User Role - Restrict access to individual bank accounts
To have the ability limit some users to access some bank accounts within Xero org.
Purpose: To limit some staff to not be able to see the information about the client’s bank balance.
Hi everyone, I want to assure you your voice is heard here and feedback is being shared back with our product teams.
We understand the desire to get this idea moving along and as mentioned in our last update we know this is an area that more controls and permissions would be most beneficial to our customers.
We’d like to share progress that we’re making for banking permissions - Work to provide more controls of sensitive banking information has started and will initially include the ability to restrict users from seeing sensitive banking information such as; account balances, bank transactions, and financial summaries.
We know this doesn’t relieve all pain points of this idea - It’ll be the first phase, a stepping stone of sorts in the development of per-bank controls.
As development continues we’ll share further updates as soon as they’re available with you all here.
Thank you for your involvement in Product Ideas and support in this idea.
-
Accounts IW Observer
commented
Is there any update since March on this issue please? Lots of people clearly want to see it. It means I cannot give my sales staff access to check whether a customer owes us any money before taking another booking.
-
Clare Barkley
commented
I would like ability to select which accounts to give user access to please. not blanket ALL accounts. URGENT please.
-
Charlotte Rix
commented
I urgently require this idea to be actioned by Xero
I cannot give staff work to do because I cannot give them access to the bank account
Every business does NOT has one person solely doing data entry and one other doing everything else
We need certain bank/credit accounts restricted to certain users with access to Debtors/Creditors reports
Net wages should be locked for those that do not use Xero Payroll Software
This is legal requirement -
Charlotte Rix
commented
I cannot believe this idea was posted in 2013 - we are still asking for it 10 years later
-
Rachael Coupe
commented
This is a critical issue Xero and I have to say it is driving clients to move to other platforms that provide multi-level access. Please move this up the list, as you can see, you will lose business if you don't start developing the platform to GDPR standards as a minimum.
-
Megan Campbell
commented
I need this too, so that we can limit access to a wages account for staff who assist with billing but have no involvement in wages. For example, now only staff who are involved in wages can do bank reconciliation tasks because visibility can't be restricted.
-
Charlotte Rix
commented
I need this implemented urgently, I need users to have access to our credit card accounts but not the current bank account, it would breach GDPR to give them access
This should be a basic requirement so business's comply with data protection and confidentiality
Xero needs to understand how accounts work in business and help us adapt to our workplace, not the other way round
-
Moolchand Dubey
commented
I have recently added to Xero a client who wants to restrict access to some of the bank accounts for few user. It is very critical for the client. Could Xero create a new User role to meet such requests from the clients.
-
Robert Flynn
commented
I think your teams resource should be focused on Building on Useful work instead
this is vital, there is no way standard users should have access to all bank accounts and financial information, or even any of that confidential information.
get on with it Xero, this is essential
-
Maria McAdam
commented
I agree wholeheartedly with Carol. When I am asked my opinion on Xero I advise it's great for a one or two man business, but unfortunately struggles to grow with a business - due to the inflexibility of user level access. When our business changed over 7 years ago, we were much smaller and this inflexibility was not a problem, but now it means I am unable to delegate aspects of my work without allowing access to sensitive information.
-
Carol Evans
commented
No business should be in the position that every member of staff has access to its confidential financial position! Come on XERO Please hurry up and get on with such a basic requirement.......
The limited amount of user access levels you provide leaves you way behind SAGE, where, as I'm sure you are aware, admin can tailor make the access every user has.
By ignoring the amount of requests that have already been made by Xero users you are simply causing more work for them, they need to get on with more complex tasks in running a business, however, until you do something about this they are also having to do basic tasks that should delegated to other staff members eg why does a user that is dealing with purchase orders and inventory items need access to the bank???
It was a big decision for me to move from SAGE to XERO and for all the plus points I can honestly say had I known how limited this area was, I would not have moved until it was sorted.
I'm often asked how I'm finding Xero, and as recommendations go I can only tell other businesses about this hugely negative point until it's sorted.
How many 'votes' does it take for you to support your users and prioritise a vital function over spending time making it look 'beautiful'???
I look forward to hearing from you.
-
Noel McKenney
commented
It's pretty obvious that Xero's interest in sorting this ongoing critical issue and their care factor in general is absolutely ZERO !!!
PATHETIC !!!! -
Ryan Kent
commented
Each user definitely needs more specific access rights, for example, an invoice only user cannot currently add new tracking options when raising sales invoices which is frustrating. Instead, they have to be a standard user to have full access to tracking, where they will then be able to view the bank account and its transactions, which our client is wanting to avoid. So there is no way around this currently
-
Kosta Court
commented
My client pays staff from a seperate account and would like to keep that account nonaccessible on Xero by the administrative staff whilst allowing them to reconcile the other bank accounts.
-
Jason Ward
commented
Vital feature to be integrated into Xero.
-
Helen Jackson
commented
I agree, we have new look reports forced upon us which are not as useful or quick as the old reports. There's nothing wrong with the old reports anyway. Instead I continue to work Xero that administration staff could be doing.
-
Rebecca Rotheram
commented
Basically Xero are currently spending a lot of time working on the 'look' of the software rather than the functionality. I'm very disappointed that after hiring an accounts admin I can't ask her to post journals otherwise she will have access to a lot of sensitive information. Doing month end accounting journals are part of a low level accountancy role. To have access to a whole host of information just to post a journal seems crazy to me. Yet again another work around needs to be done. She will just have to fill in a template for me to upload. Until xero work on this...
-
Rod Fay
commented
i totally support this concept, i have a number of clients that want this feature and from an audit view it is a great management tool that adds assurance to the internal controls.
Please add your voice to this request so Xero will prioritise it -
GS THOMPSON
commented
Adapt or die. Xero needs to catch up.
-
Alan Oversmith
commented
@Ethan M as you pointed out there are several user access ideas on this site and many of them have been here for a long period of time. Xero doesn't appear to be interested in addressing this issue whatsoever as most of them have basically the same response you've provided here.
For me, it's absolutely amazing the software was ever designed without any basic user access control as literally, every other accounting software provides. Being with a franchise system that will bring hundreds of locations onto the platform, I can confidently say this won't be acceptable and will only be a matter of time before the system decides to move on.
Given the hundreds of related "ideas" posted and likely thousands of "votes" in favor of them, Xero better start listening to their customers or they will become former customers.