Docs / Finance / Accountant Access

Finance · Customer guide

Accountant Access

Invite your accountant or auditor into a scoped, time-boxed, revocable view of your Finance workspace. They log in with their own credentials — you never share a password.

Audience: owners, finance staff Part of the Finance guide set

What this guide covers: Finance → Accountant Access — a Finance-specific version of scoped external access, built for the person who needs to see your books without becoming an employee.

If this sounds familiar, it's the same underlying idea as the External Access Portal used for transporters, vets and auditors elsewhere in Agribantu — Accountant Access is that same pattern, purpose-built for Finance.

How it works

Three steps, always in this order:

  1. You invite — enter their email, pick scopes and an expiry date. Agribantu creates a secure, branded invite link.
  2. They accept — they open the link, create a free Accountant account (or sign in if they already have one), and the invite appears in their own portal.
  3. Scoped access — they see your Finance workspace filtered to exactly what you granted. You can revoke it at any time.

Inviting an accountant

  1. Click Invite an Accountant.
  2. Enter their email address — the invite can only be accepted by an Agribantu account signed in with that exact address.
  3. Optionally start from a recommended preset: Auditor (read, reports and export access, 30 days — "a short audit window with reporting and evidence export"), Bookkeeper (read and write access, 90 days — "operational posting without settings or access management"), or Tax Prep (read, reports and export, 90 days — "VAT, tax summaries, and source exports for filing"). Or build your own combination — see Access permissions below.
  4. Set an expiry — quick presets for 30 days, 90 days, 6 months, 1 year, or a manual date. An expiry date is always required; there's no permanent-access option.
  5. Add optional Notes for your own reference (e.g. "Year-end audit access for Smith & Associates").
  6. Click Send Invite.
Email delivery may not be configured for your organisation. If so, you'll see a note after sending: "Invite created. Email delivery is not configured yet." In that case, use the Copy Link button to send it yourself, or Open Email Client to hand off to your own mail app with the invite message pre-filled — the same pattern used for invoices and other external-access invites across Agribantu.

Access permissions

Every grant is built from four toggleable scopes — at least one is required:

ScopeGrantsNever includes
Read AccessView accounts, contacts, transactions; download reports.Creating entries, posting journals, exporting raw data.
Write AccessEverything in Read, plus maintaining contacts/items, creating invoices and bills, recording payments.Changing finance settings, managing accountant access, bulk data export.
ExportEverything in Read, plus CSV/Excel export, bank statement downloads, audit-trail export.Creating or editing entries.
ReportsEverything in Read, plus P&L, balance sheet, VAT reports, cash flow.Creating entries, exporting raw data.

Reviewing & revoking

The main screen shows every grant as a card — accountant, acceptance status, a computed risk label, granted scopes, and expiry. Four metrics at the top help you keep the list honest: Least-Privilege Score, Expiring Soon (active grants needing attention within 14 days), High-Trust Grants (active/pending grants with both write and export), and Stale Invites (pending more than 7 days).

Click a grant to open its detail drawer — full timeline, permissions granted, and a plain-English "What they can do" list. Click Revoke access at any time: "{email} will lose all access immediately. Their active session will be terminated." This cannot be undone — send a new invite if you change your mind.

What's always off-limits

No matter which scopes you grant, an accountant invite never includes:

  • HR, payroll, authority/LITS, device location, or platform-admin data
  • Your organisation's settings, or the ability to manage other accountant-access grants
  • Your password — they always use their own Agribantu credentials

Every acceptance and revocation is written to the audit log.

Troubleshooting

Troubleshooting & FAQ

My accountant didn't get an email.

Email delivery may not be configured for your organisation — use the "Copy Link" or "Open Email Client" option shown after you send the invite to deliver it yourself.

Can my accountant see payroll or HR data through this grant?

No — accountant access is Finance-only by design, regardless of which scopes you tick.

Can I change an accountant's scopes after inviting them?

Not directly — revoke the existing grant and send a new invite with the settings you actually want, the same pattern used everywhere else in Agribantu for scoped access.

I revoked access by mistake.

Revocation is permanent. Send a new invite.