User Role - Restrict access to individual bank accounts
To have the ability limit some users to access some bank accounts within Xero org.
Purpose: To limit some staff to not be able to see the information about the client’s bank balance.
Thanks for sharing and showing interest in how we can develop user roles to suit your needs when using Xero.
With many varying ideas for roles and permissions in different areas of our products, user roles impact all areas of the product. There are many factors we must consider when addressing how to solve for majority of our customers needs.
We’re in the process of conducting research on the current landscape and how we might approach some of the most predominant needs in roles for our customers. This being one of our highest voted ideas surrounding roles is a specific focus for the team. too.
Discovery of this work is its first stages and will be long running. There will be multiple phases of research and forms of engagement with users that’ll help shape the path ahead in this space.
We value our customers input and would like to invite you, our community to be part of this research and discovery. This may involve interviews and sharing further feedback through direct surveys or questionnaires.
✍️ If this is something you’d be interested in taking a part of please fill in our short form here.
Though we might not be able to invite everyone into every stage, our research team will be in touch with many of you over the coming months.
We'll come back and share on the outcomes of our research and any progress around development of roles in Xero.
-
Rachael Harrison commented
This is critical for our business atm as we have had a confidentiality breach , and if this was a option to hide bank account from certain staff levels would never have happended, please let me know if you are able to change this feature
-
Rachael Harrison commented
This is critical for our business atm as we have had a confidentiality breach , and if this was a option to hide bank account from certain staff levels would never have happened, please let me know if you are able to change this feature
-
Linda De Beer commented
Good day this is really a huge problem for us. Now our creditors and debtors controllers have access to all our bank account balances because they need to print reports. Bank accounts should be a separate role so that it can be taken off from certain users. Please Xero - my CEO just informed me we have to change to another system if Xero cannot comply with this
-
Wesley Nicolaai commented
Good day,
I have been reading the threads of user concerns with regards to the lack of issuing users with limited access to certain bank accounts. Our company is now in the same position as many others where we have delegated certain tasks to employees and different staff performing different roles have user access to specific modules in Xero, for example debtors and creditors clerks having role specific access. We now have an issue with a cashbook clerk, who needs to allocate transactions off the main bank account only, having access to all bank accounts. Because of the limitations of Xero, we are unable to restrict her from seeing sensitive information in the salaries account other bank accounts. Xero needs to allow businesses to customize the user rights of the staff since, in our situation, the accountant will now need to do the work that the cashbook clerk needs to do so that confidential information remains confidential. -
Sergei Shutov commented
Without this feature it's not possible to let users reconcile their department's spending without exposing all business critical information including payroll numbers. Absolutely critical feature.
-
Lisa O'Sulivan commented
would be good to have the option to password protect bank account access so we could limit employee access to just what they need to do their job
-
Elliot Del Greco commented
This would be imperative to business and I'm sure will continue to be relevant for all businesses as they look to have internal members work on the reconciliation of business spending. There are many amazing aspects and features that Xero offers that can help business performance improve or be analysed. Currently the lack of role definition within bank account access means that if you want to give access to one employee then they will have access to all accounts meaning they may have access to information that you would otherwise prefer not to have exposed to the total business insights like payroll.
-
Anne Ward commented
Adding my vote to the others - this would be a very helpful feature.
-
Esther Santos commented
This is a message directly from my client....We were able to access reports in Sage and there is an expectation to do the same thing in Xero. Are we the only ones who ask for this reporting functionality without having to see bank account? Is it unreasonable to request this functionality from Xero, in the immediate future?
-
Lindsey Jones commented
Absolutely critical for my business.
Don't understand why this is not possible. -
Steve Ziara commented
I took the time to fill out the survey posted in April. I'm really hoping that there is some action taken on this issue soon. I can't delegate tasks that should be delegated until this update happens. There are a lot of great things about Xero but this is a big opportunity to make a big difference in many businesses.
-
Yuri Lazu commented
Absolutely critical for my business.
Don't understand why this is not possible. -
Wynne Tan commented
We are reaching out to seek clarification and assistance regarding the governance of user settings within our Xero system.
Restricting user access in Xero is essential for data security, ensuring compliance with regulations and protecting sensitive financial information. It allows organizations to align access with specific roles, minimizing risks of unauthorized exposure. This control is especially important when collaborating with external auditors, enabling them to work effectively without compromising sensitive data like bank balances. Proper access management also supports audit readiness by creating clear trails and demonstrating robust user permission controls. -
Donna Kenton-Smith commented
I Agree with Jasmine (below) and have tailored it to fit our situation: There are confidentiality issues with users being able to access ALL Business Bank Accounts within an entity. I know you have a limited access feature but it is unsuitable for what we need.
Business owners should be able to select which bank accounts and reports each user can access. This is a basic business confidentiality and process requirement issue.
Xero, please urgently address this, as these user access issues are holding our business back. Thank you! -
Melissa Iland commented
Restricting certain users to certain or specific bank accounts is helpful in people's different roles within a business. It would be a great addition to have a person still able to use functions within Xero but only to a specific bank account.
-
Craig Gilfoyle commented
Adding my input to this to hopefully find a solution. We have multiple small receipts every day but due to access rights we cannot allow the accounts assistant to post and allocate receipts as this allows access to the bank balance. There should be the possibility to allocate bank receipts to invoices without the ability to see the bank balance.
-
Jasmine Shine commented
Agreed, There are confidentiality issues with users being able to access all business Bank Accounts.
Business owners should be able to select what bank accounts each user has access to. This is quite basic and I would have thought would have been apart of the initial set up.
Xero you need to urgently set this up in user access. -
Alan Gomes commented
I have 2 bank accounts connected to xero for one of my clients.
Is there any way that i can allow a user to access only one of them and not the other. This is just for reconciling purposes. -
Andrew Clerihew commented
There are confidentiality issues with users being able to access the Bank Account. The Bank Account should be a specific function that can be provisioned to users on an as needs basis.
-
Len Weideman commented
We need a user role where an employee can have full access to all features , but not seeing the bank account or bank recons. There is confidential information that should be kept that way