Karbon, Microsoft 365 and SharePoint, a CRM where the firm runs one, selected tax systems, and document stores. Each separately governed, and activating a connector is not blanket permission to read it.
Updated July 2026
One accounting job rarely lives in one application. Proxara Connect draws the exact context an approved piece of work needs from the systems the firm already runs, then acts back through those same systems. Each connection stays separately governed, and activating one is not blanket permission to read it.
| System | What a definition may select |
|---|---|
| Karbon | Work items, document requirements and Integration Tasks, assignments, notes, work status, contacts where the provider supports them, and file metadata |
| Microsoft 365 | Outlook mail and calendar, Teams messages, OneDrive and SharePoint files and their metadata, and To Do and Planner tasks |
| A CRM, where the firm runs one | Client relationship, service, case and task context. Salesforce is one supported option, and no CRM is required by the accounting product |
| Selected tax systems | Client, engagement and return identity, period and jurisdiction, form and schedule state, filing and review status, diagnostics, workpaper and source-document references, and mapped input fields |
| Document stores | Files and their metadata, admitted through document ingress |
Which of these a firm connects is the firm's decision. Each connection is separate, and none is a precondition for another.
Authority is assigned to an exact source capability, for one role, inside one approved kind of work, at one revision. A provider does not become the firm's policy authority because its connector is active, and a system that supplies a role in one approved kind of work supplies nothing in another.
The definition names the role it needs. A versioned normalizer translates the provider's records into that role's neutral facts, so requirement, evidence, scope, relationship and status semantics belong to the firm rather than to one vendor's field names.
Every connection carries:
Several connections to the same provider family can coexist. No firm-wide switch stands in for a source.
Every Microsoft permission Proxara requests is delegated. Every read carries the signed-in employee's own credential, and there is no application-only permission anywhere in the read path.
The granted set is held by two independent checks: the infrastructure definition refuses to build an environment whose permission list falls outside the reviewed set, and the setup runner fails the run if the environment it has just built reports any other set. Acting is a separate consent. The consent screen the administrator approves is the authoritative list, and For the Microsoft administrator shows it as written.
Each read and each write is a pinned descriptor for that provider, proven against its actual contract. Where a tax system exposes no safe supported write for a change, the result is a review artifact the preparer can act on rather than a fabricated mutation. A generic create-or-update tool pointed at a tax engine is refused.
An absent system produces an honest partial result: what is known, which source is missing, which conclusion cannot be drawn, and what resumes when authority returns.
| To understand | Read |
|---|---|
| What authorizes a system to be consulted at all | Approved work |
| How files and scans are read and accounted for | Documents and coverage |
| Where each part of the work runs | Where each part of the work runs |
| How a change is committed and confirmed | Execution and verification |