans; in Staks it is a Scale plan feature.
Can Claude see all my data once connected?
It can call the tools you approved, within the scopes you granted, and only when a question needs them. It does not copy your whole ledger up front. If you granted read access to payroll, though, it can read payroll when asked, so grant that scope only if you need it.
Can Claude send invoices to my customers?
If the connector has a send tool and you granted the write permission, yes. We recommend keeping send tools on "always ask", reviewing the draft in your accounting app first, and checking the customer, currency, VAT and total before approving.
How do I disconnect it?
Revoke access in your accounting system (in Staks: Integrations → Configurations) and remove the connector in Claude. Revoking on the accounting side is the one that actually cuts access.
Can Claude prepare my VAT return?
It can pull the figures you need to prepare one, such as output VAT, input VAT and invoices missing tax numbers. It cannot decide treatments or submit the return. Your accountant or tax agent should review the figures before filing.
Related reading
- Can AI do your bookkeeping? What an AI accountant can and can't do
- How to chase late payments in Dubai
- UAE tax invoice requirements
- How to track business expenses in the GCC
Connecting Claude takes a few minutes once your books are in one place. Start a 14-day free trial of Staks, set up your invoices and expenses, and connect Claude when you are ready.