Why controller-led?Talk to an expert

What Access and Permissions Do You Keep When You Hire a Professional Bookkeeping Service?

Handing your financial records to someone else feels like it should be all-or-nothing: either they have access to everything, or the engagement can’t work. CoCountant structures every engagement around proving that assumption wrong, because the right access model gives a provider exactly what they need to do the job well while leaving you in full control of everything that matters.

Professional bookkeeping services should never require you to hand over full control of your accounting software, your online banking credentials, or your ability to remove them from the account entirely. The standard, and reasonable, model is role-based access: the provider gets exactly the permissions needed to categorize transactions, reconcile accounts, and produce reports, while you retain administrative control, read-only bank connections stay read-only, and you can revoke access at any point without a data-portability crisis.

The core access categories in any bookkeeping engagement

Different systems carry different levels of risk, and the right access model varies accordingly.

SystemAccess typically neededWho should hold ultimate control
Accounting software (QuickBooks Online, Xero)Standard user or accountant-level roleYou, as Primary Admin
Bank and credit card accountsRead-only transaction feedYou, exclusively; no provider needs your login credentials
Payroll platformScoped access to run payroll, if in contract scopeYou, with the provider’s access limited to what’s contracted
Bill pay or AP toolsAbility to prepare and queue paymentsYou, retaining final payment approval unless explicitly delegated
Client portal or document systemFull access to your own documents and historyShared, but you should retain export rights at all times

The pattern across every row is the same: the provider needs enough access to do the work, not enough access to operate independently of you or to disrupt your business if the relationship ends badly.

Your accounting software: why you should always be the admin

Accounting software access control starts with a simple rule: the platform should be licensed in your business’s name, with you holding the Primary Admin or Company Admin role, not the bookkeeping firm. From that position, you grant your provider a scoped role, often called an Accountant or Standard User role in QuickBooks Online, that lets them view and edit transactions, run reports, and reconcile accounts without the ability to remove other users, change your subscription, or alter your billing.

This matters because Company Admin status is what determines who actually controls the account if a dispute ever arises. A properly structured bookkeeping engagement never asks to be the sole admin on your platform, because doing so would put your own access at their discretion rather than the other way around. If a provider requests to be made the primary account holder, treat that as a direct question worth asking rather than a routine setup step.

Bank and credit card connections: read-only, not login-sharing

This is the access category most often misunderstood, and it’s worth being specific about how it actually works. Read-only bank access bookkeeping arrangements use a secure connection, commonly built on a service like Plaid, that pulls transaction data into your accounting software through an encrypted token rather than your actual banking username and password. Your bookkeeper sees the transactions; they never see or hold your login credentials, and critically, this kind of connection has no ability to move money, initiate a transfer, or change anything about the account itself.

If a provider ever asks for your actual online banking username and password, rather than setting up a standard read-only feed, that’s a meaningful departure from how this is supposed to work, and it’s reasonable to ask why a feed-based connection isn’t sufficient for what they’re describing.

Payroll and bill pay access: scoped to exactly what’s in your contract

Payroll and accounts payable are different from basic bookkeeping in one important way: running payroll or initiating a bill payment involves actually moving money, not just recording that money moved. If these services are part of your engagement, the access granted should be scoped specifically to that function, and the provider’s role in your payroll or AP platform should match exactly what you’re contracting for, nothing broader.

A reasonable structure keeps final payment approval with you, even when a provider is preparing and queuing payments on your behalf, so that a second set of eyes, yours, sits between “payment prepared” and “payment sent.” This isn’t about distrust; it’s a standard internal control that protects both sides, and a provider confident in their own processes shouldn’t push back on it.

Tax filing access: a different category entirely

If your engagement includes tax preparation or filing, that introduces a separate layer of authorization beyond anything covered above, and it’s worth understanding as its own category rather than assuming it’s bundled into general bookkeeping access. Authorizing a provider to prepare or file on your behalf typically involves a specific IRS form, either a Power of Attorney (Form 2848) or an e-file authorization (Form 8879), each of which grants a defined, limited scope of authority rather than blanket access to your tax affairs.

These forms are worth reading before signing them, the same way you’d read any access grant. A Power of Attorney can be scoped to specific tax years and specific matters; it shouldn’t be an open-ended grant of authority beyond what the engagement actually requires. If tax services aren’t part of your current scope, no legitimate bookkeeping provider needs you to sign either of these forms at all.

What “client owns the books” should actually guarantee

The phrase gets used often, but it’s worth unpacking what it should mean in practice rather than treating it as a slogan.

GuaranteeWhat it actually protects
Platform licensed in your nameYou control the account regardless of what happens to the provider relationship
Full data export available anytimeYou’re never dependent on the provider’s cooperation to retrieve your own records
You hold Primary Admin statusYou can add, remove, or restrict any user, including the provider, at will
Historical data remains intact after the engagement endsSwitching providers doesn’t mean starting your financial history over

Controller-led engagements built around this structure treat the client’s platform ownership as a starting assumption, not a negotiated concession, which is a meaningfully different posture than a provider that owns the platform account and grants you access as a courtesy.

How to verify what access you’re actually granting

Before connecting any account or platform, walk through exactly what role you’re assigning and confirm it matches what’s actually needed for the contracted scope. If you’re only paying for basic bookkeeping and reconciliation, there’s no reason a provider needs payroll platform access at all. If your plan does include payroll or AP management, confirm the specific role being granted rather than accepting a broad “give them access to everything” setup instruction.

This is also a useful moment to revisit what your specific plan actually includes. CoCountant’s pricing page outlines which services, and by extension which systems, are part of each tier, since a Launch-level engagement covering basic bookkeeping has no reason to touch your payroll platform the way a Scale or Command engagement with payroll included would.

A simple pre-connection checklist covers most of what matters: confirm you hold Primary Admin on the accounting platform, confirm any bank connection is feed-based rather than credential-based, confirm payroll or AP access (if applicable) matches your contracted scope exactly, and confirm you know how to revoke every one of these access grants yourself, without needing the provider’s cooperation, before you connect a single account.

Red flags: access requests that go too far

A request for your actual online banking username and password. Legitimate bank connections use read-only, token-based feeds. A request for raw login credentials is a request for more access than the job requires.

Being asked to make the provider the sole or primary admin on your accounting software. This inverts the correct control structure and should be a hard no regardless of how routine it’s framed as being.

Vague or unscoped payroll and AP access when only basic bookkeeping is contracted. Access should match contracted scope. A mismatch is worth questioning directly.

No clear process for revoking access when the engagement ends. If a provider can’t describe how access gets removed and confirmed at offboarding, that’s a gap worth resolving before you ever grant access in the first place.

What happens to access when the engagement ends

A clean offboarding process mirrors the access structure that should have existed from day one. Because you held Primary Admin status throughout, ending the relationship means removing the provider’s user access from your accounting software, payroll platform, and any other connected system, a process that should take minutes, not require their cooperation or sign-off. Bank feed connections should be disconnected the same way you’d remove any third-party app. Your historical data, financial statements, and transaction history remain exactly where they were, since none of it ever lived anywhere but your own accounts.

This is also the moment that reveals whether the access model was actually structured correctly the whole time. If removing a provider’s access turns into a negotiation, or if critical historical data disappears along with them, that’s confirmation the underlying structure gave them more control than it should have.

Where CoCountant fits in

CoCountant is added as a user on your existing QuickBooks Online account with role-appropriate permissions, never as the account owner. Our guide to how outsourced bookkeeping actually works walks through the full onboarding sequence, including exactly how account access gets configured from day one, so nothing about the process depends on trusting a verbal assurance rather than seeing the structure itself.

The right access model gives a provider everything they need to do excellent work and nothing they’d need to do anything else. Talk to an expert about exactly how access and permissions are structured for your business.

FAQs

Does my bookkeeper need my online banking password?

No. Standard bank connections use a read-only, token-based feed that pulls transaction data without ever requiring or storing your actual login credentials.

Who should be the admin on my QuickBooks Online account?

You should, always. Your bookkeeping provider should be added as a user with a scoped role, not made the primary account holder.

Can my bookkeeper move money out of my bank account?

No, not through a standard read-only bank feed connection. If payroll or bill pay services are part of your engagement, any payment-initiation access should be specifically scoped and should typically still require your final approval.

What happens to my books if I switch bookkeeping providers?

If the platform was properly licensed in your name throughout, switching providers means removing the old provider’s user access and adding the new one. Your historical financial data stays intact and unaffected.

Is it normal for a bookkeeper to ask for payroll platform access?

Yes, if payroll processing is part of your contracted scope. It shouldn’t be requested if payroll isn’t part of what you’re paying for.

How do I know if my accounting software access is set up correctly?

Check who holds the Primary Admin or Company Admin role. If it’s not you or someone at your business, that’s worth correcting regardless of how long the current arrangement has been in place.

What should I do if my current bookkeeper already has more access than seems necessary?

Ask them directly to walk through why that level of access is needed, and consider whether the roles can be adjusted to match actual contracted scope without disrupting service.

Do third-party apps connected to my accounting software need the same scrutiny?

Yes. Expense management, inventory, and reporting apps connected to your accounting software each carry their own access scope, and it’s worth periodically reviewing which third-party apps are connected and why, the same way you’d review user roles.

Disclaimer

CoCountant assumes no responsibility for actions taken in reliance upon the information contained herein. This resource is to be used for informational purposes only and does not constitute legal, business, or tax advice.  Make sure to consult your personal attorney, business advisor, or tax advisor with respect to believing or acting on the information included or referenced in this post.