← All articles

For business owners

How to give a bookkeeper QuickBooks access without giving up control

Your bookkeeper needs to see and record everything. They do not need to move money, and they do not need your bank login. Those are two separate permissions, and most owners hand over both by accident.

Bookkeeping access and payment authority are two different things. Your bookkeeper needs the first and almost never needs the second. Most owners collapse them into one decision, usually by sharing an admin login and a bank password, and then have no way to tell who did what.

The fix is not trust. Trust is fine. The fix is structure, so that a mistake stays small and visible, and so that nothing depends on remembering who has which password.

The permission levels, conceptually

Every accounting platform, QuickBooks Online included, sorts users into a few tiers. The names vary and the menus move, so think in terms of capability rather than screens.

Admin. Can do everything: add and remove users, change permissions, connect and disconnect banks, alter core settings, close the books, and in some cases delete the file. This is the owner's role. There should be exactly one primary admin and it should be you, on an email address you personally control. Not your bookkeeper's email. Not a shared info@ inbox.

Standard or full-access user. Can see and record everything in the books: customers, vendors, invoices, bills, banking, reconciliation, reports, journal entries, without controlling users, permissions or company settings. This is where a bookkeeper belongs. They can do the entire job from here.

Limited-access user. Restricted to one area, typically AR-only or AP-only. Useful when you have someone doing invoicing but nothing else, or a clerk entering bills. Too narrow for a full bookkeeper, and constraining them into it usually creates workarounds that are worse than the risk you were managing.

Reports-only or view-only. Read access to reports, nothing more. Right for an investor, a lender, a partner who wants visibility, or a bookkeeper during an initial diagnostic before you have decided anything.

Accountant or accounting firm access. A separate invitation type for your CPA or bookkeeping firm. It carries elevated tools (reclassification, write-off and adjusting-entry utilities) and does not consume a normal user seat. Use it for your accountant, and apply the same audit trail rules.

Separating bookkeeping from payment authority

This is the control that matters most and the one most small businesses skip. The person who records transactions should not also be the person who releases money. Not because they are dishonest, but because a single person doing both means nothing gets caught by anyone.

Practically:

  • Your bookkeeper enters bills, matches them to purchase records, and stages a payment batch.
  • You, or a designated approver, review the batch and release it.
  • Bank and card reconciliation is done by the bookkeeper; you review the completed reconciliation report monthly.
  • Adding a new vendor with new bank details is a step you personally confirm, ideally by calling a known number rather than replying to an email. Vendor-detail fraud is the most common way small businesses lose real money.
  • Check-signing authority and card issuance stay with you.

If your volume genuinely requires the bookkeeper to release payments, at minimum set a dollar threshold above which you approve, and read every reconciliation.

The setup sequence

  1. Confirm you hold the primary admin role on your own email. If a former bookkeeper, an old accountant, or a family member is still the admin, fix that before anything else. Verify: you can open the user management area and see every user listed.

  2. Audit who already has access. Every prior bookkeeper, intern and one-off contractor. Remove everyone who does not currently need it. Verify: every remaining user is a person you can name and justify.

  3. Invite the bookkeeper as a named standard user. Their own email, their own login, their real name. Verify: the user list shows them individually, not as a generic account.

  4. Connect bank and card feeds yourself, under your own credentials. The feed then works for everyone without anyone else touching your banking login. Verify: the bookkeeper can see and categorize transactions but there is no path from the accounting file to initiating a transfer.

  5. Configure the payment workflow with preparer and approver as different people. Verify: your bookkeeper can build a payment run and cannot release it.

  6. Turn on multi-factor authentication on your admin account and require it of anyone with access. Verify: a login attempt prompts for a second factor.

  7. Close periods once reviewed. Most platforms let you lock a closed period behind a password only the admin holds. This stops prior-month figures from shifting after you have reported them. Verify: an edit attempt in a closed period is blocked.

  8. Put an NDA and a written scope in place before granting access. What they can see, what they can do, what requires your approval. Verify: signed before the invitation goes out.

  9. Review the audit log monthly. Ten minutes. Look for deletions, edits to prior periods, and changes to vendor bank details. Verify: nothing surprises you.

  10. Have an offboarding step written down. When a bookkeeper leaves, access is revoked the same day. Verify: the removal is done in user management, not by changing a shared password.

The audit trail, and why shared logins ruin it

QuickBooks Online and comparable platforms record who created, changed or deleted each transaction, with a timestamp. That log is the single most useful control you have. It answers "who changed this invoice" without a conversation.

It only works if identity is real. One shared login means every action is attributed to "the login," and the log becomes useless at exactly the moment you need it. This is the practical reason to never share credentials, well ahead of any question of trust.

Two habits make the log worth having. First, individual named accounts for everyone, always. Second, actually read it monthly, focused on deleted transactions, edits to closed periods and vendor banking changes.

When your bookkeeper is offshore

The controls above do not change. They are the same controls you would apply to someone in your office, because the risks are the same risks.

Ask any provider three things: is this a named individual or a rotating pool, has that individual signed a comprehensive NDA, and can you provision their access yourself at the permission level you choose. A shared pool working through a ticket queue cannot give you a clean audit trail, no matter what the log says.

Every operator we place signs a comprehensive NDA before access is granted, works full-time on US business hours, and is added to your file by you, at the permission level you decide. You see daily reports, live online and offline status and task visibility through the client portal.

Common questions

What QuickBooks user role should I give my bookkeeper?

A named standard, non-admin user. That covers everything a bookkeeper needs: transactions, banking, reconciliation, reports, while leaving user management, permissions and company settings with you. Keep the admin role in your own name.

Should I give my bookkeeper my bank login?

No. Connect the bank feed yourself under your own credentials; the accounting system's connection is read-only and cannot move money. Sharing banking credentials also generally breaches your bank's account agreement and can void fraud protection.

Can a bookkeeper delete transactions in QuickBooks?

A standard user generally can, but the audit log records the deletion, who did it and when. That is why individual logins matter and why closing periods with an admin-held password is worth setting up.

How do I remove a bookkeeper's access when they leave?

Deactivate their user account in user management the same day. Do not simply change a password, and do not leave the account dormant. Also review the audit log for their final weeks and confirm nothing was left mid-reconciliation.

Is it safe to give an offshore bookkeeper access to my books?

It is as safe as the structure you put around it. A named individual under NDA, a non-admin permission level you set yourself, no banking credentials shared, payment authority kept separate, and a monthly audit log review. Those controls do the work regardless of where the person sits.