# What are the best document tools for bookkeepers managing multiple clients?

Applies to: United States · Updated 2026-10-01

No tool is best in general. The right one passes tests built from the work you repeat across every client: keeping each client's documents separate, filing them the same way for everyone, seeing what is outstanding across the roster, and handing one client a complete set without anyone else's. Confirm each claimed capability in the provider's own current documentation, and trial the tool on a slice of clients for a full period before moving everyone.

## Which work should decide the choice?

Choose on the document work you repeat every period for every client, not on a feature list. That work has six parts:

- **Intake.** Documents arrive from many clients as uploads, email attachments, statements and paper.
- **Separation.** Each document is tied to exactly one client before anyone works on it.
- **Review and filing.** Each is checked and filed under the same structure for every client.
- **Association with the books.** Each supports a transaction in that client's own ledger.
- **Status.** You can see across the roster what has arrived and what is still missing.
- **Close-out.** When an engagement ends, you can produce one client's complete set without exposing anyone else's.

A tool built for one business never has to separate clients, report a roster's status or close one client out, so that is where it tends to fail. Note how many clients, staff and documents each operation involves today; those numbers decide which criteria below bind.

## Which capabilities separate practice-grade tools from single-business apps?

Six capabilities carry most of the difference:

| Capability | What it must do | Typical single-business gap |
|---|---|---|
| Client separation | Each client is a walled space; users see only the clients assigned to them, and search, previews and shared links never cross clients | One shared space, where a misfiled document is visible to everyone |
| Roles and permissions | Separate rights to view, upload, edit, delete and export, set per person and per client | Everyone is an owner or editor |
| One firm structure | A firm template of folders, tags and naming applied to each client in one action, with exceptions visible | Each client set up by hand and drifting apart |
| Bulk handling | A mixed batch is routed to the right clients and corrected in bulk | One document at a time |
| Roster-wide status | One view of every client's expected and missing documents for the period | Status kept in a separate spreadsheet |
| Capacity model | Limits and licensing counted per client, user, storage or document, as the provider states them, projected to your roster | Limits sized for one business |

Hold the firm structure strictly even where the tool allows variation: per-client improvisation removes the advantage of roster tooling and makes covering for a colleague slow.

## Where should the documents live?

Three arrangements weigh those criteria differently:

| Arrangement | Client separation | Roster-wide view | At disengagement |
|---|---|---|---|
| Inside each client's accounting platform | Between clients' books, yes; which staff reach which client depends on the platform's accountant-access settings, so test it | Only as far as the platform's accountant view reaches, and none across platforms | Documents stay in the client's account |
| One firm-wide document system | As strong as its per-client permissions | Across every client and platform | You produce the client's set from the tool's export |
| Document module of a practice or workflow system | Tied to each client record | Across clients, beside tasks and deadlines | Depends on that system's document export |

Choosing the practice system itself is a separate question.

A second choice cuts across all three: whether documents sit in the client's own account with access granted to you, or in your system on the client's behalf. In the client's account, the client as owner controls who keeps access and the documents stay with the client when you leave, so keep copies of the working papers you need in your own system. In your system, you control access and must produce the client's records under any rule below that applies, so the one-client export test becomes a hard requirement.

## How should the tool connect to each client's accounting software?

The document tool is never the only system, and much of its cost sits at that seam. A working connection delivers each document to the right client's ledger, attached to the transaction it supports, without retyping its figures, and leaves one copy clearly the record. Without it, staff rekey figures, documents sit away from the transactions they support, and duplicate copies drift apart until nobody knows which is right. Find the connection in the provider's documentation for every platform your clients use, then test it on each.

## Which confidentiality and client-record rules limit the choice?

Each rule below binds only the practitioners its scope names, so check which describe your practice; engagement letters, and your state's confidentiality, records and accountancy-board rules, can add to them. A practice's data-security obligations in full are a separate question.

### What does the AICPA Code require of members in public practice?

For members in public practice, the AICPA Code of Professional Conduct sets these conditions:

- **Telling the client.** Interpretation 1.150.040 says that before disclosing confidential client information to a third-party service provider, a member should inform the client, preferably in writing, and if the client objects, either not use the provider or decline the engagement. No notice is needed for administrative support such as record storage or software application hosting.
- **Contract or consent.** Interpretation 1.700.040 says that before such a disclosure the member should either contract with the provider to keep the information confidential, with reasonable assurance that it has procedures to prevent unauthorized release, or obtain the client's specific consent. The Code does not say whether placing files with a provider that only stores or hosts them is a disclosure under this interpretation; 1.150.040 exempts that kind of administrative support only from the notice requirement.
- **Who counts.** The Code's definition of a third-party service provider covers an entity the member does not control, individually or with the member's firm, and an individual not employed by the member who assists with professional services, with bookkeeping named as an example; the provider of a tool you do not control falls within the first, and subcontractors within the second.
- **Returning records.** Interpretation 1.400.200 covers current and former clients and treats client-provided records, including electronic reproductions, as belonging to the client. On an initial request, the member should make those in its custody or control available to whoever provided them, in any usable and accessible format, as soon as practicable and, absent extenuating circumstances, within the interpretation's outer time limit. Working papers are the member's property, though state and federal statutes and regulations and contractual agreements may impose additional requirements, and stricter rules from a state board of accountancy must be followed.

### What do IRS rules require of tax return preparers and practitioners?

The IRS's Section 7216 FAQ treats as tax return preparers those who assist in preparing returns or perform auxiliary services in connection with them, and contractors who receive tax return information from preparers. The FAQ notes that Revenue Procedure 2013-14 explains the difference between tax return preparation or auxiliary services and other financial accounting services, so check which describes your work. Disclosure to another preparer who is assisting in the preparation of the return or providing auxiliary services generally needs no taxpayer consent, but if that preparer is outside the United States or any U.S. territory or possession, the taxpayer must agree and sign a consent form containing the language Revenue Procedure 2013-14 specifies. Preparers who engage contractors and disclose tax return information to them must give them written notice of the rules and consequences, and the FAQ says preparers generally may not obtain consent to disclose Social Security numbers to preparers outside the United States; where those numbers appear in documents covered by a consent, they must be redacted or masked before disclosure, unless the taxpayer consents and both preparers maintain the adequate data protection safeguards the FAQ refers to.

Treasury Circular 230 (Rev. 6-2014), section 10.28, requires a practitioner, at a client's request, to promptly return the client's records necessary for the client to comply with federal tax obligations; copies may be kept. Section 10.8 applies these practice duties to anyone who, for compensation, prepares or assists with all or substantially all of a tax return.

### What does the FTC Safeguards Rule add?

The FTC's guide says coverage turns on the activities your business undertakes, not on how it is categorized, and lists tax preparation firms among its examples; IRS Publication 5708, a sample-plan guide, says tax and accounting professionals are considered financial institutions under the rule. The FTC's guide adds that the FTC has exempted from certain provisions of the rule institutions that maintain customer information concerning fewer than five thousand consumers. Neither document settles whether a practice that only keeps books for business clients holds customer information the rule protects, so confirm your position before treating the duties below as yours. For the customer information the rule protects, the FTC's guide says to:

- Reconsider regularly whether each person with access still has a legitimate business need for it.
- Require multi-factor authentication for anyone accessing customer information on your system, unless your Qualified Individual has approved another equivalent form of secure access controls in writing.
- Monitor when authorized users access customer information on your system, and detect unauthorized access.
- Select service providers able to maintain appropriate safeguards, with contracts that spell out your security expectations, build in ways to monitor the provider's work, and provide for periodic reassessment of its suitability.

## How do you control and remove access when people come and go?

Nothing in daily work reveals access that has outlived its need, so build access control into the tool and run it this way:

- **Named logins.** Give each employee and contractor their own login, and keep an administrator login of your own that no one else uses; the IRS's sample plan in Publication 5708 provides that the firm will have no shared passwords.
- **Per-client scope.** Give each login only the clients that person works on, with the role their work needs.
- **Removal at the moment it ends.** When a person leaves, or an assignment or engagement ends, you or another administrator, never the person leaving, end all their access at once: the document tool, their user on each client's accounting platform (above all any login that can approve or send payments), shared mailboxes, firm devices holding client files, and any shared credential they knew, which is changed then. The sample plan in Publication 5708 likewise provides that a terminated employee's logins and passwords are disabled at the time of termination.
- **When a client engagement ends.** Take that client out of every login's scope in the document tool, and end the firm's own users on that client's accounting platform yourself rather than waiting for the client to.
- **Confirmation from complete lists.** From your own administrator login, check the removal against the tool's user and permission report across every client and against each client platform's user list, never against the departing person's account of what they had.
- **Activity record.** Keep a record of who viewed, downloaded, changed or deleted which client's documents that ordinary users cannot alter, and review it yourself.

## Which provider claims should you verify, and how?

Find each capability in the provider's own current documentation for its U.S. product, note the page and its date, and treat anything the documentation does not state as absent. Check at least these points:

- **Authentication.** Confirm that multi-factor authentication is offered and can be required of every user, contractors included.
- **Activity logging.** Find which actions are logged for each client, and who can see or change the log.
- **Data location.** Find where the provider says client files are stored.
- **Third parties.** Find which other companies the provider discloses as able to reach stored data.
- **Export and withdrawal.** Find how one client's files are exported, and how one person's access is withdrawn for one client or altogether.
- **Licensing basis.** Find whether the tool is licensed by client, user, storage or document.

Documentation tells you what to test, not that it works. Intuit's help page Add and manage your accounting team in Intuit Accountant Suite (updated 9/24/2026) says you grant a team member access to a client by assigning a role, and that team members can be made inactive "so they don't show up in the Team menu" but cannot be completely deleted, using the page's Delete action; the page does not say this ends their client access, so the matching trial test is to remove a test member that way and confirm they can no longer open any client's books. One product's documentation speaks only for that product.

## How do you trial a candidate before moving the whole roster?

Before any client's documents go into a candidate, even for a trial and including the ledger-connection test, meet the notice, contract or consent conditions above that apply to you and, if the Safeguards Rule reaches you, have a provider contract that spells out your security expectations and carries the FTC's other contract terms; trial only clients for whom those conditions are met.

Pick a slice that represents the roster: clients on each accounting platform you serve, your highest-volume client, one that sends paper and one that sends little. Run them through the candidate for a full period, time the operations you repeat, and keep your own list of every file you load for each trial client. Then run these tests:

| Criterion | Test with your own client data | Passes when |
|---|---|---|
| Separation | Sign in as a test user assigned to two trial clients and search for a payee that appears only at a third | Nothing from the third client appears in search, previews or links |
| Roles | Give a test user view-only rights, then try to delete and to export | Both are blocked |
| Firm structure | Apply the firm template to three clients, then change it once | All three follow without manual rebuilding |
| Bulk intake | Load one mixed batch from several trial clients | Every file lands in exactly one client, and misroutes surface for review |
| Roster status | Build each client's expected list from its bank, card and other accounts, not from what arrived | Missing items show, even for a client that sent nothing |
| Ledger connection | Send ten documents to each trial client's accounting platform | Each is attached to the right transaction in the right client's books, with nothing retyped |
| Access removal | From your own administrator login, remove a test user mid-period | The user cannot reach any client, and the activity record shows the removal |
| Per-client withdrawal | Remove one trial client from a test user's scope | The user can no longer reach that client but still reaches the others, and the activity record shows the change |
| Activity record | Open, download and rename a file as a test user | The record shows who, which client, what and when, and the test user cannot edit it |
| One-client export | Export one trial client's complete set | It matches your own load list, opens in usable formats and holds nothing from any other client |

Before committing, measure switching cost: how long each client takes to move, and whether your current tool can export each client's set as cleanly. Then move the roster in groups, starting the next group only after the previous one has run a full period and passed the export test.

## What does one month's intake look like under two setups?

Take a firm with three staff and 40 clients that each send about 25 documents a month, 1,000 documents in all.

| Step | Shared cloud drive, one folder per client | Practice-grade system, one space per client |
|---|---|---|
| Routing | Someone opens, renames and files all 1,000 | Files arrive in each client's own space; staff resolve only the exceptions, say 1 in 10, or 100 |
| Who sees what | All three staff can open all 40 folders | Each person sees only the 13 or 14 clients assigned to them |
| What is missing | A spreadsheet holds what someone remembered to add | Each client's expected list, built from its accounts, is matched against what arrived |
| Close-out | Copying a folder misses files misfiled elsewhere or left in email | One export, checked against your load list |

The difference shows only in the repeated work: 900 fewer routing decisions a month, and a misfiled document no longer open to every colleague.

## How does the answer change for your practice?

Four facts decide which criteria bind:

- **Roster size.** The more clients an operation repeats across, the more bulk handling, the firm structure and roster status matter.
- **Staff count.** Roles and per-client scope bind once more than one person can reach client files, and the activity record does too unless the Safeguards Rule already requires it.
- **Platform mix.** One platform makes documents inside that platform viable; several make platform neutrality a criterion.
- **Volume per client.** High volume makes bulk intake and the ledger connection decisive.

A solo bookkeeper can set aside roles and internal access control, which are firm-only criteria. The record of who did what is firm-only too unless the Safeguards Rule reaches you, because the FTC guide states its duty to log authorized users' activity and detect unauthorized access without reference to staff count. Separation, one structure, roster status, the ledger connection, one-client export and any other Safeguards duty that reaches you still apply. The firm-only criteria bind the day a second person gets access.

With clients on several accounting platforms, a firm-wide tool keeps one structure and one roster view but must be tested on every platform; working inside each platform keeps documents beside their transactions but gives up the single roster view and lets structure drift.

Where contractors or offshore staff do the work, give each a named login scoped to named clients, meet the notice, contract or consent conditions above that apply to you before they see client files, and end every access, including client platform logins, the moment the assignment ends. If offshore staff will reach documents carrying Social Security numbers, test that the tool lets you mask them or keep those documents out of their scope.

## Sources

1. American Institute of CPAs — *Code of Professional Conduct*, Effective December 15, 2014; updated for all official releases through September 2026. https://pub.aicpa.org/codeofconduct/ethicsresources/et-cod.pdf
2. Internal Revenue Service — *Section 7216 Frequently Asked Questions*, Page last reviewed or updated 28-Jun-2026. https://www.irs.gov/tax-professionals/section-7216-frequently-asked-questions
3. Internal Revenue Service — *Treasury Department Circular No. 230, Regulations Governing Practice before the Internal Revenue Service*, Rev. 6-2014. https://www.irs.gov/pub/irs-pdf/pcir230.pdf
4. Federal Trade Commission — *FTC Safeguards Rule: What Your Business Needs to Know*, December 2024. https://www.ftc.gov/business-guidance/resources/ftc-safeguards-rule-what-your-business-needs-know
5. Internal Revenue Service — *Publication 5708, Creating a Written Information Security Plan for your Tax & Accounting Practice*, Rev. 8-2024. https://www.irs.gov/pub/irs-pdf/p5708.pdf
6. Intuit Inc. — *Add and manage your accounting team in Intuit Accountant Suite*, Updated 9/24/2026 (QuickBooks Online Accountant, Intuit Accountant Suite). https://quickbooks.intuit.com/learn-support/en-us/help-article/access-permissions/add-manage-accounting-team-quickbooks-online/L13kRqbLq_US_en_US

## Related questions

- [How can a bookkeeping firm standardize document intake across many clients?](https://uppago.com/resources/how-a-bookkeeping-firm-can-standardize-document-intake-across-clients)
- [How can a bookkeeping firm automate document collection across many clients?](https://uppago.com/resources/how-a-bookkeeping-firm-can-automate-document-collection-across-clients)
- [What monthly document workflow should a bookkeeper run for each client?](https://uppago.com/resources/a-monthly-document-workflow-a-bookkeeper-runs-for-each-client)
- [What practice workflow or client-management software should an accounting or bookkeeping firm use to run and track its client work and document flow?](https://uppago.com/resources/how-to-choose-practice-management-software-for-a-bookkeeping-firm)
- [How does an accountant collect documents from clients?](https://uppago.com/resources/how-an-accountant-collects-documents-from-clients)
