Caribooks decides what your assistant may do in each QuickBooks company, and some actions also need your yes. These checks run on Caribooks' side, whichever assistant you use and whatever it is asked.
Read-only or full access
Each company you connect starts Read-only: the assistant runs reports and searches and reads records, and changes nothing.
Full access lets it also create, update, delete, void and send records, and attach files. The account owner turns it on with the switch on the company's card under Settings → Companies. Team members see the access level but not the switch.
On a read-only company, any change is refused before it reaches QuickBooks, and the assistant gets this message to pass on:
This QuickBooks connection is read-only. The account owner can enable write access for this company in the Caribooks portal.
Turning full access on or off takes effect on the assistant's next request. See Connect QuickBooks.
Deletes and voids need your yes
Even with full access, the assistant cannot delete or void a record on its own. Caribooks refuses the first attempt and tells it:
This operation cannot be undone: it deletes or voids a QuickBooks record, or emails a document to a customer. Ask the user to explicitly confirm this specific action, then retry with confirm: true.
So the assistant asks you about that specific record, and goes ahead only after you say yes. Removing a file from your document box works the same way.
Emails wait in Approvals
An invoice, estimate, credit memo, receipt or purchase order is never emailed from the chat. When you ask the assistant to send one, Caribooks puts it in Approvals with the document number, the customer or vendor, the amount and the address it will go to. Nothing leaves until you click to send it there. If you refused the same email before, it is not queued again.
Sends need full access on the company, like any other change.
Creating an invoice does not email it
Caribooks never asks QuickBooks to email an invoice or estimate it creates. One QuickBooks setting can still do it: if your company sends imported invoices automatically (in QuickBooks, Settings → Account and settings → Sales → Invoice payments), QuickBooks emails the new invoice to the customer on its own. When that happens, Caribooks sees it in QuickBooks' answer and tells the assistant to let you know.
Updates start from the current record
QuickBooks keeps a version number on every record. To change one, the assistant first reads it, then sends the update with that version. If someone changed the record in QuickBooks in between, QuickBooks refuses the update, and the assistant reads it again before retrying. An update changes only the fields it sends.
Bookkeeping only, never money
Caribooks records accounting entries. A payment, bill payment or transfer recorded through it moves no money, and a request to process a card payment is refused. Government identifiers, birth dates and card-processing details are left out of what the assistant reads and cannot be written through Caribooks; manage those in QuickBooks.
Your assistant's own permission prompts
Your assistant app has its own layer on top of Caribooks. Claude, for example, asks before it uses a tool unless you set that tool group to always allow. When you add Caribooks to Claude, set Read-only tools to Always allow and leave Write/delete tools on Needs approval: Claude stops asking each time it reads, and every change still waits for your click. See Add Caribooks to your assistant.
If the app asked and you did not click, the assistant may report "No approval received". That message comes from the assistant app, not from Caribooks: nothing reached QuickBooks. Ask again and approve the prompt.
Company rules are data, not orders
Rules you save for a company ("Uber goes to Travel") tell the assistant and the loops how your books are kept. They never change a company's access level, skip a confirmation or override what you ask. A rule saved from the chat waits in Approvals until you approve it. See Rules.
Ask your assistant
- "Which of my companies are read-only?"
- "Void invoice 1042." (It asks you to confirm first.)
- "Email invoice 1043 to the customer." (It waits in Approvals for your click.)
