For tax, bookkeeping and accounting firms
AI help with the office work, on a machine your firm controls
For US firms of 2 to 20 people where an owner reviews what goes to clients. AI employees draft the routine work, a person in your firm approves it, and every decision is logged. With local models, model calls can stay on hardware your firm runs.
Not legal advice
We are not lawyers, and nothing on this page is legal, tax or compliance advice. Nothing in Agent Office makes a firm compliant with any rule. It can help you meet some of them, and its audit log, approvals and data policy are evidence you can show. Ask your own adviser how the rules apply to your firm.
The rules you already work under
- The FTC Safeguards Rule covers tax preparers. The FTC's guidance asks for, among other things, access controls, multi-factor authentication, encryption, monitoring and logging of authorised users' activity, oversight of service providers, and an incident response plan. A firm that holds information on fewer than 5,000 consumers is exempt from some of the requirements, among them the written risk assessment and the written incident response plan; ask your adviser whether that applies to you. (FTC guidance)
- Section 7216 of the Internal Revenue Code restricts disclosing or using tax return information without the taxpayer's consent, and the consent must say who receives the information. Practitioners have written that typing tax return information into a third-party AI tool is a disclosure that needs such a consent. (Rev. Proc. 2013-14; Gorczynski and Youngblood, March 2026)
- A written information security plan. The IRS reminds tax professionals that federal law requires one. (IRS reminder, August 2026)
- Review of AI output. The IRS Office of Professional Responsibility's first guidance on AI, in June 2026, expects practitioners to review what AI produces and to keep taxpayer data off public or unsecured AI tools. (Journal of Accountancy report)
How Agent Office fits, today
What the platform does in this release, and the evidence it keeps. All of this works with any company pack.
| What the rules ask for | What Agent Office does | Evidence on the machine |
|---|---|---|
| Multi-factor authentication | Two factors for every human sign-in, in every mode. Onboarding cannot finish without the owner's authenticator. | Second-factor enrolments, failures, lockouts and resets in the audit log |
| Access control | Roles come only from a root-owned file on the machine. Five guard tiers; owner actions need a PIN for each action. | The instance file; every decision in the audit log |
| Logging of authorised users' activity | One hash-chained log of every state change, owner decision, credential use and send, anchored hourly into a root-owned file. | The Audit page and its export; ao audit verify |
| A person reviews AI output before it reaches a client | Every message class starts at approve. You approve the exact text, and the sender refuses anything that changed. | Each approval, with who approved it, in the audit log |
| Oversight of service providers | You choose every model provider, and the data policy decides which may receive which data. Web search goes to the search service you configure; with none configured, to free public search services you did not choose, so configure one or turn web search off. The security summary lists everything that leaves the machine. | ao infer export: providers, models and policy, without secrets |
| An incident response plan | Your incident plan is yours to write; the kill switch and the audit export are tools it can name. The kill switch has three levels, and any signed-in member can engage it in one step. | Kill-switch events in the audit log and the system journal |
| Encryption | Credentials, authenticator keys and inbound message text are encrypted by the application. The disk is yours to encrypt. | Credential names, status and fingerprints on the console's Credentials page; values are never shown |
Local models: model calls that stay on hardware you run
With a model server you run registered as a local provider, the gateway's data policy can admit local models only. Model calls through the gateway then go to a model server you run, not to an outside AI provider. Whether that avoids a disclosure under your rules is a question for your adviser; no IRS guidance addresses it.
- Other ways data can leave. Turn web search off for any employee that reads client material, and read the known gaps: one route around the gateway is still open in this release.
- A limit of this release. The machine cannot yet prove which service is listening on a local port, so every local model server reads as attested (stated by the owner), not verified. The starter packs' strictest floors require verified, so a local-models-only install has to loosen them, an owner action with the PIN.
- The hardware. A machine that holds a capable model needs a graphics card with 24 GB of memory or more. It can be the Agent Office machine or a separate model host on your network; either way, keep it on hardware your firm controls. See hardware for dated examples and pricing for what the first year costs.
Cloud models instead? Send client material to a cloud provider only after you hold each client's consent naming that provider, in the form your rules require. The data policy can limit calls to zero-data-retention deployments in the regions you choose.
Coming
An accounting-firm pack Coming
We are writing a company pack for small tax, bookkeeping and accounting firms. It is not released yet. It is planned to cover five jobs, each as drafts a person in the firm approves, working from files you put on the machine (client lists, checklists, templates) rather than new connections to your other systems.
Missing-documents chaser
Reminders naming each client's outstanding items, follow-ups at your interval, stopping when you mark items received. It is designed never to ask for identifiers by email, and to point clients to your portal instead.
Status notes and a weekly summary
A weekly summary for the owner of who is waiting on what, and short client notes such as "we have your documents; your return is in review", with no figures.
Onboarding packages
Your own engagement-letter and organizer templates filled in for a named client, with scope and fees only from your fee schedule. Designed to be always a draft for professional review, never sent by the AI.
Inbox triage
Incoming client mail sorted into documents received, questions for a professional, tax-agency notices, billing and scheduling. Every notice and every tax question will go to a person.
Deadline and close calendar
Filing, extension and estimated-payment dates from a list you keep, and a month-end close checklist per bookkeeping client. It will not work out due dates or amounts.
What the pack is being designed never to do
- Give tax, accounting, legal or investment advice, or tell a client what they owe or will get back.
- Prepare, sign, file or transmit any return, form or election.
- Move money, take payments or change bank details.
- Answer or contact the IRS, a state agency or anyone's lawyer: those messages go to you.
- Ask a client to send a Social Security number, bank number or IRS PIN by email or text.
- Send anything to a client before a person in your firm approves it.
Until the pack is released, you can evaluate the platform itself with a general starter pack and your own templates.
Evaluating as a tax or accounting firm
Evaluate with fictional client data on any model, or with real client data on local models only, with web search turned off for the employees that read it. Never send real client material to a cloud model during an evaluation unless you already hold consents that name that provider. The evaluation terms say the same for any regulated business.
Have an IT provider? They can install and run the evaluation for you, on a machine your firm owns or controls. See IT partners.