Double-entry bookkeeping you can read, run, and change. A desktop app built by a practicing CPA to keep real books: multiple clients, journal entries with debit-credit validation, bank imports, AI-assisted categorization, standard reports, and a close workflow that ends in a branded PDF package.
A Ledger Labs LLC product — the software studio of Charlie Barmore, CPA, who built this with Claude Code. Shared with the AI Lab for Accountants community as a working example of what one accountant can build.
- Clients: separate books per client, with chart-of-accounts templates by entity type (S corp, partnership, nonprofit, and more) and industry — and a chart importer that speaks QuickBooks type names directly (Bank, Credit Card, A/R, COGS, …), so a QB export comes in whole, with unmappable rows reported rather than silently dropped. Charts with no account numbers (QBO's default) get numbers assigned by type range, shown before anything imports; any existing numbering scheme is kept as-is.
- Journal entries: classic double-entry with validation. If it doesn't balance, it doesn't post. Reusable templates can prefill the normal entry form, and monthly, quarterly, or annual schedules generate one idempotent draft per fiscal period for human approval, including optional period-end reversal drafts.
- Bank imports: bring in transactions from CSV with saved per-bank formats, duplicate detection, and an import verification step (including row-continuity checks — a balanced trial balance is not proof an import was complete). New accounts can be created right in the category dropdown. Or skip the format question entirely: hand any statement — CSV, PDF, a pasted table — to your assistant, which normalizes and stages it into the same review flow (see Assistant access below).
- AI categorization: Claude suggests the account for each imported transaction and learns your patterns over time. Suggestions only: you review, you post. The audit trail records what happened either way.
- Book Review: a deterministic integrity sweep (unbalanced entries, unposted imports, broken links, date problems, quiet accounts) plus an AI category-consistency review governed by your own per-client policy notes, and an analytical memo.
- Close Map: every year-end balance gets a reusable lead-sheet assignment, supporting references, variance explanation, review notes, and append-only preparer/reviewer signoffs. New fiscal years retain the mapping and show the adjacent prior year's review context, while requiring fresh evidence and signoff. A later ledger, reconciliation, or evidence change automatically reopens only the affected account. The map is included in annual close-package PDF and Excel exports.
- Reports & the close: trial balance, income statement, balance sheet, general ledger (whole-book view), trial balance worksheet, bank reconciliation — and an exportable close package (PDF + Excel). Client branding leads each package while your firm's logo, letterhead details, and identity remain visible as the preparer.
- Assistant access (MCP): opt-in MCP server so Claude Desktop or Claude Code can work the currently open book — query everything (trial balance, ledgers, entry search, the integrity sweep), set up a new client and its chart, file draft entries, stage imports from any statement format, propose client branding text/colors for human approval, export the close package to your workpaper tool, and — only if you turn the dial up — post balanced entries itself. Each book is authorized separately, with its own access level and export folder on Data Safety. The setting lives outside the assistant's reach, and every level is enforced by the database engine, not by promises: even at full access the assistant is append-only and can never edit or delete anything. See
docs/MCP.md. - Assistant Review: one page gathering everything the assistant has done — proposals waiting on you, plus every AI-attributed action since your last sign-off, with an append-only, audit-logged "reviewed through here" checkpoint. Agent-proposed corrections carry a structured link to the original journal entry and present the original and proposed lines together. Approval retains the original → draft → posted-correction chain; rejection remains in the review history. The sidebar badges what's unreviewed; nothing the assistant does can look pre-approved.
- Firm mode: book files can live on a shared drive, ProSystem-style — the app installs locally, each book has its own passphrase, and an in-use lock keeps two writers out of one book. See
docs/FIRM-MODE.md. - Audit trail: every change is logged, with the OS account name as the actor — and assistant actions stamped "(AI)", so automated work is never presented as yours. Bookkeeping without an audit trail is just a spreadsheet with opinions.
- Data safety: the database is encrypted at rest behind a launch passphrase (SQLCipher), verified backups are built in, and a production-readiness checklist gates real use. Release builds refuse to ship without SQLCipher. A source build without it refuses to open books unless you set
LEDGERTB_ALLOW_UNENCRYPTED=1, and then says so on every page.
Grab the latest from the Releases page.
Windows — download LedgerTB-windows-x64-setup.exe and run it. Because the
build is not yet code-signed, Windows shows a SmartScreen warning ("Windows
protected your PC"): click More info, then the button to run it anyway
(Windows labels it Run anyway or Open anyway depending on version). It
installs for you alone, under your own user profile, and never asks for an
administrator password — so it works on a locked-down firm laptop. You get a
Start Menu entry and a normal entry in Add/Remove Programs.
A LedgerTB-windows-x64.zip is also attached for anyone who needs to deploy
without an installer. Read this before using it: when Windows extracts a
downloaded zip it marks every file as coming from the internet, and that stops
part of LedgerTB loading — the app will refuse to start and tell you so. To use
the zip, right-click it → Properties → tick Unblock → OK, then
extract. The installer has none of this friction and is the supported path.
macOS — download LedgerTB-mac.zip, unzip, and drag LedgerTB to
Applications. It is signed and notarized by Apple, so it opens with no
warnings. (Apple Silicon; the Mac build is produced and notarized locally
rather than by CI — see DESKTOP.md.)
The app is self-contained — no Python and no dependencies to install. Your books live in an encrypted database under your user profile, never inside the app folder, so upgrading keeps your data and uninstalling does not delete it.
The in-app Help & Updates page shows the installed version and provides safe upgrade instructions plus browser links to the latest release, guided bug report and feature request forms, and private security-report instructions. It does not call GitHub, check for updates in the background, or send telemetry; GitHub opens only after the user chooses a link.
ProBooks was LedgerTB's pre-release name; it never shipped publicly. If you
tested one of those builds, everything keeps working: existing .probooks
book files, saved book choices, probooks-* backups, credential-vault
entries, and PROBOOKS_* environment settings are all still honored, and the
app reuses your existing data folder rather than moving financial data. New
books use the .ledgertb extension and new configuration uses LEDGERTB_*.
LedgerTB installs as its own program. On Windows, remove the old ProBooks
entry from Add/Remove Programs; on macOS, delete the old
/Applications/ProBooks.app once LedgerTB opens your book. Neither the
installer nor the app ever deletes book data. If assistant (MCP) access was
configured, point your assistant's configuration at the LedgerTB binary and
re-approve access from Data Safety.
Requires Python 3.12 or later. Tested on 3.12 (CI) and 3.14 (a clean Linux install — see below).
git clone https://github.com/charliebarmore/LedgerTB.git
cd LedgerTB
python3 -m venv .venv
source .venv/bin/activate # Windows: .venv\Scripts\activate
pip install -r requirements.txt
streamlit run app.py --server.address=127.0.0.1The virtual environment matters: installing into your system Python often fails outright on current installs ("externally managed environment") and mixes LedgerTB's dependencies into everything else you run.
Verified on a clean macOS install (Python 3.12.7, fresh venv, nothing preinstalled): pip install -r requirements.txt pulls a prebuilt sqlcipher3 wheel and needs no Homebrew step. The same is true on Windows x64.
Verified on a clean Linux install (Arch-based Omarchy, Python 3.14.7, empty home folder, nothing preinstalled, 2026-09-22): the same steps work unchanged. pip pulls a prebuilt sqlcipher3 wheel with SQLCipher 4.12 built in — the database file is encrypted on disk — and the full test suite passes (901 passed; the 5 skips are Windows-only checks). There is no Linux installer yet; on Linux, run from source.
If your platform has no wheel and the sqlcipher3 build fails, you need the SQLCipher system library (macOS: brew install sqlcipher, Debian/Ubuntu: libsqlcipher-dev) — or drop that line from requirements.txt and set LEDGERTB_ALLOW_UNENCRYPTED=1 to evaluate with sample data. Without that variable the app and MCP server refuse to open books and say why. With it, the database is unencrypted and every page says so. Install SQLCipher before keeping real books. The release selfcheck always requires SQLCipher, even when this demo variable is set.
The app runs fully without any API key. To turn on AI categorization, either set ANTHROPIC_API_KEY in a .env file or save a key on the Firm Settings page (stored in your system credential vault, not in a file).
- macOS: download the signed and notarized Apple Silicon
LedgerTB.appfrom the latest release. To build it yourself, create a clean Python 3.12 environment, installrequirements-macos-arm64.lock, and run./scripts/build_release.sh. The build verifies the lock before packaging. Signing is configured via a localscripts/signing.env. - Linux: no packaged build yet. From source, the app also runs in its own window instead of a browser tab: inside the virtual environment from the quickstart, run
pip install "pywebview>=5.0,<7.0" PyGObject, thenpython desktop.py. The window uses the system's WebKitGTK 4.1 and GTK 3, and PyGObject compiles during install, so it also needs a C compiler and the GLib and cairo headers. Verified on Arch-based Omarchy (2026-09-22) withwebkit2gtk-4.1,gtk3andbase-develinstalled. On Debian/Ubuntu, install the build prerequisites before the pip command above. The matching packages should belibwebkit2gtk-4.1-0,gir1.2-webkit2-4.1,libgirepository-2.0-dev,libcairo2-dev,pkg-config,build-essentialandpython3-dev. The Python headers are required to compile PyGObject and Pycairo; if the virtual environment uses a non-default Python, install the development headers matching that version instead. This Debian/Ubuntu setup has not been tested end to end. - Windows: an Inno Setup installer built by CI (
.github/workflows/release.yml, tag-triggered) fromscripts/ledgertb.iss. The release pipeline refuses to ship a build whose encryption is unavailable, installs the pinned set inrequirements-windows.lock, and will not publish a build that cannot serve a page (scripts/smoke_serve.ps1) or fully exit after its native window closes (scripts/smoke_close.ps1).
This tool follows the same rule we teach in the Lab: AI drafts, the professional decides. Categorization suggestions are never auto-posted, everything is reviewable, and the audit trail keeps the record. Assistant access via MCP is off by default and permissioned at read / propose / post; the default is propose, while direct posting requires an explicit warning and confirmation. The database always blocks assistant edits and deletes. LedgerTB itself makes an outbound call only when you enable Anthropic categorization. If you enable MCP, your MCP client may also send returned book data to its configured AI provider—vet that provider and your firm's data policy before using client data. The books remain in the local encrypted database.
See docs/TESTING.md for complete accounting workflows, upgrade/recovery
checks, real MCP transport tests, and repeatable browser acceptance.
python -m pytest -q -m "not performance"(Dropping the marker filter also runs the slower volume baselines described in
PERFORMANCE.md.) More than 700 tests cover the ledger math, posting rules, imports, reports, the MCP tools and access levels, the Close Map and assistant review checkpoints, firm-mode locking, and export hardening. The release suite has been exercised on macOS and Windows (and the full suite on Linux from source), and on both pandas 2.2 and pandas 3.0; CI records results for proposed changes.
CONTRIBUTING.md— development setup and contribution expectationsSUPPORT.md— support scope and safe bug-reporting guidanceCODE_OF_CONDUCT.md— community participation standardsDESKTOP.md— desktop builds, packaging, notarizationdocs/MCP.md— assistant access setup and security modeldocs/CLOSE-MAP.md— account support, review, signoff, and stale-change rulesdocs/RECURRING-JOURNAL-ENTRIES.md— the v1.7.0 template and recurrence contractdocs/LEDGERPDF-PAIRING.md— books-to-binder workflow with LedgerPDFdocs/FIRM-MODE.md— shared-drive book files and the in-use lockdocs/WINDOWS-TESTING.md— the Windows smoke-test checklistPERFORMANCE.md— performance baselinesSECURITY.md— private vulnerability reporting and supported versions
LedgerTB is software, not accounting advice. It gives you double-entry rails,
an audit trail, and review workflows, but every judgment in your books —
categorization, adjustments, what gets posted — is yours, whether you made it
directly or accepted a suggestion from the AI assistant. Nothing it produces
is a substitute for professional judgment on questions that matter. Your books
and their accuracy remain your responsibility, and the software is provided
as-is, without warranty of any kind (see LICENSE).
See the full Disclaimer, Privacy & Data Practices, and Website and Distribution Terms. In particular, optional AI and MCP features can send selected data to providers you configure; approve those providers and their data practices before using client information.
MIT. See LICENSE. Third-party components retain their own terms; see
THIRD_PARTY_NOTICES.md.