Business situation
A firm uses Xero for its own books or its clients’ books. Staff use Claude and want to ask it questions about that data — which invoices are overdue, what a client’s position is — without exporting spreadsheets into chats.
Why existing tools alone are insufficient
Connecting Claude directly to Xero means deciding, once, what Claude may do for everyone who uses it. There is no per-person permission, no approval step and no single audit trail across the firm’s AI tools.
Systems involved
- Xero, connected to Kroy by the firm.
- Claude, connected to Kroy.
Kroy architecture
Xero is connected to Kroy once. Kroy holds the Xero connection. Claude reaches Xero only through Kroy, which decides each request against the person, the agent and the firm’s policy.
Workflow
- A user asks Claude: “Which invoices for ABC Limited are more than 30 days overdue?”
- Claude requests the data through Kroy.
- Kroy checks the user’s access to ABC Limited, the agent’s delegation and policy.
- Kroy calls Xero and returns the permitted invoices.
- The user asks Claude to prepare a draft invoice. Kroy permits a draft; approving it stays with a person.
Agent permissions
Claude has the user’s delegated access, never more. Actions that move money or change financial records require approval.
Human permissions
Users see only the Xero organisations and resources their Kroy role allows.
State changes
- Draft invoices are created in Xero and linked to the client entity in Kroy.
Audit outcome
Every Xero request made by Claude through Kroy is recorded with the user, the agent and the decision.
Security considerations
- Claude never receives Xero credentials.
- Payroll is excluded by default.
- Revoking Claude’s connection to Kroy removes its access to Xero immediately.
Setup requirements
- A Kroy organisation with Xero connected.
- Claude connected to Kroy.
- Roles mapping users to the Xero organisations they may see.