Trust and safety

Read-only Xero access. No accounting changes.

An official Xero connection (OAuth) keeps things controlled: PlainOps never sees your Xero password, asks for read-only Xero access, and uses no write scopes. You approve every action, and you can revoke access in Xero whenever you like.

Read-only and reversible. No passwords reach us, and a real person reviews your report during the private beta.

Boundaries before access

Official Xero connection (OAuth)

You authenticate on Xero’s own screen. PlainOps never sees your Xero password — no passwords are shared with us.

Read-only Xero access

PlainOps requests read permissions for accounting evidence only. No write scopes, no write access, no money movement.

Human QA in the private beta

A person reviews every report, then we send a founder-readable report in 24 hours with evidence and confidence labels.

Revoke access in Xero, disconnect and delete

You can revoke access in Xero at any time, disconnect the app, and ask us to delete your data.

What PlainOps will not do

No changes to Xero. No cancellations. No vendor emails. No accounting changes. No card required. No auto-cancellations. No money movement.

No invented savings claims: synthetic demo numbers are labelled and real customer results require permission.

What we can and cannot see

We would rather be straight about the boundary. Xero accounting data is rich, but it has limits — so we tell you up front.

  • What Xero shows us: bills, invoices, payments, vendor names, amounts, and how often each one recurs (billing cadence). That is enough to surface likely recurring vendors and annual renewals.
  • What it cannot show: seat-level usage or in-app activity. Xero-only data cannot prove whether a licence is actually being used, or who logged in — that would need future SaaS admin integrations you approve separately.