Written by: Andrew Cohen, CFA, CPA, Managing Partner, Condesa Financial Group
Key Takeaways for QuickBooks User Permissions
- QuickBooks user permissions must follow least-privilege access to reduce fraud risk and audit exposure for staff, bookkeepers, and fractional CFOs.
- QBO Advanced and QuickBooks Desktop Enterprise both support custom roles, but differ in user limits, granular controls, and external accountant access methods.
- Common permission mistakes include shared logins, over-granting admin rights, and failing to deactivate users promptly during offboarding.
- Proper role configuration, such as read-only CFO View roles or scoped custom roles, improves audit trails, reduces permission tickets, and supports secure outsourced accounting.
- Contact Condesa Financial to structure QuickBooks access for outsourced and fractional CFO engagements with ex-Big-4 security discipline.
Scoping QuickBooks Access Before You Add Users
Define three items before adding any user: the role’s scope of work, the data it must touch, and the data it must never touch. User limits, preset roles, custom roles, and capabilities vary by plan and connected services, so inventory your active subscription first. Once you know what is technically possible, document the agreed permission scope in the engagement letter for any outsourced or nearshore arrangement before sending invitations.
Prerequisites by platform:
- QBO: Primary Admin or Company Admin credentials, plus Advanced or Intuit Enterprise Suite subscription for custom roles
- QBO Accountant: Admin or full-access user status within the accountant firm’s portal
- Desktop Enterprise: Admin password for the company file
- All platforms: Multi-factor authentication enabled on every user account before granting access to outsourced teams
Request your pre-engagement QuickBooks access checklist tailored to nearshore accounting teams.
After you confirm your subscription tier and document permission requirements, you can configure access for each user. The next sections walk through the exact steps for adding, editing, and restricting users in QuickBooks Online and Desktop Enterprise.
Step-by-Step User Setup in QuickBooks Online
To add a user:
- Go to Settings ⚙ → Manage users.
- Select Add user.
- Enter the user’s name and email address.
- Select a role from the Roles dropdown and expand sections to review permissions.
- Configure any applicable Account management settings.
- Select Send invitation. The user receives an email and must click “Let’s go!” to activate access.
To create a custom role (Advanced/Enterprise Suite only):
- Go to Settings ⚙ → Manage users → Roles tab → Add role.
- Enter a Role name and Role description.
- Select specific access areas using View, Create, Edit, Delete, Print, or Share toggles across Sales, Expenses, Banking, Payroll, Reports, and Accounting tabs.
- Select Save Role.
To edit an existing user’s role:
- Go to Settings ⚙ → Manage users → Users tab.
- Select Edit in the Action column for the relevant user.
- Change the role from the Roles dropdown.
- Select Save. The user must sign out and back in for changes to take effect.
To delete a user:
- Go to Settings ⚙ → Manage users.
- Select the ellipsis icon on the user row, choose Delete, and confirm. Deletion is permanent, but the user’s history remains visible in the audit log.
Step-by-Step User Setup in QuickBooks Desktop Enterprise
To add a user:
- Go to Company menu → Users → Set Up Users and Roles.
- Enter the admin password.
- Select the User List tab → New.
- Enter a username and optional password.
- Select roles from Available Roles, click Add, then OK.
To create a custom role:
- Go to Company → Users → Set Up Users and Roles and enter the admin password.
- Select Role List tab → New.
- Name the role with a descriptive permission-level label.
- Set None / Full / Partial access for each Area and Activities section.
- Select OK.
To review all role permissions:
- Go to Company → Users → Set Up Users and Roles → Role List tab → View Permissions.
- Select the roles to review and click Display to run the Permission Access by Roles report.
Get help configuring Desktop Enterprise roles for your outsourced accounting engagement.
Even when you follow these steps correctly, configuration mistakes can still weaken your permission structure and increase risk. The next section highlights the most common issues and how to avoid them.
Common Permission Mistakes and Risk Areas
Additional risks specific to nearshore and outsourced arrangements include the following patterns.
- Indefinite accountant access: A provider added as a generic accountant user and retained indefinitely ends up with over-permissioned access and slow offboarding.
- Shared logins: Sharing one Intuit login between staff, outside accountants, or support personnel makes audit evidence and recovery ownership unreliable.
- Desktop file exposure: QuickBooks Desktop shifts responsibility for file encryption, host patching, network segmentation, and backups onto the firm when the company file resides on local machines, which increases exposure for outsourced access.
- Time-zone gaps: For nearshore teams operating across time zones, set a closing date with password immediately after each monthly close to prevent retroactive edits during off-hours.
- Payroll over-access: Payroll access in QuickBooks is never automatic with the Standard role and must be deliberately assigned, then paired with a local review step before each pay run is finalized.
Troubleshooting tip: If a user cannot see updated permissions, they must sign out and back in to QBO for role changes to take effect. Time-tracking roles cannot be edited, so delete and re-invite those users when changes are required.
How to Tell If Your Permission Setup Is Working
A well-structured permission setup produces measurable improvements within the first monthly close cycle. Look for the following indicators of a healthy configuration.
- Cleaner audit trails: QBO’s audit trail records who made each change, what changed, when it happened, and the before-and-after values, and named individual logins make this log actionable.
- Fewer permission tickets: When roles match engagement scope at onboarding, ad-hoc access requests drop significantly.
- Clearer reporting: A fractional CFO with a read-only CFO View role can pull any report without risk of inadvertent edits, which reduces review friction.
- Quarterly access audits passing cleanly: Remove users who have not logged in during the last quarter, review disconnected app connections via Gear → Apps → My Apps, and verify that a closing date with password is active.
Once your baseline permission structure runs smoothly, you can tighten security further with several advanced configurations. These options help complex or multi-entity environments improve control without slowing day-to-day work.
Advanced QuickBooks Access Controls for Outsourced Teams
Time-limited accountant access: Contemporary outsourced-bookkeeping security controls favor time-bound or just-in-time access where possible, with immediate deprovisioning during offboarding. For year-end CPA engagements, deactivate a Tax Preparer role with View-only access on the day the return is filed.
Custom roles in Advanced: Custom roles in QBO Advanced can be restricted by scope filters for class, location, or customer lists, so a Sales Rep role scoped to specific customers can only edit invoices for those customers. This approach works well for multi-entity or multi-location SMEs.
Cross-border controls: Intuit bank connections include read-only options such as Web Connect and Express Web Connect, and two-way options such as Direct Connect that support bill pay and transfers, but bank-portal permissions live in a separate system. Bank read-only access does not automatically restrict what a user can do in QuickBooks Online, so review permissions separately across banking platforms, accounting software, and payroll systems.
MFA hardening: Use authenticator apps or hardware keys instead of SMS for MFA on admin and banking accounts to reduce SIM-swap risk.
Learn how our ex-Big-4 nearshore team operates within a least-privilege QuickBooks framework on every engagement.
Sample Role-Access Matrix for Common QuickBooks Users
| Permission Area | External Bookkeeper | Senior Accountant / Controller | Fractional CFO |
|---|---|---|---|
| Invoices & Sales | Create, View | Create, Edit, Delete, View | View only |
| Bills & Expenses | Create, View | Create, Edit, Delete, View | View only |
| Journal Entries | Create, Edit, View (JEs over $1,000 routed for owner approval) | Create, Edit, Delete, View | View only |
| Bank Feeds & Reconciliation | View, Categorize | Full access including undo reconciliation | View only |
| Financial Reports (P&L, Balance Sheet) | Blocked under standard Bookkeeper role | Full access | Full read-only access (CFO View role) |
| Payroll | View only (to record entries from outside service) | View; no run-payroll rights without explicit assignment | View only |
| Chart of Accounts | Blocked | Edit with owner approval | View only |
| User Management | Blocked | Blocked | Blocked |
| Company Settings | Blocked | Blocked | Blocked |
| Audit Log | No access | View | View (blocked under standard View reports role; requires custom CFO View configuration) |
Frequently Asked Questions
What is the difference between the Bookkeeper role and the In House Accountant role in QuickBooks Online?
The Bookkeeper role in QuickBooks Online permits entering invoices, bills, payments, and project transactions but blocks viewing financial reports such as Profit & Loss, balance sheet, or cash flow statements. The In House Accountant role grants those bookkeeping functions plus full access to financial reports, the activity log, budgets, bank feeds, reconciliations, and journal entries. Neither role permits payroll management or user management. For an outsourced bookkeeper focused on transaction entry and close support, the Bookkeeper role enforces appropriate least-privilege access. For a senior accountant or controller who must review financials and prepare reporting packages, the In House Accountant role is the correct starting point, with custom restrictions added in QBO Advanced if needed.
Can a fractional CFO access QuickBooks Online without being able to edit or delete data?
Yes. QuickBooks Online Advanced supports a custom CFO View role that provides read-only access to all areas of the file and full access to reports, with no Create, Edit, or Delete permissions anywhere. This configuration allows a fractional CFO to pull any financial report, review the audit log, and analyze data without risk of inadvertent changes to the books. It is the recommended configuration for strategic oversight engagements where the CFO’s role is analysis and direction rather than transaction processing. The standard View reports non-billable role is a lighter alternative but does not include audit log access, so the custom CFO View role is preferable for formal fractional CFO arrangements.
How should a business handle QuickBooks access when offboarding a nearshore bookkeeper or outsourced accounting firm?
Revoke access on the same day the engagement ends, not after a transition period. In QuickBooks Online, the Primary Admin navigates to Settings ⚙ → Manage users, selects the ellipsis icon on the departing user, and chooses Delete. Before deletion, confirm that no recurring transactions, report schedules, or connected-app authorizations are tied to that user account, and transfer any such responsibilities to an active user. For QuickBooks Desktop Enterprise, remove the user from the User List and change the admin password. A post-offboarding audit log review covering the final 30 days of the departing user’s activity provides a strong internal control. Condesa Financial builds offboarding checklists into every engagement agreement so this step is never overlooked.
Does QuickBooks Online Advanced support restricting a user to specific customers or locations only?
Yes. Custom roles in QuickBooks Online Advanced can be scoped by class, location, or customer list when those dimensions are enabled in the company file. A Sales Rep role, for example, can be configured to allow editing invoices only for a specific customer subset, with no visibility into other customer records. This approach works well for multi-location SMEs or businesses where different outsourced team members handle distinct revenue streams. The restriction applies at the row level across the three built-in dimensions, and field-level restrictions within a single transaction record are not supported, so a user who can view an invoice sees all fields on that invoice.
What security controls should be in place before granting QuickBooks access to any outsourced or nearshore team?
Confirm five controls before sending any invitation. First, confirm the MFA requirement mentioned in the prerequisites is met, using an authenticator app or hardware key rather than SMS. Second, enforce the unique-login requirement discussed in the risks section, with no shared credentials. Third, scope the assigned role to the minimum permissions required for the engagement and document that scope in writing. Fourth, set a closing date with password to prevent prior-period edits. Fifth, establish a quarterly access audit schedule to remove inactive users, review app connections, and verify that permission configurations still match current engagement scope. These controls align with FTC Safeguards Rule requirements that apply to accounting firms handling consumer financial information.
Conclusion
QuickBooks user permissions function as a financial control, not an administrative afterthought. Matching roles to engagement scope, whether for an external bookkeeper, a senior accountant, or a fractional CFO, protects sensitive data, preserves audit trail integrity, and reduces the friction that comes from over- or under-permissioned access. The steps, matrices, and checklists in this guide reflect the realities of outsourced and nearshore accounting, where least-privilege access and named individual logins are non-negotiable.
Condesa Financial Group structures every client engagement around these principles from day one. Our ex-Big-4 nearshore team operates within these principles from day one, and our fractional CFO oversight layer ensures that access configurations are reviewed, documented, and updated as engagements evolve, delivering Big-4-caliber security discipline at price-competitive rates built for SMEs.
Schedule a free consultation to learn how Condesa Financial can structure your QuickBooks access for a secure, high-quality outsourced accounting engagement.
