📘

Dynamics 365 Business Central + Meridian

Connect Business Central, set up the MERIDIAN journal batch and permission set, and post locked AI chargeback months as general journal entries tagged with a Department dimension. Written for controllers and the admins who carry out the setup.

Early accessShipped: 2026-09-27Time: 45 minutesDifficulty: Intermediate

Available to customers now. We confirm the first import with you in a sandbox before production.

Best for: Controllers and finance leads posting AI chargebacks to Business Central

Connect Dynamics 365 Business Central to Meridian

Meridian posts your AI cost chargebacks into Business Central as general journal entries, one line per department on each department's G/L account and tagged with a Department dimension, so AI spend lands with the teams that used it. This guide covers setup from a finance point of view and explains why each step matters, so your controller and your auditor can follow the logic.

Time: about 45 minutes, most of it one-time setup. Who's involved: this needs two people, or one person with both roles:

  • a Business Central administrator, to set up accounts, the journal batch and permissions;
  • a Microsoft Entra (Azure AD) administrator, to approve Meridian's access to your Microsoft tenant.

Your finance lead should own the decisions in Steps 2–4 and 8. The admins carry them out.


What Meridian does (and doesn't do) in your books

Meridian doesMeridian never does
Read your chart of accounts, dimensions and posting-date setup, so it can validate before postingRead customers, vendors, sales, purchasing, bank or payroll data
Create journal lines in one dedicated journal batch (MERIDIAN), and post that batch when a person clicks PostWrite to any other journal batch, or edit or delete posted entries
Read back the resulting G/L entries to confirm they match what was sentPost anything without a person clicking Post on a locked chargeback month
Keep a record of every posting (document number, period, amounts, who posted)Store a Business Central password or secret. Access is granted to Onaro's registered app and can be revoked by you at any time

Why this matters: your auditor will ask what a third-party system can do in your general ledger. The short answer is "read the chart of accounts, and post only reviewed chargeback entries into one dedicated batch, under a permission set we control."


Before you start

  • Dynamics 365 Business Central (cloud), with a company you'll post chargebacks into.
  • We strongly recommend testing in a sandbox environment first. Business Central lets you create a sandbox copy of your company. Post a test month there, review it with your controller, then connect production.
  • Your departments and G/L mapping in Meridian. These are the teams AI costs are charged to, and the G/L account each team's AI cost should land in. They're set on Meridian's GL mapping page.
  • A list of the apps installed in your Business Central company (Extension Management). Some Microsoft and partner apps take part in journal posting and need Meridian to have a little extra read access. Step 5 covers the known ones.

Step 1: Choose the environment and company

Decide which Business Central environment (sandbox or production) and which company Meridian will post into. Meridian connects to one company per connection.

Why: Business Central tenants often hold several companies (legal entities) and several environments. Chargebacks must land in the right legal entity, and the first posts should never go straight into production books. Meridian shows a prominent Sandbox or Production badge on every screen, and for production it asks you to type the company name before posting.


Step 2: Set up the G/L accounts

In Business Central: search Chart of Accounts → New, and create or confirm:

PurposeExample No.Example name
Where each department's AI cost is charged (one or more accounts, matching your Meridian GL mapping)6100AI Platform Costs
The offset for chargebacks (contra method)6200AI Cost Allocations
Where unattributed AI spend goes (suspense)AI-UNALLOCAI Spend — Unallocated
Where your AI vendor bills are recorded (reclass method only)6300AI Software Subscriptions

For each account:

  • Income/Balance: Income Statement
  • Account Category: Expense
  • Account Type: Posting
  • Direct Posting: On
  • Blocked: Off
  • Gen. Posting Type and all posting groups: leave blank

Why "Income Statement / Expense": AI spend is an operating cost of running the business, so it belongs in operating expenses, not below the line.

Why Direct Posting must be on: Business Central only accepts journal lines on accounts that allow direct posting. Without it, the post fails.

Why leave posting groups blank: a chargeback moves an existing cost between departments; it isn't a new purchase. Leaving the general posting type and posting groups blank keeps sales tax and VAT logic from being applied to these internal entries.

Why the account numbers must match Meridian: Meridian posts to the G/L codes on its GL mapping page and in its journal entry settings. Meridian's preflight check confirms every one of them exists in Business Central and accepts direct posting before anything is posted.


Step 3: Set up the Department dimension

In Business Central: search Dimensions. If a DEPARTMENT dimension exists, open Dimension Values and add any missing departments. If not, create it (Code DEPARTMENT), then add one value per team you charge back to, for example ENG, MKT, SALES, SUP, plus UNALLOC if you want suspense tagged.

Why a dimension, and not just separate accounts: dimensions let you report AI cost by department across any account, and they're how most Business Central customers already track departments. Every line Meridian posts carries the department's dimension value, so Trial Balance by Dimension and account analysis reports show AI cost per team without any extra work.


Step 4: Create a dedicated journal batch

In Business Central: search General Journals, choose template GENERAL, open the Batch Name list, and create a batch:

  • Name: MERIDIAN
  • Description: Meridian AI chargeback postings
  • No. Series: blank
  • Bal. Account No.: blank (Bal. Account Type can stay at its default)

Leave the batch empty. Don't use it for anything else.

Why a dedicated batch: it isolates Meridian's entries from your team's manual journals. Your staff can't accidentally post Meridian's lines, and Meridian can't touch theirs.

Why it must stay empty: in Business Central, posting a journal posts the whole batch. If someone left other lines in it, Meridian's post would post those too. So Meridian checks the batch is empty before it starts, and refuses to post otherwise.

Why no number series or balancing account: Meridian sets its own document number and supplies its own balancing line. The document number looks like MRD202608-ce764180: MRD, the chargeback month (202608 = August 2026), and the first part of the Meridian chargeback run ID, so every entry traces back to the exact run that produced it.

Decide on the journal archive now. The batch has a setting, Copy to Posted Jnl. Lines. When it's on, Business Central keeps an archive copy of every posted journal line. Your options:

  • Turn it off for the MERIDIAN batch (simplest): Meridian needs no access to the archive tables. Every posting is still fully traceable through its G/L Register, its document number, and Meridian's own posting history.
  • Leave it on if your team relies on the posted-journal archive: Meridian's permission set then needs insert access to the two archive tables (see Step 5). Business Central requires this access to be direct; the more limited "indirect" level doesn't work for the archive.

Step 5: Create the MERIDIAN POSTING permission set

In Business Central: search Permission Sets → New:

  • Permission Set (Role ID): MERIDIAN POSTING
  • Name: Onaro Meridian: AI chargeback journal posting

In Permission Sets (included sets), add: LOGIN, System App - Basic, BaseApp Objects - Exec.

In Permissions, add the table rows in the appendix:

  • Core rows: always.
  • Posting support rows: always. Business Central's posting routine reads these setup tables even when your accounts carry no tax settings.
  • Journal archive rows: only if you left Copy to Posted Jnl. Lines on (Step 4).
  • App-specific rows: only for apps installed in your company.

Every row is read-only except the journal line table (which Meridian must create and clean up), the ledger tables that Business Central's own posting routine writes to, and the optional archive rows.

Three ways to enter it:

  1. Type it in from the appendix. This always works.
  2. Use Onaro's Excel checklist of the same rows, if you'd rather tick through a spreadsheet.
  3. Import Onaro's XML file (Permission Sets → Import Permission Sets). It's the fastest, but some companies' security settings block XML downloads; if yours does, use option 1 or 2.

If another table is ever named: your company may have an app we haven't seen. Preflight or posting will stop with a message naming the table and the access needed (for example, "TableData 6217 Sustainability Setup Read"). Add exactly that table with exactly that access, then rerun preflight. Read or indirect-read access is safe to add. Contact Onaro support before granting anything beyond read.

Important: when you create a new permission set, Business Central may add a default row with Object ID 0 ("All objects of type Table Data"). Change or delete it. Left in place, it grants read access to every table.

Why a custom permission set: it's the principle of least privilege. Meridian gets exactly what it needs to validate and post chargebacks, and nothing else: no customers, vendors, bank or payroll data. It's also the control your auditor will want to see documented.

Why "indirect" permissions on the ledger tables: Meridian never writes G/L entries directly. It asks Business Central to post the journal, and Business Central's own posting logic creates the ledger entries. Indirect permission allows exactly that and nothing more.


Step 6: Register Meridian's app in Business Central

In Business Central: search Microsoft Entra Applications → New:

  • Client ID: Onaro's application ID (shown on Meridian's Business Central settings page, and in any Meridian error that asks for it)
  • Description: Onaro Meridian – AI chargeback posting
  • State: Enabled
  • User Permission Sets: add only MERIDIAN POSTING, with Company set to the company from Step 1. Remove any other permission set Business Central adds by default.

Don't use the "Grant Consent" button on this page. It returns to a Business Central address that isn't registered for Onaro's app, so it shows a redirect error. Consent is given in Step 7 instead.

Why set the company: without it, the permission set applies to every company in the environment. Scoping it to one company means Meridian can only post into the legal entity you chose.


Step 7: Connect and approve Meridian's access (Entra admin)

In Meridian: Integrations → Destinations → Dynamics 365 Business Central → Connect, and enter your tenant, environment and company. You'll be sent to Microsoft's consent screen; your Entra administrator approves Onaro's app for your organization.

The consent screen shows the permission "API.ReadWrite.All" for Business Central.

Why does it say "ReadWrite.All"? It's the only permission Microsoft offers for apps that call Business Central's APIs. Consent alone gives Meridian no access to your data. Actual access is controlled by the Business Central permission set you assigned in Step 6: MERIDIAN POSTING, and nothing else.

To check consent afterwards: in the Entra admin center, go to Enterprise applications → Onaro's app → Permissions. Dynamics 365 Business Central – API.ReadWrite.All should be listed under admin consent. If it isn't, click Grant admin consent for [your organization] there.


Step 8: Run preflight, then map

In Meridian, on the Business Central settings page:

  1. Run preflight. Meridian checks that it can sign in, that it can reach your environment and company, that the MERIDIAN batch exists and is empty, that every mapped G/L account exists and allows direct posting, that the dimension values exist, and that the posting date is open. Fix anything it flags before continuing.
    • The posting-date check shows a caution rather than a pass: your company settings allow the date, but Business Central can also apply per-user or journal-template date limits that its API doesn't reveal. Only the post itself is final.
  2. Journal settings: the batch (MERIDIAN), the dimension that holds departments (DEPARTMENT), and the posting method (next section).
  3. Department mapping: each Meridian department to its dimension value (Engineering → ENG, and so on), plus the Unallocated (suspense) row: either a dimension value, or an explicit "no dimension."

Why preflight first: Business Central rejects postings for many reasons (a blocked account, a closed period, a missing dimension value). Catching them before posting means no failed or partial entries in your books.


Step 9: Lock the chargeback month

In Meridian: Reports → Chargeback, review the month, and Lock it.

Why: posting to your general ledger should only happen with final numbers. A lock freezes that month's allocation so what you reviewed is exactly what posts. Meridian won't post an unlocked month.


Step 10: Preview and post

In Meridian: choose the locked month → Preview, check the lines, then Post.

A contra-method entry for $1,000 of AI spend, split across three departments on the same expense account, looks like this:

LineG/L accountDEPARTMENTDebitCredit
16100 AI Platform CostsENG600.00
26100 AI Platform CostsSALES300.00
36100 AI Platform CostsSUP100.00
46200 AI Cost Allocations1,000.00

Debits always equal credits. The posting date is the last day of the chargeback month. Each department gets its own line, even when departments share the same G/L account, so the dimension shows exactly who spent what.

What happens when you click Post: Meridian (1) confirms the batch is empty, (2) creates the lines in the MERIDIAN batch, (3) asks Business Central to post the batch, then (4) reads back the resulting G/L entries and checks they match. If the read-back doesn't match, the posting is flagged Needs review.

Why you can't post the same month twice: Meridian blocks a second post for the same company, month and method, which prevents double-charging a department. To re-post, reverse the original entry in Business Central first and mark it reversed in Meridian.

If a post fails: Meridian deletes the lines it created, so your batch is left empty. If that cleanup itself fails, the posting shows Cleanup required, listing the exact lines to delete, and further posting is blocked until the batch is clean.


Step 11: Check the result in Business Central

  • G/L Registers: open the latest register to see the entries Meridian's post created.
  • General Ledger Entries, filtered by the Document No. Meridian shows after posting (for example MRD202608-ce764180). Meridian also shows the range of G/L entry numbers it created. Add the Department Code column (personalize the page) to see each line's department. Use Find entries (Navigate) on the document number to see everything linked to it.
  • Trial Balance by Dimension, or an account analysis by DEPARTMENT, for the month: AI cost appears under each department, and the net effect company-wide is zero.

Why check on the first post: it's the view your finance team will rely on, and confirming it once catches any mapping mistake before it repeats every month.


Choosing a posting method

Contra (default)Reclass
Credit side goes toA separate offset account (AI Cost Allocations)The source expense account where your AI bills are recorded
The team that pays the AI bills seesFull gross spend and a visible recovery lineSpend drops as it's charged out
Best whenA central team (IT, platform) owns the AI bills and wants to show what it recoveredYou want costs to sit only with the departments, with no gross-up

For reclass, Meridian's settings ask for the Source expense account (where your AI bills are recorded). Both methods are standard practice; ask your controller which your company prefers.


If your company uses journal approvals

Some companies require approval before general journals can post. If an approval workflow applies to the MERIDIAN batch, Meridian's post fails cleanly: Business Central refuses it, Meridian removes its lines, and nothing is posted. Meridian doesn't wait for approval and never posts unapproved.

This is a control decision for your controller:

  • Exclude the MERIDIAN batch from the journal approval workflow. The review then happens in Meridian: the chargeback month is reviewed and locked, the entry is previewed, and a named user posts it. Every posting is recorded with who posted it and when.
  • Keep approvals on the batch, and post Meridian's entries through your normal approval process instead of Meridian's Post button.

Disconnecting

  • In Meridian: Integrations → Business Central → Disconnect. Meridian deletes its stored connection details.
  • In Business Central: on Microsoft Entra Applications, set Onaro's app to Disabled or delete it. Your Entra admin can also revoke consent in the Entra admin center.

Entries already posted stay in Business Central untouched.


Troubleshooting

Message or symptomWhat it meansFix
"Chargeback month is not locked"Posting requires final numbersLock the month (Step 9)
"Journal batch is not empty"Other lines are in the MERIDIAN batchRemove them; keep the batch for Meridian only
"Account … does not allow direct posting" or "is blocked"G/L account settingsStep 2: Direct Posting on, Blocked off
"Posting date is not within the allowed range"The period is closed, or your allowed posting dates exclude itOpen the period or adjust allowed posting dates in General Ledger Setup / User Setup
"Dimension value … is blocked" or missingDEPARTMENT valuesStep 3
"Business Central rejected Onaro's app"The app isn't registered, enabled or permissioned in Business Central, or consent is missingStep 6 (right environment and company, State Enabled, only MERIDIAN POSTING), then check consent in Entra (Step 7). Allow a few minutes after changes
"Sorry, the current permissions prevented the action (TableData … )"MERIDIAN POSTING is missing a table, often from an installed appAdd exactly the table and access named. Read or indirect read is safe; contact support before granting more
An error mentioning Posted Gen. Journal Line or BatchCopy to Posted Jnl. Lines is on for the MERIDIAN batchTurn it off for the batch, or add the archive rows (Step 4, appendix)
A record-restriction or approval errorA journal approval workflow covers the MERIDIAN batchSee "If your company uses journal approvals"
"Already posted for this period"Duplicate-post protectionReverse the original entry and mark it reversed in Meridian first
"Cleanup required"A failed post left lines behindDelete the listed lines from the MERIDIAN batch, then click Recheck batch

When contacting support (support@onaro.io), include the environment, company, month and the exact message.


Appendix: MERIDIAN POSTING permissions

Each row: Type Include, Object Type Table Data. "Yes" = direct, "Indirect" = only through Business Central's own posting routine, blank = none.

Included permission sets: LOGIN, System App - Basic, BaseApp Objects - Exec.

Important: delete any row with Object ID 0 ("All objects of type Table Data"); Business Central may add one by default.

Core rows (always)

Object IDTableReadInsertModifyDelete
15G/L AccountYes
17G/L EntryYesIndirect
45G/L RegisterYesIndirectIndirect
50Accounting PeriodYes
80Gen. Journal TemplateYes
81Gen. Journal LineYesYesYesYes
91User SetupYes
98General Ledger SetupYes
230Source CodeYes
232Gen. Journal BatchYes
242Source Code SetupYes
348DimensionYes
349Dimension ValueYes
350Dimension CombinationYes
351Dimension Value CombinationYes
352Default DimensionYes
354Default Dimension PriorityYes
480Dimension Set EntryYesIndirect
481Dimension Set Tree NodeYesIndirectIndirect

Posting support rows (always)

Business Central's posting routine reads these even when your accounts carry no tax settings or approval workflows.

Object IDTableRead
189VAT SetupIndirect
254VAT EntryIndirect
325VAT Posting SetupYes
330Currency Exchange RateYes
1108Cost Accounting SetupIndirect
1501WorkflowIndirect
1502Workflow StepIndirect
1520Workflow EventIndirect

Journal archive rows (only if Copy to Posted Jnl. Lines is on)

Object IDTableReadInsert
181Posted Gen. Journal LineYesYes
182Posted Gen. Journal BatchYesYes

App-specific rows (only if the app is installed)

Object IDTableAppRead
6121E-DocumentE-Document CoreYes
6217Sustainability SetupSustainabilityYes