User Role - Restrict access to specific Settings
Ability to customise user roles to restrict some access in Xero.
Purpose: Some staff should only have limited access in Xero.
Hi everyone, we appreciate all your feedback on how we could evolve roles for customers using Xero. As you can see through the ideas on the platform, there are a wide range of combinations of permissions our customers want to see us build. As user roles impact all areas of the product, there are many considerations we must factor in when assessing how to solve for majority of our customers needs.
We’re beginning to conduct research on the current landscape and how we might approach some of the most predominant needs in roles for our customers. Front footing this, the discovery of this work will be long winded and there will be multiple phases of research and forms of engagement with users that’ll help shape the path ahead in this space.
We’d like to invite you, our community to be part of this research and discovery. This may involve interviews and sharing further feedback through direct surveys or questionnaires.
✍️ If this is something you’d be interested in taking a part of please fill in our short form here.
Though we won’t be able to invite everyone into every stage, our research team will be in touch with many of you over the coming months.
We will be back to share on the outcomes of our research and any progress around development of roles in Xero.
-
Murli Vasu commented
Payroll reports should not be available to all advisor. Where an advisor doesn't have payroll admn. role, should not have access to payroll reports. This is very preliminary and basic restriction to be implemented asap.
thanks
Murli SBA Albany. -
Louis Nicotra commented
We need to be able to split access by region so our EU staff can only see invoices raised in their sales territories.
The differences between the levels of customisation is huge and massively restrictive to us.
-
Greg Inwood commented
We need to be able to split access by region so our EU staff can only see invoices raised in their sales territories.
The differences between the levels of customisation is huge and massively restrictive to us.
-
Heather Stitt commented
Bank Account access and information should be able to be removed, or add on if required.
I am sure that Xero employee's don't have Bank Account access...!!!
Not being able to remove access to Bank makes the User access rather a redundant feature.
Please fix this as a matter of URGENCY.
-
Jon Simcox commented
We need to allow our credit control staff to access outstanding invoices only, currently they would see our whole business.
-
Jarred Walmsley commented
Agree with many of the other comments, access is far to wide.
The gulf between being able to run the AR report & the P&L report is massive!
Many admin staff will need to do the bank rec, update staff on debtor balances, send out invoices and the like but not have access to any of the financial information like profit & such, but that's not possible with the current settings.
-
Gerard Lillicrap commented
I agree that current access levels are too coarse. I need to give a Director access to the reports only (even if I could restrict it to a selection of reports). In computer parlance, I need a read only access level.
-
Charlotte Woodbridge commented
I agree, the user roles are ridiculous, there is a huge jump between invoice only and standard, bank feeds are visible when they don't need to be, there should be a lot more options available so you can select if you want them to see bank feeds and if so which ones! There should ALWAYS be the option to keep certain bank feeds/reports private. This is a big issue and needs addressing ASAP!
-
David Kim commented
I stumbled onto this issue after finding out that one of the admin person from a different company division was creating an account in general ledger as it fits in Chart of Account.. There is no option to give limited access to a standard Xero user account it's either give them full access or none..
When will this issue be resolved !
-
Tracy Hunt commented
Hello Xero Team,
If you are aiming at small businesses to make it easier for them working with third party accountants then why would you have users rights that combine business function with accounting???
So the junior who raises PO's in the business can reconcile and see ALL transactions of the bank accounts!!
-
Marco Brown commented
Come on Xero, some of your access levels does not make sense.
For example, I have a client that has a junior finance person with invoice-only access who processes invoices and in some instances takes cash from customers, process the cash payment and must issue a receipt to the customers. But unfortunately the same person who processed the receipt cannot print it! Unfathomable!
Come on Xero, your whole access needs re-looking at with a wide variety of options where the administrator can tick what a person has access to NOT pre-designed and fixed by Xero. It's just not working.
-
Olivia Darcy commented
Agree, I would like to give staff more responsibility so they can reconcile accounts with having limited access.
-
James Thurlow-Craig commented
How many more of your customers need to scream and shout on this thread before you listen to them? The access levels and permissions are all over the place! I need a member of staff to reconcile certain bank accounts, but not all of them and not to see the current balance of accounts (and everyone's wages!) yet that's not remotely possible without giving out full access. Sort it our Xero.
-
Tracy O'Donnell commented
WE need this setting set up now
-
Gillian Jackson commented
I would like to be able to stop some of the adviser users to be able to change COA, tax codes and Tracking categories. But I still want them to be able to close the period
-
Kevan Wells commented
It is almost beyond belief there is no user setting which enables a member of staff to match and allocate customer and supplier invoices without also being able to see what other staff members are paid!
-
Rachel Coldicott commented
I need to give access to raise Purchase orders and copy purchase order to draft bills only, as we have sensitive purchases that should not be viewable to all. Unfortunately Xero is almost a free for all with the access options, which is troubling and makes me hesitate to give access to others.
This is a critical update, as it is holding back decisions on how much we use other Xero functionality in our Business.
-
Jimmy Hempenstall commented
I have clients who need to give access to operatives to record spends in real time from company cards but should not have any visibility of bank accounts, client balances etc etc and they cannot roll this out without greater user access control and visibilty
-
Lorraine Forbes commented
100% back the comments below. There needs to be some kind of way of setting restrictions that is in between 'invoicing' and standard. As we have staff who process purchase invoices for us, and it would be helpful for them to be able to access the aged payables so that they can reconcile purchase information they have inputted to Xero, with supplier statements, and be able to get a drill down if there is a difference between the two so that they can check what's missing or if they have made an error. I am being told the only option is to give standard access. This then gives access to sensitive informaiton like bank accounts etc. Which is really not good enough. So the only way for me to tackle this is to keep the person restricted at purchase invoices only, and I am having to print off the aged payables totals, then print the drilldowns of the informaiton of each supplier that doesnt match our supplier statements. This is causing me time, whereas the person doing this job, should be able to do all of this herself. (Without having access to other areas that are outwith her brief)
-
Bo Cui commented
In practice, we may have some overseas contractors who are doing simple jobs and as an accounting practice, we have been constantly dealing with sensitive and confidential information so when we have sent out document packs to clients to sign, XERO does not have any restriction setting available for us to choose from so that limited access staff won't be able to get their hands on sensitive data. I do hope XERO can resolve this issue ASAP which doesn't seem like a difficult job. Thanks