An invoice created by accident. A customer record overwritten with the wrong details. A credit invoice on the wrong debtor. These are the scenarios that keep you awake when you consider connecting AI to your accounting.
Rightly so. But the solution is not to avoid AI, it is to set up AI properly. In the first article of this series we discussed why responsible AI use starts with conscious choices. This article goes a step further: how do you concretely prevent the AI from doing things you do not want?
The most important protection is simple: the AI connector performs no write action whatsoever without your explicit confirmation. No creating an invoice, no changing a record, no deleting an entry, unless you approve it.
Here is how that works in practice:
This is not an optional setting. It is a fixed part of the connector that cannot be switched off. Every mutation, whether creating, changing or deleting, goes through this confirmation step.
The AI does exactly what you ask. That sounds like an advantage, and it is. But it does mean that the quality of your question directly affects the result.
Be specific. “Show invoices” could produce anything. “Show outstanding invoices from January 2026 for customer Joanknecht” gives you exactly what you are looking for. The more concrete your question, the smaller the chance of unwanted results.
Name the entity. The AI works with customers, invoices, general ledger accounts and items. If you say “look up Joanknecht”, the connector knows you mean a customer and remembers that context. If you then ask “show outstanding invoices”, the AI automatically filters on that customer.
Split complex actions. Do you want to create a credit invoice? First ask to show the original invoice. Check the details. Only then ask to create the credit invoice. Step by step.
The most powerful habit you can develop: always ask to show data before you make changes. This sounds obvious, but it makes a big difference.
Suppose you want to make an address change for a customer. Do not immediately ask “Change the address of Bakkerij Janssen”. First ask: “Show the details of Bakkerij Janssen.” You then see the current address, the customer number, any outstanding invoices. Only after that do you pass on the change.
The connector helps you with this. When you look up a customer and there is exactly one match, the AI remembers that context. If you then ask for invoices, the invoices of that customer are shown automatically. If there are several matches, for example three companies with “Janssen” in the name, the AI asks which one you mean before anything happens.
Every interaction with the connector is logged automatically. Which question was asked, which tool was called, which parameters were passed, and whether the action succeeded or failed. This is not an optional feature, the audit log always runs.
That gives you two benefits. First, you can find out afterwards exactly what happened. If a colleague asks “who created that invoice?”, the answer is in the log. Second, it works preventively: knowing that everything is recorded encourages careful use.
| Do | Don’t |
|---|---|
| “Show outstanding invoices for customer Ecolux” | “Show invoices” (too broad) |
| Request data first, then change | Immediately “Create an invoice” without context |
| Check the preview before you confirm | Confirming blindly without reading the details |
| “Look up customer Bakkerij Janssen” and then “Show invoices” | Cramming everything into one sentence without checking |
| “Change the VAT number to NL123456789B01” | “Change the customer details” (too vague) |
| Use a test administration for new actions | Experimenting in your production administration |
Suppose you accidentally created an invoice that should not have been created. The audit log shows exactly what happened, including all parameters. You can find the invoice through the AI (“show the last created invoice”) and then create a credit invoice, again with the confirmation step.
The connector prevents most mistakes through the confirmation process. But mistakes that are confirmed by the user themselves are human errors. The audit log ensures they are always traceable and recoverable.
Responsible AI use is not a technical configuration you set up once. It is a way of working. Asking specific questions, checking data before you change it, reading previews before you confirm. The connector enforces the most important steps. The rest is discipline you build up with experience.
In the next article we go deeper into data privacy: which data does the AI process exactly, where is it stored and how does it work with the GDPR?
Ready to get started? Start your free trial period →