Skip to content
Candor

Read-only finance AI: what your agent can see in Candor, and what it can never do.

Candor is read-only toward your bank. Your agent, whether Claude, ChatGPT, Grok Bot, Meta Muse, or another, can read your balances, transactions, holdings, and debts, and can save the budgets, goals, notes, and decisions you approve. It cannot move money, pay a bill, trade, or cancel a service through Candor, because Candor has no tool that does. This page covers that boundary in detail: sign-in, access, logging, training, and how to leave.

How it works with your agent

  1. 1

    You connect accounts through secure, bank-grade sign-in. Your bank password never reaches Candor or your agent.

  2. 2

    You approve your agent's access in the browser, and can disconnect it from the Agents page at any time.

  3. 3

    Your agent reads records and saves what you approve. Every read and write is logged with its reason.

  4. 4

    Anything that changes the outside world happens through your agent's own tools, with your approval.

What does read-only mean in Candor?

Candor never changes anything at your bank. Your agent can read balances, transactions, holdings, debts, and recurring payments, and can save workspace records you approve: budgets, goals, notes, decisions, and corrections. It cannot move money, pay a bill, trade, open or close an account, or cancel a subscription through Candor.

Read-only describes the direction that matters: nothing flows from Candor to your institutions. Inside the workspace your agent does real work. It keeps the budget you agreed on, fixes a mislabeled merchant, records why you kept a charge, and notes a refund to check next month. Those records are what let the next conversation, or a different agent, start where the last one ended.

The read-only line
  • Your agent can, in Candor
    Read balances, transactions, holdings, and debts
    No one can, through Candor
    Move money
  • Your agent can, in Candor
    See recurring payments and price changes
    No one can, through Candor
    Pay bills
  • Your agent can, in Candor
    Read the short list of what needs a decision
    No one can, through Candor
    Trade
  • Your agent can, in Candor
    Save budgets, goals, notes, and decisions you approve
    No one can, through Candor
    Open or close accounts
  • Your agent can, in Candor
    Export your organized data when you ask
    No one can, through Candor
    Cancel subscriptions

Can AI move my money through Candor?

No. Candor ships no tool that moves money, pays a bill, trades, or cancels a service, so no agent, bug, or attacker can do it through Candor. When a decision needs action, such as cancelling a subscription, your agent does it elsewhere with its own tools and your approval. Candor keeps the decision so your agent can confirm later that the charge stopped.

A policy can change quietly. A missing capability cannot be misused. That is why Candor holds the facts and the follow-up, and leaves action with the agent you already trust, under the permissions you already gave it.

In practice the split looks like this: Candor keeps the list of what needs a decision, with the figures behind each item. Your agent brings it to you. You decide. If the decision needs action outside Candor, your agent asks you before it acts, and the decision stays in Candor so the next check-in can confirm it happened.

How does bank sign-in work, and who sees my password?

You connect accounts through secure, bank-grade sign-in in your browser. You enter your credentials on the linking screen, and Candor receives a revocable connection, not your password. Neither Candor nor your agent ever sees your bank login, and the connection's credentials never enter the CLI, local files, browser storage, or agent prompts.

The access credentials for each bank connection stay in Candor's backend. The CLI on your own machine keeps only its own Candor sign-in: on macOS and Linux in a credential file only your user can read, or in the system keyring if you set CANDOR_CLI_CREDENTIAL_STORE=keyring; on Windows in the native credential store.

What does my agent's access actually include?

Only what you approve in the browser. When your agent connects, Candor shows what it is asking for: reading your workspace, keeping budgets, goals, notes, and corrections, refreshing the accounts you connected, and staying connected in the background. Connecting or removing accounts stays with you in Candor. You approve once, and you can disconnect it later from the Agents page.

Access is granted to an agent client, such as a Claude connector or a CLI install, not to each individual process. Any agent that can use that approved client can read within its scope, so disconnect clients you no longer use.

You also choose what goes in. Candor only sees the accounts you connect or the statements you import. Leave an account out and no agent sees it through Candor.

Is every read of my financial data logged?

Yes. Every operation your agent runs in Candor, including every read, is recorded as an entry that cannot be edited, with its reason, and kept for as long as your workspace exists. You can review that history on the Activity page. The log says what kind of data was read, when, and why, without copying your raw financial data into it.

Reasons are the agent's own words, such as checking whether a price increase has been billed again. They make the history useful to you and to the next agent: you can see what was looked at and why. A reason is not approval. Anything that needs your decision still comes to you.

Does Candor train AI on my data or sell it?

No. Candor never sells your financial data, never uses it for advertising, and never trains models on it. When Candor uses outside services to organize transactions, they run under zero-data-retention settings. What your agent reads from Candor then follows your agent's own settings, such as ChatGPT's Data controls or Claude's Model Improvement setting.

That last point is worth acting on. Candor controls what Candor stores. The conversation where your agent discusses your figures lives in ChatGPT, Claude, Muse, or wherever your agent runs. OpenAI says ChatGPT finance chats follow your training setting, Anthropic uses Claude consumer chats for training when Model Improvement is on (and may use a chat flagged for safety review to improve Usage Policy enforcement), and Meta lets you opt out for Muse. Set those the way you want.

How do I revoke access or delete my data?

Disconnect any agent from the Agents page, and it can no longer read your workspace. Export your organized data from Settings. Delete your account from Settings, which disconnects your institutions, revokes all agent access immediately, removes bank connection credentials, and deletes your workspace, including records, notes, and history.

Disconnecting a single bank ends Candor's access to it and keeps the history you already have, unless you delete your data. Revoking an agent keeps your workspace intact, so approving a different agent later picks up where you left off. Managed backups expire on their own schedule, up to 14 days, and the privacy policy lists every retention period.

Why is read-only enough for a financial advisor's job?

Most of what a careful advisor does is reading, remembering, and arithmetic: noticing a price increase, idle cash while a card charges interest, or budget drift, and raising it with the figures. Candor does that review and keeps the list. Your agent brings it to you, you decide, and any action runs through your agent with your approval.

Candor is not a licensed advisor and gives no advice. Your agent makes suggestions from the figures, and you make the call. Keeping action outside Candor is what makes it reasonable to give an agent a complete view of your money.

Common questions

Is read-only enforced, or just promised?
Enforced by what Candor ships. Candor has no tool that moves money, pays bills, trades, or changes anything at a financial institution, so read-only does not depend on an agent behaving well. There is nothing in Candor for it to misuse.
What can my agent write to Candor?
Only workspace records you approve: budgets, goals, notes, decisions, category corrections, and confirmed recurring payments. Each write is logged with its reason. None of it reaches your bank.
Is ChatGPT Finances read-only too?
OpenAI says ChatGPT's Finances connection cannot see full account numbers or make any changes to your accounts. The differences are elsewhere: it works only inside ChatGPT, keeps no log of what it read, and your chats follow your ChatGPT training setting.
Can I choose which accounts my agent sees?
Yes. Candor only holds the accounts you connect or the statements you import. Leave an account out and no agent can read it through Candor. You can disconnect an institution later without deleting your history.
What happens when I revoke an agent's access?
It stops working at once. Your records, budgets, goals, notes, and history stay in your workspace, so approving a different agent later, or the same one again, starts from everything already saved.

Sources

  1. Privacy policy Candor
  2. Trust and data controls Candor
  3. A new personal finance experience in ChatGPT OpenAI, June 25, 2026
  4. Is my data used for model training? (Claude consumer plans) Anthropic, March 16, 2026
  5. Introducing Muse Meta, September 8, 2026

Let your agent see the full picture.

Create your Candor account and connect your accounts. Then copy one setup message into the agent you already use and approve its access.