The workflow

Watch this workflow run through Kroy.

  1. The request.

    “Which invoices for ABC Limited are more than 30 days overdue?”

  2. Who is asking.

    Kroy identifies the person in finance and Claude acting for them, within the delegation they gave it.

  3. Only what the task needs.

    Kroy retrieves contacts, invoices and bills for permitted organisations and reports the user is permitted to view from Xero.

  4. Excluded by design.

    Payroll, Organisations outside the user’s permissions and Xero credentials never reach Claude. That boundary is Kroy’s, not an instruction to the AI.

  5. The proposed action.

    Permitted: read permitted Xero resources and create draft invoices, where policy allows.

  6. What Kroy refuses.

    Refused: approve or send invoices without a person and change bank details.

  7. A person decides.

    Approving an invoice.

  8. State changes. Everything is recorded.

    The work is updated in Kroy, and every request — allowed or refused — is written to the audit trail.

Claude
Finance
Kroy
Xero
Read permitted Xero resourc…
Approve or send invoices…
! Approval
AUDIT · STATE

Retrieved

  • Contacts, invoices and bills for permit…
  • Reports the user is permitted to view

Excluded

  • Payroll
  • Organisations outside the user’s permis…
  • Xero credentials
Claude
Finance
Kroy
Xero
Read permitted Xero resourc…
Approve or send invoices…
! Approval
AUDIT · STATE

Retrieved

  • Contacts, invoices and bills for permit…
  • Reports the user is permitted to view

Excluded

  • Payroll
  • Organisations outside the user’s permis…
  • Xero credentials
Claude + Xero through Kroy: the workflow through Kroy. The request.. Who is asking.. Only what the task needs.. Excluded by design.. The proposed action.. What Kroy refuses.. A person decides.. State changes. Everything is recorded..

What the AI can and cannot do

Data accessed

  • Contacts, invoices and bills for permitted organisations
  • Reports the user is permitted to view

Data excluded

  • Payroll
  • Organisations outside the user’s permissions
  • Xero credentials

Actions permitted

  • Read permitted Xero resources
  • Create draft invoices, where policy allows

Actions refused

  • Approve or send invoices without a person
  • Change bank details

Human approval required

  • Approving an invoice

Business situation

A firm uses Xero for its own books or its clients’ books. Staff use Claude and want to ask it questions about that data — which invoices are overdue, what a client’s position is — without exporting spreadsheets into chats.

Why existing tools alone are insufficient

Connecting Claude directly to Xero means deciding, once, what Claude may do for everyone who uses it. There is no per-person permission, no approval step and no single audit trail across the firm’s AI tools.

Systems involved

  • Xero, connected to Kroy by the firm.
  • Claude, connected to Kroy.

Kroy architecture

Xero is connected to Kroy once. Kroy holds the Xero connection. Claude reaches Xero only through Kroy, which decides each request against the person, the agent and the firm’s policy.

Workflow

  1. A user asks Claude: “Which invoices for ABC Limited are more than 30 days overdue?”
  2. Claude requests the data through Kroy.
  3. Kroy checks the user’s access to ABC Limited, the agent’s delegation and policy.
  4. Kroy calls Xero and returns the permitted invoices.
  5. The user asks Claude to prepare a draft invoice. Kroy permits a draft; approving it stays with a person.

Agent permissions

Claude has the user’s delegated access, never more. Actions that move money or change financial records require approval.

Human permissions

Users see only the Xero organisations and resources their Kroy role allows.

State changes

  • Draft invoices are created in Xero and linked to the client entity in Kroy.

Audit outcome

Every Xero request made by Claude through Kroy is recorded with the user, the agent and the decision.

Security considerations

  • Claude never receives Xero credentials.
  • Payroll is excluded by default.
  • Revoking Claude’s connection to Kroy removes its access to Xero immediately.

Setup requirements

  • A Kroy organisation with Xero connected.
  • Claude connected to Kroy.
  • Roles mapping users to the Xero organisations they may see.

Try this with your own systems.

Try Kroy with Xero