Create the machine user
- In Procountor, go to Management → Users and user rights.
- Add a user dedicated to the Control integration. Use contact details monitored by your organization, not an individual employee’s personal details.
- Set the rights in the table below to Viewing rights. Add the conditional rights only for features enabled on this data source.
- Do not grant payment execution, approval, or unrelated write permissions to the machine user.
- If Procountor shows the Allow only M2M login to API limitation, enable it for this user.
A standard accounting or payroll role can be a starting point, but review its rights before using it. Payroll access
is only needed when salary data import is enabled in Control.
Rights required
Do not enable limitations such as Access only … created by user or Access only personal salaries. Those
limitations would hide company-wide records from the integration.
Create the API key
- Sign in to the intended Procountor environment as an administrator.
- Open Basics from the person icon in the upper-right corner, then choose API client keys.
- Choose New API key.
- Select the dedicated Control machine user.
- Enter
FinataClient, Control’s Procountor client ID. - Choose Create.
- Copy the API key immediately.
Connect in Control
- Open the Procountor data source in .
- Paste the generated value into Procountor API Key.
- Save and verify the credentials.
Data imported
- General-ledger receipts and their transaction rows
- Chart of accounts and dimensions
- Sales and purchase invoices, invoice rows, payment events, and payments when invoice import is enabled
- Employees, persons, and salary types when salary-data import is enabled and the machine user has payroll access
Common problems
Paid APIs are not enabled
If verification says the company does not allow paid APIs, go to Management → Company info → Usage settings → Integration settings, allow invoiceable API clients, and try again. This setting is independent of the machine user’s rights. Both must be configured; disabling invoiceable API clients stops an otherwise valid connection.Some data is missing
Review the machine user’s rights in Management → Users and user rights. Make sure it has read access to every data category enabled for the Control integration, then verify the credentials and run the sync again.Wrong company data appears
Confirm that the machine user and API key were created in the intended Procountor environment.Optional: enable native write-back
Control can post AI-proposed journals back to Procountor after an Owner or Admin approves them. The write path uses a separate machine user and API key from the read/sync credential above, so it can be revoked independently. Grant the write machine user the rights to create ledger receipts in Management → Users and user rights → Accounting. Do not grant sending, invalidation, or payment execution rights. Control creates journals with statusUNFINISHED
only; a person still opens each journal in Procountor to finish it.
Configure the write credential in .
See Write-back approvals for the proposal, review, and
reconciliation flow.