Skip to content

Accounting with AI

What an AI assistant can and cannot do in your books — with 30 things to ask

Last reviewed SUPPORTED

An AI assistant connected to KRONENWERK can read everything the person who connected it can read, can create anything that is still a draft, and — only if the company allows it, and only up to an amount the company sets — can issue an invoice, send it and record that it was paid. It can never cancel a document, approve or pay a supplier, post a journal entry, close a period or touch a setting. This page lists the boundary exactly, tool by tool, and then gives thirty things to say to an assistant that produce useful work on the first try.

The boundary in one table

CanCannot — at any level
Search and read customersChange a customer's master data
List and read issued invoices, drafts and their totalsCancel or correct an issued invoice
Draft invoices and quotes, with lines and taxIssue or send them — unless the company chose Act within a limit
Record a supplier's bill with its figures as printed and the file it came asApprove or pay a supplier bill
Create jobs (transactions), notes and links between records and jobsDelete a job or a record
File a document with a job, bill, customer or supplierRemove a document
Read receivables, payables, P&L, balance sheet, the attention listPost a journal entry, enter an opening balance, close or unlock a period
Record a customer's payment — with the acting level, up to the limitRecord a payment to a supplier
Create, rotate or revoke keys and connections; change the level or the limit; change any setting

The right column is not a list of features still to come. It is the list of acts that KRONENWERK reserves for a person signed in with their own name, because each of them either changes a legal document that already exists, moves money out, or changes what the books say about the past. The assistant's side of the table is everything that produces a draft, a record awaiting confirmation, or an answer.

The three levels, precisely

The company sets one level under Settings → AI agent (MCP), and it applies to every assistant and every key alike.

Read only
Twelve read tools. A draft request is answered with a sentence saying drafts are switched off. Nothing is written.
Propose (default)
The read tools plus seven draft tools: invoice draft, quote draft, transaction, note, supplier bill, filed document, link to a transaction. Nothing the assistant does at this level is a financial fact. A draft invoice has no number; a recorded bill is not approved and not due to anyone until a person confirms it.
Act within a limit
Adds issue_invoice, send_invoice and record_payment. Each act is checked against a gross amount in the company's base currency inside the act's own transaction: an invoice whose total exceeds the limit is rolled back whole — no number spent, no record, no e-mail. The limit is per act, not per day.

When an assistant asks for something outside its level, the server does not say "unknown tool", which a model would read as a naming problem and try again around. It returns a normal result marked as an error whose text states the rule, says that nothing was done, and names the setting a person would change. The assistant relays something true and stops.

What the assistant cannot even see

  • Other companies. A connection is bound to one company. Identifiers from another company come back as "not found", not as "forbidden", so the answer reveals nothing.
  • Screens the connecting person cannot open. Reads are scoped by the same permissions as the equivalent screen. A bookkeeper without access to the balance sheet connects an assistant without it.
  • Table names, file paths, stack traces. Internal failures are described in one fixed sentence. Nothing about the server's insides enters a model's context.
  • A rate table. KRONENWERK carries none. The assistant states the tax rate the company or the document gave it; it cannot look one up, because there is nothing to look up.

Thirty things to ask

Each of these maps onto one or two tools and works at the default level unless marked. Say them in your own words; the assistant decides which tool to call.

Knowing where you stand

  1. "What needs my attention today?" — the attention list: overdue in both directions, due soon, queues waiting on a person.
  2. "Who owes us money, aged by how late?"
  3. "What do we owe suppliers this month?"
  4. "How did last month go?" — profit and loss from the ledger, with a flag whether the period is closed.
  5. "What is on the balance sheet as of today?"
  6. "Is invoice 2026-0143 paid?"
  7. "List every invoice to Meyer still open."
  8. "Find the customer whose name contains 'Dubois'."
  9. "Show me job V2026-0142 with everything linked to it."
  10. "Which jobs are in production right now?"

Getting things recorded

  1. "Record this supplier bill" — attach the PDF. Figures are taken as printed, never recomputed.
  2. "File this receipt as an expense on the Dubois job."
  3. "Keep this waybill with job V2026-0142."
  4. "Attach the customer's purchase order to their customer record."
  5. "Add a note to the Meyer job: customer confirmed delivery for the 24th."
  6. "Create a job for the Lambert order, stage 'quoting', due end of October."
  7. "Link quote Q-2026-0031 to the Lambert job."
  8. "Move the Lambert job to 'approved'." — a note on the timeline; stages are set by a person in KRONENWERK.

Preparing what customers receive

  1. "Draft an invoice for the Meyer job: 500 units at 12.40, standard VAT, due in 30 days."
  2. "Draft the September retainer invoice for Meyer, Dubois and Lambert — same lines as August." — one draft per customer; you issue each.
  3. "Draft a quote for Lambert: two positions, delivery in six weeks, valid for 30 days."
  4. "Make the draft in US dollars; the customer pays in USD."
  5. "Put the customer's PO number on the draft as their reference."
  6. "What will draft 4711 total, and can it be issued as it stands?" — the draft as the books hold it, with the totals the issuing engine computes, or the reason it cannot be issued yet.

With the acting level, up to the limit

  1. "Issue draft 4711."
  2. "Send invoice 2026-0150 to the customer's address on record."
  3. "Record that Meyer paid invoice 2026-0143 in full today by bank transfer."

Asking for what it cannot do — and what happens

  1. "Cancel invoice 2026-0143." — refused with the rule; a person cancels it in KRONENWERK, which issues the credit note.
  2. "Pay the Fastlink bill." — refused; approving and paying suppliers is a person's act.
  3. "Close September." — refused; period close stays with a person.

How to work with it well

Give it the job number. An assistant that knows "on job V2026-0142" files documents, bills and notes where they belong, and the job page shows the whole story — see transactions. Attach the document rather than describing it: a supplier bill recorded from the PDF carries the PDF, and the figures on it are the figures the supplier printed. Ask for drafts in batches on invoicing day, then issue them in KRONENWERK in one sitting. Read the authorship record weekly; it lists every draft and act with the tool, the connection and the time.

How KRONENWERK handles this

SUPPORTED Twenty-two tools exist today — twelve read, seven draft, three act — offered per the credential's scopes and the company's level; the acting tools only under Act within a limit with a gross amount checked per act. Cancelling, correcting, paying suppliers, posting, closing and configuring have no tool by design. Every draft and act is written to the authorship record and to the audit trail under the connection. Technical detail: the MCP developer page and API security.

Frequently asked questions

Can the assistant delete something by mistake?

No. There is no delete tool of any kind. The worst an assistant can do at the default level is create a draft or a record awaiting confirmation that you then discard.

Can it change an invoice after issuing?

No — and neither can a person. An issued invoice is frozen; a correction is a credit note and a new invoice, and issuing the credit note is a person's act.

What if I set the limit too high?

Lower it. The limit is read at the moment of each act, so a change applies to the next request. Revoking the connection under Settings → Integrations ends its access entirely.

Does the assistant know my tax rates?

It knows what you tell it in the conversation and what stands on the documents it reads. It states a rate on a draft; the draft's validation checks that the structure is right for the seller's country and the customer's place — two named taxes for a Québec sale, one VAT rate for a German one. It does not look rates up.

Can it read my bank account?

No. There is no bank tool. Payments it records at the acting level are the ones you tell it about.

Is there a log?

Two. The authorship record under Settings → AI agent (MCP) lists every draft and act by tool, connection and time; the audit trail beneath the records names the connection instead of a person.

Sources

  1. KRONENWERK developer documentation — MCP server read on
  2. Model Context Protocol — Tools read on
  3. KRONENWERK developer documentation — API security read on

How KRONENWERK handles this

E-invoicing in the product Countries

Read next