The weak point of any approval window is the person who clicks Yes without reading.
Release 0.4.2 is out. This post describes release 0.4.1. If you install 0.4.2:
- Remove the older extension in Claude Desktop first: 0.4.2 installs beside an older one instead of replacing it (seen with 0.4.1 on a Mac and expected for earlier versions; not tried on Windows). Keep ComplyEaze Bridge’s data folder, which both versions use.
- Enter your settings again, including the Terms setting, which every tool needs. Posting starts off, and Response redaction starts at none, so set it again if you had shortened or masked names.
- Its posts no longer tag the narration, and it matches a posted voucher another way. Check what it posted with
verify_import, nevervoucher_presence, before entering anything again by hand. The one-voucher post the extension makes has not been run live with this matching. From the first post 0.4.2 sends to Tally, even one Tally refuses or never answers, do not run 0.4.1 or earlier on that computer: they stop preparing, posting and checking vouchers. - If you asked 0.4.1 or earlier to read a ledger, such as its movement or vouchers, by a name that differed from its spelling by a symbol, an accent or words run together, the figures may be for a different ledger with the same letters and digits. Ask again with 0.4.2.
The changelog has the rest.
93%
of permission prompts that Claude Code users approve
Anthropic, “How we built Claude Code auto mode”, 25 March 2026. Anthropic ties it to approval fatigue.
About 2 in 3
decisions right in a small browser game about spotting harmful commands, over 40,000 runs, played under artificial time pressure
11.7% obviously destructive commands, to 35.0% scope violations
scalex.dev; its author says it is “not an academic study”.
We have no figure for our own window. As far as we know ComplyEaze Bridge sends us nothing, so we cannot measure it in the field.
This is what we built, and what it costs.
ComplyEaze Bridge is an Apache-2.0 MCP server and Claude Desktop extension for TallyPrime. TallyPrime has a local XML gateway that can import vouchers, so a tool that calls it can post to someone’s books. By default the extension reads, prepares voucher files and reads bank-statement PDFs. Posting is a separate setting, off for a new install. When it is on, the assistant prepares a voucher file, calls post_import, and a native window on the user’s computer asks a person to approve that one voucher.
Our evidence is thin. On 1 October we installed a candidate build of 0.4.0 on a Windows 11 computer, with a new Claude account that had no paid plan and TallyPrime Silver 7.1 holding one made-up company. We declined one post in the approval window, and nothing was sent. We approved another. One Journal was posted, and the read-back found it. That was one run of one candidate build. The README records what ran on other builds.
What the assistant reads through ComplyEaze Bridge goes to the AI provider the user chose: company, ledger and party names, GSTINs, PAN and bank details, narrations and amounts. Claude Desktop sends it. A masking setting shortens party and ledger names or drops narrations, and nothing hides amounts. We do not receive Tally data through ComplyEaze Bridge, and our Privacy Policy says so. We found no upload in the code we read (release 0.4.0, re-read for the 0.4.1 changes to network destinations). That is our reading of the code, and we do not warrant it (Terms, section 13).
1. With posting off, the posting tools are absent
Turn the setting and restart: what the model can see.
- Read and prepare tools always listed in the extension
post_importtries to post one voucher after a person approves itacknowledge_post_reviewrecords a review; writes nothing to Tally
With posting off, the two posting tools leave the tool list, and if something calls them anyway, they refuse.
With posting on, the assistant prepares a voucher file, calls post_import, and a native window on the user’s computer asks a person to approve that one voucher.
acknowledge_post_review writes nothing to Tally; it records a review. The model has no posting tool to try. An earlier install may have saved the setting as on, so check it after an upgrade.
2. Approval is a window, and no ComplyEaze Bridge tool can answer it
The extension starts a second copy of itself to show a system dialog.
ComplyEaze Bridge — post this voucher?
Create ONE Receipt in "Demo Traders Pvt Ltd (synthetic)" Company GUID: 3f9a6c1e-52b7-4d08-a1e4-7b20c9d5e386 Company number: 200417 Books from: 20250401 Tally: http://127.0.0.1:9000 Date: 20260312 Voucher number: Tally assigns it Reference: (none) Narration: (none) Dr 124600.00 "Example Bank Ltd" Cr 124600.00 "Nevrika Agro Foods" Total debit: 124600.00 Total credit: 124600.00 Checked in Tally: every Dr ledger is bank/cash; every Cr ledger holds no money. Batch: bridge-8e41d2a7-0c6b-4f93-b5a8-1d7e93c04f26 Ledgers checked by identity against the build; ComplyEaze Bridge adds its batch reference. Do not post a file already imported manually. Pause other edits/imports; keep this company and Tally mode as is until ComplyEaze Bridge finishes. After a timeout, reconcile this batch; do not rebuild or resend it. ComplyEaze Bridge posts now or if asked again within 15 min, unless cancelled, refused or restarted.
On macOS
ComplyEaze Bridge — approve one voucher
with the buttons Cancel and Post voucher (labels as the code sets them; on-screen order not shown)
- A fresh one-time token per window; only the positive button returns it.
- Two minutes without an answer, and the window closes itself.
- Held in memory, used once, and dropped fifteen minutes after the click or on restart.
The descriptions of post_import and acknowledge_post_review tell the model that it cannot approve.
What the approval window shows, and what stops it opening
- Before the window opens, the approval text is refused, and nothing is posted, if the company name, voucher number, reference, narration or a ledger name contains a control character, a line or paragraph separator, or an invisible format character.
- It is also refused if it runs over 1,600 characters, 24 lines, or 100 characters on one line, so one voucher stays reviewable in a native window.
- Names and the narration appear in quotes, as written apart from an escaped quote mark or backslash. The window cannot tell whether what a narration says is true.
- Its last line says when the approval is spent: now, or if the assistant asks again within fifteen minutes, unless the assistant’s request is withdrawn, the post is refused, or ComplyEaze Bridge restarts.
From agent_import_post.rs and agent_import_approval.rs at release 0.4.1.
Software that can click on the screen can press the button, and a desktop-control connector in an assistant is such software. Our Privacy Policy says not to let it run while a posting is waiting, and our Terms (9.4) say we are not responsible if software acting for a user gets around the window. The window also cannot tell whether the entry is right. It shows what will be posted. The person who approves is responsible for it (Terms 9.3), except where what is posted differs from what it showed.
3. The Tally transport accepts a local address and nothing else
The Tally transport in our own code accepts a loopback address or localhost, uses no proxy, follows no redirects, and refuses anything else (bridge-tally-transport). That costs us remote Tally and Tally Cloud Access. A local port that someone forwards sends traffic wherever it was forwarded. We have not taken a network capture of the running extension.
One path outside the transport, found in our own code
We found one exception ourselves, by reading the code. We published it as an advisory and fixed it in 0.4.1. In 0.3.0 and 0.4.0 the bank-statement tool opened any absolute path it was given, including a Windows network path. That is the operating system opening a file, so our transport checks did not see it. Windows may then send the signed-in user’s network sign-in response to that computer. No Tally data is sent. It needed the assistant to be steered into the path, the user’s approval of that call or an always-allow setting, and outbound file-sharing traffic to that computer. 0.4.1 refuses these forms as text before opening anything, but some forms can still pass (the security page lists them), and we have not measured the PDF library’s behaviour. We had checked our own network client. We had not checked the paths a tool opens.
4. A local log of every result
Each result ComplyEaze Bridge returns, read or write, successful or refused, gets an entry in a log on the user’s computer. It holds the time, the tool, Tally’s internal code for the company, counts, sizes, and fingerprints of the request and the result. It is designed to hold no amounts or names, though sizes can hint at a name’s length. It is an ordinary local file that anyone with access to the computer could alter, so treat it as the user’s own record. A separate journal holds every batch prepared or posted, unmasked, and is how ComplyEaze Bridge refuses to send the same batch twice. Nothing is deleted automatically. The Privacy Policy (section 7) says how to archive it.
What is still weak
- A post can land in the wrong company or ledger.
- Tally aims an import at a company by name and cannot bind it to a company’s GUID. In its last request before the post, ComplyEaze Bridge checks that exactly one loaded company has the target’s GUID and name and that no other loaded company has the same name ignoring case and spacing. A company renamed or loaded in the moment after that check could still receive the voucher if it has the voucher’s ledgers, and a ledger renamed and replaced in that moment could receive the entry. The README lists this among the limits of posting.
- There is no undo.
- No tool deletes or reverses a posted voucher.
- Read-back is partial.
- It compares date, voucher type and ledger entries, not every field, and a match is no check of correctness.
- One voucher per approval.
- A batch setting exists in the server program. The published extension does not set it.
- Tally can slow down.
- Requests can make Tally slow or unresponsive, sometimes until it is restarted, including for other users of a shared Tally. Reads on very large books can fail or take longer than the assistant waits.
Nobody independent has audited it.
What we have not run
The release check confirms that each package launches, lists its tools and parses a synthetic encrypted bank statement. It does not run against TallyPrime. The README lists what we have run against a real TallyPrime, on which edition and operating system. It also lists what we have not run in a controlled test:
- posting with a published package against a live TallyPrime
- each way of declining in the Windows approval window (we tried one)
- the tools answering through Claude Desktop on macOS after the Terms are accepted (
tally_statusandlist_companiesanswered once, on a CI build of 0.4.1) - posting on TallyPrime Education
- posting on TallyPrime Gold with its approval step recorded
We have also not yet run the published 0.4.1 file in Claude Desktop.
Try it, and tell us what breaks
It is Apache-2.0. We publish it for Windows x64 and Apple Silicon Macs, and it is not yet code-signed. The download and install guide are on the Download page, and the source is at github.com/ComplyEaze/bridge. If you reproduce any of this on another TallyPrime edition, or find a problem in the approval design, open a GitHub issue. If you find a vulnerability, report it privately, as SECURITY.md explains.
Nothing here is accounting, tax, audit or legal advice. ComplyEaze Bridge is not a product of, or endorsed by, Tally Solutions, Anthropic or ICAI. Email contact@complyeaze.com · Questions and answers · Download and release notes · Source on GitHub · Security and privacy · Security policy
Read next
Where your client’s data goes when Claude reads Tally
When you ask Claude about a client’s books, what Claude reads goes to Anthropic. That can be party names, narrations, GSTINs and amounts. A setting can shorten the names. Nothing hides the amounts.