Cloud-accounting permissions should reflect each person’s actual responsibilities, with separate control over viewing, editing, approving and administering where the system allows. Use named accounts and review access when staff, advisers or roles change.
Pay particular attention to bank details, payroll integrations and bulk exports. Strong account recovery and multi-factor authentication support access control but do not replace sensible role design.
Start with the tasks each user performs
List the people using the accounting system and the work they need to complete. Separate viewing reports, entering bills, approving payments, changing bank details, exporting data and administering users. A job title such as 'finance assistant' does not establish the appropriate permission level on its own. Use the actual task list to choose a role and identify any temporary access needed for a specific project.
ICO security guidance calls for appropriate technical and organisational measures for personal information. Accounting tools can contain customer addresses, supplier bank details and payroll data, so access decisions should consider the sensitivity and consequences of misuse. Strong authentication helps protect an account, but it does not correct an unnecessarily broad role assigned to someone who is successfully signed in. [1]
Use named accounts and limit administration
Give each person an individual login so changes can be attributed and access removed without disrupting others. Avoid sharing an administrator account because it appears cheaper or easier to manage. Keep high-level permissions limited to people who need them and review their recovery arrangements. The business should know who can add users, alter integrations or export the entire ledger, not only who can enter an invoice.
Where the software offers only broad roles, document the limitation and consider practical compensating controls. These might include a separate approval of bank-detail changes or a review of bulk exports. Do not claim that a role design provides segregation the product cannot actually enforce. A clear understanding of the limitation is more useful than a policy describing controls that exist only on paper.
Protect changes that affect money or identity
Set an independent check for supplier and employee bank-detail changes, using a trusted contact route. Distinguish authority to edit a record from authority to release a payment. Review the audit trail for unusual changes before a material payment run. A valid user account can still be misused or receive an inaccurate instruction, so the business process should not rely solely on the fact that the system accepted the edit.
Consider what connected applications can read or change. A receipt tool, reporting dashboard or payroll integration may have access beyond the main user's visible role. Keep an inventory of connections, their owner and purpose. Remove unused integrations through the supported process and review permissions when a provider changes its service, rather than assuming that an integration approved years ago remains appropriate indefinitely.
Review access at role changes and departures
Build accounting permissions into staff and adviser onboarding, role changes and offboarding. Check shared document folders and downloaded reports as well as the main application. A former user may lose their login while still retaining access to a live export folder. Identify the authoritative records and apply the business's retention and removal process to working copies without deleting evidence that must be preserved.
For temporary reviewers, set an end date and provide the narrowest usable access. Where an accountant needs to inspect a particular period, consider whether a controlled report or limited role is sufficient. Do not grant permanent administration simply because it avoids one setup conversation. Keep a record of why access was provided and who is responsible for confirming that it can be removed.
Test the permissions in ordinary use
Check that users can complete their assigned tasks and cannot perform actions outside the intended role. Use appropriate internal verification without exposing real personal information unnecessarily. If a role prevents essential work, adjust the specific permission or workflow rather than immediately promoting the user to full administrator. Record the decision so the same problem is not solved differently for each new staff member.
Use Software access when changing accountants for adviser handover access and Cloud bookkeeping setup to discuss accounting permissions within a bookkeeping process. Describe the system, roles and the particular access concern. A practical review can then connect permissions to approval and reconciliation controls, giving the business a workable arrangement rather than an abstract rule that nobody can follow during a payment deadline.
Schedule a periodic user and integration review, with attention to inactive accounts, external advisers and powerful roles. Confirm the owner of each account and remove permissions that no longer serve a defined task. Keep the outcome brief but explicit so the review demonstrates action, not merely that a list of users was exported and filed.
Illustrative scenario
A business gives a temporary bookkeeper entry access while reserving payment approval and user administration for authorised staff. The temporary account is reviewed and removed when the assignment ends.
Preparation checklist
- List user responsibilities
- Apply suitable roles
- Protect administrator accounts
- Review leavers and temporary access
Frequently asked questions
Does multi-factor authentication make every permission level appropriate?
No. Authentication protects sign-in, while role design determines what an authorised user can do. Both need attention.
Why avoid shared accounting logins?
They obscure who made changes and complicate access removal. Named accounts support accountability and more controlled onboarding and offboarding.
Should a temporary adviser receive administrator access by default?
No. Match access to the agreed task and duration, and document any product limitation that requires a broader role with additional controls.
Do integrations need separate review?
Yes. Connected applications can retain access beyond ordinary user roles. Record their purpose, permissions and owner and remove unused connections appropriately.
Official sources
Sources checked: 8 September 2026. Check the linked guidance for subsequent changes.
General information only. The appropriate action depends on your circumstances and the applicable jurisdiction.
Report a correction