Pleo say it plainly, which is more than most do — expense data including the names of colleagues on those expenses is processed by whichever AI provider you connect, under that provider's terms, possibly outside the UK and EU. That is a finance-team decision, not an individual one, which is presumably why the switch is an admin toggle per entity rather than a user setting. The permission inheritance is the right model; the disclosure is the thing to actually read.
Pleo's hosted endpoint over their company card and expense platform. Included with eligible Pleo plans at no extra charge, though the docs do not name which plans qualify.
Read and write access to the spend data the connecting user can already see — the agent inherits that user's permissions and nothing more. It cannot alter company setup or configuration.
- An admin has to enable it first: Settings, General, Pleo AI, MCP access — per entity, and off until they do
- OAuth 2.0 with PKCE and dynamic client registration for the connection itself
- A user can revoke their own connection under My Account, Security and Devices, MCP Connections
Paste a URL, then authorize — add the endpoint to your client, then approve the OAuth consent screen