How do I invite my accountant or bookkeeper into my accounting software and grant them access to my books?
Applies to: United States · Updated 2026-09-27
Do not hand over your own login. Invite the accountant by name at the narrowest role covering their work: in QuickBooks Online, Add user with a narrow role, or the Accounting Firms tab for firms that need accountant tools, a broad grant that can correct and close your books; in FreshBooks, the Accountant role; elsewhere, a limited role. Confirm the invitation shows as accepted, grant bank, payroll and document access separately, and remove the grant when the engagement ends.
Why issue a named grant instead of sharing your login?
A named grant gives your accountant their own sign-in, under an access class you chose, which you can narrow or remove without touching your own credentials. Your own login usually carries the top role, so sharing it hands that over: Intuit's "User roles and access rights" help for QuickBooks Online says the primary admin and company admin can access everything in the account, including admin tasks such as changing people's permissions and roles. Separate sign-ins also leave a trail: Intuit's "Add and manage users" help says that after you delete a user, you can still view their history in the audit log. On a shared login every change looks like yours, and access ends only when you change your password.
Some vendors forbid sharing. The FreshBooks Terms of Service say access credentials are personal to you and may not be shared with any other person, and that you are responsible for all activity on your FreshBooks account. FreshBooks may revoke credentials shared other than as the Terms allow. If an accountant already knows your password, change it once their own grant works.
Should you admit a firm or add a person as an ordinary user?
Platforms admit an accountant in one of two ways, and some offer both:
- Accountant grant. This is a dedicated invitation for accounting professionals. Intuit's "Invite accountant users" help puts it on its own tab of Manage users in QuickBooks Online. FreshBooks' undated team-member help lists accountant as a role alongside admin, manager, employee and contractor.
- Ordinary user. The person joins like a staff member and you choose a role. Intuit has you select Add user and pick from the Roles dropdown. Zoho Books' undated Users & Roles help works this way: you add a user and select a role such as Admin or Staff.
Use the accountant grant when the accountant needs the platform's accountant tools; otherwise add an ordinary user at the narrowest role that covers the work. Role lists differ by product and edition, so choose from the list on your own screen; Intuit, for example, places custom roles in QuickBooks Online Advanced and Intuit Enterprise Suite.
What will each access class let the holder see, change and export?
Choose the narrowest class that covers the engagement. NIST's online glossary defines least privilege as restricting users' access privileges to the minimum necessary to accomplish assigned tasks.
For QuickBooks Online, Intuit's help pages describe these options:
- Accountant firm grant. Intuit says accountant users have access to specific accountant tools to review your books and make corrections. Intuit's "Review clients' books in QuickBooks Online Accountant" says that tool's Wrap-up tab lets the firm prepare reports, send the reports package and close the books.
- Bookkeeper. Intuit's roles page gives this role all the bookkeeping transactions and tools, but lists viewing financial reports such as profit and loss, approving or paying bills online, and managing and running payroll among the things it cannot do. It can still pay bills, write and print checks, enter refunds and receive customer payments.
- In house accountant. The same page gives this role everything related to customers, sales, vendors and purchases, all bookkeeping, account tools and financial reports, reconciliations, journal entries and fund transfers, but no payroll, role management or admin tasks.
- View reports. The same roles page says this role sees all reports except those that show payroll or contact info. It cannot view the actual transactions or access the audit log.
- Custom role. You define access area by area, in the editions named above.
- Primary or company admin. Keep these all-access roles for the people who run the business.
Treat the firm grant as broad, since it can correct and close your books. Bookkeeper suits someone who enters day-to-day transactions, including bill payments and checks; In house accountant, an accountant who adjusts and reports but should not run payroll or manage users; and View reports, someone who only reads results.
FreshBooks' undated help "What permissions can I assign to my team member?" says the Accountant role can manage the chart of accounts, create journal entries and export the chart of accounts to CSV; can only view invoices and manage payments to them, with CSV export of invoices; and has no access to the Retainer Summary, Profitability Summary or Profitability Details reports. The page's Accountant - Full Access role reaches your entire account, with some limits; if the firm pays for your subscription, only that user can change billing or cancel the account. Use it only if the Accountant role cannot do the work.
Zoho's Users & Roles help says an Admin has complete access to all modules, transactions and settings, while Staff can access all modules except reports, settings and accountant. The same page lets you build a role by selecting the modules and the level of access, which may let you give an accountant less than Admin, but it does not say whether a custom role can include the Accountant module or which plans offer custom roles, so check both with Zoho before settling on Admin.
Neither Intuit's roles page nor Zoho's Users & Roles help says whether a role can be limited by date or which roles can export: assume a class that opens a report opens earlier years, and that anything viewable can be copied.
How do you protect periods that are already closed?
Lock closed periods before the accountant starts. In QuickBooks Online, Intuit's "Lock your books" help says any attempt to change transactions dated on or before the lock date triggers the warning or password prompt you set. Choose the password option, since Intuit says that with the warning option users see a warning but can still make changes, and keep the password yourself unless you have decided the accountant should change closed periods. That page does not say whether an accountant firm user can change the closing date, and the firm's review tool can close the books, so check the date and setting at each review. On another platform, find its period-lock or closing-date setting.
Does the grant use a paid seat, and is there a cap?
Seat rules are set per product:
- QuickBooks Online accountant grant. Intuit says inviting an accountant this way does not count toward your subscription's user limit, and suggests upgrading to QuickBooks Online Advanced if you need to add more than 2 accountant firms.
- QuickBooks Online users. Intuit says your subscription level determines how many users you can add, and that people with non-billable roles, such as View reports, do not count toward your plan limit.
- FreshBooks. Its help says you can invite up to 10 accountants per business at no extra cost on Plus, Premium and Select plans. Otherwise invitations come at an additional cost, so check your available invitations under Role and Permissions before you invite.
- Other products. Check your plan's user allowance before inviting.
What should you check before you invite anyone?
Run these checks first:
- That you can issue it. Intuit says you must be a primary admin or company admin to invite users, and Zoho says only users with Admin access can add new users. If you lack that role, ask whoever holds it to send the invitation; never borrow their login.
- Who you are admitting. Grant only to a named person or firm you have engaged. Confirm the exact email address, or the QuickBooks Online firm ID, with them in person or by calling a number you held before the request arrived and did not take from any email or message. A number, link or address in the request or any other email does not count, nor does a call or video meeting arranged through that mailbox, since whoever controls it can plant or join them; if you cannot confirm, wait.
- The address they sign in with. Intuit's "What to do if you can't accept client invites" says the invitation should go to the email tied to the user ID the accountant signs in with.
How do you send the invitation?
Intuit gives these steps for QuickBooks Online:
- Go to Settings, then select Manage users.
- Select the Accountants or Accounting Firms tab.
- Select Invite firm.
- Enter the accountant's email address or their firm's user ID, as you confirmed it.
- Select Send the invitation.
Intuit says your accountant receives an email with a link to access your company, and if they do not have QuickBooks Online Accountant, the email includes a link to sign up before they can accept. For an ordinary user, use Add user on the same screen instead.
FreshBooks has you invite from the Team Members section with the Accountant role, and the person receives an email inviting them to join. Zoho has an Admin select Users under Users & Roles in Settings, then Invite User, enter the name and email address, and select the role; where the role uses segmented access control, Restrict Access To can narrow the user to certain locations or reporting tags.
How do you confirm the access is live?
An invitation sent is not access granted. Check two things:
- Status. Intuit says the accountant's status on Manage users changes from Invited to Active once they accept. FreshBooks says a status of Invitation Sent means the team member has not accepted yet. Zoho says the invitee must verify the link and set a password to access your organization.
- A working sign-in. Ask the accountant to open the file and confirm they can reach what the engagement needs. Check that the class shown against their name is the one you chose, then record the date.
What if the invitation does not arrive or cannot be accepted?
For QuickBooks Online, Intuit's help gives these causes:
| If | Then |
|---|---|
| The email is not in the accountant's inbox | It might be in junk or spam, or their mail servers might be blocking it; ask them to check, then use Resend invite on Manage users. |
| It was sent close to or over 30 days ago | For an accountant firm, do not resend: delete the original invite and any duplicates on the Accounting firms tab, then send a new one. For an ordinary user showing Invite expired, use Resend invite. |
| Email delivery keeps failing | Ask the accountant for their firm ID, confirmed as above, and invite from the Accounting firms tab; this bypasses their email server completely. |
| No invitations reach anyone | A company email address formatted wrong in the Company tab under Account and settings is one cause; correct it. |
| The accountant signs in under a different email | The invite must go to the correct email address; delete it and send a new one to the address tied to their user ID. |
| The accountant cannot accept, or sees no firm listed | Ask them to sign out of other QuickBooks companies and sign in to the firm account the invitation is for; only members of that account can accept. |
| The invitation appears broken | Invites can get corrupted; delete the original invite and send a new one. |
FreshBooks says its plane icon re-sends an invitation. If your file and the accountant's account sit on different products or country editions, ask the vendor's support which route applies; do not fall back on sharing your login.
What does the ledger grant not reach?
A ledger grant does not open your online banking, card portals, outside payroll service, document storage or other apps, so the accountant needs a separate grant in each system they must use, issued there at the narrowest level. Banks, for example, set rights inside online banking: Chase's undated Access & Security Manager help assigns rights by selecting an access level under each account. Some ledgers also carry payment, payroll and document tools: Intuit's roles page lists QuickBooks Online roles that pay bills or run payroll, and FreshBooks' Accountant role can manage uploaded documents. Intuit's "Invite accountant users" does not say whether the firm grant can pay bills or run payroll, so ask Intuit before granting it.
If you run payroll or connected apps in or alongside your books, decide on each system separately:
- Bank and card accounts. Add the accountant in the bank's or card issuer's own portal only if they need more than your books show.
- Payroll. Add them in the payroll service, or check the payroll limits of their ledger role.
- Document storage. Share the folders the engagement needs, not the whole drive.
- Connected apps. Add them in each app they must work in, such as receipt capture or bill pay.
Where a tool in the ledger or outside it can move money, grant view access only unless you have separately decided the accountant should move money. Do not share your credentials for any of these to close a gap.
How do you review, narrow and remove access?
Work through these at each review date and whenever the engagement or the firm's staff changes:
- Review. Open your user list and compare it with your record. In QuickBooks Online, check both the users list and the Accounting Firms tab on Manage users.
- Narrow. Intuit has you select Edit in the Action column, change the user role from the Roles dropdown, select Save and ask the user to sign out and back in to see the update; then check that the role shown for them is the new one. To narrow a firm admitted on the Accounting Firms tab, remove it and add the person as an ordinary user with a narrower role. In Zoho Books, a role sets a user's access, so narrow through the role.
Remove. First move any filings or other work the accountant still handles to someone else. Intuit's "Remove an accountant user" says a primary or company admin removes an accountant from the Accounting Firms tab by selecting Delete in the Action column, and that the accountant user is immediately removed and can no longer access your company file. For an ordinary user, Intuit has you confirm with Delete user.
In FreshBooks, the trash can icon deletes a team member not on FreshBooks Payroll; if the accountant held a paid seat you are not refilling, FreshBooks says to downgrade to remove the seat, and a deleted team member's email address cannot be reused without FreshBooks Support. Zoho Books lets you delete a user you no longer want to have access; marking them inactive also stops access, but can be reversed.
- Confirm. Reload the list, check the name is gone, and remove the same person from each separate grant in your record.
What order do you follow when replacing an accountant?
Admit before you remove, and remove as soon as the handover is done:
- Run the checks above on the incoming accountant and invite them.
- Wait until their access shows as accepted, they confirm they can work, and open work such as filings in progress has passed to them.
In QuickBooks Online, find out whether the outgoing accountant holds the primary admin role. Intuit's "Change the primary admin role in QuickBooks Online and Intuit Enterprise Suite" says you must be able to sign in as the current primary admin, the new person must already have the Admin role, and Simple Start users contact Intuit to transfer it. Have the role moved to you first.
Zoho Books gives the Super Admin, by default the organization's creator, exclusive rights over other admins; if that is the outgoing accountant, have them make you Super Admin, which requires you to be an admin active across all Zoho Finance apps.
- Remove the outgoing grant and confirm the name has gone.
- Remove the outgoing accountant from every separate grant, change any password they knew, and change the lock password if they held it.
- Update your access record.
If QuickBooks Online already holds 2 accountant firms, remove any you no longer engage, or consider the QuickBooks Online Advanced upgrade Intuit suggests. If the outgoing firm must make room, have its work handed over and step 3 done before you remove it at step 4, then invite the incoming firm at once. The outgoing firm's own exit and handover, and a former firm that will not release your file, are separate questions.
What should your access record show?
Keep one entry per grant and update it at every change:
- Who. Record the named person, their firm, and the email address or firm ID the invitation went to.
- Class. Record the access class or role granted, and why you chose it.
- Issued. Record the date the invitation was sent and who sent it.
- Accepted. Record the date the status showed accepted and the date the accountant confirmed they could work.
- Separate grants. Record each connected system where you granted access, at what level and on what date, or write "none".
- Closed periods. Record the lock date and who holds the password.
- Next review. Record the date you will next review the access.
Sources
- Intuit Inc. — Invite accountant users, last updated 8/28/2026
- Intuit Inc. — User roles and access rights, last updated 9/8/2026
- Intuit Inc. — Add and manage users, last updated 8/5/2026
- Intuit Inc. — Remove an accountant user, last updated 8/5/2026
- Intuit Inc. — Invited user didn't receive your email invitation, last updated 8/28/2026
- Intuit Inc. — What to do if you can't accept client invites, last updated 8/3/2026
- Intuit Inc. — Change the primary admin role in QuickBooks Online and Intuit Enterprise Suite, last updated 9/8/2026
- Intuit Inc. — Lock your books in QuickBooks Online, last updated 9/15/2026
- Intuit Inc. — Review clients' books in QuickBooks Online Accountant, last updated 8/7/2026
- FreshBooks — How do I invite and manage team members?, undated
- FreshBooks — What permissions can I assign to my team member?, undated
- FreshBooks — Terms of Service, last updated October 29, 2025
- Zoho Corporation — Users & Roles | Help | Zoho Books, undated
- JPMorgan Chase Bank, N.A. — Access & Security Manager: Add users and assign rights, undated
- National Institute of Standards and Technology, Computer Security Resource Center — Glossary: least privilege, undated