User Role: Quotes access only
Ability to only give new users quote access only.
Purpose: Having more options when giving someone else access to Xero org.

-
Campbell Green commented
Granular Access Control – Secure, Zero Trust Permissions
Control-C’s new security model introduces a level of granularity never seen before in managing access to your Xero financial data. Traditionally, giving an employee access to run an Aged Payables or Aged Receivables report meant exposing your entire financial landscape – including sensitive areas like your Profit & Loss, balance sheet, bank transactions, and even other employees’ bonus information. Xero’s native user roles are fairly broad (e.g. standard user or advisor roles grant wide access). Not anymore.With Control-C’s Zero Trust-based security framework, you can now restrict access to just the specific data or reports your team members need – and nothing more. Want a staff member to run only the Aged Receivables report? You can grant that exact permission, without also giving away the rest of your accounting info. No more over-exposure or “all-or-nothing” access. For example, an accounts clerk can be set up to view and export customer invoices and aging reports, but cannot see the general ledger or payroll details. A junior bookkeeper could be limited to inputting bills and viewing the payables report, without any visibility of bank balances or management reports. You define roles at a fine-grained level – a stark contrast to Xero, where even a read-only user can see almost everything.
This precision access control is built from the ground up, aligning with modern Zero Trust security principles that assume no implicit trust – every access is explicitly granted and minimal. For accountants and compliance officers, this means better internal controls and cleaner audit trails. You can demonstrate that even within your organisation, sensitive financial data is only accessible on a strict need-to-know basis. For instance, an auditor or external accountant could be given a special “Auditor” role on Control-C: read-only access to relevant reports and the audit log, but nothing else. Meanwhile, your sales manager might have access to customer contact list backups (for business continuity) but not to any financials. These tailored permissions greatly reduce the risk of internal data leaks or unnecessary snooping.
For business owners, the benefit is peace of mind and professionalism. You no longer have to say, “I’ll give my assistant access to Xero, but I hope they don’t poke around the salaries or bank accounts.” Instead, you define their role on Control-C to exactly what they require (perhaps invoice creation and nothing else). It shows a commitment to confidentiality: employees see only what’s relevant to their job, which also reduces temptation and errors. And because the platform logs every access and download, you have a full audit trail of who viewed or exported data.
This Zero Trust security model is a unique selling point of Control-C’s platform. It effectively adds a new permission layer on top of Xero’s data, one that many businesses have long wished Xero itself had. By deploying it, you protect sensitive information by default while still empowering your team with the tools they need. The result is a more secure, compliant operation, where data access is precisely aligned with role and purpose – no more, no less.
If you would like to learn more visit Control-C.com or find us in the Xero App Store.
-
Sharee Keane commented
This is a must for our business and makes things much harder without this function
-
Ivana Samra commented
Hi There,
Therefore from your response you are sending me to a different section of Xero to share my frustration with others who also share the same frustration as I, that your platform has an inability to supply your client base with a simple tool to enable quoting done from a member of staff who by no means needs to know any other function than simple quoting. Seriously Xero! How old are you? Have you never been able to build something so simple as this request - what is wrong with you data back end building staff, can't they construct this code? Maybe you need new and uptodate IT coding staff. It's 2025 and still financial privacy is put at risk by your platform as you seem to be too lazy to assist so many people who need this. Has Xero ever heard of Privacy - it appears not!Not at all happy - seriously!
-
Country Contractors (Norfolk) Limited commented
This is really needed, I am now having to quote outside of Xero as I do not want the quoting team seeing invoices for my whole business.
-
Marisa De Carlo commented
this is critical for our small business to free up the MD having to do all quotations but limiting access to financial data. How is this not a function yet?
-
Robert Dickinson commented
This would be great. Do you have any update on this??
-
John Paul Williams commented
This would be an excellent function
-
Natalie Smith commented
This would be really useful.
-
Matthew James Mifsud commented
this is a critical function - just the ability to issue, send quotes via email and send to invoice (to be approved) once quote is confirmed.
-
Candyce Grew commented
would be great to have this function please
-
Jill Hartmann commented
It would help immensely to be able to have our estimator to view the quotes that send and approve.
-
Damian Haremza commented
Do we have an update on this? We require this in our business to allow for employees to do quotes without being able to see invoice, payroll and other business critical information.
-
Matthew James Mifsud commented
The user role to just be able to issue/send quotations without access to anything else
-
Lorraine Adams commented
Xero - Isn't it pretty obvious? Anything would be better than access to pretty much EVERYTHING, as things have stood since Xero was invented.
Sorry to be rude, but you do understand accounting right? & GDPR yeah?
Let me help - Purchase ledger clerk needs access to supplier contacts, bill processing, supplier reports, aged creditor reports, bills reports, purchase day book reports, bill production, quotes, purchase orders, bank supplier payments, refunds, credit notes and .........
Purchase ledger clerk DOESN'T NEED and NOR SHOULD SHOULD HAVE ACCESS to staff pay & personal information, the director's dividends & tax information, the companies balance sheet, staff bonuses, HMRC arrears (or otherwise), investments, how much the company spent on the last client event, or the christmas party, or the computers, Joe's redundancy payment (oh, did I let the cat out of the bag or should I call it something else in Xero so no one knows, HMRC won't mind....)..........do you really need me to go on?......
Perhaps some one else could be kind enough to waste some of their time explaining what the sales ledger clerk needs. or what the treasurer or in house accountant needs - which surprisingly is where the 'access all areas' should sit.
A waterfall access level approach with a tickbox list (just like staff access in MY XERO - (miss that - it was good and clear)....I've seen this before, oh yes, in SAGE. Works a treat. Easy. Clear. Transparent.
I have to give some staff access to EVERYTHING and freeze out others which not only causes causes offence, but also inconvenience to those that have to be disrupted in their own work to provide reports to other staff.
If the current reporting structure/platform can't be changed, why not build a suite of smaller reporting modules - task or job role specific??
It's stunning that this FLOOR exists in the first place, and beyond belief that in more than 10 years, and despite GDPR, and many many requests in the old & new voting system, NOTHING, EVER, has changed in this regard, or other items I've voted for..... -
Greg Knowles commented
As a small business, this would be extremely beneficial to us, so that our business development manager can prepare quotes, but not have access to all the other invoicing and banking details. A tick box option to manage user access to components would be the BEST outcome for many businesses, I'm sure. We would greatly appreciate Xero fast-tracking this option.
-
Laura Low commented
This is an option I am hoping will come through soon for a new employee.
-
Gina Chapman commented
Agreed - user roles can be very granular - this blanket approach is extremely problematic. It should be a tick box function at a far more granular level.
-
tiffany chia commented
Hi xero, pls update on this as We requested for this feature 3 years ago. It will be very beneficial to the sales team to use ONLY quotes function. Hope to see this coming soon Tks
-
Jonathan OReilly commented
Very important for company to maintain confidential accounting numbers
-
Jonathan OReilly commented
I want to give a user the ability to send quotes ONLY from xero. Currently xero also allows that user to invoice a client as well which is inappropriate and too much access.