Offshore and outsourced bookkeeping is common at this company size precisely because it’s cheaper than hiring locally — but it comes with a trust gap most businesses just live with instead of solving.
The anxieties are specific, not vague unease: can they see payroll, I never actually checked. If they void an invoice or change a bank account on a contact, would I even know. If something goes wrong, do I have any record of who did what, or is it just their word against mine. Right now the only tools available are blunt ones — restrict their Xero user permissions, or just trust them, which is what most businesses actually do by default.
What changes: payroll access controls mean an offshore bookkeeper’s AI access simply can’t see payroll data or payroll account codes — not "please don’t look," an actual block. Write access and workflow role tiers mean they can query and prepare, but posting a journal, voiding an invoice, or updating a contact’s bank details requires a role tier they may not have. The agent activity log means every write the AI performs on their behalf is recorded: what, when, result, and the reason given.
Said precisely, not oversold: this is control and visibility over what the AI does on an outsourced team’s behalf, not a full segregation-of-duties guarantee — their direct Xero access, outside this system, isn’t touched by any of it. That’s the accurate, narrower claim, and it’s still a strong one.
Connect your Xero account and see what it finds on your actual last close, not a demo.