Finance integration guide

Xero + UbiGrowth workflows

Xero is a cloud accounting platform that owns invoicing, bank reconciliation, and financial reporting for small and mid-sized businesses. This guide covers the records that matter, how the connection should be scoped, and what the first bounded workflow should be.

Introduction

Make Xero part of the workflow, not another silo.

Validate connector availability for your workspace

This guide covers how a team designs a finance workflow around Xero with UbiGrowth: which records stay authoritative, how the connection should be scoped, what the first bounded workflow should be, and how to tell whether it worked.

The records that matter are Contact, Invoice, Bill, Payment, Bank Transaction, Account, and Tracking Category. Xero uses a single Contact record for both customers and suppliers, so the same organisation you sell to and buy from is one record with balances on both sides. Treating Contact as a customer misreads the position.

Xero is not currently on UbiVibe's verified connector list. This page is an implementation design reference: use it to specify the workflow, then validate whether the connection is available and correctly scoped for your workspace before you make it a dependency. The verified UbiVibe connections today are Salesforce, HubSpot, Gmail, Google Drive, Slack, and GitHub.

The platform layer is the usual destination for this connection, because the value shows up as governed context and execution shared across more than one team.

Why teams evaluate this connection

Integrations create value when they remove operating friction.

The first design decision is not which API endpoint to call; it is which system owns the record, what event should trigger work, who owns the exception path, and what successful completion means.

Finance integrations carry a different risk profile from the rest of the stack. A duplicated CRM record is annoying; a duplicated payment, a double-posted invoice, or an unauthorized write into Xero is a real financial and control problem.

That is why most finance teams end up doing the work manually. The available automation is fast but cannot demonstrate what it did, and a number without a traceable basis is unusable in a function where everything has to be defensible.

You're likely here because

  • Recurring finance analysis is mostly export, match, and reformat
  • Approval trails live in email rather than in a system
  • AI answers cannot be traced back to a source anyone will accept

Record model

What a Xero integration actually reads and writes.

Integration design starts from the objects the system really exposes, not from a generic connector diagram. These are Xero's.

ContactInvoiceBillPaymentBank TransactionAccountTracking Category

Identity and matching

Xero uses a single Contact record for both customers and suppliers, so the same organisation you sell to and buy from is one record with balances on both sides. Treating Contact as a customer misreads the position.

Start here

Read authorised invoices past their due date and prepare the follow-up, using the Tracking Categories the business already uses to segment.

What this will not do

It will not classify bank transactions. Reconciliation rules live in Xero and encode accounting judgment the workflow should not override.

The constraint to plan around

Xero applies both per-minute and daily API limits per tenant and requires tenant selection on every call, so a multi-entity group needs the tenant resolved before any read.

Build notes

What you actually have to reason about in Xero.

The fields that carry meaning, how the connection authenticates, and whether the event surface can be trusted. This is the part that decides whether the integration works in month three.

FieldWhy it matters
ContactIDone record serves both customer and supplier, so a balance can exist on both sides
StatusDRAFT, SUBMITTED, AUTHORISED, PAID, VOIDED — only AUTHORISED and beyond affect the ledger
TrackingCategoriesthe business's own segmentation, and the dimension reporting actually needs
AmountDue vs Totalthe outstanding position after part-payment, which Total does not reflect
UpdatedDateUTCthe incremental cursor, used with the If-Modified-Since header

Authentication

OAuth 2 with a tenant id required on every call, since one authorisation can span several organisations. Omitting the tenant header, or caching the wrong one, writes into a different company's books.

Events and delivery

Webhooks deliver create and update notifications per event type with payload signing, and Xero disables a webhook that fails validation. The notification carries ids, so a fetch follows.

Workflow

How the Xero workflow runs.

The operating sequence, from reading the source system through to the result landing back where it belongs.

01Read the source records02Match and reconcile03Present the working queue04Stage the action for approval

Step 01

Read the source records

Connected Xero records replace the recurring export step, so the analysis starts from current data.

Step 02

Match and reconcile

Records are matched against the other systems involved, and anything that does not match becomes an explicit exception rather than a silent adjustment.

Step 03

Present the working queue

Exceptions and items needing attention are presented with owners, so the review is a queue rather than a highlighted spreadsheet.

Step 04

Stage the action for approval

Where an action is required, it is prepared with its supporting records and held for explicit human authorization.

Design decisions

The finance decisions this connection forces.

Each of these has to be settled before the Xero workflow is allowed to write anything.

01Start read-only and stay there longerthan feels necessary02Keep authorization human

Step 01

Start read-only and stay there longer than feels necessary

Read access to Xero delivers most of the reporting and reconciliation value with none of the write risk. Add write paths only when a specific, bounded workflow requires them.

Step 02

Keep authorization human

Anything that moves money, changes billing state, or affects a closed period requires an explicit human authorization step that is recorded, not inferred.

Implementation path

How to implement the Xero workflow.

  1. 01

    Define the data boundary: which Xero records the workflow may read, and what is explicitly out of scope.

  2. 02

    Start with a reporting or reconciliation workflow you already produce manually, so the output can be checked against a known-good answer.

  3. 03

    Reconcile the connected output against the last two closed periods before anyone relies on it.

  4. 04

    Once overdue follow-up works, add tracking-category-aware reporting so the business sees receivables by the dimension it actually manages.

Governance

Controls that matter.

01

Control 01

Payment, billing, and period-affecting actions require explicit human authorization; automation prepares, people approve.

02

Control 02

Credentials are least-privilege and reviewed, with read and write scopes separated wherever the platform allows it.

03

Control 03

Every automated action leaves a record that can be reconciled against the source system.

Failure modes

How a Xero integration breaks in production.

Not generic integration advice. These follow from how this system actually behaves, which is why they look nothing like the list on the next guide over.

Symptom 01

Data is written into the wrong company.

Cause

The tenant id header was cached or omitted and one authorisation spans several organisations.

Fix

Require an explicit tenant id per call and never default it.

Symptom 02

A webhook is disabled by Xero.

Cause

Signature validation failed or the endpoint did not respond in time.

Fix

Validate the signature correctly and respond immediately, processing asynchronously.

Symptom 03

An invoice cannot be corrected.

Cause

It was authorised, and authorised documents post to the ledger.

Fix

Void and reissue rather than expecting to edit, and design the workflow so authorisation is deliberate.

What changes at scale

Rate limits are per tenant per minute and per day, so a multi-entity group has independent budgets. Use If-Modified-Since for incremental reads rather than full pulls.

Examples

What a working Xero workflow looks like.

Bounded scenarios rather than a feature list. Each one can be verified against work the team already does.

Accounting workflows

With Xero connected read-only, the recurring view is assembled from live records rather than a fresh set of exports each cycle.

Reconciliation exception queue

Unmatched or unexpected items from Xero become a working queue with owners, instead of highlighted rows in a spreadsheet emailed around the team.

Limitations and considerations

What to validate before you depend on this.

  • Xero applies both per-minute and daily API limits per tenant and requires tenant selection on every call, so a multi-entity group needs the tenant resolved before any read.
  • Authorising an invoice posts it to the ledger, which is an accounting event rather than a data change. Voiding is possible; deleting an authorised document is not, so mistakes become permanent audit trail.
  • When bank reconciliation is the target. Reconciliation rules encode accounting judgment, and automating around them creates work for whoever owns the books.
  • Nothing produced here is accounting, tax, or audit advice, and no output should be treated as a professional opinion.
  • Write access to Xero carries real financial risk. Duplicate protection, idempotency, and an approval step are requirements rather than refinements.

FAQ

Xero integration questions.

What records does a Xero integration actually work with?

The primary records are Contact, Invoice, Bill, Payment, Bank Transaction, Account, and Tracking Category. Xero uses a single Contact record for both customers and suppliers, so the same organisation you sell to and buy from is one record with balances on both sides. Treating Contact as a customer misreads the position.

What should the first Xero workflow be?

Read authorised invoices past their due date and prepare the follow-up, using the Tracking Categories the business already uses to segment.

What will a Xero integration not do?

It will not classify bank transactions. Reconciliation rules live in Xero and encode accounting judgment the workflow should not override.

What is the main constraint to plan around?

Xero applies both per-minute and daily API limits per tenant and requires tenant selection on every call, so a multi-entity group needs the tenant resolved before any read.

What changes about a Xero integration at scale?

Rate limits are per tenant per minute and per day, so a multi-entity group has independent budgets. Use If-Modified-Since for incremental reads rather than full pulls.

How does authentication work for Xero?

OAuth 2 with a tenant id required on every call, since one authorisation can span several organisations. Omitting the tenant header, or caching the wrong one, writes into a different company's books.

Does Xero support webhooks, and can they be trusted?

Webhooks deliver create and update notifications per event type with payload signing, and Xero disables a webhook that fails validation. The notification carries ids, so a fetch follows.

What is the risk of writing to Xero?

Authorising an invoice posts it to the ledger, which is an accounting event rather than a data change. Voiding is possible; deleting an authorised document is not, so mistakes become permanent audit trail.

When is connecting Xero the wrong call?

When bank reconciliation is the target. Reconciliation rules encode accounting judgment, and automating around them creates work for whoever owns the books.

What should a Xero integration automate first?

Start with one bounded workflow that removes a measurable handoff, duplicate-entry step, reporting delay, or follow-up gap. Expand only after the first workflow is reliable.

Does UbiGrowth require Xero to be replaced?

No. The operating model is designed around connecting to systems that should remain authoritative and building workflows around them rather than forcing a wholesale replacement.

Is connector availability identical for every workspace?

No. Availability can depend on provider configuration, authentication, scopes, workspace setup, and deployment state. Validate the required connection before treating it as an operational dependency.

Can the workflow write into Xero?

Only where a specific bounded workflow requires it, with duplicate protection and an explicit human approval step. Most of the value is available read-only.

Is the output auditable?

Execution state and results return to the product surface, and analysis is grounded in connected records rather than an uploaded file, so an answer can be checked against its source.

Is this a replacement for the accounting system?

No. Xero stays authoritative. The workflow layer sits around it to remove the export, match, and reformat cycle.

How this access is governed

What ARIA is allowed to do in Xero, and who decides.

Connecting Xero is a permission decision, not just a setup step. These are the controls that decide what ARIA can reach, what it can change, what gets recorded, and how you take the access back.

Required permissions

ARIA works through the scopes the connection was granted, and no others. Authorization happens at the provider, so the permissions being requested are shown by the system itself before anything is connected.

What it can reach

Reachable systems are the intersection of what your organization approved in the connector registry and what the requesting identity is permitted to use. Identity resolves before execution, not after.

What it can do

Actions run through explicit execution paths with state, spend, and failure boundaries — a bounded worker path rather than an open-ended agent loop with a credential.

Credential handling

Credentials live in the governed connection layer and are resolved through canonical connection identity. They are not pasted into individual workflows, prompts, or generated artifacts.

Action logging

Execution carries state and traces: what triggered the work, which connection it used, and what came back — including an explicit failure when something did not run.

Approval and revocation

Consequential actions can be made to require a person to approve them. Access can be changed or revoked at the connection, and ARIA loses that reach without unpicking the work already completed.

Start with ARIA

Ask ARIA to run this integration.

Describe the outcome you need across this system. ARIA works out the scopes, data, and actions the job requires, and operates inside the access you grant — which you can change or revoke.

  • ARIA acts only through the systems and permissions you connect.
  • Connections use scoped credentials you can change or revoke.
  • Actions are recorded, and consequential ones can require approval.

Goes to UbiGrowth, with the page you asked from attached. We do not sell or share it. Prefer to talk? Call 972-823-1294.

Start here

Turn the integration into a working business outcome.

Start with ARIA to describe the outcome, then continue into the product path that fits the workflow. Connector availability and required scopes should be validated for the specific workspace before production use.