7 minute read

Read-only vs. full bank access: setting permissions for your accountant

Cover Image for Read-only vs. full bank access: setting permissions for your accountant

One misplaced permission is all it takes when the same few people touch invoices, payroll, and the bank feed—here's how to match access to the actual engagement, not the easiest default.

An accountant access request usually looks broader than the work behind it. The right question to ask first isn't how much access to grant, but which kind: does this person need to see money movement, or create it? Your accountant may need records without needing authority to move a dollar, and that distinction is where good permissioning starts.

The answer should come from the engagement scope, not convenience or whatever default role is easiest to assign. Grant too much access and you create avoidable exposure; grant too little and you slow close, delay reconciliations, and leave your accountant waiting on documents they could have pulled themselves. A permission set that matches the work, no more and no less, avoids both.

Read-only access keeps visibility separate from control

Most accountant work (statement pulls, month-end reconciliation, tie-outs) needs to see the bank record, not touch it. Read-only access does exactly that: your accountant sees every posted transaction, every balance, every payee, but they can't initiate a transfer, pay a bill, or alter a transaction. Keeping visibility separate from control also produces a clearer audit trail when you later review who could view records versus who could move money.

What read-only covers

Read-only access gives your accountant the records they need without payment rights. That includes posted activity, payee details, monthly PDFs, current and past balance figures, and the bank data needed to match your books.

If the platform supports statement downloads, use the named read-only login for that work instead of sending bank PDFs through email. Relay is built for this separation. Role-based access controls let you invite your accountant with view-only rights on the accounts they need, so they can pull statements and reconcile without ever seeing a "pay" or "transfer" button.

Confirm the label

Banks and software tools use the same permission names differently. One banking platform may block money movement but allow certain edits or settings changes. Another may lock down everything but viewing.

Before you settle on read-only for a given person, confirm what the setting blocks on the specific platform you use. Check transfers, bill payments, transaction edits, and settings changes instead of relying on the label. Save a note or screenshot of the exact permissions tested so you can verify the setting during access reviews. If the bank offers custom roles, build the role from the minimum viewing rights first, then add only the specific record-download functions the work requires.

When full access makes sense for accountant workflows

There's a smaller set of engagements where read-only isn't enough because the accountant is running payments for you. Accounts payable, approved vendor transfers, or a fractional CFO who moves cash between accounts as part of the engagement all need transactional access. The test is whether the engagement assigns the work. If you hired the accountant only for review and reporting, transactional access adds risk without helping the work.

Even when someone needs full access, don't leave it unchecked. Use approval controls when your banking platform supports them. When one person prepares a payment and another approves it, you get a clean control against both error and fraud. Transactional access for the right person, gated by an approval step, is not the same as unrestricted payment authority.

Before the permission goes live, write down who prepares payments and who approves them, so nobody has to reconstruct it later.

Match each role to the right access level

A tax filing engagement doesn't require the same authority as ongoing close or cash management, so permissions should differ by role. Start with the lowest access each role requires: a tax preparer may only need records, while your fractional CFO may need approval-backed transfer rights if cash movement is in scope. A bookkeeper usually sits between those points, with bank visibility and accounting-software rights for close work. Add more only when the scope demands it.

Relay's role-based permissions map to exactly this problem. You can invite an accountant, bookkeeper, or fractional CFO as a named user, set their exact rights account by account, and route any bill payment they prepare through an approval step you own. Records access doesn't have to come bundled with payment authority. You decide which one, both, or neither.

Match roles to scope

Before you create the login, write down whether the person reconciles monthly, supports tax filing, reviews statements, pays bills, sends vendor transfers, or manages cash. Your tax preparer should start with viewing rights so they can review records and pull statements for filing.

Your full-charge bookkeeper usually needs bank visibility plus categorization rights in your accounting software so they can reconcile and maintain your books. Your fractional CFO may need transfer rights when cash movement is part of the engagement, but those rights should sit behind approvals and belong to a named user, not a shared login.

For example, a tax preparer who joins for March and April can receive viewing access to the account that holds the filing records, then lose that access after the return is done. A bookkeeper who works every month may keep viewing access year-round, but still doesn't need transfer rights unless the engagement says they pay bills.

Keep an access register for smaller teams

Keep a simple access register and attach the written scope, so each permission has a reason you can review later.

For each named user, record the connected account, allowed actions, payment approver, access start date, and next review date. Assign one owner to update the register after new engagements, scope changes, and offboarding. Relay's Partner Portal keeps client access tied to named people instead of shared credentials, which makes the register easier to compare against active client work.

Why this matters at your size: in a smaller company where the same few people touch invoices, payroll, and bank activity, one misplaced permission can do real damage. Businesses with fewer than 100 employees had a median fraud loss of $141,000, according to the Association of Certified Fraud Examiners (ACFE) 2024 Report to the Nations, the second-largest loss among size categories. Matching access to the role is one low-effort control that can reduce that risk.

When different professionals need different access, use role-based access controls instead of shared logins. Your tax preparer shouldn't work from the same credentials as your staff bookkeeper who reconciles every month or your fractional CFO who prepares transfers. Shared credentials blur the audit trail and make it harder to tell who viewed records, prepared a payment, or changed a setting.

Bank permissions are only one layer

Locking down the bank portal doesn't lock down the rest of the systems your accountant can touch. When the same accountant has bank access, QuickBooks Online access, and payroll rights, each system carries its own permission model. If the same login can approve payroll and move bank cash, the risk sits across both systems.

Check accounting software roles

Consider what happens inside your books. A QuickBooks Online Accountant role can:

  • View and categorize bank feeds

  • Make deposits

  • Transfer money

  • Reconcile accounts

  • Make journal entries

Those are a wide set of powers, and the capabilities hold regardless of how you set bank-portal access. You can restrict someone to read-only at your banking platform, while that same person may still have the ability to move money and post journal entries inside the accounting system.

Software roles also vary in how much they restrict. Xero's read-only role gives access to most areas without the ability to change data. The same word, "read-only," behaves differently across the tools you use, and an accountant-level role in one system can carry powers a read-only role in another never would.

Map combined exposure

Review permissions together because the risk comes from what the person can do across all systems. The same person might have narrow bank access, broad accounting-software permissions, and payroll approval rights.

When you set someone up, check bank-platform rights first. Then check QuickBooks Online or Xero, and review payroll access separately. The final payroll check matters when the same person can approve payroll in one system and see or move cash in another.

Review access before month-end close

Month-end close is a practical time to check whether access still matches each person's role. You already have bank portals and accounting software open, and close forces you to look hard at the accounts. A few minutes here prevents access from quietly drifting out of alignment with who needs it.

During close, use the same quick pass every time:

  1. Confirm who currently has access to your accounts, across every person and role

  2. Confirm each person's level still matches current scope

  3. Remove bank-portal access for anyone whose engagement has ended rather than assuming it expires

  4. Check whether removing software access also severs the bank feed, or whether the two need separate action

This pass keeps access review tied to work you're already doing, not a separate project that waits for a quieter week.

Offboarding is easy to miss because most systems won't expire access for you. If your bookkeeper leaves or your fractional CFO engagement ends, their credentials stay live until you deliberately remove them.

When a scope shifts or a relationship ends, adjust or revoke the person's permissions in the systems where they have access. If close work is still in progress, set a dated reminder and name the person responsible for final removal.

Give your accountant the right access from day one

Match the access to the work, and review the match on a regular cadence. Relay is built around that principle. Named users, role-based access controls, per-account permissions, and approval workflows mean your accountant, bookkeeper, or fractional CFO gets exactly the rights their engagement calls for.

That might be records without payment authority when the job is reconciliation. It might be payment prep behind an approval step when the job is running AP. When a lender, auditor, or new advisor asks who could see or move cash, you have a clear record to show.

If you're setting up an accountant today and want records access clean from the start, open a Relay account and assign permissions from the work they perform.


Frequently asked questions

Should I give my accountant access to my business bank account?

Yes, if the permission matches the job. Viewing access usually covers records work, statement pulls, and reconciliation support. Payment rights should stay limited to roles that create approved money movement under the written engagement.

Can an accountant move money with read-only access?

No, not when the setting is truly read-only. Confirm the platform's exact limits before relying on the label, because banks and software tools use permission names differently.

Does read-only bank access mean my accountant can't change anything in QuickBooks Online?

No. Bank access and accounting-software access are separate permission systems, so a narrow bank role doesn't automatically limit what someone can do in QuickBooks Online. Review both systems before you rely on the bank setting.

What access should a tax preparer have versus a bookkeeper?

A tax preparer typically needs viewing access for filing records. A bookkeeper usually needs bank visibility and accounting-software permissions for reconciliation. Transfer rights depend on whether bill pay or cash movement is part of the written engagement.

How do I remove my accountant's bank access when we stop working together?

Remove the accountant's login in the bank portal as part of offboarding. Then review accounting software and payroll access separately, because each system keeps its own permission list.

More about the authorThe Relay Editorial Team produces practical, expert-backed content for small business owners navigating the financial side of running a company. Our work is informed by contributions from CPAs, advisors, and experienced operators, and held to rigorous editorial standards for accuracy and relevance. Relay is a banking platform built for small businesses—and our editorial mission reflects that focus.View more articles by Relay Editorial Team

Relay is a financial technology company and is not an FDIC-insured bank. Banking services provided by Thread Bank, Member FDIC.