Every app connected to your QuickBooks Online company file was authorized by one named user, and it keeps that user's level of access until someone takes it away. Most apps ask for the full accounting scope, which means they can read every customer, vendor, invoice, bank feed and journal entry, and many can write to them too. To see your QuickBooks Online connected apps, open Integrations, then Find integrations, and look at the list with its Action menu. Only the user who connected an app, or a new owner after a transfer, can disconnect it.
Why this matters more than it did a year ago
Intuit says QuickBooks integrates with more than 800 business apps, and a file that has been open for five years has usually collected a handful of them. Until recently the worst case was a stale expense tool reading your vendor list. Since 28 July 2026 the list can include ChatGPT and Claude, and Intuit's own release for those connectors says they can create, update, send and delete invoices and estimates, add customers and items, and import transactions. Only destructive actions ask for confirmation. The ailedger newsletter's review of the connector noted that it has no permission model of its own, no approval queue and no dry-run mode; it inherits the QuickBooks role of whoever connected it.
That inheritance applies to every app on the list, not just the AI tools that connect to QuickBooks. The permission question to ask is "what can this app do as the person who clicked Connect", because the app on its own has no permissions at all.
Verizon's 2026 Data Breach Investigations Report, published in May 2026, found breaches involving a third party now account for 48 percent of all breaches. Your accounting file is reachable by every third party on that list.
What "connected" means
A connected app is a piece of software that holds a key to your QuickBooks Online company file, issued by Intuit in the name of the user who authorized it. The app does not sign in as you and it does not know your password. When that user clicked Connect and approved the request, Intuit handed the app a token, and the app presents that token every time it reads or writes. The token stays valid until it is revoked, whether or not anyone still uses the app.
Scope is the set of things a token is allowed to do. Intuit's accounting scope covers the whole company file, and as far as we can tell from Intuit's public developer documentation it is granted as read and write together. We looked for a read-only variant and could not find one. Intuit's help article on allowing third-party access to your company file, updated 5 August 2026, puts the consequence plainly: authorizing an application lets it access any personal data in your company file until you revoke access, and the same page advises using only signed applications. That article reads as if it was written with QuickBooks Desktop in mind, but the principle holds for Online: the key is broad, and it is yours to take back.
So a well-behaved app might only ever read your reports. A badly behaved one, or a well-behaved one with a bug, or a chatbot that reads a sentence loosely, can post. The list does not tell you which is which. The vendor has to.
The two-minute check
In QuickBooks Online, open Integrations in the left menu, then Find integrations. Below the marketplace is the list of apps connected to this company file. Intuit's help article on installing apps, updated 3 August 2026, says each entry shows who connected the app and the support contact, and each has an Action menu. Older instructions will tell you to look under Settings, Apps, My Apps, which is where Insightful Accountant found it in 2017; the menu has moved twice since and was renamed Integrations this year.
Read the list slowly. Suppose an owner with three files does this for the first time in October and finds fourteen entries. File one has six: payroll, the point-of-sale system, the expense-card app, a spreadsheet connector nobody remembers installing, a scheduling tool from 2022 that was replaced the following year, and ChatGPT, which she connected herself in August to ask about the quarter. File two has five, three of them connected by a bookkeeper who left in March. File three has three, one of them the same spreadsheet connector, this time under her husband's login. Of the fourteen, five are in daily use, three are still being billed, and six should not be there.
For each entry the questions are the same. Who connected it. Is it still used. Is it still paid for. Does it write, or only read. If nobody in the business can answer the last one, the vendor's website usually can, and if the website cannot, that is its own answer.
How to disconnect, and what stays behind
From the connected list, open the Action menu next to the app and choose Disconnect. Intuit asks a short questionnaire about why you are leaving, then confirms. Those are Intuit's own steps in the help article on transferring app ownership and disconnecting apps, updated 5 August 2026. Then go to the app's own settings and revoke the QuickBooks link from that side too, so a cached token cannot be presented again. Do both.
The same help article carries the line that surprises owners: your data may be separately maintained by apps after transferring or disconnecting, and you should reach out to the app developer to manage your data rights. Disconnecting closes the door. It does not bring back what already walked out. Whatever the scheduling tool copied in 2022 is still on the scheduling tool's servers under the scheduling tool's terms, and getting it deleted is a request to them, not a button in QuickBooks.
Last, open the audit log (gear icon, then Audit log) and filter by the user the app connected as. Anything the app wrote will be there under that name, dated. If the app connected as you, its edits look exactly like yours, which is the strongest argument we know for giving anything with write access a user of its own. The reports-only user route for the AI connectors is in how to keep the ChatGPT and Claude connectors read-only.
The app someone else added
The QuickBooks Community has a long thread of owners trying to remove Square and being told the app was added by another person. The same happens with a bookkeeper who left, a business partner who is no longer a partner, or the office manager's predecessor. The token was issued in their name, so the Action menu will not let you revoke it.
Intuit's route is a transfer of ownership. Sign in as yourself, connect the same app again from the marketplace, and when QuickBooks warns that it is already connected by someone else, choose Connect anyway. The app is now held under your user ID, and you can disconnect it from the Action menu like any other. Removing the old user from the company file is a separate step under Manage users, and worth doing at the same time, because a departed bookkeeper's login is the same kind of standing key as a token.
The usual advice is to read the permissions carefully at the moment you connect an app. We think that moment is the wrong one to worry about, because the person connecting it has a reason and the app looks useful. The moment that matters is when that person leaves, which nobody schedules. A quarterly look at the list is the only reliable way to catch it.
A quarterly list for an owner with three files
The connected list is per company file. Three files means three lists, and often three different people's tokens, because the bookkeeper connected the bank-feed tool in one file, the partner set up the card app in another, and the owner did the third. So the quarterly check is the same four questions, once per file: who connected it, is it used, is it paid for, does it write. Anything that fails two of the four gets disconnected.
While you are there, note what each remaining vendor told you before you connected. A well-behaved app says whether it reads only or writes, what it stores on its own servers and for how long, and whether it has a SOC 2 report you can ask for. What that report does and does not tell you is in what SOC 2 means when you choose a finance app. A vendor that cannot answer those three questions in a sentence each is not ready for your general ledger.
Navigator appears on this same list, and should be checked like everything else on it. It connects to QuickBooks Online read-only, in two clicks, with no password shared, and has no way to post, edit or delete anything in the file. On the base plan it reads each company you connect, refreshes daily, and cites the entry behind every figure it shows. That does not exempt it from the quarterly check; it just means the "does it write" question has a short answer.
What the check cannot do is tell you what an app has already read. The list shows who connected it and when, not what left. It also cannot see keys that were never issued through Intuit, such as a bookkeeper's exported backup on a laptop. For that, the review of the file itself in the five-minute check of your bookkeeper's QuickBooks file is the companion to this one.
Questions owners ask
How do I see which apps are connected to my QuickBooks Online?
Open Integrations in the left menu, then Find integrations, and look for the connected apps section. Each entry shows the app, the user who connected it and a support contact, with an Action menu beside it. The list is per company file, so if you run three files you have three lists to read.
How do I disconnect an app from QuickBooks Online?
From the connected apps list, open the Action menu next to the app and choose Disconnect. Intuit asks a short questionnaire about why, then confirms. Revoke the link from the app's own settings as well, so a stale token cannot be reused, and then read the audit log for anything it changed while connected.
Why can't I disconnect an app that someone else added?
Because the app's key was issued in that person's name, and QuickBooks only lets the connecting user, or a new owner after a transfer, remove it. Intuit's route is to reconnect the app under your own user ID, choosing Connect anyway when warned, which transfers ownership to you. Then you can disconnect it.
Does disconnecting an app delete the data it already pulled?
No. Disconnecting revokes the app's key so it cannot read or write anything new. Intuit's help page says plainly that your data may be separately maintained by apps after disconnecting, and points you to the app developer to manage your data rights. What was copied out stays with the vendor under its own terms.
Can a connected app change my QuickBooks data?
Many can. Intuit's accounting scope is granted as read and write together, and an app with it can create, edit and delete transactions within the permissions of the user who connected it. We could not find a read-only scope in Intuit's public documentation. Ask any vendor whether it writes before you connect, and check the audit log afterward.
Related
If the app in question is ChatGPT or Claude, what the QuickBooks connectors read, what they can change, and how to keep them read-only goes through the reports-only user step by step. If you are deciding whether to connect at all or just paste a report, is it safe to upload financial statements to ChatGPT or Claude covers that choice. And for what a vendor's security page should actually tell you, see what SOC 2 means when you choose a finance app.
If you would like a second pair of eyes on the file before you prune the list, the free accounting health check takes about fifteen minutes: navigatorhq.ai/health-check.
You're on the list.
The next post goes to . While you wait, the free Accounting Health Check scores your own books.
Published . Last updated . Reviewed by a CFO on the Navigator team.