EPOS Accountancy · Business insights

Accounting software access: permissions, approvals and business continuity

← All articles

Your accounting software can contain customer details, supplier bank information, payroll records and the reports used to make business decisions. Access should reflect what each person needs to do. Giving everyone administrator rights is convenient until a payment is changed, a record disappears or the only account owner leaves.

In this article
The process at a glance
  1. List who needs access and why
  2. Set appropriate permissions and approvals
  3. Protect sign-ins and recovery access
  4. Review users when responsibilities change

A workable arrangement combines named users, limited permissions, clear approval responsibilities and a recovery plan. It also makes ordinary work easier because staff know which decisions they can make and when to ask for approval.

Start with the tasks, not the job titles

List the actions carried out in the system: entering bills, checking expenses, creating invoices, changing supplier details, running reports, approving payments and submitting returns. Then assign each action to a person or role.

Do not assume the software's standard role names fit your business. Test what a user can actually view, edit, export or approve. Some packages separate payroll access; others offer fewer controls. Check the current product and subscription rather than relying on a feature mentioned in an old demonstration.

Role or task Access to consider Boundary to check
Sales administration Create invoices and view relevant customer balances Access to payroll or unrelated supplier records
Bookkeeping Enter and reconcile agreed transactions Changing users or approving payments
Business owner Review reports and approve significant actions Routine use of broad administrator rights
External adviser Records needed for the engagement Access outside the agreed service scope
Technical support Limited, time-bound access where needed Continued access after the issue is resolved

These are illustrative arrangements, not universal settings. A small business may combine roles, but it should still identify where one person can create and approve the same transaction.

Use named accounts and protect recovery routes

Shared logins make it harder to establish who changed an entry and harder to remove one person's access. Use individual accounts where the product permits them, with business-controlled ownership of the subscription and recovery arrangements.

Enable strong authentication supported by the service. The NCSC's guidance on securing important online accounts explains additional verification and recovery options. Protect the email account used for password resets as carefully as the accounting login.

Keep recovery codes and ownership information securely, accessible to authorised people in an emergency. Avoid making the business dependent on a former employee's personal phone or email. Record how an administrator can be replaced and how access would be recovered if the owner were unavailable.

Illustration of bookkeeping records being reviewed
Illustrative scene: organising and reviewing business finances.

Separate accounting access from payment authority

Being able to record a supplier invoice should not automatically mean being authorised to pay it. Accounting software permissions, bank permissions and payment-provider permissions are separate settings that need a joined-up review.

Agree who can create or amend supplier bank details and how changes are independently verified. Use a trusted contact route already held for the supplier rather than the contact information in an unexpected change request. Decide who approves payments and how that approval is recorded.

Where the team is too small to separate every task, introduce a compensating review. The owner might inspect supplier changes and payment reports before releasing money. Write down the arrangement so a busy week does not remove the check by accident.

Protect personal information proportionately

Permission design also concerns data protection. Payroll records and customer information should not be available simply because a colleague needs to issue invoices. Consider exports and downloaded reports as well as what appears on screen.

The ICO's access-control guidance supports restricting access according to need and reviewing permissions. Apply the principle to connected apps and external advisers, not only employees. Confirm who manages access reviews and how the business records their completion.

Plan for absence, departure and lost access

Create a short access register showing users, permissions, approval dates, connected applications and the responsible business owner. Review it when someone changes role or leaves, and periodically even if the team is stable.

A departure checklist should cover accounting access, bank access, payment providers, shared folders, devices and recovery arrangements. Transfer ownership of necessary records without keeping unnecessary access active. Preserve the audit history rather than deleting evidence of past activity.

For continuity, identify which reports and source documents the business would need during an outage. Confirm the supplier's export and recovery arrangements. Keep usable copies of essential information under an agreed policy and test that authorised staff can retrieve them. The NCSC's backup guidance explains why recovery copies and testing matter. A cloud subscription alone does not describe your complete recovery process.

An illustrative access review

Imagine a growing consultancy gives its office assistant administrator access during initial setup. Months later, that person needs only invoicing and expense entry. An access review finds they can also export payroll data and change the subscription owner.

The business adjusts the role, gives the external accountant separately scoped access and records a second authorised recovery contact. It then tests an invoice workflow to ensure the restrictions do not prevent the assistant doing their job. This illustrative example shows how reviewing permissions can improve both control and usability.

EPOS Accountancy can discuss access arrangements alongside your accounting software support. Bring your user list, approval process and continuity concerns. Confirm the available accounting support and whether separate IT or security assistance is needed; the engagement should define responsibilities. Visit pricing to understand the route to a scoped quote.