# How do I set up users and permissions in my accounting file so people only see and change what they should?

- **[not stated in the document; general accounting-concept article published by US-based AccountingTools, Inc. · businesses generally; applied per transaction]** The article states that no single person should control authorization, recordkeeping and custody of assets for the same transaction — these are the three functions segregation of duties separates. → [CG-MCE-022#S01](#s-CG-MCE-022-S01)
- **[QuickBooks Online Advanced / Intuit Enterprise Suite · Help article updated 8/3/2026 · United States (en-US QuickBooks Online support edition) · QuickBooks Online Advanced and Intuit Enterprise Suite subscribers]** Custom-role permissions define what actions a user can perform within a feature, with view only, create, edit, delete, approve and all access given as examples of those action levels. → [CG-MCE-022#S15](#s-CG-MCE-022-S15)
- **[Zoho Books · US-EN help edition, current release · United States (Zoho Books US-EN help edition) · Zoho Books organizations]** The Super Admin privilege is automatically assigned to the user who creates the organization and carries, beyond standard admin permissions, exclusive rights over other admins. → [CG-MCE-022#S46](#s-CG-MCE-022-S46)
- **[Zoho Books · US-EN help edition, current release · United States (Zoho Books US-EN help edition) · Zoho Books organizations]** A user who should no longer have access to the Zoho Books organization can be deleted. → [CG-MCE-022#S64](#s-CG-MCE-022-S64)

## What this page establishes

- The roles each platform offers, what they reach, and how many user seats you get — Not established
- Which capabilities the platforms let you switch on and off separately — Not established
- The control principle behind the settings: keep recording, approving and custody in different hands — Partly established (Required authority: authoritative professional or accounting standard. Highest achieved: high quality professional secondary reference.)
- Handing the administrator account over, and what happens if you lose control of it — Not established
- What removal leaves behind, and what has to be handed to someone else — Not established
- The joiner, leaver and review discipline expected of a small business's accounting system — Not established
- Start from the work, not the software: list what each person actually needs to do — Not established
- How your platform expresses access: the unit it is granted in, fixed roles or adjustable permissions, and what it cannot express — Established
- The areas to restrict beyond ordinary bookkeeping - payroll, money movement, customer and vendor records, and the whole financial picture — Not established (Required authority: authoritative professional or accounting standard, official platform documentation. Highest achieved: high quality professional secondary reference, official platform documentation.)
- Seeing, recording, and changing or deleting: how the three levels appear in the settings — Established (Required authority: authoritative professional or accounting standard, official platform documentation. Highest achieved: official platform documentation.)
- Deleting, reopening a closed period, paying money out and changing other people's access: the actions to hold back separately — Not established (Required authority: authoritative professional or accounting standard, official platform documentation. Highest achieved: high quality professional secondary reference, official platform documentation.)
- The owner or administrator account: who holds it and why it is not your everyday login — Partly established
- Adding someone: decide the level first, then grant it and record what you granted — Partly established (Required authority: authoritative professional or accounting standard, official platform documentation. Highest achieved: official platform documentation.)
- When someone leaves: removing their access in the file and checking it took effect — Partly established (Required authority: authoritative professional or accounting standard, official platform documentation. Highest achieved: official platform documentation.)
- Reviewing the user list on a set schedule instead of setting it once — Not established
- Whether removing a user also removes the record of what they did — Not established

## Start from the work, not the software: list what each person actually needs to do
<a id="need-CG-MCE-022-P1"></a>

_Not established from an authoritative source._

## The control principle behind the settings: keep recording, approving and custody in different hands
<a id="need-CG-MCE-022-C3"></a>

- <a id="s-CG-MCE-022-S01"></a>The article states that no single person should control authorization, recordkeeping and custody of assets for the same transaction — these are the three functions segregation of duties separates. _(jurisdiction: not stated in the document; general accounting-concept article published by US-based AccountingTools, Inc., entity_scope: businesses generally; applied per transaction, conditions: for the same transaction)_ `CG-MCE-022#S01`
  > “No single person should control authorization, recordkeeping, and custody of assets for the same transaction.” — [AccountingTools, Inc. (author Steven Bragg) — Segregation of duties definition](https://www.accountingtools.com/articles/segregation-of-duties.html), 2026-02-05; Section "What is Segregation of Duties?", second sentence. Verified 2026-09-09.

- <a id="s-CG-MCE-022-S02"></a>In this illustrative accounts payable example, the employee who enters vendor invoices into the accounting system should not also be the person who authorizes or processes payments. _(jurisdiction: not stated in the document; general accounting-concept article published by US-based AccountingTools, Inc., entity_scope: businesses generally; stated as an example of how the concept is used within a business, conditions: given as an example, not as a requirement)_ `CG-MCE-022#S02`
  > “An employee who enters vendor invoices into the accounting system should not be the same person who authorizes or processes payments.” — [AccountingTools, Inc. (author Steven Bragg) — Segregation of duties definition](https://www.accountingtools.com/articles/segregation-of-duties.html), 2026-02-05; Section "Examples of Segregation of Duties", bullet "Accounts Payable: Invoice processing vs. payment authorization". Verified 2026-09-09.

- <a id="s-CG-MCE-022-S03"></a>In payroll, the person who adds new employees or updates payroll records should not also distribute or authorize payroll payments. _(jurisdiction: not stated in the document; general accounting-concept article published by US-based AccountingTools, Inc., entity_scope: businesses generally; illustrative example, conditions: given as an example, not as a requirement)_ `CG-MCE-022#S03`
  > “The person responsible for adding new employees or updating payroll records should not also be responsible for distributing or authorizing payroll payments.” — [AccountingTools, Inc. (author Steven Bragg) — Segregation of duties definition](https://www.accountingtools.com/articles/segregation-of-duties.html), 2026-02-05; Section "Examples of Segregation of Duties", bullet "Payroll: Employee setup vs. payroll disbursement". Verified 2026-09-09.

- <a id="s-CG-MCE-022-S04"></a>The ability to create journal entries should be held separately from the authority to approve them. _(jurisdiction: not stated in the document; general accounting-concept article published by US-based AccountingTools, Inc., entity_scope: businesses generally; illustrative general-ledger example, conditions: given as an example, not as a requirement)_ `CG-MCE-022#S04`
  > “The ability to create journal entries should be distinct from the authority to approve them.” — [AccountingTools, Inc. (author Steven Bragg) — Segregation of duties definition](https://www.accountingtools.com/articles/segregation-of-duties.html), 2026-02-05; Section "Examples of Segregation of Duties", bullet "General Ledger: Journal entry creation vs. approval". Verified 2026-09-09.

_Partly established. Established: separating the ability to record from the ability to approve or to remove (S01, S02, S03, S04); payroll warrants restriction beyond ordinary bookkeeping access (S03); the movement of money warrants restriction beyond ordinary bookkeeping access (S01, S02, S03). Missing: granting the least access the work requires; the distinction control practice draws between access that only permits viewing, access that permits recording and access that permits altering or removing records; altering or deleting entries warrants restriction beyond ordinary bookkeeping access; reopening a closed period warrants restriction beyond ordinary bookkeeping access._

_Required authority: authoritative professional or accounting standard. Highest achieved: high quality professional secondary reference._

## How your platform expresses access: the unit it is granted in, fixed roles or adjustable permissions, and what it cannot express
<a id="need-CG-MCE-022-P2"></a>

- <a id="s-CG-MCE-022-S07"></a>When setting up a new role the account may instead choose from a list of built-in QuickBooks roles, with Company admin and Time tracking only given as examples. _(jurisdiction: United States (en-US QuickBooks Online support edition), entity_scope: QuickBooks Online Advanced and Intuit Enterprise Suite subscribers, platform: QuickBooks Online Advanced / Intuit Enterprise Suite, platform_edition: Help article updated 8/3/2026, effective_from: 2026-08-03)_ `CG-MCE-022#S07`
  > “Choose from the list of QuickBooks roles, like Company admin or Time tracking only.” — [Intuit Inc. — Add and manage custom roles in QuickBooks Online Advanced and Intuit Enterprise Suite](https://quickbooks.intuit.com/learn-support/en-us/help-article/access-permissions/add-manage-custom-roles-quickbooks-online-advanced/L8Ugph7xl_US_en_US), 2026-08-03; Intro, 'When you set up a new role, you have the option to:' list. Verified 2026-09-09.

- <a id="s-CG-MCE-022-S08"></a>Some permission fields are read-only and are automatically included in a role rather than being chosen by the person defining the role. _(jurisdiction: United States (en-US QuickBooks Online support edition), entity_scope: QuickBooks Online Advanced and Intuit Enterprise Suite subscribers, platform: QuickBooks Online Advanced / Intuit Enterprise Suite, platform_edition: Help article updated 8/3/2026, effective_from: 2026-08-03)_ `CG-MCE-022#S08`
  > “Some fields are read-only and are automatically included in a role for your information.” — [Intuit Inc. — Add and manage custom roles in QuickBooks Online Advanced and Intuit Enterprise Suite](https://quickbooks.intuit.com/learn-support/en-us/help-article/access-permissions/add-manage-custom-roles-quickbooks-online-advanced/L8Ugph7xl_US_en_US), 2026-08-03; Intro, 'Note :' block above 'Add a new role'. Verified 2026-09-09.

- <a id="s-CG-MCE-022-S09"></a>Custom roles manage access only to standard reports, not to custom reports created by other users. _(jurisdiction: United States (en-US QuickBooks Online support edition), entity_scope: QuickBooks Online Advanced and Intuit Enterprise Suite subscribers, platform: QuickBooks Online Advanced / Intuit Enterprise Suite, platform_edition: Help article updated 8/3/2026, effective_from: 2026-08-03)_ `CG-MCE-022#S09`
  > “Custom roles let users manage access only to standard reports and not custom reports created by other users.” — [Intuit Inc. — Add and manage custom roles in QuickBooks Online Advanced and Intuit Enterprise Suite](https://quickbooks.intuit.com/learn-support/en-us/help-article/access-permissions/add-manage-custom-roles-quickbooks-online-advanced/L8Ugph7xl_US_en_US), 2026-08-03; Section 'Custom roles and access' → 'Area: Reports' → 'Note :'. Verified 2026-09-09.

- <a id="s-CG-MCE-022-S11"></a>In Wave the unit access is granted in is the individual business: a user must be invited to each business separately in order to reach additional business profiles. _(jurisdiction: Wave platform as documented in Wave's en-us Help Center; the article's only stated geographic limits are the US condition attached to Block Advisor Tax Pros and the CAD/USD currency options, entity_scope: Each business profile within a Wave account, platform: Wave, platform_edition: current Wave release; article undated, conditions: applies where the user is to access more than one business profile)_ `CG-MCE-022#S11`
  > “You must invite a user to each business individually for them to access additional business profiles.” — [Wave Financial Inc. — Invite or remove collaborators from your business](https://support.waveapps.com/hc/en-us/articles/208621236-Invite-or-remove-collaborators-from-your-business), current Wave release; undated help article (packet notes date not obtainable - host returned HTTP 403); Introduction, under the title "Invite or remove collaborators from your business". Verified 2026-09-09.

- <a id="s-CG-MCE-022-S12"></a>Choosing Selected access opens the Sage 50 User Security window, which lets the areas of Sage 50 the user may access be selected individually. _(jurisdiction: United States (Sage 50 U.S. edition help, en-us), entity_scope: Sage 50 company user records with Selected access, platform: Sage 50 (U.S.), platform_edition: 2026)_ `CG-MCE-022#S12`
  > “If you have chosen Selected access , the Sage 50 User Security window appears. It lets you select exactly the areas of the Sage 50 that you want the user to be able to access.” — [The Sage Group plc (Sage 50 U.S. product help) — Set Up Company Users, Passwords, and Access Rights](https://help-sage50.na.sage.com/en-us/2026/Content/USERS/Set_Up_Company_Users_Passwords_and_Access_Rights.htm), 2026-06-17; Setting up additional company users — after clicking OK or Next. Verified 2026-09-09.

## The roles each platform offers, what they reach, and how many user seats you get
<a id="need-CG-MCE-022-C1"></a>

- <a id="s-CG-MCE-022-S14"></a>Permissions in custom roles are assigned by area of QuickBooks, with banking, sales, payroll, expenses, reports, budgets and inventory given as examples of such areas (list introduced by 'like', not closed). _(jurisdiction: United States (en-US QuickBooks Online support edition), entity_scope: QuickBooks Online Advanced and Intuit Enterprise Suite subscribers, platform: QuickBooks Online Advanced / Intuit Enterprise Suite, platform_edition: Help article updated 8/3/2026, effective_from: 2026-08-03)_ `CG-MCE-022#S14`
  > “Choose what users can see and do within different areas of QuickBooks like banking, sales, payroll, expenses, reports, budgets, and inventory.” — [Intuit Inc. — Add and manage custom roles in QuickBooks Online Advanced and Intuit Enterprise Suite](https://quickbooks.intuit.com/learn-support/en-us/help-article/access-permissions/add-manage-custom-roles-quickbooks-online-advanced/L8Ugph7xl_US_en_US), 2026-08-03; Intro paragraph beginning 'With custom roles, you can manage user access in...'. Verified 2026-09-09.

- <a id="s-CG-MCE-022-S15"></a>Custom-role permissions define what actions a user can perform within a feature, with view only, create, edit, delete, approve and all access given as examples of those action levels. _(jurisdiction: United States (en-US QuickBooks Online support edition), entity_scope: QuickBooks Online Advanced and Intuit Enterprise Suite subscribers, platform: QuickBooks Online Advanced / Intuit Enterprise Suite, platform_edition: Help article updated 8/3/2026, effective_from: 2026-08-03)_ `CG-MCE-022#S15`
  > “What actions they can perform within those features, like view only, create, edit, delete, approve, and all access.” — [Intuit Inc. — Add and manage custom roles in QuickBooks Online Advanced and Intuit Enterprise Suite](https://quickbooks.intuit.com/learn-support/en-us/help-article/access-permissions/add-manage-custom-roles-quickbooks-online-advanced/L8Ugph7xl_US_en_US), 2026-08-03; Section 'Custom roles and access', bullet list under 'Custom roles let you assign detailed permissions...'. Verified 2026-09-09.

- <a id="s-CG-MCE-022-S16"></a>Intuit states that a QuickBooks Online customer can add unlimited accounts or users if they upgrade to QuickBooks Online Advanced. _(jurisdiction: United States (en-US QuickBooks Support article), entity_scope: QuickBooks Online subscribers, platform: QuickBooks Online, platform_edition: QuickBooks Online Advanced (upgrade required); article listed as applying to QuickBooks Online Advanced, Plus, Simple Start, Essentials, Intuit Enterprise Suite, QuickBooks Solopreneur Plus, effective_from: 2026-08-05, conditions: conditional on upgrading to QuickBooks Online Advanced; as stated on this help page updated 8/5/2026)_ `CG-MCE-022#S16`
  > “You can add unlimited accounts or users if you upgrade to QuickBooks Online Advanced .” — [Intuit Inc. — How to add and manage users](https://quickbooks.intuit.com/learn-support/en-us/help-article/manage-users/add-manage-users-company/L5anZQ0XH_US_en_US), 2026-08-05; Article body, first line under heading "How to add and manage users" (Updated 8/5/2026 04:44). Verified 2026-09-09.

- <a id="s-CG-MCE-022-S17"></a>The Staff role, assigned by the admin, gives access to all modules except reports, settings and accountant. _(jurisdiction: United States (Zoho Books US-EN help edition), entity_scope: Zoho Books organizations, platform: Zoho Books, platform_edition: US-EN help edition, current release)_ `CG-MCE-022#S17`
  > “The Staff role is assigned by the admin to other users who can access all modules except reports, settings, and accountant.” — [Zoho Corporation — Users & Roles | Help | Zoho Books](https://www.zoho.com/us/books/help/settings/users.html), not published on the page; Roles > Staff. Verified 2026-09-09.

- <a id="s-CG-MCE-022-S18"></a>The Free plan's stated user limit is 1 user plus 1 accountant. _(jurisdiction: United States (Zoho Books US-EN help edition), entity_scope: Zoho Books organizations on the Free plan, platform: Zoho Books, platform_edition: US-EN help edition, current release)_ `CG-MCE-022#S18`
  > “Free 1 User + 1 Accountant” — [Zoho Corporation — Users & Roles | Help | Zoho Books](https://www.zoho.com/us/books/help/settings/users.html), not published on the page; Users > Available Plans (Plans / Limits table). Verified 2026-09-09.

- <a id="s-CG-MCE-022-S19"></a>Wave offers Admin, Editor and Viewer user types, and only Pro Plan subscribers can invite them. _(jurisdiction: Wave platform as documented in Wave's en-us Help Center; the article's only stated geographic limits are the US condition attached to Block Advisor Tax Pros and the CAD/USD currency options, entity_scope: Wave accounts on the Pro Plan, platform: Wave, platform_edition: current Wave release; article undated, conditions: requires a Pro Plan subscription)_ `CG-MCE-022#S19`
  > “Only Pro Plan subscribers can invite Admins, Editors, and Viewers.” — [Wave Financial Inc. — Invite or remove collaborators from your business](https://support.waveapps.com/hc/en-us/articles/208621236-Invite-or-remove-collaborators-from-your-business), current Wave release; undated help article (packet notes date not obtainable - host returned HTTP 403); Section "Add a user to your business profile", closing note after the steps. Verified 2026-09-09.

- <a id="s-CG-MCE-022-S20"></a>Wave offers Payroll Manager and Block Advisor Tax Pro user types; all Wave account owners can add Payroll Managers, and can add Block Advisor Tax Pros only if the business is based in the US. _(jurisdiction: Wave platform; the Block Advisor Tax Pro option is stated to require a business based in the United States, entity_scope: All Wave account owners; Block Advisor Tax Pro limited to US-based businesses, platform: Wave, platform_edition: current Wave release; article undated, conditions: Block Advisor Tax Pro conditional on the business being based in the US)_ `CG-MCE-022#S20`
  > “All Wave account owners can add Payroll Managers, and Block Advisor Tax Pros (if your business is based in the US).” — [Wave Financial Inc. — Invite or remove collaborators from your business](https://support.waveapps.com/hc/en-us/articles/208621236-Invite-or-remove-collaborators-from-your-business), current Wave release; undated help article (packet notes date not obtainable - host returned HTTP 403); Section "Add a user to your business profile", closing note after the steps. Verified 2026-09-09.

- <a id="s-CG-MCE-022-S21"></a>When setting up an additional company user, the access level chosen is Full access, Selected access, or None. _(jurisdiction: United States (Sage 50 U.S. edition help, en-us), entity_scope: Additional Sage 50 company user records, platform: Sage 50 (U.S.), platform_edition: 2026)_ `CG-MCE-022#S21`
  > “Choose the appropriate level for the user: Full access , Selected access , or None.” — [The Sage Group plc (Sage 50 U.S. product help) — Set Up Company Users, Passwords, and Access Rights](https://help-sage50.na.sage.com/en-us/2026/Content/USERS/Set_Up_Company_Users_Passwords_and_Access_Rights.htm), 2026-06-17; Setting up additional company users. Verified 2026-09-09.

- <a id="s-CG-MCE-022-S22"></a>Setting up Sage 50 users starts with a company administrator, and individual users can then be set up up to the number of licences held. _(jurisdiction: United States (Sage 50 U.S. edition help, en-us), entity_scope: A Sage 50 company data file and its users, platform: Sage 50 (U.S.), platform_edition: 2026, conditions: number of additional users is bounded by licences held)_ `CG-MCE-022#S22`
  > “Setting up users in Sage 50 involves setting up a company administrator first. After that, you can set up individual users, as many as you have licenses for.” — [The Sage Group plc (Sage 50 U.S. product help) — Set Up Company Users, Passwords, and Access Rights](https://help-sage50.na.sage.com/en-us/2026/Content/USERS/Set_Up_Company_Users_Passwords_and_Access_Rights.htm), 2026-06-17; Set Up Company Users, Passwords, and Access Rights — opening paragraph. Verified 2026-09-09.

_Not established from an authoritative source._

## The areas to restrict beyond ordinary bookkeeping - payroll, money movement, customer and vendor records, and the whole financial picture
<a id="need-CG-MCE-022-P3"></a>

- See above: In this illustrative accounts payable example, the employee who enters vendor invoices into the accounting system should not also be the person who authorizes or processes payments. ([CG-MCE-022#S02](#s-CG-MCE-022-S02))

- See above: In payroll, the person who adds new employees or updates payroll records should not also distribute or authorize payroll payments. ([CG-MCE-022#S03](#s-CG-MCE-022-S03))

- <a id="s-CG-MCE-022-S24"></a>A role with all payroll access cannot view bank registers or bank info. _(jurisdiction: United States (en-US QuickBooks Online support edition), entity_scope: QuickBooks Online Advanced and Intuit Enterprise Suite subscribers, platform: QuickBooks Online Advanced / Intuit Enterprise Suite, platform_edition: Help article updated 8/3/2026, effective_from: 2026-08-03, conditions: role has all payroll access)_ `CG-MCE-022#S24`
  > “View bank registers or bank info” — [Intuit Inc. — Add and manage custom roles in QuickBooks Online Advanced and Intuit Enterprise Suite](https://quickbooks.intuit.com/learn-support/en-us/help-article/access-permissions/add-manage-custom-roles-quickbooks-online-advanced/L8Ugph7xl_US_en_US), 2026-08-03; Section 'Custom roles and access' → 'Area: Payroll' → 'All payroll access' → 'You cannot:'. Verified 2026-09-09.

- <a id="s-CG-MCE-022-S25"></a>Paying bills online through QB Bill Pay requires the separate 'pay' permission, so online payment initiation is controlled apart from recording bill payments. _(jurisdiction: United States (en-US QuickBooks Online support edition), entity_scope: QuickBooks Online Advanced and Intuit Enterprise Suite subscribers, platform: QuickBooks Online Advanced / Intuit Enterprise Suite, platform_edition: Help article updated 8/3/2026, effective_from: 2026-08-03, conditions: 'pay' permission held)_ `CG-MCE-022#S25`
  > “Pay bills online using QB Bill Pay if you have the ‘pay’ permission” — [Intuit Inc. — Add and manage custom roles in QuickBooks Online Advanced and Intuit Enterprise Suite](https://quickbooks.intuit.com/learn-support/en-us/help-article/access-permissions/add-manage-custom-roles-quickbooks-online-advanced/L8Ugph7xl_US_en_US), 2026-08-03; Section 'Custom roles and access' → 'Area: Expenses' → 'Bill Payments' → 'You can:'. Verified 2026-09-09.

- <a id="s-CG-MCE-022-S26"></a>Access to certain lists can be controlled as part of custom roles, and assigning transaction access may automatically give users access to lists such as customers and vendors. _(jurisdiction: United States (en-US QuickBooks Online support edition), entity_scope: QuickBooks Online Advanced and Intuit Enterprise Suite subscribers, platform: QuickBooks Online Advanced / Intuit Enterprise Suite, platform_edition: Help article updated 8/3/2026, effective_from: 2026-08-03)_ `CG-MCE-022#S26`
  > “You can control access to certain lists in QuickBooks as part of custom roles. When you assign access to transactions, users may automatically get access to lists like customers and vendors.” — [Intuit Inc. — Add and manage custom roles in QuickBooks Online Advanced and Intuit Enterprise Suite](https://quickbooks.intuit.com/learn-support/en-us/help-article/access-permissions/add-manage-custom-roles-quickbooks-online-advanced/L8Ugph7xl_US_en_US), 2026-08-03; Section 'Custom roles and access' → 'Area: Lists'. Verified 2026-09-09.

- <a id="s-CG-MCE-022-S27"></a>A role with all access to projects cannot reach the company Profit and Loss, Balance sheet or other financial reports; those require separate permissions. _(jurisdiction: United States (en-US QuickBooks Online support edition), entity_scope: Intuit Enterprise Suite subscribers only, platform: Intuit Enterprise Suite, platform_edition: Help article updated 8/3/2026, effective_from: 2026-08-03, conditions: role has all access to projects)_ `CG-MCE-022#S27`
  > “Access company Profit and Loss, Balance sheet, or other financial reports (requires separate permissions).” — [Intuit Inc. — Add and manage custom roles in QuickBooks Online Advanced and Intuit Enterprise Suite](https://quickbooks.intuit.com/learn-support/en-us/help-article/access-permissions/add-manage-custom-roles-quickbooks-online-advanced/L8Ugph7xl_US_en_US), 2026-08-03; Section 'Custom roles and access' → 'Area: Projects (Intuit Enterprise Suite only)' → 'You cannot:'. Verified 2026-09-09.

- <a id="s-CG-MCE-022-S28"></a>A role with all bookkeeping access cannot view Reconcile, Budgeting or the Audit Log. _(jurisdiction: United States (en-US QuickBooks Online support edition), entity_scope: QuickBooks Online Advanced and Intuit Enterprise Suite subscribers, platform: QuickBooks Online Advanced / Intuit Enterprise Suite, platform_edition: Help article updated 8/3/2026, effective_from: 2026-08-03, conditions: role has all bookkeeping access)_ `CG-MCE-022#S28`
  > “View Reconcile, Budgeting, or Audit Log.” — [Intuit Inc. — Add and manage custom roles in QuickBooks Online Advanced and Intuit Enterprise Suite](https://quickbooks.intuit.com/learn-support/en-us/help-article/access-permissions/add-manage-custom-roles-quickbooks-online-advanced/L8Ugph7xl_US_en_US), 2026-08-03; Section 'Custom roles and access' → 'Area: Bookkeeping' → 'All bookkeeping access' → 'You cannot:'. Verified 2026-09-09.

- <a id="s-CG-MCE-022-S29"></a>Segmented access control lets an organization limit which records users can view and modify, based on locations, reporting tags or bank accounts. _(jurisdiction: United States (Zoho Books US-EN help edition), entity_scope: Zoho Books organizations, platform: Zoho Books, platform_edition: US-EN help edition, current release)_ `CG-MCE-022#S29`
  > “Segmented access control lets you limit which records users can view and modify based on locations, reporting tags, or bank accounts.” — [Zoho Corporation — Users & Roles | Help | Zoho Books](https://www.zoho.com/us/books/help/settings/users.html), not published on the page; Roles > Configure Segmented Access Control for Roles. Verified 2026-09-09.

_Not established from an authoritative source._

_Required authority: authoritative professional or accounting standard, official platform documentation. Highest achieved: high quality professional secondary reference, official platform documentation._

## Which capabilities the platforms let you switch on and off separately
<a id="need-CG-MCE-022-C2"></a>

- See above: Paying bills online through QB Bill Pay requires the separate 'pay' permission, so online payment initiation is controlled apart from recording bill payments. ([CG-MCE-022#S25](#s-CG-MCE-022-S25))

- See above: Access to certain lists can be controlled as part of custom roles, and assigning transaction access may automatically give users access to lists such as customers and vendors. ([CG-MCE-022#S26](#s-CG-MCE-022-S26))

- <a id="s-CG-MCE-022-S30"></a>Managing users is restricted to administrators and to custom users who hold the Manage users permission, so user management is itself a separately held permission. _(jurisdiction: United States (en-US QuickBooks Online support edition), entity_scope: QuickBooks Online Advanced and Intuit Enterprise Suite subscribers, platform: QuickBooks Online Advanced / Intuit Enterprise Suite, platform_edition: Help article updated 8/3/2026, effective_from: 2026-08-03)_ `CG-MCE-022#S30`
  > “Only administrators and custom users with Manage users permissions can manage users.” — [Intuit Inc. — Add and manage custom roles in QuickBooks Online Advanced and Intuit Enterprise Suite](https://quickbooks.intuit.com/learn-support/en-us/help-article/access-permissions/add-manage-custom-roles-quickbooks-online-advanced/L8Ugph7xl_US_en_US), 2026-08-03; Intro, 'Note :' block above 'Add a new role'. Verified 2026-09-09.

- <a id="s-CG-MCE-022-S32"></a>A user with the report View permission can filter dates, export and schedule reports, so exporting a report comes with view-level report access. _(jurisdiction: United States (en-US QuickBooks Online support edition), entity_scope: QuickBooks Online Advanced and Intuit Enterprise Suite subscribers, platform: QuickBooks Online Advanced / Intuit Enterprise Suite, platform_edition: Help article updated 8/3/2026, effective_from: 2026-08-03, conditions: report View action permission)_ `CG-MCE-022#S32`
  > “Filter dates, export, and schedule reports.” — [Intuit Inc. — Add and manage custom roles in QuickBooks Online Advanced and Intuit Enterprise Suite](https://quickbooks.intuit.com/learn-support/en-us/help-article/access-permissions/add-manage-custom-roles-quickbooks-online-advanced/L8Ugph7xl_US_en_US), 2026-08-03; Section 'Custom roles and access' → 'Area: Reports' → 'View' → 'You can:'. Verified 2026-09-09.

- <a id="s-CG-MCE-022-S33"></a>Only users with Admin access can add new users. _(jurisdiction: United States (Zoho Books US-EN help edition), entity_scope: Zoho Books organizations, platform: Zoho Books, platform_edition: US-EN help edition, current release)_ `CG-MCE-022#S33`
  > “Only users with Admin access can add new users.” — [Zoho Corporation — Users & Roles | Help | Zoho Books](https://www.zoho.com/us/books/help/settings/users.html), not published on the page; Users > Add User > Note. Verified 2026-09-09.

- <a id="s-CG-MCE-022-S34"></a>At the Full Access level the user can display the program area or specified window, add new records or transactions, edit existing data and delete data, and full access also allows the ability to perform specified system functions. _(jurisdiction: United States (Sage 50 U.S. edition help, en-us), entity_scope: A user's access level for a Sage 50 program area or window, platform: Sage 50 (U.S.), platform_edition: 2026)_ `CG-MCE-022#S34`
  > “Full Access: 
 The user can display the program area or specified Sage 50 window, 
 add new records or transactions, maintain (edit) existing data, and delete 
 data. Full access also allows the ability to perform specified system 
 functions.” — [The Sage Group plc (Sage 50 U.S. product help) — Set Up Company Users, Passwords, and Access Rights](https://help-sage50.na.sage.com/en-us/2026/Content/USERS/Set_Up_Company_Users_Passwords_and_Access_Rights.htm), 2026-06-17; User Roles: Security Access Levels. Verified 2026-09-09.

- <a id="s-CG-MCE-022-S35"></a>The accounting Delete action permission lets a user view and delete accounts or transactions. _(jurisdiction: United States (en-US QuickBooks Online support edition), entity_scope: QuickBooks Online Advanced and Intuit Enterprise Suite subscribers, platform: QuickBooks Online Advanced / Intuit Enterprise Suite, platform_edition: Help article updated 8/3/2026, effective_from: 2026-08-03)_ `CG-MCE-022#S35`
  > “Delete View and delete accounts or transactions.” — [Intuit Inc. — Add and manage custom roles in QuickBooks Online Advanced and Intuit Enterprise Suite](https://quickbooks.intuit.com/learn-support/en-us/help-article/access-permissions/add-manage-custom-roles-quickbooks-online-advanced/L8Ugph7xl_US_en_US), 2026-08-03; Section 'Custom roles and access' → 'Area: Accounting' → 'Action permissions' table, Delete row. Verified 2026-09-09.

_Not established from an authoritative source._

## Seeing, recording, and changing or deleting: how the three levels appear in the settings
<a id="need-CG-MCE-022-P4"></a>

- See above: Custom-role permissions define what actions a user can perform within a feature, with view only, create, edit, delete, approve and all access given as examples of those action levels. ([CG-MCE-022#S15](#s-CG-MCE-022-S15))

- See above: A user with the report View permission can filter dates, export and schedule reports, so exporting a report comes with view-level report access. ([CG-MCE-022#S32](#s-CG-MCE-022-S32))

- See above: At the Full Access level the user can display the program area or specified window, add new records or transactions, edit existing data and delete data, and full access also allows the ability to perform specified system functions. ([CG-MCE-022#S34](#s-CG-MCE-022-S34))

- See above: The accounting Delete action permission lets a user view and delete accounts or transactions. ([CG-MCE-022#S35](#s-CG-MCE-022-S35))

- <a id="s-CG-MCE-022-S36"></a>The sales View action permission lets a user view transactions without the ability to modify or delete them. _(jurisdiction: United States (en-US QuickBooks Online support edition), entity_scope: QuickBooks Online Advanced and Intuit Enterprise Suite subscribers, platform: QuickBooks Online Advanced / Intuit Enterprise Suite, platform_edition: Help article updated 8/3/2026, effective_from: 2026-08-03, conditions: sales transactions)_ `CG-MCE-022#S36`
  > “View View transactions without the ability to modify or delete them” — [Intuit Inc. — Add and manage custom roles in QuickBooks Online Advanced and Intuit Enterprise Suite](https://quickbooks.intuit.com/learn-support/en-us/help-article/access-permissions/add-manage-custom-roles-quickbooks-online-advanced/L8Ugph7xl_US_en_US), 2026-08-03; Section 'Custom roles and access' → 'Area: Sales' → 'Action permissions' table, View row. Verified 2026-09-09.

- <a id="s-CG-MCE-022-S37"></a>The sales Edit action permission lets a user view, create and edit transactions without the ability to delete them, so editing and deleting are separately granted. _(jurisdiction: United States (en-US QuickBooks Online support edition), entity_scope: QuickBooks Online Advanced and Intuit Enterprise Suite subscribers, platform: QuickBooks Online Advanced / Intuit Enterprise Suite, platform_edition: Help article updated 8/3/2026, effective_from: 2026-08-03, conditions: sales transactions)_ `CG-MCE-022#S37`
  > “Edit View, create, and edit transactions without the ability to delete them” — [Intuit Inc. — Add and manage custom roles in QuickBooks Online Advanced and Intuit Enterprise Suite](https://quickbooks.intuit.com/learn-support/en-us/help-article/access-permissions/add-manage-custom-roles-quickbooks-online-advanced/L8Ugph7xl_US_en_US), 2026-08-03; Section 'Custom roles and access' → 'Area: Sales' → 'Action permissions' table, Edit row. Verified 2026-09-09.

- <a id="s-CG-MCE-022-S38"></a>At the View Only level the user can display the program area or specified window and view existing data, but cannot enter a new record or change existing data — seeing without recording or altering. _(jurisdiction: United States (Sage 50 U.S. edition help, en-us), entity_scope: A user's access level for a Sage 50 program area or window, platform: Sage 50 (U.S.), platform_edition: 2026)_ `CG-MCE-022#S38`
  > “View Only: The 
 user can display the program area or specified Sage 50 window or view 
 existing data but cannot enter a new record or change existing data.” — [The Sage Group plc (Sage 50 U.S. product help) — Set Up Company Users, Passwords, and Access Rights](https://help-sage50.na.sage.com/en-us/2026/Content/USERS/Set_Up_Company_Users_Passwords_and_Access_Rights.htm), 2026-06-17; User Roles: Security Access Levels. Verified 2026-09-09.

- <a id="s-CG-MCE-022-S39"></a>At the Add level the user can display the program area or specified window and add new records or transactions. _(jurisdiction: United States (Sage 50 U.S. edition help, en-us), entity_scope: A user's access level for a Sage 50 program area or window, platform: Sage 50 (U.S.), platform_edition: 2026)_ `CG-MCE-022#S39`
  > “Add: The 
 user can display the program area or specified Sage 50 window and add 
 new records or transactions.” — [The Sage Group plc (Sage 50 U.S. product help) — Set Up Company Users, Passwords, and Access Rights](https://help-sage50.na.sage.com/en-us/2026/Content/USERS/Set_Up_Company_Users_Passwords_and_Access_Rights.htm), 2026-06-17; User Roles: Security Access Levels. Verified 2026-09-09.

- <a id="s-CG-MCE-022-S40"></a>At the Edit level the user can display the program area or specified window, add new records or transactions, and maintain (edit) existing data. _(jurisdiction: United States (Sage 50 U.S. edition help, en-us), entity_scope: A user's access level for a Sage 50 program area or window, platform: Sage 50 (U.S.), platform_edition: 2026)_ `CG-MCE-022#S40`
  > “Edit: The 
 user can display the program area or specified Sage 50 window, add new 
 records or transactions, and maintain (edit) existing data.” — [The Sage Group plc (Sage 50 U.S. product help) — Set Up Company Users, Passwords, and Access Rights](https://help-sage50.na.sage.com/en-us/2026/Content/USERS/Set_Up_Company_Users_Passwords_and_Access_Rights.htm), 2026-06-17; User Roles: Security Access Levels. Verified 2026-09-09.

_Required authority: authoritative professional or accounting standard, official platform documentation. Highest achieved: official platform documentation._

## Deleting, reopening a closed period, paying money out and changing other people's access: the actions to hold back separately
<a id="need-CG-MCE-022-P5"></a>

- See above: The ability to create journal entries should be held separately from the authority to approve them. ([CG-MCE-022#S04](#s-CG-MCE-022-S04))

- See above: Paying bills online through QB Bill Pay requires the separate 'pay' permission, so online payment initiation is controlled apart from recording bill payments. ([CG-MCE-022#S25](#s-CG-MCE-022-S25))

- See above: Managing users is restricted to administrators and to custom users who hold the Manage users permission, so user management is itself a separately held permission. ([CG-MCE-022#S30](#s-CG-MCE-022-S30))

- See above: A user with the report View permission can filter dates, export and schedule reports, so exporting a report comes with view-level report access. ([CG-MCE-022#S32](#s-CG-MCE-022-S32))

- See above: The sales Edit action permission lets a user view, create and edit transactions without the ability to delete them, so editing and deleting are separately granted. ([CG-MCE-022#S37](#s-CG-MCE-022-S37))

- <a id="s-CG-MCE-022-S41"></a>Journal entry access is granted per action — viewing, creating, copying, editing and deleting journal entries each follow the action-level permissions set. _(jurisdiction: United States (en-US QuickBooks Online support edition), entity_scope: QuickBooks Online Advanced and Intuit Enterprise Suite subscribers, platform: QuickBooks Online Advanced / Intuit Enterprise Suite, platform_edition: Help article updated 8/3/2026, effective_from: 2026-08-03)_ `CG-MCE-022#S41`
  > “View, create, copy, edit, and delete journal entries based on action-level permissions” — [Intuit Inc. — Add and manage custom roles in QuickBooks Online Advanced and Intuit Enterprise Suite](https://quickbooks.intuit.com/learn-support/en-us/help-article/access-permissions/add-manage-custom-roles-quickbooks-online-advanced/L8Ugph7xl_US_en_US), 2026-08-03; Section 'Custom roles and access' → 'Area: Accounting' → 'Journal entries' → 'You can:'. Verified 2026-09-09.

- <a id="s-CG-MCE-022-S43"></a>Only the Super Admin can delete an organization. _(jurisdiction: United States (Zoho Books US-EN help edition), entity_scope: Zoho Books organizations, platform: Zoho Books, platform_edition: US-EN help edition, current release)_ `CG-MCE-022#S43`
  > “Only the Super Admin can delete an organization.” — [Zoho Corporation — Users & Roles | Help | Zoho Books](https://www.zoho.com/us/books/help/settings/users.html), not published on the page; Roles > Super Admin > Unique Privileges For a Super Admin. Verified 2026-09-09.

_Not established from an authoritative source._

_Required authority: authoritative professional or accounting standard, official platform documentation. Highest achieved: high quality professional secondary reference, official platform documentation._

## The owner or administrator account: who holds it and why it is not your everyday login
<a id="need-CG-MCE-022-P6"></a>

- <a id="s-CG-MCE-022-S44"></a>Intuit documents a process by which a person can request to be made the primary admin or the primary contact for a QuickBooks Desktop or QuickBooks Online account. _(jurisdiction: United States (en-US QuickBooks Support edition), entity_scope: Holders of and claimants to a QuickBooks Desktop or QuickBooks Online account, platform: QuickBooks / Intuit account, platform_edition: QuickBooks Desktop and QuickBooks Online, en-US help article updated 9/1/2026)_ `CG-MCE-022#S44`
  > “Learn how to request to be the primary admin or contact for a QuickBooks Desktop or QuickBooks Online account.” — [Intuit Inc. — Request to be the primary admin or contact in QuickBooks Desktop or QuickBooks Online](https://quickbooks.intuit.com/learn-support/en-us/help-article/primary-administrator/request-primary-admin-contact/L2P0XAUIT_US_en_US), 2026-09-01; Article introduction, before "Step 1: Check prerequisites". Verified 2026-09-09.

- <a id="s-CG-MCE-022-S45"></a>Intuit warns that changing the primary admin can affect the user's access to certain things on the Intuit account (the article then lists billing, user management, support plan and bank account changes, without saying the list is exhaustive). _(jurisdiction: United States (en-US QuickBooks Support edition), entity_scope: Intuit account holders using QuickBooks Desktop or QuickBooks Online, platform: QuickBooks / Intuit account, platform_edition: QuickBooks Desktop and QuickBooks Online, en-US help article updated 9/1/2026, conditions: when the primary admin is changed)_ `CG-MCE-022#S45`
  > “Note : Changing the primary admin can affect your access to the following on your Intuit account:” — [Intuit Inc. — Request to be the primary admin or contact in QuickBooks Desktop or QuickBooks Online](https://quickbooks.intuit.com/learn-support/en-us/help-article/primary-administrator/request-primary-admin-contact/L2P0XAUIT_US_en_US), 2026-09-01; Article introduction, "Note" immediately before "Before you proceed, take note of the following:". Verified 2026-09-09.

- <a id="s-CG-MCE-022-S46"></a>The Super Admin privilege is automatically assigned to the user who creates the organization and carries, beyond standard admin permissions, exclusive rights over other admins. _(jurisdiction: United States (Zoho Books US-EN help edition), entity_scope: Zoho Books organizations, platform: Zoho Books, platform_edition: US-EN help edition, current release)_ `CG-MCE-022#S46`
  > “In Zoho Books, the Super Admin is a privilege that is automatically assigned to the user who creates an organization. In addition to the standard admin permissions, the Super Admin has exclusive rights over other admins in an organization.” — [Zoho Corporation — Users & Roles | Help | Zoho Books](https://www.zoho.com/us/books/help/settings/users.html), not published on the page; Roles > Super Admin. Verified 2026-09-09.

- <a id="s-CG-MCE-022-S47"></a>A current Super Admin can transfer the role to another eligible admin at any time, and the new Super Admin then gains Super Admin privileges across all Zoho Finance applications of that organization. _(jurisdiction: United States (Zoho Books US-EN help edition), entity_scope: Zoho Books organizations, platform: Zoho Books, platform_edition: US-EN help edition, current release, conditions: acting user is the current Super Admin; recipient is an eligible admin)_ `CG-MCE-022#S47`
  > “If you’re already a Super Admin and want to make another eligible admin as the Super Admin, you can do so at any time. Once done the new Super Admin will gain the Super Admin privileges across all Zoho Finance applications of that organization.” — [Zoho Corporation — Users & Roles | Help | Zoho Books](https://www.zoho.com/us/books/help/settings/users.html), not published on the page; Roles > Super Admin > Make Another Admin the Super Admin. Verified 2026-09-09.

- <a id="s-CG-MCE-022-S48"></a>An Admin has complete access to all modules, transactions and settings, and can create and assign roles for other users in the organization. _(jurisdiction: United States (Zoho Books US-EN help edition), entity_scope: Zoho Books organizations, platform: Zoho Books, platform_edition: US-EN help edition, current release)_ `CG-MCE-022#S48`
  > “An Admin in a Zoho Books organization has complete access to all modules, transactions, and settings. They can create and assign roles for other users in their organization.” — [Zoho Corporation — Users & Roles | Help | Zoho Books](https://www.zoho.com/us/books/help/settings/users.html), not published on the page; Roles > Admin. Verified 2026-09-09.

- <a id="s-CG-MCE-022-S49"></a>The first Sage 50 user record must be an administrative user holding full rights to each area of the program plus the ability to set up and maintain user records and passwords, and that administrator can then add other users. _(jurisdiction: United States (Sage 50 U.S. edition help, en-us), entity_scope: The first (administrator) user record of a Sage 50 company, platform: Sage 50 (U.S.), platform_edition: 2026)_ `CG-MCE-022#S49`
  > “The first user you set up must be an administrative user with full rights to each area of Sage 50 and the ability to set up and maintain user records and passwords. Once the administrator is set up, he/she can then add other users to the system.” — [The Sage Group plc (Sage 50 U.S. product help) — Set Up Company Users, Passwords, and Access Rights](https://help-sage50.na.sage.com/en-us/2026/Content/USERS/Set_Up_Company_Users_Passwords_and_Access_Rights.htm), 2026-06-17; Setting up the first user (administrator). Verified 2026-09-09.

- <a id="s-CG-MCE-022-S51"></a>Only the administrator can give a user access to the company or change the areas of Sage 50 to which the user has access. _(jurisdiction: United States (Sage 50 U.S. edition help, en-us), entity_scope: A Sage 50 company's user access rights, platform: Sage 50 (U.S.), platform_edition: 2026)_ `CG-MCE-022#S51`
  > “Only the administrator can 
 give the user access to the company or change the areas of Sage 50 to 
 which the user has access.” — [The Sage Group plc (Sage 50 U.S. product help) — Set Up Company Users, Passwords, and Access Rights](https://help-sage50.na.sage.com/en-us/2026/Content/USERS/Set_Up_Company_Users_Passwords_and_Access_Rights.htm), 2026-06-17; Setting up additional company users — None (No Program Access). Verified 2026-09-09.

_Partly established. Established: how the administrator or owner account is held and used (S46, S49, S51); how the administrator or owner account is transferred (S44, S47); what recovery exists if control of it is lost (S44, S52, S53). Missing: why it is not the account used for daily work._

## Handing the administrator account over, and what happens if you lose control of it
<a id="need-CG-MCE-022-C4"></a>

- See above: Setting up Sage 50 users starts with a company administrator, and individual users can then be set up up to the number of licences held. ([CG-MCE-022#S22](#s-CG-MCE-022-S22))

- See above: Intuit documents a process by which a person can request to be made the primary admin or the primary contact for a QuickBooks Desktop or QuickBooks Online account. ([CG-MCE-022#S44](#s-CG-MCE-022-S44))

- See above: Intuit warns that changing the primary admin can affect the user's access to certain things on the Intuit account (the article then lists billing, user management, support plan and bank account changes, without saying the list is exhaustive). ([CG-MCE-022#S45](#s-CG-MCE-022-S45))

- See above: The Super Admin privilege is automatically assigned to the user who creates the organization and carries, beyond standard admin permissions, exclusive rights over other admins. ([CG-MCE-022#S46](#s-CG-MCE-022-S46))

- See above: A current Super Admin can transfer the role to another eligible admin at any time, and the new Super Admin then gains Super Admin privileges across all Zoho Finance applications of that organization. ([CG-MCE-022#S47](#s-CG-MCE-022-S47))

- See above: The first Sage 50 user record must be an administrative user holding full rights to each area of the program plus the ability to set up and maintain user records and passwords, and that administrator can then add other users. ([CG-MCE-022#S49](#s-CG-MCE-022-S49))

- <a id="s-CG-MCE-022-S52"></a>Owners and other authorized parties have 14 business days to verify their identity and upload all required documents; otherwise the system automatically declines the request and the requester needs to submit a new one. _(jurisdiction: United States (en-US QuickBooks Support edition), entity_scope: Requests requiring verification by owners or other authorized parties, platform: QuickBooks / Intuit account, platform_edition: QuickBooks Desktop and QuickBooks Online, en-US help article updated 9/1/2026, conditions: 14-business-day window from the verification request)_ `CG-MCE-022#S52`
  > “Note : Owners and other authorized parties have 14-business days to verify their identity and upload all required documents. Otherwise, the system automatically declines the request and you’ll need to submit a new one.” — [Intuit Inc. — Request to be the primary admin or contact in QuickBooks Desktop or QuickBooks Online](https://quickbooks.intuit.com/learn-support/en-us/help-article/primary-administrator/request-primary-admin-contact/L2P0XAUIT_US_en_US), 2026-09-01; Step 3: Have the owner or other authorized parties submit the required documents — "Note". Verified 2026-09-09.

- <a id="s-CG-MCE-022-S53"></a>Where the previous owner is deceased, the documents needed include a notarized document with the name of the executor of their estate. _(jurisdiction: United States (en-US QuickBooks Support edition), entity_scope: Requests where the previous owner is deceased, platform: QuickBooks / Intuit account, platform_edition: QuickBooks Desktop and QuickBooks Online, en-US help article updated 9/1/2026, conditions: previous owner is deceased)_ `CG-MCE-022#S53`
  > “If the previous owner is deceased, a notarized document with the name of the executor of their estate.” — [Intuit Inc. — Request to be the primary admin or contact in QuickBooks Desktop or QuickBooks Online](https://quickbooks.intuit.com/learn-support/en-us/help-article/primary-administrator/request-primary-admin-contact/L2P0XAUIT_US_en_US), 2026-09-01; Step 1: Check prerequisites — bullet in the list of documents "that you’ll need". Verified 2026-09-09.

- <a id="s-CG-MCE-022-S54"></a>There can be only one Super Admin in an organization, and that Super Admin is the same across the Zoho Finance applications, including (an open list) Zoho Invoice, Zoho Billing, Zoho Expense, Zoho Inventory, Zoho Payroll, Zoho Commerce, Zoho Checkout, Zakya, Zoho Practice and Vikra. _(jurisdiction: United States (Zoho Books US-EN help edition), entity_scope: Zoho Books organizations and their Zoho Finance applications, platform: Zoho Books, platform_edition: US-EN help edition, current release)_ `CG-MCE-022#S54`
  > “There can be only one Super Admin in an organization, and they’re same across all the Zoho Finance applications, including Zoho Invoice, Zoho Billing, Zoho Expense, Zoho Inventory, Zoho Payroll, Zoho Commerce, Zoho Checkout, Zakya, Zoho Practice, and Vikra of that organization.” — [Zoho Corporation — Users & Roles | Help | Zoho Books](https://www.zoho.com/us/books/help/settings/users.html), not published on the page; Roles > Super Admin. Verified 2026-09-09.

_Not established from an authoritative source._

## Adding someone: decide the level first, then grant it and record what you granted
<a id="need-CG-MCE-022-P7"></a>

- See above: Only users with Admin access can add new users. ([CG-MCE-022#S33](#s-CG-MCE-022-S33))

- See above: Only the administrator can give a user access to the company or change the areas of Sage 50 to which the user has access. ([CG-MCE-022#S51](#s-CG-MCE-022-S51))

- <a id="s-CG-MCE-022-S60"></a>After an invitation is sent, Wave shows the pending invitation on the Users page and the invited person receives an email inviting them to join the business. _(jurisdiction: Wave platform as documented in Wave's en-us Help Center; the article's only stated geographic limits are the US condition attached to Block Advisor Tax Pros and the CAD/USD currency options, entity_scope: Wave business profile, platform: Wave, platform_edition: current Wave release; article undated)_ `CG-MCE-022#S60`
  > “On the Users page, you will now see the pending invitations. The user will receive an email, inviting them to join your business in Wave.” — [Wave Financial Inc. — Invite or remove collaborators from your business](https://support.waveapps.com/hc/en-us/articles/208621236-Invite-or-remove-collaborators-from-your-business), current Wave release; undated help article (packet notes date not obtainable - host returned HTTP 403); Section "Add a user to your business profile", step 7. Verified 2026-09-09.

- <a id="s-CG-MCE-022-S61"></a>Sage 50 passwords are case sensitive and must be unique, and two or more user records cannot have the same password. _(jurisdiction: United States (Sage 50 U.S. edition help, en-us), entity_scope: Passwords on Sage 50 company user records, platform: Sage 50 (U.S.), platform_edition: 2026)_ `CG-MCE-022#S61`
  > “Passwords 
 are case sensitive (that is Password , PASSWORD , and password 
 are all different passwords) and must be unique. Two or more user records 
 cannot have the same password.” — [The Sage Group plc (Sage 50 U.S. product help) — Set Up Company Users, Passwords, and Access Rights](https://help-sage50.na.sage.com/en-us/2026/Content/USERS/Set_Up_Company_Users_Passwords_and_Access_Rights.htm), 2026-06-17; Setting up the first user (administrator) — Password. Verified 2026-09-09.

_Partly established. Established: what is decided about the person's access before it is granted (S12, S21). Missing: what is recorded about the grant and its approval._

_Required authority: authoritative professional or accounting standard, official platform documentation. Highest achieved: official platform documentation._

## The joiner, leaver and review discipline expected of a small business's accounting system
<a id="need-CG-MCE-022-C6"></a>

_Not established from an authoritative source._

## When someone leaves: removing their access in the file and checking it took effect
<a id="need-CG-MCE-022-P8"></a>

- <a id="s-CG-MCE-022-S62"></a>Users can be deleted to reduce the user count and avoid reaching the account's usage limit, so the number of users is subject to a usage limit. _(jurisdiction: United States (en-US QuickBooks Online support edition), entity_scope: QuickBooks Online Advanced and Intuit Enterprise Suite subscribers, platform: QuickBooks Online Advanced / Intuit Enterprise Suite, platform_edition: Help article updated 8/3/2026, effective_from: 2026-08-03)_ `CG-MCE-022#S62`
  > “If you need to reduce your users, you can delete them so you won’t reach your usage limit.” — [Intuit Inc. — Add and manage custom roles in QuickBooks Online Advanced and Intuit Enterprise Suite](https://quickbooks.intuit.com/learn-support/en-us/help-article/access-permissions/add-manage-custom-roles-quickbooks-online-advanced/L8Ugph7xl_US_en_US), 2026-08-03; Section 'Reactivate or deactivate a user’s role', closing paragraph. Verified 2026-09-09.

- <a id="s-CG-MCE-022-S63"></a>A user can be marked as inactive to restrict them from accessing the organization, and can be made active again. _(jurisdiction: United States (Zoho Books US-EN help edition), entity_scope: Zoho Books organizations, platform: Zoho Books, platform_edition: US-EN help edition, current release)_ `CG-MCE-022#S63`
  > “Sometimes, you might want to restrict a user from accessing your organization. In such a case, you can mark a user as inactive. You can make the user active again if you wish.” — [Zoho Corporation — Users & Roles | Help | Zoho Books](https://www.zoho.com/us/books/help/settings/users.html), not published on the page; Users > Mark User as Inactive. Verified 2026-09-09.

- <a id="s-CG-MCE-022-S64"></a>A user who should no longer have access to the Zoho Books organization can be deleted. _(jurisdiction: United States (Zoho Books US-EN help edition), entity_scope: Zoho Books organizations, platform: Zoho Books, platform_edition: US-EN help edition, current release)_ `CG-MCE-022#S64`
  > “You can delete a user whom you no longer want to give access to your Zoho Books organization.” — [Zoho Corporation — Users & Roles | Help | Zoho Books](https://www.zoho.com/us/books/help/settings/users.html), not published on the page; Users > Delete User. Verified 2026-09-09.

- <a id="s-CG-MCE-022-S65"></a>In Wave a user is removed by clicking Delete next to the user's name and confirming with Remove user. _(jurisdiction: Wave platform as documented in Wave's en-us Help Center; the article's only stated geographic limits are the US condition attached to Block Advisor Tax Pros and the CAD/USD currency options, entity_scope: Wave business profile administrator removing an existing user, platform: Wave, platform_edition: current Wave release; article undated)_ `CG-MCE-022#S65`
  > “To delete a user, next to the user’s name click Delete , then Remove user to confirm.” — [Wave Financial Inc. — Invite or remove collaborators from your business](https://support.waveapps.com/hc/en-us/articles/208621236-Invite-or-remove-collaborators-from-your-business), current Wave release; undated help article (packet notes date not obtainable - host returned HTTP 403); Section "Edit or delete a user", step 5. Verified 2026-09-09.

- <a id="s-CG-MCE-022-S66"></a>The None option gives the user no access to the current Sage 50 company, and on attempting to log on the system displays a message telling them to contact the company administrator. _(jurisdiction: United States (Sage 50 U.S. edition help, en-us), entity_scope: A user's access to the current Sage 50 company, platform: Sage 50 (U.S.), platform_edition: 2026, conditions: applies to the current company only)_ `CG-MCE-022#S66`
  > “Select the None option if you 
 want the user to have no access to the current Sage 50 company. When 
 they try to log on, the system will display a message telling them to contact the company administrator.” — [The Sage Group plc (Sage 50 U.S. product help) — Set Up Company Users, Passwords, and Access Rights](https://help-sage50.na.sage.com/en-us/2026/Content/USERS/Set_Up_Company_Users_Passwords_and_Access_Rights.htm), 2026-06-17; Setting up additional company users — None (No Program Access). Verified 2026-09-09.

_Partly established. Established: prompt removal inside the accounting file (S63, S64, S65). Missing: verification that the removal took effect; reassignment of anything owned by the removed account._

_Required authority: authoritative professional or accounting standard, official platform documentation. Highest achieved: official platform documentation._

## What removal leaves behind, and what has to be handed to someone else
<a id="need-CG-MCE-022-C5"></a>

- See above: A user can be marked as inactive to restrict them from accessing the organization, and can be made active again. ([CG-MCE-022#S63](#s-CG-MCE-022-S63))

- See above: A user who should no longer have access to the Zoho Books organization can be deleted. ([CG-MCE-022#S64](#s-CG-MCE-022-S64))

_Not established from an authoritative source._

## Reviewing the user list on a set schedule instead of setting it once
<a id="need-CG-MCE-022-P9"></a>

_Not established from an authoritative source._

## Whether removing a user also removes the record of what they did
<a id="need-CG-MCE-022-P10"></a>

_Not established from an authoritative source._

## Not yet fully established from an authoritative source

- Establish the user and permission model of mainstream small-business accounting platforms: the roles offered, what each can see and do, which permissions are adjustable, how user seats are limited, and what the model cannot restrict. _(not established)_
- Establish which capabilities mainstream platforms treat as separately restrictable, including payroll, banking and payment initiation, deleting or altering transactions, changing closed periods, managing users and exporting data. _(not established)_
- Establish the recognised access-control principle applied to accounting systems in a small business: granting the least access the work requires, and separating the ability to record from the ability to approve or to remove. Establish also the distinction control practice draws between access that only permits viewing, access that permits recording and access that permits altering or removing records, and which functions and actions warrant restriction beyond ordinary bookkeeping access, including payroll, the movement of money, altering or deleting entries and reopening a closed period. _(partly established; below the required authority class)_
- Establish how mainstream platforms handle the primary administrator or owner account, including how it is transferred to another person and what recovery exists if control of it is lost. _(not established)_
- Establish what mainstream platforms retain about a removed user's past activity, and whether their attribution in the change history survives the removal of their access. Establish also what a removal leaves still attached to that user - items, connections and scheduled work assigned to them - that must be reassigned to another user. _(not established)_
- Establish the recognised access-lifecycle control practice for a small business's accounting system: that the access a person will hold is decided and authorised before it is granted, that the grant and its approval are recorded, that access is withdrawn promptly when the person leaves and the withdrawal is verified, and that who holds access at what level is re-examined on a stated recurring trigger against an independent record of who should hold it. _(not established)_
- Establish the principle that access is derived from the work the person does, and show how that principle is turned into a concrete list of what each person needs before any setting is touched. _(not established)_
- Identify the areas that warrant restriction beyond ordinary bookkeeping access and establish which of them the platform can actually restrict separately. _(not established; below the required authority class)_
- Distinguish seeing, recording, and altering or removing, and show how those three levels map onto the settings the platform offers. _(established; below the required authority class)_
- Establish the destructive and high-consequence actions that should be restricted independently of ordinary transaction entry, and state which of them the platform treats as separately controllable. _(not established; below the required authority class)_
- Establish how the administrator or owner account is held and used, why it is not the account used for daily work, how it is transferred, and what recovery exists if control of it is lost. _(partly established)_
- Set out the joiner steps: what is decided about the person's access before it is granted, and what is recorded about the grant and its approval. _(partly established; below the required authority class)_
- Set out the leaver steps inside the accounting file: prompt removal, verification that it took effect, and reassignment of anything owned by the removed account. _(partly established; below the required authority class)_
- Establish the periodic review of who holds access at what level, including what triggers it and what the reviewer compares against. _(not established)_
- Establish what remains attributable to a removed user in the file's history, so a business knows whether removing access also removes the record of what that person did. _(not established)_

## Related

- [What checks can a very small business put in place when the same person records, pays and reconciles?](https://uppago.com/resources/what-checks-can-a-very-small-business-put-in-place-when-the-same-person-records)

_Reference date 2026-09-07. Statements are quoted verbatim from their sources; scope and verification dates are shown on each._
