User Role: More options for access rights
More granular level for user access rights
I have seen lots of ideas around this same topic but worded slightly differently.
Essentially, the access rights are far too high level causing users to have access to tasks and rights to delete, approve when they shouldn't
Appreciate your looking through the forums and existing ideas, Tracy.
Although it might seem quite specific it does help to have detail of the specific permission sets and what is missing in the existing roles shared for each idea, and get a sense of the users that are interested in these differing permissions.
As you can likely imagine, with the number of features and different roles & responsibilities staff may have across businesses a matrices of options for every single permissions across every feature in Xero would be quite complex and cumbersome when trying to assign what a user can or can't do in your organisation.
While we don't have direct plans for this level of incremental control, our product teams are definitely interested to consider the makeup of permissions within a given area or feature of Xero. I'd urge you and others here to add your support to any ideas that have been raised, or add new ones for permission sets that you'd find most useful for your business.
-
Judith Story commented
We are accountants too and find that this is an issue for larger businesses wanting to use Xero - we can't have staff looking at the financial reports of the business or having access to other areas than their job description allows. I agree the access levels should be completely customisable.
-
Cat Graham commented
Kelly I think you are being obtuse.... you want specifics.... thats the issue... xero thinks they can class users in 4 roles with minor access changes.... if you take one thing from all the comments on here is that every company / role has different requirements so we require complete customisation of user access....
My suggestion - simplify access to the headings in the drop down, so we can tick on which drop down items they can view/have access to and allow us to select whether access is read only or edit.
-
Matthew James Mifsud commented
this should be done to specific sections such as quotations section only i.e the ability to just be able to issue/send quotations without access to anything else
-
Alan Oversmith commented
General User Access:
There are several very specific user access ideas, all of which are great. The bottom line is though that Xero basically has Zero user access control nor any interest in putting it in place. Many of these "ideas" were posted quite a long time ago with the same generic response of the teams being focused on other areas of improvement.
This system needs to develop the same basic user access control that literally every other accounting system provides if it has any interest in growing and retaining its client base. As part of a large franchise system that will bring on hundreds of locations and users, I'm certain our tolerance for the lack of user access control will be short-lived. Xero may not need to listen to our complaints, but our Franchisor will.
-
Jacqui Lobjoit commented
Can we please have user permissions that we can select which areas/functions we want to assign to staff. The stock standard user permissions do not work as it either limits the work that can be allocated to the staff or gives them access to information we do not want them to have.
-
Lorraine Adams commented
Xero - Isn't it pretty obvious? Anything would be better than access to pretty much EVERYTHING, as things have stood since Xero was invented.
Sorry to be rude, but you do understand accounting right? & GDPR yeah?
Let me help - Purchase ledger clerk needs access to supplier contacts, bill processing, supplier reports, aged creditor reports, bills reports, purchase day book reports, bill production, quotes, purchase orders, bank supplier payments, refunds, credit notes and .........
Purchase ledger clerk DOESN'T NEED and NOR SHOULD SHOULD HAVE ACCESS to staff pay & personal information, the director's dividends & tax information, the companies balance sheet, staff bonuses, HMRC arrears (or otherwise), investments, how much the company spent on the last client event, or the christmas party, or the computers, Joe's redundancy payment (oh, did I let the cat out of the bag or should I call it something else in Xero so no one knows, HMRC won't mind....)..........do you really need me to go on?......
Perhaps some one else could be kind enough to waste some of their time explaining what the sales ledger clerk needs. or what the treasurer or in house accountant needs - which surprisingly is where the 'access all areas' should sit.
A waterfall access level approach with a tickbox list (just like staff access in MY XERO - (miss that - it was good and clear)....I've seen this before, oh yes, in SAGE. Works a treat. Easy. Clear. Transparent.
I have to give some staff access to EVERYTHING and freeze out others which not only causes causes offence, but also inconvenience to those that have to be disrupted in their own work to provide reports to other staff.
If the current reporting structure/platform can't be changed, why not build a suite of smaller reporting modules - task or job role specific??
It's stunning that this FLOOR exists in the first place, and beyond belief that in more than 10 years, and despite GDPR, and many many requests in the old & new voting system, NOTHING, EVER, has changed in this regard, or other items I've voted for..... -
Loretta Sutcliffe commented
We need to separate out some of the access for some users. So for example why cant there be user access by an employee whos role will be to authorise timesheets but no other payroll access, enter sales and payments, check bank feeds, upload supplier invoices but not entry. MYOB has a good structure for setting access to different parts of a file - Xero could do similiar. At moment there are only limited access - you either give access to the whole file or restricted to a level thats specific to one task which is crazy. Im uncomfortable about users being able to access the whole file just so they can see the bank feeds. I know the system shows who might change something but its more the power of "looking" and having too much information about a company that can be dangerous.
-
Loretta Sutcliffe commented
When is Xero looking at User access controls. I have an instance where an employee only needs to authorise timesheets but at moment has access to all levels of information including other employees pay details etc which is not ideal. The same goes for other areas. Say an admin needs to see reports but I dont need them to be able to run reports on all areas incl payroll it would be nice to restrict the type of info they can access or see. Its very frustrating and unethical to allow full access to certain people. Especially when they are not in high end roles.
-
Barbara Saunders commented
We are looking for the ability to allow a manager to view items in draft and waiting approval without having to access the program. Attachments would need to be viewable.
Perhaps like the email to bill it could be reversed and a link could be created from these items to be sent to the approver for viewing?