What Invio's Xero connector can see, and what it can never touch

Handing an AI assistant access to your general ledger is not a small decision.

If you run the books for a group, it is the kind of thing you have to be able to explain to a partner, an auditor or a board - so this page is the plain-English version: exactly what Xero asks you to approve, what happens when your assistant tries to change something, and what Invio keeps.

Reads are live. Writes wait for you.

Your assistant drafts

It reads your live Xero data directly. When it wants to create or change an invoice, a contact, a credit note or a journal, that becomes a draft - not a change to your books.

Invio holds it

The draft sits in your approval queue, showing the exact organisation and the exact payload Invio would send. Left untouched, it expires after 24 hours and nothing happens.

You approve

Approve or reject it - in Invio, or by telling your assistant to go ahead. Nothing reaches Xero until you do, and every approval records who made it.

Approving in Settings is a click from your own signed-in session. Telling your assistant to go ahead relies on it correctly relaying what you actually said - the tool it calls only fires on an explicit yes, and it is built to ask first rather than infer consent. Either way, the same queue in Settings shows you exactly what happened, so you can always check it there too.

Who on your team can approve

Roles exist because the person who asks and the person who may commit it are rarely the same person in a group.

Owner
Connects organisations, invites the team, approves anything. Always the account holder.
Approver
Approves or rejects drafts.
Viewer
Sees the same queue, can't act on it.

Owner is always the account holder. Approver and Viewer roles are available on Pro and Growth.

On Growth you can also restrict a team member to specific organisations - so someone who works on three entities cannot see the rest of your account - and see a named audit trail of who approved each change, not just that someone did.

What Invio stores

Your Xero refresh token, encrypted, so you are not asked to sign in again every session. The list of organisations you have authorised. Call metadata for your audit trail - which tool ran, when, and against which organisation.

A drafted change - the exact amounts and contact details your assistant proposed - for as long as it is waiting on you: until you approve or reject it, or for up to 24 hours if you do neither.

Once a drafted change is resolved, or that window passes, its financial detail is cleared from our records within 90 days, whether or not it was ever approved. We do not keep a copy of your ledger: reports and balances are read from Xero when a question is asked, answered, and not stored afterwards.

See the Subprocessors page for the governing wording on Xero as a subprocessor, including how long any of this is kept.

How to disconnect

Revoke one connector
Settings, MCP, Xero, Active connectors, Revoke. That one AI client loses access on its very next call. Every other connector, and your underlying Xero connection, are untouched.
Disconnect Xero entirely
Every connector loses access to every organisation, anything still waiting in your approval queue is cancelled, and Invio asks Xero to revoke the token on its side too.

Neither touches your Invio invoicing data, and neither changes anything inside Xero beyond what you asked it to do.

Questions we get asked

Can the assistant read data without asking me?
Yes, within the organisations and permissions you have authorised. Reads are the point of the product. Writes are what the approval queue exists for.
Can I limit what it reaches?
Yes, three ways: choose which organisations to authorise, leave the payments and payroll permissions off, and on Growth restrict a team member to named organisations.
What if I revoke access while my assistant is mid-conversation?
It loses access on its very next call. Revoke any connector from Settings > AI connections at any time - there is no separate confirmation step or delay, and it does not touch your underlying Xero connection or any other connector URL you've generated.
Who is responsible for what gets posted?
You are. Invio shows you every change before it happens and records who approved it, but the approval is a human decision and the entries are yours. Review what your assistant drafts the way you would review anyone else's work before it goes in your books.
Is my financial data used to train AI models?
Not by us, and not by Xero's terms, which prohibit it. What the assistant's own provider does with your query is governed by your agreement with them, not with us - check their current terms before you rely on that.

Check your next step

New to this category, or comparing it against Xero's own options? Read what an MCP connector actually is, or go straight to setup.

Invio is an independent connector built on Xero's official API. Invio is not affiliated with, endorsed by, or certified by Xero. Xero is a trademark of Xero Limited. Claude, ChatGPT and Microsoft Copilot are trademarks of their respective owners, and we are not affiliated with, endorsed by, or certified by any of them. You remain responsible for reviewing and approving any changes made to your Xero organisations.

Xero connector security: what it can see, what it can't touch | Invio