Claude for Canadian Tax Preparers: What It Can Do This Season, What It Cannot, and How to Set It Up Safely

Every week now a preparer asks us some version of the same question: can I use Claude for tax prep? The honest answer has three parts, and most of what has been written on the subject gives only one of them. Claude cannot prepare or file a Canadian return, and it must never be handed a CRA credential. Claude can do a large share of the work that happens before the return, from reading a client's slips to drafting the follow-up email, and firms are already using it that way. And the setup decisions a firm makes in September, about which plan, which data, and which connectors, matter more than anything Claude itself does.

This guide is the version we would hand a Canadian T1 practice that asked. It is written from our own runs, on live systems, over the 2025 filing season and the months since, and it is organized as five levels of setup, from Claude in a browser tab to Claude connected to a system of record for intake. We build one of the tools in the last level, and we say so where it comes up. The first four levels do not need it.

"Claude" here means the Claude apps a firm can subscribe to, on the web, on the desktop, and in Chrome and Excel. Everything below reflects Anthropic's published plans, terms, and documentation as of September 2026, with links; these change often, and we will refresh this page in January before slips start arriving.

The short answer

Claude cannot EFILE. It cannot run Auto-fill my return. It cannot sign in to a CRA account or to Represent a Client, and it should never be asked to, for a reason that has nothing to do with capability: the CRA's terms of use for its sign-in services prohibit scripts, robots, screen scrapers and any other automated device, and prohibit sharing credentials. A preparer who lets an agent drive a CRA session has broken the terms the firm accepted, whatever the agent managed to do. Calculation and filing stay in CRA-certified software, operated by a person who is signed in.

What is left is most of the season. Reading what a client sent. Noticing what they did not send. Turning a shoebox of receipts into a table. Reconciling a self-employed client's books against what they reported. Drafting the email that asks for box 24 from the missing T4. Explaining a notice of assessment in plain language. Keeping track of which of two hundred files is actually complete. Claude can do each of those today, at a level of reliability that depends almost entirely on how it has been set up and what it has been given to read.

Three rules run through everything that follows. Claude never holds a CRA credential. A qualified person reviews anything that reaches a client or a return. And every figure Claude reads from a slip gets read from the slip itself, not from a summary of it.

Which Claude, and what happens to client data

Before any of the levels below, a firm has to pick a plan, and the plan determines what happens to client data. This is the decision most firms get wrong by not making it.

Anthropic sells Claude to individuals on Free, Pro and Max plans and to organizations on Team and Enterprise plans; the plan comparison has current prices, which are quoted in US dollars. The differences that matter to a tax firm are not the usage limits. They are the data terms.

On the individual plans, each user chooses whether their conversations may be used to improve Anthropic's models, and the choice sets the retention period: conversations are kept for five years if model improvement is allowed and thirty days if it is not, per Anthropic's training-data policy. A preparer on a personal Pro account who never opened that setting may be handing client slips to a training pipeline and keeping them for five years. On the Team and Enterprise plans, Anthropic states that inputs and outputs are not used for training by default, deleted conversations are removed from back-end storage within thirty days, and Enterprise owners can set a custom retention period with a thirty-day minimum. Team requires a minimum of two seats.

Our recommendation is plain: client data goes through a Team or Enterprise account, never through a personal one. If a preparer is going to use a Pro or Max account for anything touching a client, the model improvement setting is turned off first, and the firm accepts that it is relying on a consumer plan's terms for professional data.

Two more facts belong in the firm's file. Anthropic publishes SOC 2 Type II, ISO 27001 and ISO 42001 attestations through its trust portal, which answers the question a client or an insurer will ask. And there is no Canadian data residency option for the Claude apps: processing is global, Enterprise can restrict inference to the United States, and Canadian-region hosting exists only through the cloud platforms that resell Claude, per Anthropic's regional compliance page. Firms with a residency requirement in their engagement letters need to know that before September, not in March.

None of this is legal advice. A firm's obligations under privacy law and its professional body's rules are its own to confirm, and the point of this section is that the plan choice is where those obligations are met or missed.

Level 1: Claude in a browser tab

No connectors, no setup beyond an account. This is where most preparers start and it is where the most damage is done, because it is where Claude is asked to know things instead of read things.

What it does well is language work with material you give it. Paste a CRA letter and ask for a plain-English summary and a list of what the client has to do. Paste last year's engagement letter and ask for a version that adds an AI disclosure paragraph. Give it a client's emailed list of medical expenses and ask for a table with dates, payees, amounts and who the expense was for. Draft the seasonal email that goes with the T1 client questionnaire. Rewrite the follow-up that asks a client, for the third time, for their RRSP receipt, so it reads as helpful rather than exasperated. Explain the difference between a T4A and a T4A(P) to a client who has just retired.

What it does badly is answer tax questions from memory. Ask Claude a hard question about the 2025 rules and it will answer fluently, and a meaningful fraction of the time it will answer with a threshold from 2022, a credit that has been repealed, or a form number that does not exist. The digital news subscription credit ended after 2024 and still turns up in answers. The RRSP deadline for the 2025 return was March 2, 2026, not March 1, because the sixtieth day fell on a Sunday, and Claude will not know that unless told. The fix is not to stop asking; it is to change what you ask. Paste the CRA page and ask Claude to apply it. Ask it to draft the question you should look up rather than the answer. Treat every rule it states as a claim to be checked against canada.ca, the way you would treat a junior's memo.

Slips are the other hazard at this level. Claude can read an image of a T4 and pull the box amounts, and it usually gets them right. Usually is not a standard a return can carry. Anything with box numbers on it gets read from the original file, gets checked by a person, and gets recorded somewhere the firm can audit, which is the argument for the levels that follow.

Level 2: Claude with your documents

The Claude desktop app is available on every plan, and on the paid plans it comes with three things that change the job: connectors to where your documents already live, Cowork for multi-step work, and Claude in Chrome for the systems that have no other door.

The Google Drive connector and the Microsoft 365 connector are generally available on all plans and let Claude search and read a client's folder in Drive, SharePoint or OneDrive, read the Outlook thread where the client explained the condo sale, and, with write access enabled by an administrator, save a summary back to the folder. A firm that keeps one folder per client per year already has the document layer an agent needs. We covered what each connector does and does not do on the Google Drive and Microsoft 365 pages.

One lesson from our own build carries over to every Drive or SharePoint setup. When we ran intake against a Google Drive folder, the connector's text extraction was fine for letters and not fine for slips; a misread box on a T5 is a wrong return. The agent was told to fetch the file itself for anything with numbers on it, and it should be told the same at your firm.

Cowork, on the paid plans, is where Claude stops answering questions and starts doing tasks: sweep this client's 2025 folder, list every document, identify each one, tell me what is missing against last year, draft the follow-up. It runs in an isolated environment on Anthropic's servers, reaches local folders only while the desktop app is open and only in the folders the user granted, and can be scheduled to repeat. Claude in Chrome, also on the paid plans, lets Claude work inside a web app in the preparer's own logged-in session; we ran intake for a firm whose practice management system has no API at all through Claude's own browser in exactly that way. It is slower and more brittle than a connector, and it is never used on a CRA site. Claude for Excel, for the working papers, comes with Anthropic's own caution against client deliverables without human review, which is the right caution.

What Level 2 does not give you is memory of what any document means. Drive knows it holds a file. It does not know the file is a 2025 T4 from a specific employer with box 24 blank, or that the T3 the client is waiting on has not been issued yet. Every question Claude answers at this level, it answers by re-reading the folder.

Level 3: Claude with your clients' books

For self-employed and rental clients, the numbers that end up on the T2125 or T776 live in Xero or QuickBooks Online, and both now have a door an agent can use.

Xero ships an official MCP server that runs locally and works with any MCP client including the Claude desktop app, plus a hosted Claude connector that is read-only and available to Canadian subscribers. Intuit ships an official QuickBooks Online MCP server, labelled early preview, and a hosted Claude connector that is currently restricted to US customers, so Canadian firms use the local server. Either way, an agent can pull the calendar-year profit and loss, reconcile it against what the client reported on the questionnaire, list the transactions behind a suspicious category, and flag what a preparer should look at before anything is keyed into the return. The details, with sources and the September 2026 status of each, are on the Xero and QuickBooks Online pages.

Local MCP servers are added in the Claude desktop app under Extensions, and on Team and Enterprise plans an owner controls which ones users may enable, which is the right place for that control to sit. Neither Xero's nor Intuit's server touches Canadian tax software; TaxCycle and ProFile have no MCP servers, and the scoreboard explains what each Canadian package offers instead.

Level 4: Claude with your practice management system

This is where the season is actually managed, and it is the level where the vendors are furthest behind their announcements. Karbon announced a public MCP server in June 2026 and has not shipped it, but its REST API is documented and complete enough that we have already run T1 intake through it, with missing documents turned into Karbon client requests. TaxDome has promised MCP support by the end of the third quarter of 2026 on an API that is still in private beta. Jetpack Workflow has no API, and we ran the full loop anyway through Claude's browser and Google Drive.

The practical advice for September is to check the current status of your platform on the Karbon, TaxDome or Jetpack Workflow page, and to design your process so that the platform holds the work and the client conversation while something else holds the tax facts. When the MCP servers ship, the agent's calls change and the process does not.

Level 5: Claude with a system of record for intake

Everything above shares a gap. The documents live in one place, the work in another, the client's answers in a PDF, and the tax facts in nobody's system until a preparer keys them into the return. Claude can read all of it, and it has nowhere to put what it learned that the firm can audit, that carries the source document, that refuses a box it does not recognize, and that knows when a file is actually complete.

That is the layer we built. Armada T1 is the system of record for Canadian T1 intake, with its own MCP server, and an agent connected to it does the intake job end to end: it reads each slip and receipt as it arrives, records the figures as validated section records with the source stored alongside, rejects unknown fields by name, reconciles against what the file expected from last year and from the questionnaire, and routes each open question as a task to the preparer or to the client. A file cannot move to ready-to-prepare until a completeness check passes, and the check names every open item when it refuses. Every agent acts as a named, revocable user; SINs are stored encrypted and read back masked; only a person can dismiss a blocking task. Armada T1 does not calculate or EFILE returns, it never asks a firm for a CRA credential, and the completed file is handed off to the CRA-certified tax software the firm already runs.

In practice a firm at Level 5 runs Claude the same way it did at Levels 2 through 4, with one more connector, and the difference shows up in March: the question "which files are actually ready" has an answer that nobody had to assemble. If you want to see it against your own files, request access.

What to put in writing

Three documents change when a firm starts using Claude on client work, and it is easier to change them in September.

The engagement letter gets a paragraph that says the firm uses AI tools in preparing the return, that a qualified person reviews all work before it is filed, and what the firm's data terms are. Anthropic's own usage policy treats financial decisions as a high-risk use and requires, when outputs reach consumers, that a qualified professional review them and that the use of AI be disclosed; a preparer's clients are consumers, and both requirements are what a firm should be doing regardless. A one-line disclosure in the letter satisfies the second and costs nothing.

The firm's internal AI policy gets specific. Which plan holds client data and who owns the account. Which connectors are enabled and who may add one. That no Claude session, agent, or automation ever touches a CRA sign-in, Represent a Client, or a client's own CRA account, in any form. That slip figures are read from the source file and checked by a person. What the retention setting is and who verified it. Which client questions Claude may draft answers to and which go to a preparer. The policy is short, and it is what you will show an insurer, a client who asks, or your provincial body.

The client questionnaire and document request get a sentence explaining that documents should be uploaded to the portal or folder the firm names rather than emailed, because that is where the agent reads them, and asking clients to send slips as files rather than photographs pasted into email messages is the single change that most improves what an agent can do with them.

A plan for the season

September and October are for the decisions above: pick the plan, set the data controls, write the policy, and run Claude against last year's files for a handful of clients, with their consent or on anonymized copies, so the firm learns where it is reliable before there is a deadline. November and December are for the documents: the questionnaire, the engagement letter, the folder structure, and the connector setup, tested by the person who will use it least. January is when the T1 intake checklist and questionnaire go out and the agent starts watching the folders. February through April is running the process and keeping a list of every place the agent was wrong. May is reading that list.

Where this guide will be out of date by February

Connector availability changes monthly, at least one practice management vendor has promised an MCP server before the end of the year, and Anthropic revises its plans and policies several times a year. Every product claim above links to the page it came from so you can check the current state, and the integrations scoreboard tracks the vendor side with a verified date on each page. We will refresh this guide in January 2027 for the season, and if you find something wrong before then, tell us.

This guide provides general information for tax professionals and is not tax, legal, or filing advice. Product descriptions, plan terms and policies reflect Anthropic's published documentation and vendor documentation as of September 2026. Claude is a trademark of Anthropic, PBC; Blackspark is not affiliated with or endorsed by Anthropic. Karbon, TaxDome, Jetpack Workflow, Xero, QuickBooks, TaxCycle, ProFile, Google Drive and Microsoft 365 are trademarks of their respective owners, and no partnership or endorsement is implied.

Next
Next

T1 Client Questionnaire Template for Canadian Accounting Firms, and How to Run It Online