Permission levels
| Level | What they can do |
|---|---|
| Full access | View and edit everything (like an owner) |
| Edit access | Make changes, but can’t modify settings |
| View only | See everything, can’t change anything |
| Limited | See only what you explicitly share |
| Portal only | Document uploads and messaging only |
Setting permissions
Feature-level permissions
Fine-tune access by area:| Feature | Permission options |
|---|---|
| Transactions | View / Edit / Hide |
| Reports | View / Hide |
| Invoicing | View / Edit / Hide |
| Payroll | View / Hide |
| Banking | View / Edit / Hide |
| Documents | View / Upload / Hide |
| Settings | View / Edit / Hide |
| Team | View / Manage / Hide |
Example setups
Hands-off client (you do everything):- Base: Portal only
- Documents: Upload
- Everything else: Hidden
- Base: View only
- Documents: Upload
- Reports: View
- Base: Edit access
- Payroll: View only
- Settings: View only
Client users
A client can have multiple users with different permissions:| Role | Typical permissions |
|---|---|
| Owner | Full access |
| CFO | Full access |
| Bookkeeper | Edit transactions only |
| Manager | View reports only |
| Assistant | Document upload only |
Adding client users
- Go to Client → Settings → Users
- Click Invite User
- Enter email and select role
- Send invitation
Managing client users
You control:- Who can access the client portal
- What role each person has
- Whether they receive notifications
- Multi-factor authentication requirements
Sensitive data
Some data requires explicit permission to view:| Data type | Default visibility |
|---|---|
| Bank balances | Visible to View+ |
| Transaction amounts | Visible to View+ |
| Payroll details | Hidden by default |
| SSN/EIN | Hidden by default |
| Bank account numbers | Hidden by default |
Action restrictions
Beyond viewing, control what clients can do:| Action | Who can do it |
|---|---|
| Create transactions | Edit+ only |
| Categorize transactions | Edit+ only |
| Create invoices | Edit+ only |
| Run payroll | Requires specific permission |
| Connect banks | Requires specific permission |
| Change settings | Admin only |
Audit trail
All permission changes are logged:- Who changed what
- When it changed
- Previous and new values
Common questions
Can clients see my notes?
Can clients see my notes?
No. Internal notes and team comments are never visible to clients unless you explicitly share them.
Can clients see other clients?
Can clients see other clients?
Never. Each client only sees their own data. There’s no way for clients to access or even know about other clients.
Can I restrict specific reports?
Can I restrict specific reports?
Yes. In feature permissions, expand Reports and choose which specific reports they can access.
What if a client needs temporary elevated access?
What if a client needs temporary elevated access?
You can temporarily upgrade their permissions, then downgrade later. Consider using time-limited access for sensitive situations.
Communicate with clients
Send messages and request documents.