# MCP worksheets for an accounting firm

Three pages. Fill in one entry or one page per MCP. Keep them with your written information security plan.

From the guide _MCPs for Accounting Firms: What Permissions and Data You're Actually Granting_, at https://www.legix.ai/articles/mcps-for-accounting-firms. Version 2026-09.

An MCP is what Claude calls a connector and ChatGPT calls an app: the thing that lets your AI work inside another system.

---

## Page 1. The MCP register

One entry for every MCP anyone at the firm has connected, including the ones connected under a personal login. Copy the block below once per MCP.

The test of a finished entry: on the day this person leaves, could someone else, with the permissions the entry names, switch the MCP off in ten minutes using only what is written here?

**Entry number:** `______`

1. **The MCP, and what it reaches:** `____________________________________________`
2. **Who connected it, and under which login:** `____________________________________________`
3. **Which clients that login can open** (one company, a list, or every client of the firm): `____________________________________________`
4. **Read only, or can it change things?** If it can change things, say what: `____________________________________________`
5. **Where the login is kept:** `____________________________________________`
6. **How to switch it off, in your AI:** `____________________________________________`
7. **How to switch it off, in the system it reaches, and what permission that takes:** `____________________________________________`
8. **Approved by** (the person responsible for your security plan), **and date:** `____________________________________________`
9. **Last reviewed** (update each quarter, and after any vendor announcement): `____________________________________________`

**How to fill in line 5.** For an MCP added from your AI's own list (Claude's Connectors page, for example), write "with the firm's Claude account." For one that someone installed on a computer, write which computer and which folder, and whether the login sits in a plain text file.

**How to fill in lines 6 and 7.** There are always two places. One is in your AI: in Claude, Customize, then Connectors, then Disconnect. The other is in the system it reaches, under the same login: in QuickBooks Online, Integrations, then Manage integrations, then Action, then Disconnect; in Xero, the organisation name, then Settings, then Connected apps; in Gusto, App directory, then Connected apps, then the app, then About, then Disconnect. Write both. Disconnecting in only one can leave the other side's permission standing. Menu paths as at 19 September 2026.

**Two filled-in entries, for a made-up firm**

Entry 1

1. The MCP, and what it reaches: QuickBooks MCP from Claude's Connectors page. Reaches QuickBooks Online.
2. Who connected it, and under which login: M. Ortiz, under her own QuickBooks login.
3. Which clients: Alder Street Bakery only. One company is chosen at sign-in.
4. Read only, or can it change things: Can change. Imports transactions, creates and emails invoices. Deletes ask first.
5. Where the login is kept: With the firm's Claude Team account.
6. Switch it off in your AI: Claude, Customize, Connectors, QuickBooks, Disconnect.
7. Switch it off in the system: QuickBooks, Integrations, Manage integrations, Action, Disconnect, under M. Ortiz's login. Needs admin or the Third Party Apps permission.
8. Approved by, and date: D. Finch, 3 Sept 2026.
9. Last reviewed: 3 Sept 2026.

Entry 2

1. The MCP, and what it reaches: Payroll MCP from Claude's Connectors page. Reaches the payroll provider.
2. Who connected it, and under which login: D. Finch, under the firm's accountant login.
3. Which clients: Every payroll client of the firm.
4. Read only, or can it change things: Can change. Can prepare and run payroll. Every change asks first.
5. Where the login is kept: With the firm's Claude Team account.
6. Switch it off in your AI: Claude, Customize, Connectors, the payroll MCP, Disconnect.
7. Switch it off in the system: Payroll provider, Settings, connected applications. Needs an admin.
8. Approved by, and date: D. Finch, 10 Sept 2026.
9. Last reviewed: 10 Sept 2026.

**Add one line to your offboarding checklist:** "Check the MCP register for entries under this person's name. Disconnect each in both places."

---

## Page 2. Is connecting a disclosure?

One page per MCP. This is not legal advice. It is the list of facts your counsel will ask for, written down once so the conversation is short.

**The MCP:** `______________________`

**What it reaches:** `______________________`

1. **Does any client behind this login have a tax return prepared by the firm?** Yes / No

   If yes, some of what the MCP can read may be tax return information under section 7216.

2. **Which companies receive client data when this MCP is used?** One line per company: the company that runs the MCP, the company that makes your AI, and anyone else either one names in its terms as handling the data. For each, say whether it is located in the United States, where it says data is processed, what it keeps, and for how long.

   Company 1: `____________________________________________`

   Company 2: `____________________________________________`

   Company 3: `____________________________________________`

   What each one keeps comes from your AI provider's data terms: whether it trains on your conversations, how long it keeps them, and whether any reduced-retention arrangement covers MCPs.

3. **Can the MCP change the client's books, or only read them?** Read only / Can change

4. **What does your engagement letter currently say about AI?** Nothing / A general clause / A clause that covers a live connection to the client's books

5. **Has each client behind this login been told?** Yes / No / Some. Attach the client list if the login reaches more than one.

6. **Can a client say no, and what happens if one does?** `____________________________________________`

7. **Is each of these companies on the service provider list in your written information security plan?** Yes / No

**Reviewed with counsel on:** `____________`

**By:** `____________`

**Decision:** `____________________________________________`

---

## Page 3. Connect, or export?

Use this before connecting an MCP for a new purpose.

**The MCP:** `______________________`

**The purpose:** `______________________`

**Stop first.** If you could not establish who built this MCP and who runs it, whether its tool descriptions do what they say, where the data goes after it is fetched, and where the login is kept and how to switch it off, do not connect it. Those four are not factors to weigh.

**The rule of thumb.** Connect when the question will be asked again, the data changes between askings, and the answer needs more than one system. Export a file when it is a one-off, or when the period is closed and the numbers will not move.

Tick what is true.

**Reasons to connect**

- [ ] The question will be asked again next week or next month.
- [ ] The data changes between one asking and the next.
- [ ] Answering it properly needs more than one system.
- [ ] Someone currently exports, renames and uploads a file to do this.
- [ ] A written procedure (a skill) will run against it for many clients.

**Reasons to export a file instead**

- [ ] It is a one-off question.
- [ ] The period is closed and the numbers will not change.
- [ ] The only MCP available can change data, and this job only needs to read.
- [ ] The MCP's login would reach clients this job has nothing to do with.

**If you connect:** tick each of the four permissions you narrowed before anyone used it.

- [ ] Read: switched off tool groups this job does not need.
- [ ] Write: set to "needs approval," or blocked.
- [ ] Which clients: used the narrowest login that does the job.
- [ ] Who confirms: "always allow" is off, for everyone.

**Decision:** Connect / Export

**By:** `____________`

**Date:** `____________`

**Review again on:** `____________`
