User Role - Restrict access to individual bank accounts
To have the ability limit some users to access some bank accounts within Xero org.
Purpose: To limit some staff to not be able to see the information about the client’s bank balance.
Thanks for sharing and showing interest in how we can develop user roles to suit your needs when using Xero.
With many varying ideas for roles and permissions in different areas of our products, user roles impact all areas of the product. There are many factors we must consider when addressing how to solve for majority of our customers needs.
We’re in the process of conducting research on the current landscape and how we might approach some of the most predominant needs in roles for our customers. This being one of our highest voted ideas surrounding roles is a specific focus for the team. too.
Discovery of this work is its first stages and will be long running. There will be multiple phases of research and forms of engagement with users that’ll help shape the path ahead in this space.
We value our customers input and would like to invite you, our community to be part of this research and discovery. This may involve interviews and sharing further feedback through direct surveys or questionnaires.
✍️ If this is something you’d be interested in taking a part of please fill in our short form here.
Though we might not be able to invite everyone into every stage, our research team will be in touch with many of you over the coming months.
We'll come back and share on the outcomes of our research and any progress around development of roles in Xero.
-
ROBIN HOLT commented
I can't believe in this time of security being so important Xero hasn't addressed this earlier. People have been calling for this for years. Other platforms have much more customised security. I didn't think I would say it but I am looking at changing.
-
Claire Kelly commented
This has become a critical issue for clients, who we want to migrate to Xero to a single platform, rather than consolidate 15 different accounts datasets. They require each user to have an access to single bank accounts and not all bank accounts. Please update us on progress in this area
-
Nick Joyce commented
I'm at a total loss as to why this hasn't been resolved yet. We will actively look at alternative software if this isn't implemented in the next few months as it's such a glaring omission.
-
Rebecca Rotheram commented
Hi is there any update on this? I am unable to delegate a lot of admin tasks because I don't want to give out access to our bank accounts. Which would give users view of director dividends paid, salary levels paid etc. Many other companies must have the same issue
-
Rachael Harrison commented
Is there any update if the bank account settings has been changed to restrict user access please
-
Noel McKenney commented
This request for limited access to bank accounts has been going on for a significant number of years and Xero has zero interest in listening to users comments. I think it will take a user suing Xero for negligence if their business gets defrauded by an employee having full operating access to bank accounts when this restrictive feature has been requested so many times by so many users. Absolute gross negligence by Xero.
-
Joy Lorraine Ford commented
I have a staff member, I believe another commentator called it a "CashBook Clerk" which is HUGE due to the nature of the company.
Happy for her to see the bank account called: "PETTY CASH"
However, I am far from keen to have her see the general bank account balance of the company, which I believe is sensitive and confidential in may aspects.
Xero - puts itself out there as a Premium product - I surprised there are not more user friendly pathways within the software. -
Rachael Harrison commented
This is critical for our business atm as we have had a confidentiality breach , and if this was a option to hide bank account from certain staff levels would never have happended, please let me know if you are able to change this feature
-
Rachael Harrison commented
This is critical for our business atm as we have had a confidentiality breach , and if this was a option to hide bank account from certain staff levels would never have happened, please let me know if you are able to change this feature
-
Linda De Beer commented
Good day this is really a huge problem for us. Now our creditors and debtors controllers have access to all our bank account balances because they need to print reports. Bank accounts should be a separate role so that it can be taken off from certain users. Please Xero - my CEO just informed me we have to change to another system if Xero cannot comply with this
-
Wesley Nicolaai commented
Good day,
I have been reading the threads of user concerns with regards to the lack of issuing users with limited access to certain bank accounts. Our company is now in the same position as many others where we have delegated certain tasks to employees and different staff performing different roles have user access to specific modules in Xero, for example debtors and creditors clerks having role specific access. We now have an issue with a cashbook clerk, who needs to allocate transactions off the main bank account only, having access to all bank accounts. Because of the limitations of Xero, we are unable to restrict her from seeing sensitive information in the salaries account other bank accounts. Xero needs to allow businesses to customize the user rights of the staff since, in our situation, the accountant will now need to do the work that the cashbook clerk needs to do so that confidential information remains confidential. -
Sergei Shutov commented
Without this feature it's not possible to let users reconcile their department's spending without exposing all business critical information including payroll numbers. Absolutely critical feature.
-
Lisa O'Sulivan commented
would be good to have the option to password protect bank account access so we could limit employee access to just what they need to do their job
-
Elliot Del Greco commented
This would be imperative to business and I'm sure will continue to be relevant for all businesses as they look to have internal members work on the reconciliation of business spending. There are many amazing aspects and features that Xero offers that can help business performance improve or be analysed. Currently the lack of role definition within bank account access means that if you want to give access to one employee then they will have access to all accounts meaning they may have access to information that you would otherwise prefer not to have exposed to the total business insights like payroll.
-
Anne Ward commented
Adding my vote to the others - this would be a very helpful feature.
-
Esther Santos commented
This is a message directly from my client....We were able to access reports in Sage and there is an expectation to do the same thing in Xero. Are we the only ones who ask for this reporting functionality without having to see bank account? Is it unreasonable to request this functionality from Xero, in the immediate future?
-
Lindsey Jones commented
Absolutely critical for my business.
Don't understand why this is not possible. -
Steve Ziara commented
I took the time to fill out the survey posted in April. I'm really hoping that there is some action taken on this issue soon. I can't delegate tasks that should be delegated until this update happens. There are a lot of great things about Xero but this is a big opportunity to make a big difference in many businesses.
-
Yuri Lazu commented
Absolutely critical for my business.
Don't understand why this is not possible. -
Wynne Tan commented
We are reaching out to seek clarification and assistance regarding the governance of user settings within our Xero system.
Restricting user access in Xero is essential for data security, ensuring compliance with regulations and protecting sensitive financial information. It allows organizations to align access with specific roles, minimizing risks of unauthorized exposure. This control is especially important when collaborating with external auditors, enabling them to work effectively without compromising sensitive data like bank balances. Proper access management also supports audit readiness by creating clear trails and demonstrating robust user permission controls.