What the connector does, in Intuit's words
A connector is a link between one piece of software and another that lets the first act on your behalf inside the second. When you add QuickBooks inside ChatGPT or Claude, you sign in to Intuit once, approve the link, and from then on the chatbot can call QuickBooks whenever a question needs it.
Intuit's news release of 28 July 2026 lists what the link can do. On the reading side: profit and loss, cash flow, and benchmarks against similar businesses. On the writing side: create, update, send and delete invoices, set up recurring invoices, build estimates, generate payment links, add customers and items, look up payroll, and import transactions into the general ledger. The release also says that customer data is never used to train foundation models, and that destructive actions require user confirmation.
Read that list twice. Most of it is not reading. A tool that was built to answer "how did July go" was shipped with the ability to change what July says.
Where it genuinely helps
For an owner with one QuickBooks file and a quick question, this is a real improvement. Type "how does my gross margin this year compare with last year" into Claude and you get an answer in plain language in a few seconds, without exporting anything or waiting for the bookkeeper. Ask it to draft an invoice for a job you just finished and it will. The customer and items come filled in. If you already pay for ChatGPT Plus or a Claude plan, the connector costs nothing extra, which compares well with the Intuit route: QuickBooks Advanced at $340 a month list price includes 25 AI chat questions a month, and Intuit Intelligence sells extra prompts as a $10 monthly add-on.
The catch is that the answer is only as good as the file, and only covers that file. A question like "which of my three companies lost money last month" is not one it can answer, because it is connected to one company at a time.
The write-access problem
Write access is permission to add, change or remove records, as opposed to read access, which only lets a program look. In QuickBooks terms, write access means the connector can post to your ledger.
The connector has no permission model of its own. The ailedger newsletter on AI in accounting, in its review of the connector, put it plainly: no approval queue, no dry-run mode, and it inherits the QuickBooks role of whoever connected it. Intuit's confirmation step covers deletions. It does not cover edits, new invoices, or transactions imported into the general ledger. Those go straight in.
"Chase the June invoices that are still unpaid." The owner of a landscaping company types that into Claude on a Thursday evening. There are 23 of them, totaling $61,400. A sensible reading of that request is to list them. Another reading, and one the model may well take, is to re-send them, and in doing so update the invoice date to today on four of them. Now $18,250 of June revenue sits in August, the AR aging that the bank asked for shows customers 40 days younger than they are, and the bookkeeper finds out at month end, if she finds out at all. Nothing was deleted, so nothing asked for confirmation.
The common advice here is to be careful what you type. We think that is the wrong control, because it depends on you predicting how a model will interpret a sentence, and the whole reason people like these tools is that they interpret loosely. The better control is to remove the permission.
How to make it read-only
A reports-only user is a QuickBooks Online role that can run every standard report except payroll, cannot open or edit any transaction, and does not count toward your plan's user limit. Insightful Accountant's write-up of the role confirms all three points. It is available on QuickBooks Plus and Advanced, not on Simple Start or Essentials.
The setup takes about ten minutes. In QuickBooks Online, go to the gear icon, Manage users, Add user, and pick Reports only. Give it an email address you control, something like reports@yourcompany.com, and accept the invitation. Then sign out of ChatGPT or Claude, sign back in, and when you add the QuickBooks connector, authenticate as that reports-only user rather than as yourself. If you have already connected as the owner, disconnect first (instructions below) and reconnect as the new user.
What you get is a chatbot that can read the P&L, the balance sheet, the cash flow statement and the aging reports, and cannot post anything. What you lose is the ability to ask about a single invoice or open a transaction, because the role cannot see them. For most owner questions, which are about totals and trends rather than line items, that trade is worth it.
Nobody outside Intuit seems to have confirmed whether the underlying accounting scope that the connector requests has a read-only variant; as far as we can tell it does not, so the user role is the only lever. And a reports-only user on Essentials or Simple Start is not an option, which means owners on those plans are choosing between full write access and no connector at all.
If you run more than one QuickBooks file
The connector attaches to one company at a time. An owner with three LLCs and three files can connect one, ask questions about it, disconnect, and connect the next. There is no view across them, no consolidated total, and no way to ask "which one is short on cash". QuickBooks Advanced has the same gap, and Intuit Enterprise Suite was built to fill it, which we compare in QuickBooks Advanced against Intuit Enterprise Suite for the multi-entity owner.
It also multiplies the permission question. Three files means three connections and three reports-only users, or three chances to connect as the owner by mistake.
Checking and disconnecting connected apps
A connected app is any third-party program you have authorized to reach your QuickBooks data through Intuit's interface. Every one of them shows up in one place.
In QuickBooks Online, choose Apps in the left menu, then My apps. Each connected app is listed with the date it was linked. Disconnect removes its access. Do the same from the other end, in ChatGPT under connectors or in Claude under integrations, so a stale token cannot be reused. Then open the audit log (gear icon, Audit log) and filter by the user the app connected as. Anything the connector wrote will be there under that name, dated. If you connected as yourself, the connector's edits are indistinguishable from your own, which is one more reason to give it a user of its own.
What read-only by design means
Read-only by design means the software never asks for write permission in the first place, so there is nothing to misconfigure. The connector can be made read-only by an owner who knows to do it. A tool built read-only cannot be made anything else.
This is how Navigator connects. It links to QuickBooks Online read-only, in two clicks, with no password shared, and it does not have a way to post, edit or delete anything in your books. It reads every file you connect, so an owner with three companies sees each one and the total, refreshed daily, and every answer cites the transaction it came from so the figure can be opened and checked. The AI is included on every plan with no separate ChatGPT or Claude subscription and no cap on questions.
Which tool to use is a separate question from what data to give it. If you are weighing the connector against pasting a P&L into a chat, the differences are laid out in whether it is safe to upload financial statements to ChatGPT or Claude. And once anything is connected, the next problem is that the same question can get two answers, which we cover in why ChatGPT gives different answers to the same question.
Questions owners ask
Can ChatGPT read my QuickBooks?
Yes, if you are a US QuickBooks Online customer and you connect the QuickBooks app inside ChatGPT or Claude. Since late July 2026 the connector reads your profit and loss, cash flow and benchmarks, and it also has write access unless you connect it through a user whose role is limited to reports.
Can the QuickBooks connector delete invoices?
It can, according to Intuit's own July 2026 announcement, which lists creating, updating, sending and deleting invoices among the connector's abilities. Intuit says destructive actions require user confirmation. Edits and new records do not, and there is no approval queue or undo. Connect through a reports-only user if you do not want that.
How do I give read-only access in QuickBooks Online?
On QuickBooks Plus or Advanced, go to Settings, Manage users, Add user, and choose the Reports only role. That user can run every report except payroll but cannot open or edit a transaction, and does not count toward your user limit. Sign in to ChatGPT or Claude as that user when you connect QuickBooks.
Does Intuit use my data to train AI?
Intuit's July 2026 release for the ChatGPT and Claude connectors says customer data is never used to train foundation models. That covers Intuit's side of the connection. What OpenAI or Anthropic do with the conversation depends on which account you hold with them, and consumer ChatGPT trains on chats unless you turn that off.
How do I disconnect an app from QuickBooks?
In QuickBooks Online, open Apps from the left menu, then My apps, and choose Disconnect next to the app. You can also revoke access from inside ChatGPT or Claude under connectors or integrations. Do both. Then check the audit log for anything the app changed while it was connected.
Related
If the question is what to share rather than how to connect, start with is it safe to upload financial statements to ChatGPT or Claude. For why a connected chatbot can give two answers to one question, read why ChatGPT gives different answers to the same question. And if the real problem is several files with no view across them, see QuickBooks Advanced against Intuit Enterprise Suite for the multi-entity owner.
If you would rather connect something that cannot write to your books at all, the trial takes about fifteen minutes and needs no card: navigatorhq.ai.
Published . Last updated . Reviewed by a CFO on the Navigator team.