Does the agent post to NetSuite?
No. The agent prepares. A named human approves. NetSuite posts only after that approval. L2 is the approved payload only, and the identity that drafted cannot be the identity that approved.
Does our data train Grok, Claude or OpenAI?
No. Your data does not train Grok, Claude or OpenAI. Production traffic uses enterprise APIs with Zero Data Retention — not consumer chat apps.
Where does our data live?
NetSuite stays the book of record. The agent queries it live, rather than keeping bulk exports. Working files and what the agent is taught live in a folder you own in SharePoint or Google Drive. Standing rules live in your AI workspace project. Where your data lives.
Can we ban a model?
Yes. You choose the allowed models. The router fail-closes if a vendor is off the list. One kill-switch disables a model or freezes all writes. You name the allowed models and pin the region. If residency cannot be verified, the call does not go out.
What NetSuite role do you use?
A custom least-privilege MCP role. Administrator cannot use the connector. Oracle already blocks that. Write tools refuse unless they carry an approval token issued by our control plane. The path is Oracle’s official AI Connector Service: Model Context Protocol, OAuth 2.0, user-delegated.
Who is the named human?
A named Booksquire reviewer reviews every engagement. A named reviewer on our side prepares; your controller still approves the post. The same identity cannot draft and approve the same transaction. Slack sends your named accountant a card: Approve, Edit or Reject.
What is out of scope?
Payment initiation or bank-file release, period close, tax opinion or statutory audit sign-off, payroll processing, deleting master data, Administrator-role access to NetSuite, any solely-automated decision with legal or substantial effect on a person (including credit-like vendor onboarding), unsupervised posting of journals, invoices, bills or master-data changes, consumer ChatGPT, Claude.ai or grok.com as the system of record, and training any model on your books. It is not a Controller. It is not a CFO. It does not close the period, release a bank file, or sign a tax opinion. What it does not do.
How does the two-week sandbox work?
Week 1 is read-only. Custom MCP role. One mailbox or library. A controller pack and a rec exception list. Nothing writes. Week 2 is draft-only. Journals and bills appear as drafts. Your reviewer accepts or rejects. Nothing posts unless they click Approve. Exit: CISO signs the eight commitments. Controller signs that drafts are usable. Then the $2,000 seat — or stay on Monitor.
What does $2,000 include?
The Accountant seat: draft plus human-approved posts. One entity. Named reviewer included. Included in the $2,000 Accountant tier: always-on Accountant Agent on Slack and email; NetSuite MCP connection with custom least-privilege roles; inbox, Drive and SharePoint intake for invoices, statements and supporting documents; draft journals, invoice / bill coding and reconciliation exception queues; master-data review flags (vendors, items, customers); weekly insights brief and month-end exception pack; named human reviewer with dual-control on all posts; immutable audit log, exportable to the client; quarterly access and role review; client-selectable model policy (Grok / Claude / OpenAI / mix). Onboarding is $3,500 one-time. An extra legal entity is +$600 / month. The two-week sandbox is credited against the $3,500 onboarding fee if you convert.