The expense without the receipt
Three lists are read, and three only. The table further down goes down to the field.
Spendesk's interface cannot return part of a record, so it returns the whole object. The connector names one by one the fields it writes, and writes those only. A field it has not named cannot come out, including a field Spendesk might add tomorrow.
An expense claim tells the story of someone's evening
An expense claim is a management document and a personal chronicle at once. It says which restaurant someone had dinner in, on which evening, for how much, and the photographed receipt often lets a reader work out how many people were at the table. A spend-management tool concentrates that kind of detail across an entire organisation, month after month, which is what makes it a delicate source to open up.
So the connector keeps what serves management and leaves out what tells the story of the evening. The merchant, the amount, the date and the state of a settlement are enough to follow a travel budget or a supplier relationship. The photograph of the receipt and the line items, where the time, the number of guests and the exact nature of the purchase can be read, are never read at all.
Spendesk sets no read permission on an individual spend record
The Spendesk access key belongs to the entity rather than to a person. Whoever holds it sees the spending of the whole company, and there is no permission attached to one settlement or one expense claim in particular. A cost centre looks like one from a distance, but it stays a management label, and the connector never uses it to decide who is entitled to read.
There is therefore no original permission to inherit, unlike a shared file or a discussion channel. Every spend record gets the same filing, and that filing only exists once an administrator has designated the finance department entitled to read it. A name invented in a configuration file is not enough, because the connector checks that the department genuinely exists in your organisation before opening anything to it.
Without that designation, your spending comes into your Kastel and is readable there by nobody, waiting for an administrator's decision. An AI plugged into your sales team does not reach it, and the same holds for the board. The rule is the same on every source, and what each AI is entitled to see is decided at your end, department by department.
Open a spend record in Spendesk and compare
Every row can be checked in your own Spendesk account, by opening a supplier, a settlement or a spend record.
| The object in Spendesk | What comes into your Kastel |
|---|---|
| A supplier | Its name, its legal name, its VAT number, and whether it is archived or active |
| A settlement | Its type, its state, its amount and currency, its cleared date, a reference to the supplier |
| A spend record or purchase invoice | Its type, its date, the merchant's name, its amount and currency, its status label |
| The receipt attached to a spend record | Nothing |
| The line items of a spend record | Nothing |
| A payment card | Nothing, no call in this connector goes looking for a card |
| A supplier's bank details | Nothing, neither IBAN nor BIC, those fields are never read |
| An employee, their address, their phone number | Nothing, the members directory is not wired |
| An account balance, a bank fee | Nothing, those surfaces have no call at all |
| A cost centre, an analytical dimension | Nothing, and it never decides who is entitled to read |
The receipt is the most important exclusion on the list. A photographed receipt carries the time, sometimes a guest's name and often the last digits of a card. The amount and the merchant answer the management questions. The receipt, for its part, mostly informs on the person.
Access to Spendesk's own interface is itself conditioned
Spendesk does not open its programming interface to every customer. It requires a Premium or Enterprise plan, a credential provisioned by the account owner, and in practice an arrangement with their sales team. That is a Spendesk constraint, and it has a direct consequence on how the connector behaves.
If the credential exchange fails, the connection is refused before a single secret is stored, and nothing is read. The connector never falls back on a partial read to save appearances, because a partial read on a financial source is the worse of the two options. The short-lived token it obtains afterwards lives in memory for the duration of the call and is written nowhere.
Some Spendesk surfaces have no call at all in this connector
An exclusion at the point of writing stops a field from being written. An unwired surface goes further, since no call exists to go and fetch it. That is the case for the members directory, account balances, bank fees, analytical dimensions and accounting exports, none of which has a read function in this connector.
Cards are in that position for a reason worth stating. The endpoint that reads them was too uncertain in Spendesk's documentation to be wired, so it was not wired. A card number is never requested and never written, and that stays true even when Spendesk returns a full object in a response.
That leaves archiving, which is how Spendesk makes things go away. A supplier taken out of use flips to archived and carries on appearing in the lists. The connector reads that flip as a rewrite of the record, with its new state, rather than treating it as a disappearance. The accounts themselves connect elsewhere, with exclusions that are not the same ones.
What this connector does not do
It does not manage your spending. It approves nothing, reimburses nobody, reconciles no entry, and replaces neither Spendesk nor your accounting. It gives an AI enough to answer management questions from your real spend records.
A merchant's name can be a person's name, and it comes in as it stands, because it is what makes a spend record intelligible. That is precisely why nothing is readable before a finance department has been designated.
The status label and the type of a spend record come from Spendesk, and their content depends on what your team configured there. A naming convention that slips something sensitive into a label brings it in with the spend record.
A spend record deleted in Spendesk is not erased from your Kastel. It stays on file with a gone-at-the-source note, within reach of the same people as before, until an administrator decides to erase it. On a financial source, keeping is the cautious behaviour, and the disappearance is itself a piece of information.
Write to us before you connect your spending.
A source that touches your employees' spending is better discussed than read about. Tell us what you want an AI to know about your management, and we will tell you plainly where this connector stops.
Get in touch