User Role - Restrict access to specific Settings
Ability to customise user roles to restrict some access in Xero.
Purpose: Some staff should only have limited access in Xero.
Hey everyone, we've been following the conversation closely and we want to acknowledge how important this is for many of you.
Atm, we’re on a long journey to provide more controls within Xero features that our customers need. Being such a broad idea that touches many areas of our platform, we’d like to encourage adding your votes to specific user permissions that matter most to you, such as:
- Bank Accounts: For more control over who can see bank account balances and access specific accounts, please see the idea here: User Role - Restrict access to individual bank accounts
 - Sales and Invoicing: If you’d like to see changes to permissions around sales reporting and editing invoice templates, you can follow that conversation here: User roles: Restrict access to Invoice Settings
 - Reports: To have your say on restricting access to specific reports, the relevant idea is here: User permissions - Assign user access to specific reports
 
This change will allow us to focus on the more specific requests to explore. If you don’t see the user permission you’re after, raise a new idea here.
We're thankful for the time and effort you've put into sharing your thoughts on this. Your feedback is valuable, and helps us better understand the priorities and needs of the community as we continue to evolve Xero.
- 
      
Lynne Chapman
    
 commented
    
  Business critical disaster! - I have added users to allow them to draft invoices only (the lowest level access possible). They cannot see bank accounts BUT, if I have drafted their collegues wages as a bill that is "Awaiting Payment" THEY can see it by looking at their collegue as a contact and reading across the "You Owe", "They Owe" coloumns.....this has created a catastrophe. WHY do they see what the business "owes" a contact?????? Law suits pending
 - 
      
Justin Plowman
    
 commented
    
  100% needed. I want someone to be able to send remittances for payments made but this can only be done if they have access to all the bank accounts and reports.
 - 
      
Matt Kinchin
    
 commented
    
  It would be good if access to the details contained within nominals that contain sensitive info such as wages, could be restricted for certain users within an organisation. You may want somebody to be able to post bills/invoices but not be able to see private salary information or bank balance levels for example.
 - 
      
Mahesh Kunchala
    
 commented
    
  I want to restrict users Applying Payments and at the same time they can see that reports, balances, etc..
 - 
      
Sharon Toft
    
 commented
    
  We have users set up with various access, the sales team need to have access to add/edit quotes and invoices, along with customer records and tracking categories - they seem to be able to add/edit new clients but not new tracking to match the clients for reporting needs, why does user access need to change - any suggestions?
 - 
      
Samantha Harvey
    
 commented
    
  Absolutely critical.
Sales staff need access to monitor overdue customer accounts, without having access to view bank account and supplier information.
 - 
      
Eileen Cotton
    
 commented
    
  Xero needs to work on fixing these issues. I have clients that want to give their employees the ability to enter supplier bills and issue the payment and print the checks. However a USERS cannot print a check unless they have access to all the reports, including all the financial reports, Profit and Loss, Balance sheet, etc. My clients have had to give USERS access to ALL the companies financial data and ask the USER not to look at the financials, very unprofessional and problematic. This is especially frustrating because we were told by Xero the parameters were built in and we would not have this issue. Xero has great software and it's unfortunate but my clients are looking into moving to Quickbooks.
 - 
      
Chau VU
    
 commented
    
  Payroll reports are restricted but unfortunately a standard user can run wages & salary in account transactions report, please limit the accounts visibility.
 - 
      
Jane Skinner
    
 commented
    
  This is linked to Idea: User Role - Restrict access to individual bank accounts, which has also been around for some years!
Xero have admitted they have not been ready for larger organisations, but if that's the case it doesn't make sense that they keep on advertising - unless they are hoping that companies who are NOT a sole trader will give up with them & they can just have lots of sole traders who won't need the same functionality....................
Generally I like the software, but get very frustrated at their lack of communication & disinterest in their customers' needs. - 
      
Catherine Bavister
    
 commented
    
  Voting in favour of filters, for incoming balances only
Hey Dave 😁
It is not currently possible to limit a user when they are reconciling, so they only see incoming payments 👍.
However this is a request that's already been raised with us and I've found an idea that's similar to what you’re suggesting in our Xero Product Ideas. Xero Product Ideas is a Xero website where our customers can share and support ideas for change. You can click 👉here 👈 to add your vote on the product idea.
Collapse
 - 
      
Paul Hunniford
    
 commented
    
  As a new user coming over from Myob ( another business I have )
it very disappointing find so many problems that have not been fixed
I caught one of my employees looking up other employees' pay details and information
why has this not been fixed here in Australia there are privacy laws and i don't wont to be sued from a employee details being read or let out on the net if some one got angry with each other
i surprised this software ware been around a long time and no one in the USA has sued them for this lack of data securityTHIS NEED FIX ASAP MAKE IT TOP PRIORITY
(Or am I going to have go delete this software at this new business and ( a bad word in your office i reckon )
use MYOB - 
      
Paul Hunniford
    
 commented
    
  As a new user to xero
(coming over from Myob from another business that i run )
it's very disappointing that there is no privacy with employees' details as i had caught one member looking at other employees payment details to make shall he was stilling get payed more ,
this has to be fixed asap as here in Australia there are privacy laws that this breaks and also risking their data/confidentiality)
so when i get sued from information being read from different employees does this mean i go after you xero
i reckon if this was in the usa it would be fixed straight away - 
      
Brandy Wilde
    
 commented
    
  It's nice to see I am not alone in needing this feature for our business. Every update or improvement they do is great... BUT I become so frustrated that they aren't making actual important improvements such as this one. This should be top priority. I have been with Xero since 2019 and have been trying to be heard.
 - 
      
Nikki Velinsky
    
 commented
    
  Hello all,
I raised this with Xero in April 2023 when the prices were increased. After much emailing back & forth & some conversations with the customer support team I received an email from Richie in the Leadeship team who stated it wasn't part of their near term plans. As it was first raised in 2012, this does seem very poor.
I have recently posted on LinkedIn about this idea as well as the requirment to be able to have different user access levels (other than the all or nothing currently avaliable) If you want to also add your voice to this, hopefully they may be more inclined to listen on that platform? https://www.linkedin.com/feed/update/urn:li:activity:7159090871684988928/ - 
      
Maria McAdam
    
 commented
    
  @Wendy Xing I'm surprised auditors are not jumping up and down about this. It's a huge risk to businesses. It seems that Xero is not designed to support businesses in their growth phase - either they grow (and allow additional users into Xero (risking their data/confidentiality)) or the owner/bookkeeper has to remain the sole authority on the accounts.
 - 
      
Wendy Xing
    
 commented
    
  I am writing to express my serious concern regarding the current permission system implemented in our XERO platform, which I believe poses a significant risk to management processes. The existing system lacks a crucial middle layer of permissions, offering an all-or-nothing approach that is neither secure nor practical.
At present, the permissions are so broadly defined that they allow for only very limited or almost complete access. This lack of granularity means that accountants, among others, can view and even edit almost everything within the system. Such extensive access is not only unnecessary for their role but also represents a substantial security risk that could potentially lead to data breaches, unauthorized transactions, or other forms of misuse.
The absence of a nuanced permission structure does not allow for the balanced distribution of access rights, which is essential for maintaining the integrity and confidentiality of sensitive company information. It is unsettling to know that the current system does not provide the means to effectively control or limit access based on the specific needs and responsibilities of different roles within the organization.
 - 
      
Eileen Cotton
    
 commented
    
  We are struggling with this issue as well. Managers have to do the work themselves because we don't want juniors having access to all financial data. Xero please look at this.
 - 
      
A K
    
 commented
    
  Ability to restrict delete options ( users cannot delete invoices or contacts)
 - 
      
Tracey G
    
 commented
    
  This is a problem with junior staff seeing information they should have no access to and breaches workplace contracts.
I suppose at least we can see who made the change - but not the why why why - 
      
Joe Van Elburg
    
 commented
    
  Users - allow for full customizability of users in Xero.
I have a client that needs to have users to just invoice for sales. This is needed as the upgraded access to standard gives them access to the bank account and payables, potentially more confidential information. They can create invoices, edit and pay them. Unfortunately one the payment is posted, they can no longer edit the invoice and needs to contact the bookkeeper every time they need something changed. It would be nice to have full customizable user access in Xero where you can tailor to the specific needs of the client.