"An AI assistant is only as good as what it is allowed to look at. We are going to let yours look at the truth."
The one-paragraph version
MCP stands for Model Context Protocol. It is an open standard, published in late 2024 and now supported by Claude, ChatGPT, and most other assistants, for connecting an AI to an outside source of information in a controlled way. Think of it as a socket. On one side is your assistant. On the other side is a service that knows something the assistant does not, and that answers specific questions when asked. The assistant never gets a copy of the data. It asks, the source answers, and every question goes through a door the source controls.
That last part is the whole point. Without an MCP, if you wanted your assistant to know your numbers, you would paste a spreadsheet into a chat window. Now it has a stale copy, you have no idea where that copy went, and next month you paste again. With an MCP, the assistant asks a live question and gets a live answer from a source that is allowed to say no.
Why the source matters more than the assistant
Anyone can point an assistant at a QuickBooks export. What you get back is only as good as the export. If the bank feed is three weeks behind, the assistant will confidently tell you about a cash position that is three weeks wrong. If two hundred transactions are sitting uncategorized, "how much did I spend on software" is a guess dressed up as an answer.
For our bookkeeping clients, we are the ones keeping the books. Every transaction is coded by a person on our team, every account is reconciled to the bank every month, and the books are closed on a date you can count on. That makes us the source of truth for your numbers, in the literal sense: when a question is asked, the answer comes from a ledger a human has already checked. This is the thing no chatbot, no spreadsheet plug-in, and no other tax firm can hand you, because it depends on the boring, disciplined work happening first.
What you would actually do with it
You would open the assistant you already use, and ask. In your own words, on your phone, at 9pm, without logging in anywhere else. Some questions we expect to hear:
How much did I spend on software this year, and what changed from last year?
Am I on track for the Q3 estimate, and when is it due?
What did I pay myself in the last six months?
Which three vendors got the most of my money in August?
Did the state payroll deposit go through?
What is my profit so far this year compared to last year at this point?
Each answer comes back with the numbers, the date the books were last closed, and a link to the transactions behind it in Basecamp. If the assistant does not know, it says so, instead of inventing a figure. And if a question is really a planning question ("should I make the S election?"), the honest answer is "here are your numbers, and here is how to book time with Clay," because a calculation like that deserves a person.
Humans stay in the loop
Two humans, actually. One on our side, one on yours.
Ours: nothing is answerable until a person has closed it
The assistant can only quote a period our team has reconciled and closed. Open months are marked open. That is the difference between an answer and a rumor.
Yours: you decide what to ask, and what to do about it
The assistant reports. It does not move money, file anything, or change your books. Decisions stay with you, and the ones that matter still get a conversation with us.
How it stays secure
This is the part we will not compromise on, and the reason it is taking a while to build. Our rule about email applies here too: your financial life should never sit somewhere we do not control. The design, in plain terms:
Read-only. The connection can answer questions. It cannot change a transaction, send a payment, or touch QuickBooks.
Scoped to you. Your connection sees your books and nothing else. Not another client, not our firm, not a summary across anyone.
Your existing sign-in. You connect it with the same Basecamp sign-in you already have. No new password, and you can disconnect it yourself in one click.
Every question logged. You can see what was asked and when. So can we, which is how we would spot misuse.
Nothing trains anything. Your numbers are answers to your questions, not training data for any model, ours or anyone else’s.
Revocable in a minute. If a phone is lost or a login looks wrong, we cut the connection and the assistant knows nothing.
What it is not
Not a chatbot that does your taxes. Congress writes the code, and a licensed person prepares and signs your return.
Not financial advice. It reports your numbers. What to do about them is a conversation.
Not a spreadsheet upload. Nothing is copied to the assistant; it asks and we answer.
Not available yet. It is in development, and the security work comes before the fun part.
Where it stands
Basecamp is in beta with our first client, and the bookkeeping insights that this will draw from are live there today. The MCP itself is in development. The order of work is the connector, then the permission model, then a long stretch of security hardening, then a small group of Summit members as the first testers. We post each step on What's New, and we would rather build it right than fast.
Keep reading
The Basecamp preview
What we are building and what is live: insights, monitoring, planning, the What’s Mine number, and this.
Your Tax Return Should Never Live in an Inbox
The same security thinking, applied to the way we handle documents.
Bookkeeping
The monthly close that makes any of this possible.
Summit members go first.
Bookkeeping clients on the Summit tier will be the first group invited when the connector is ready. If that is you, tell us you want in. If it is not you yet, the bookkeeping page explains the tiers.
See bookkeeping tiers