Giving someone access to your accounting software feels like a bigger decision than it is, mostly because the permission screens are written for administrators rather than for business owners. The practical question is narrow: what does this person need to see, and what should they not be able to do?
Both QuickBooks Online and Xero let you add a bookkeeping team as named users with scoped permissions, on your own subscription. You keep administrator rights, you can see every action in the audit log, and removing access takes one click when the engagement ends.
Setting up access for a new bookkeeping team? WhatsApp us and we will tell you exactly what access the work needs, and what it does not.
Quick Summary
| Question | Answer |
| Whose subscription? | Yours. The team is added as a user. |
| Do they need admin rights? | No. Scoped access is enough and safer. |
| Can we see what they did? | Yes — both platforms log activity by named user. |
| Do they need our bank login? | No. Recording transactions does not require payment authority. |
| How do we end access? | Remove the user. Nothing has to be returned. |
💡 TaxKitab Tip:
Use named users, never a shared login. It is tempting to create one generic account for the bookkeeping team because it is simpler to set up, and it destroys the single most useful control you have — the ability to see which person did which thing. Both platforms log activity by user, and that log is worthless if everyone is the same user. It also means you cannot remove one person’s access without changing the password for everybody. — From our GST Filing Mistakes Guide (Book 1). Available at taxkitab.com/books (Rs 179)
The Principle Before the Steps
Your software, your subscription, your administrator rights. The bookkeeping team is a user inside it.
This matters more than it sounds. When the team works inside your system, nothing is transferred anywhere, the audit trail stays in your account, and ending the relationship is an administrative action rather than a data recovery exercise.
The alternative — sending files to a provider who works in their own system — puts your records somewhere you cannot see and makes exit a request rather than a decision.
QuickBooks Online
QuickBooks distinguishes between a regular user and an accountant user. The accountant user type carries additional tools and, importantly, does not consume one of the user seats on most plans.
For a bookkeeping engagement the accountant user type is usually the right one. It gives access to the books and to the tools the work needs, without making the team an administrator of your account.
Where you want tighter control, a standard user with limited access can be scoped to specific areas — customers and sales, vendors and purchases, or both — and can be set with or without the ability to see reports.
Access is managed from the settings area, under user management. Removing a user is done from the same place.
Xero
Xero grants access by role, set when you invite someone and changeable afterwards.
The roles relevant to a bookkeeping engagement are the adviser role, which carries the accounting tools, and the standard role, which covers day-to-day transaction work. Either can be combined with separate payroll and reporting permissions, which are granted explicitly rather than assumed.
The permission worth thinking about carefully is payroll. If the engagement does not include payroll, do not grant it. Payroll data is the most sensitive information in most accounting systems and it is routinely granted by accident because it sits on the same screen.
Xero includes unlimited users on its plans, so adding a bookkeeping team does not cost you a seat.
What Not to Grant
Two things, regardless of platform.
Bank login credentials. A bookkeeper records and reconciles transactions. That requires seeing the data, not the ability to move money. Bank feeds bring transactions into the software without giving anyone access to your banking. No legitimate provider should ask for payment authority.
Administrator rights, unless there is a specific reason. Admin allows changing subscription settings, adding and removing other users, and altering account-level configuration. A bookkeeping engagement does not need any of that.
Documents Work the Same Way
The same principle applies to source documents. Invoices, statements and receipts stay in your own cloud storage — Drive, OneDrive, Dropbox — with the team given access to a folder.
Nothing is emailed back and forth, nothing goes to a provider portal, and your document trail stays in one place. This also removes the most common security weakness in outsourced engagements, which is not an exotic breach but financial documents sitting in email threads for years.
Reviewing and Removing Access
Both platforms log activity by named user. Look at the log periodically rather than only when something goes wrong.
Review access when scope changes, when someone leaves the provider’s team, and at the end of an engagement. Access granted once and never revisited is how most problems start.
Ending an engagement is one action: remove the user. There is no deletion request and nothing to wait for, because nothing ever left your system.
Frequently Asked Questions
Does adding an accountant cost extra? In QuickBooks, the accountant user type does not consume a standard user seat on most plans. Xero includes unlimited users. Check your own plan before assuming.
Should we give admin rights? No. Scoped access is sufficient for bookkeeping and avoids giving anyone control over your subscription and users.
Can we restrict access to payroll? Yes. Both platforms treat payroll as a separate permission. If payroll is not in scope, do not grant it.
Can we see what the team has done? Yes. Both platforms record activity by named user, and those logs belong to you.
Do you need our bank login? No. Recording and reconciling transactions does not require payment authority, and it should not be granted.
What happens when the engagement ends? Remove the user. Your data never moved, so there is nothing to retrieve or delete.
Can our previous accountant keep their access? That is your decision. Adding a bookkeeping team does not remove anyone else, so review existing users at the same time.
References
- QuickBooks Online documentation on user types and access levels
- Xero documentation on user roles and payroll permissions
- Engagement scope and access terms, agreed in writing before access is granted
⚠️ User limits, role names and permission levels differ by platform and plan and change with vendor releases. Check your own subscription before relying on any detail here.
Related Reading: You Pick the Software. We Work in Your Login. · Where Does Your Data Actually Sit When You Outsource? · QuickBooks vs Xero: Which Is Right for Your Business?
Call or WhatsApp: +91 7448200422 Email: info@taxkitab.com See our Accounting & Bookkeeping service, or explore Global Desk if your business sits outside India.


