I've sat in on a handful of threads lately where accountants are lit up about MCPs. Model Context Protocol, if you haven't run into the term yet, is the standard that lets a model like Claude or GPT plug directly into your tools: your GL, your ERP, and your spreadsheets. And I get why people are into it. I spent years building an accounting function from nothing at a startup, and every hour I didn't spend reconciling something by hand was an hour I got to spend actually thinking. So if a model can wade through your spreadsheets that’s super helpful.
Here's the problem, most of the people getting excited about MCPs right now have no real sense of what they're turning on.
Read access is a demo. Write access is a decision.
An MCP that reads your GL and points at something odd is basically a smarter version of a report you already have saved. Fine. Low stakes. But the conversations I'm in are moving past that into "let's let it post the entry" or "let's have it resolve the reconciling item itself." I want to be clear about what that actually is: it's not a bigger version of the same thing. It's a different animal.
There's already a public case of an AI coding agent that had unrestricted write access and, on its own, wiped a production database. Nobody signed off on that. Nobody reviewed it before it happened. It just did it because nothing in the system was built to stop it.
Now put that in your books instead of a codebase. An agent with MCP write access into your ERP has no concept of segregation of duties unless someone built that in separately. It doesn't know your close calendar. It doesn't inherently understand materiality: you can tell it a threshold, but a model applying a threshold on its own judgment isn't the same thing an auditor means when they say a control is operating. MCP was built to move data and trigger actions fast between a model and a tool. It was never built with SOX in mind, and honestly, it shouldn't have to be. That's not what the protocol is for.
The people most excited are usually the ones least set up to see the gap.
In pretty much every one of these conversations, it's not the technical folks pushing hardest to wire in write access. It's the people excited about getting hours back who haven't spent much time thinking about what happens when the model is confidently wrong at 2am with nobody watching.
That’s not a knock, it's the exact reason this needs to be a teaching moment instead of a scary headline. Most accountants built their instincts around controls that assume a human is doing the work, at human speed, with a human-sized mess if something goes sideways.
I've watched a close break because one person who understood a workaround left the company and nobody else knew it existed. That's already a fragile way to run things, and that’s before you add an agent that can act across every entity in your GL in seconds and doesn't get tired or cautious or embarrassed. The playbook we're used to just doesn't transfer.
So what actually makes this safe?
I don't think the answer is to swear off AI in the close. I think the answer is that the controls need to be built into the accounting process itself, not something you configure yourself on top of a generic protocol and hope you got right. This is honestly the reason I care about what we're doing at Kinter. An agent touching your books needs the same guardrails you'd want around a new hire, and those guardrails need to already be there, not something you bolt on after the fact.
A Purpose-Built Agent for your accounting process will have:
- SOX-compliant controls — Segregation of duties, change management, and access controls built into every app and agent.
- Consistency and repeatability — The close runs the same way in month twelve as it did in month one, whether or not the person who set it up is still around.
- Complete audit trail — Every agent action, every human decision, every data change. Logged, timestamped, and exportable.
- Agent observability — See what every agent did, why it did it, and what data it touched. Full transparency into AI decision-making.
- Human-in-the-loop — Agents surface exceptions. Humans make the call. Nothing goes out without the review you define.
MCPs aren't the villain here. They're a useful protocol and they're going to keep showing up in finance workflows whether we've thought it through or not. The question I'd ask before hooking one up with write access isn't "can we." It's "does this come with the same controls my auditor already expects from a human doing this job." If it doesn't, you may want to explore something with more control built-in.
See how Kinter gives you unparalelled safety and control. Book a demo.

