DocsSign inInstall Kastel
All connectors

One Xero authorisation can cover several organisations, and Kastel files each one separately.

With Kastel

A single Xero authorisation can cover several organisations, and your Kastel keeps each of them in its own space, with its own key. From each organisation it keeps the number, date, counterparty, total and status of sales and purchase invoices, plus the name and tax number of your contacts. Payment details stay out, and nobody reads these records until a department has been designated.

The status is the one Xero writes, deleted included

In Xero, an invoice carries a state that runs from draft through to paid, by way of voiding and deletion. That state is a field like any other, and the connector carries it over exactly as Xero writes it, without translating or interpreting it.

What surprises people is that Xero keeps returning a voided or deleted invoice, with its state. An invoice deleted in Xero therefore comes into your Kastel as a deleted invoice. The connector treats that as a change of content and updates the record, rather than concluding that something has vanished.

The consequence is useful when reading. A voided invoice does not drop out of what the company knows, it becomes a voided invoice, and an AI that comes across it knows it no longer counts. What Xero genuinely removes from its lists, a deleted contact for instance, follows a different path, described further down.

What a Xero contact holds, and what the connector leaves alone

A Xero contact is more than a name. It holds the bank details used to pay that supplier, one or more postal addresses, phone numbers, an email address, and a list of named contact persons at that client.

The connector keeps three things from it. The contact's name, its role, and its tax or registration number. A contact that is both a customer and a supplier carries both roles, because Xero says so and there is no reason to choose on its behalf.

The rest is never requested. The people attached to a contact do not come into your Kastel, and neither does any hand-typed text, because the connector writes no note, no comment and no reference. Xero's lists return the whole record, and the selection happens at the moment of writing, against a closed list of fields. Any field Xero adds to its contacts stays outside, because nobody goes looking for it.

What comes in from an invoice and from a contact

The list of fields read is a closed one, and here it is as written in the connector.

What your Kastel reads in Xero

  • The number and date of every invoice, sales and purchase alike
  • The counterparty the invoice names, customer or supplier
  • The total and the currency code
  • The status, exactly as Xero writes it, voided and deleted included
  • A contact's name, its customer or supplier role, its tax or registration number

What it never reads

  • The bank details held on a contact
  • The named contact persons attached to a contact
  • Postal addresses, phone numbers and the email address
  • The line item detail of an invoice

A Xero contact can hold a list of contact persons, with their names and email addresses. None of those people comes into your Kastel, because the connector reads only the name of the contact itself. Line items are left out for a different reason. A single line can name a service, a person or a purchase that nobody needs to know about in order to steer the business, when the invoice total already answers the question being asked.

What happens when you connect Xero

Four steps, in this order, and the last one decides everything.

  1. Two read permissions requested, and nothing else

    Kastel asks Xero to read transactions and contacts. No write permission is requested, which you can see on Xero's own authorisation screen before you approve it. Not every publisher allows that, and the QuickBooks connector has to live with a single permission that grants write access.

  2. Xero replies with the list of your organisations

    One authorisation can cover several organisations, which happens as soon as a group or an accountancy practice keeps them in one place. Kastel asks Xero which ones the authorisation covers, instead of assuming.

  3. One key per organisation, filed apart

    Each organisation gets its own key and its own space, and the organisation concerned is named on every call. You can stop reading one of them without touching the others. If Xero returns no organisation at all, nothing is stored.

  4. And at this point nobody reads anything yet

    The token you have just authorised sees the entire ledger, with no invoice carrying a read permission of its own. So the invoices that have come in are readable by nobody until an administrator designates the department that owns the accounts, that name is admissible, and that department really appears in your organisation. The three conditions count together, and a department name that points to nothing known at your end is not enough.

If you change your mind, the next reconciliation applies it

The department entitled to read the accounts is not set in stone the moment an invoice comes in. It is recorded on every record and compared on every reread. The day you designate another department, or withdraw the one that held it, the invoices already in are picked up and filed elsewhere.

That is the reconciliation work the connector runs at regular intervals. It compares what Xero returns today with what your Kastel holds, applies the scope currently in force, and flags whatever has gone at the source. A change of organisation alters no invoice, and would therefore be invisible without that comparison.

None of this is specific to accounting. It holds for everything your Kastel governs, and it is what lets you revisit an access decision without reconnecting anything.

What this connector does not do

Kastel does not check that the designated department really is the finance one. It checks that the department exists in your organisation and that its name is admissible. Its purpose cannot be verified, so if you designate the sales department, your invoices will be filed there and readable by its members. That department is also the same for every connected organisation, because the read scope is not set organisation by organisation.

Xero can say which invoices have moved since a given date, and the connector does not use that yet. It rereads both lists in full on every pass, so a new invoice arrives one pass behind the moment you issued it.

A contact's tax number comes into your Kastel. For a sole trader or a self-employed supplier, that number identifies a person as much as a business, and it still comes in, because it is what tells two suppliers of the same name apart.

A contact removed from Xero stops appearing in the list. It is not erased from your Kastel for that. Its record remains, marked as gone at the source, and it stays readable by the people who already had access to it. Erasing it for good falls to an administrator, and to nobody else. That rule is common to every Kastel connector.

Before you connect Xero, let us talk about your organisations.

How many organisations to connect, and which department will be entitled to read them, are decisions better taken in a conversation than on a web page. Tell us where you stand and what your teams expect from an AI on the accounts.

Write to the team
Other connectors in detail
Pennylane
Number, date, counterparty and total. Never the bank details.
Sage
It reads three lists and never asks for bank details.
QuickBooks
Number, date, counterparty and total. No way to write into QuickBooks.

See the full connector catalogue