One place to control what your firm's AI can reach

FreeAgent is available today. Connect it to Claude without handing OAuth credentials to the AI: Accounting MCP gives your firm one MCP URL, checks each person's grants on every call, and records metadata-only activity so access can be reviewed and revoked immediately.

Everything between your firm's AI and client data

Your platforms on one side, your team's agents on the other — and one place to decide exactly who can use what.

Access control

Decide exactly who can access what

If every staff member's AI gets the same all-or-nothing access to client systems…

…grant each connector per person or team — Sally gets FreeAgent read access, while the front-desk group can use ElevenLabs — and revoke either in one click.

Partners who own the workspace always have access. Everyone else needs an explicit grant, direct or through a group like Bookkeeping or Payroll. Grants are checked live on every single call, so revoking a trainee or removing a leaver locks their agent out on the very next call — no token cleanup, no forgotten copies.

  • Per-person and per-group grants for every connector
  • Checked live on every call — revocation is instant
  • Groups for teams: Bookkeeping, Payroll, Audit
  • Owner, editor, and viewer roles with invitations and 2FA

Available today

Start with FreeAgent, built for accounting work

If connecting FreeAgent to AI means sharing a login or OAuth token…

…authorize it once in your workspace. Accounting MCP keeps the credentials encrypted and injects them only for an allowed call.

FreeAgent ships with five read tools for bank activity, invoices, bills, and profit and loss. ElevenLabs adds outbound AI phone calls and transcripts, while Accounting MCP Diagnostics confirms the gateway connection. Add provider accounts where needed, verify them live, and keep every credential server-side.

  • Five FreeAgent read tools available today
  • ElevenLabs outbound calls and transcripts
  • Accounting MCP Diagnostics built in
  • Credentials encrypted at rest, never exposed to AI clients

Oversight

Answer “what did the AI touch?” in seconds

If you need to review how AI access has been used and have only scattered provider logs…

…the activity log records connector, tool, access tier, status, and duration for each MCP operation.

Every MCP tool, resource, and prompt operation lands in a metadata-only activity log — tool arguments and client data are never stored. Failed calls include a safe error category, so you can troubleshoot without capturing provider payloads.

  • Metadata-only logging — never payloads, never client records
  • Newest events in one workspace feed
  • Safe failure categories without provider responses
  • Workspace isolation enforced in the database itself

Built for AI clients

Claude connects itself — no rollout project

If putting AI in front of ten staff means ten bespoke setups…

…paste one URL into Claude. It discovers the gateway, staff sign in, and each person sees only the tools they're allowed.

The gateway speaks standard MCP with OAuth discovery: Claude Desktop and Claude.ai register themselves and ask which workspace to act on. Tool lists follow each person's grants automatically, while back-office automations authenticate with workspace API keys.

  • Standard MCP over HTTP with OAuth 2.0 discovery
  • One URL for the whole practice — tools follow grants
  • Workspace API keys for backend agents

And the fundamentals a firm expects

The unglamorous parts of putting AI near client data, done properly.

Roles, invitations & 2FA

Owner, editor, and viewer roles with email invitations, seat limits, and TOTP two-factor authentication.

Encrypted credentials

Provider credentials are encrypted at rest and only decrypted server-side at the moment of the call.

Client-data isolation

Every record is scoped to your workspace, and isolation is enforced by the database itself — not just the app.

Workspace API keys

Owner-issued, workspace-bound keys let back-office automations use every tool on enabled connectors, with every call logged.

Verified connections

Provider credentials are checked live before a connector is trusted for agent use.

Predictable data handling

Activity is metadata-only and pruned on a 90-day schedule. Tool payloads are never stored at all.

Put a gateway between your firm's AI and client data

Create your practice workspace, enable your first connector, grant your team access, and paste one URL into Claude. Free throughout the beta.