User Role - Restrict access to specific Settings
Ability to customise user roles to restrict some access in Xero.
Purpose: Some staff should only have limited access in Xero.
Hey everyone, we've been following the conversation closely and we want to acknowledge how important this is for many of you.
Atm, we’re on a long journey to provide more controls within Xero features that our customers need. Being such a broad idea that touches many areas of our platform, we’d like to encourage adding your votes to specific user permissions that matter most to you, such as:
- Bank Accounts: For more control over who can see bank account balances and access specific accounts, please see the idea here: User Role - Restrict access to individual bank accounts
- Sales and Invoicing: If you’d like to see changes to permissions around sales reporting and editing invoice templates, you can follow that conversation here: User roles: Restrict access to Invoice Settings
- Reports: To have your say on restricting access to specific reports, the relevant idea is here: User permissions - Assign user access to specific reports
This change will allow us to focus on the more specific requests to explore. If you don’t see the user permission you’re after, raise a new idea here.
We're thankful for the time and effort you've put into sharing your thoughts on this. Your feedback is valuable, and helps us better understand the priorities and needs of the community as we continue to evolve Xero.
-
Natalie Copley
commented
To be able to segregate duties and have more advanced security settings would be ideal. Area managers need specific access to xero areas that reflect their business units, not the entire business.
-
Oliver Carter
commented
Yep:
"This is an excellent technique by Xero, placing any shortcomings in an 'ideas' pool gets rid of support problems, I mean, an accounts package without multi-user security.
It's been since 2014, and not a single entry from Xero, because they don't read this stuff, its to get you off their backs. -
Jon Simcox
commented
This is an excellent technique by Xero, placing any shortcomings in an 'ideas' pool gets rid of support problems, I mean, an accounts package without multi-user security.
It's been since 2014, and not a single entry from Xero, because they don't read this stuff, its to get you off their backs. -
Megan Pelser
commented
This is a big thing that needs to be changed. Most accounting packages have a check list of what you want your users to see because it can get quite complicated. I think in terms of entry level staff and restrictions this is maybe a good idea.
I don't want users to be able to create contacts at all and this to be a finance thing but there is no restriction to this
-
Lalit Gopwani
commented
How has this not been fixed yet? My client's business can't expand and have controls in place with differing levels for segregation of duties. Its quite embarrasing.
-
Bernard Malunda
commented
Report viewing should be customizable eg AP's AR's , Sales reports and Purchases reports. Accounts receivables clerks should be able so see sales and AR's e.t.c
-
LIMOR ESAKOV
commented
I would like to set up permissions on my Xero account where the user can raise quotes and convert only their quotes to invoices but they cannot see all the invoices in the business and they do not see a dashboard of all outstanding invoices owing.
-
Julie Curnow
commented
I love Xero but I think their user access is its biggest short coming. User permissions are a fundamental part of any accounts system.
This is one area where I prefer more complexity and choice.
We lose a lot of potential efficiency and effectiveness by not allowing people to do their jobs / duplicating effort so that junior staff don't end up seeing confidential data. -
Paul King
commented
Come on xero, as soon as a business grows to a certain level robust and customizable user controls are required. It’s really not difficult and clearly critical for so many of your customers.
-
Tracy Yan
commented
Business unit or area managers need limit access to Xero areas that reflect their responsibilities, without being able to access all areas and all reports.
As the Admin role of Xero, I should be able to limit their access from my side...
-
Estelle Swart
commented
Please give the quotes and invoices user the option to add new products, alternatively, give the option to hide the bank accounts and reports from the standard user.
-
Rachel Rowland
commented
I would like users to only be able to see the History and Notes in the Advanced section.
-
Joana Capela
commented
I would like to be able to set limits on payment amounts that different users can authorise eg For example, one user limited to only authorise payments up to £1000, another up to £5k, another up to £10k and so on.
-
Kristen Saunders
commented
I would like to be able to allow people who work in sales and chase money to have read only access to customers, their invoice history and invoices outstanding without seeing the rest of xero (banks, reports, purchases, payroll) as it would save time if they could look this up themselves instead of having to stop what I’m doing to get the information they need.
-
Elaine Lassman
commented
Users need to be able to perform specific tasks such as customising stationery without being able to access bank account information & other areas of accounting that bear no relevance to what they are doing.
-
Naomi Gibbins
commented
Business unit or area managers need specific access to xero areas that reflect their responsibilities, without being able to access all areas and all reports.
-
Jordan W
commented
This feels like a basic feature that's sorely lacking in Xero at the moment.
-
Joyce Dass
commented
Give options in the standard User rights role where the person cannot have bank account access.
-
Charmaine Coulston
commented
Previously had the ability to assign user roles ie just purchase orders and accounts payable. why has this disappeared?
Surely its obvious when new people start they should not have free reign over everything.
Where is the risk management of users incorporated into this aspect of Xero access?
-
Thomas Hollars
commented
This feature is necessary for adequate internal controls. In the US, accountants learned from their mistakes and now aren't so lax about permissions: https://en.wikipedia.org/wiki/Committee_of_Sponsoring_Organizations_of_the_Treadway_Commission
Checkwriting access should be selectable and monitorable. This is taught in accounting 101.