User Role - Restrict access to individual bank accounts
To have the ability limit some users to access some bank accounts within Xero org.
Purpose: To limit some staff to not be able to see the information about the client’s bank balance.
Hi everyone, I want to assure you your voice is heard here and feedback is being shared back with our product teams.
We understand the desire to get this idea moving along and as mentioned in our last update we know this is an area that more controls and permissions would be most beneficial to our customers.
We’d like to share progress that we’re making for banking permissions - Work to provide more controls of sensitive banking information has started and will initially include the ability to restrict users from seeing sensitive banking information such as; account balances, bank transactions, and financial summaries.
We know this doesn’t relieve all pain points of this idea - It’ll be the first phase, a stepping stone of sorts in the development of per-bank controls.
As development continues we’ll share further updates as soon as they’re available with you all here.
Thank you for your involvement in Product Ideas and support in this idea.
-
Kenneth Campbell
commented
This is essential.
and actually might make use of xero illegal in UK and EU due to data protection issues.
We need members of staff to be able to see what payments are made to us in one account. but they should not be able to see what is paid out (including payroll payments to other members of staff) from other accounts.
In the first instance just being able to turn off accounts on the dashboard of certain users would help. -
Harpreet Singh
commented
I just had a client who are also requiring this feature. They are happy for the admin staff to do the day to day stuff but have absolute no access to the bank accounts. That is because of the security nature especially with Payroll data and confidential data in the bank transactions which only the owners need access to
-
Martin Danger
commented
It's only been 4093 days since this revolutionary idea was suggested.
Or 11 years, 2 months, 14 days excluding the end date.
From and including: Friday, 29 November 2013
To, but not including Wednesday, 12 February 2025Quick translation of Kelly's message using non-tech-bro language:
Thank you for your interest in how we can create user roles that fit your needs in Xero.
Since there are many different ideas about roles and permissions across our products, we understand that user roles affect all aspects of what we offer. We have to think about a lot of factors to meet the needs of the majority of our customers.
We are researching the current situation [not the landscape, lol] to figure out how to best address the main needs of our users. This is one of the most requested topics, so it's a big priority for our team.
We're just getting started with this work and it will be an ongoing project. There will be multiple phases of research and we will ask users to help guide that research.
We really value your feedback and would love to invite you to help us with this by participating in interviews or surveys to share your thoughts.
✍️ If you're interested in participating, please fill out our short form here.
While we may not be able to include everyone at every stage, our research team will get in touch with many of you in the coming months.
We’ll keep you updated on what our research discovers and any developments we make to user roles.
-
Emily Wiseman
commented
@kelly Munro. Please provide an update on this request.
-
Linda De Beer
commented
This is very critical for us as well. IF this does not change soon we will have to move over to a program that do provide this critical user role function. It is ridiculous that anyone can have access to bank accounts and critical information just to enable them to print reports to do their work...
We already had confidential bank balances discussed by employees who should not be able to see this information but how can you blame them if they have unlimited access to everything -
Peter Gordon
commented
So Mr or Mrs Xero.
Are you telling me that someone working in Xero accounts, inputting transactions, has access to ALL of Xeros accounts...? No, I didn't think so. So why won't you give your customers the same?
-
Karen Browne
commented
It’s never gonna happen 🤦🏻♀️
-
Nathaniel Gordon
commented
This really needs to be added. I have bank accounts that access to is not required for the accounts team, only for owners and directors. I want to restrict access to viewing specific banks and their transactions to the bank accounts I allow. If there is a transaction to a bank account they cannot view, they can complete one side of the reconciliation, and I, with access to the hidden bank account, can reconcile the other side of the transfer.
-
Kevin Deely
commented
Ridiculous that I’ve used Xero for 10 years and they don’t have it.
-
ROBIN HOLT
commented
I can't believe in this time of security being so important Xero hasn't addressed this earlier. People have been calling for this for years. Other platforms have much more customised security. I didn't think I would say it but I am looking at changing.
-
Claire Kelly
commented
This has become a critical issue for clients, who we want to migrate to Xero to a single platform, rather than consolidate 15 different accounts datasets. They require each user to have an access to single bank accounts and not all bank accounts. Please update us on progress in this area
-
Nick Joyce
commented
I'm at a total loss as to why this hasn't been resolved yet. We will actively look at alternative software if this isn't implemented in the next few months as it's such a glaring omission.
-
Rebecca Rotheram
commented
Hi is there any update on this? I am unable to delegate a lot of admin tasks because I don't want to give out access to our bank accounts. Which would give users view of director dividends paid, salary levels paid etc. Many other companies must have the same issue
-
Rachael Harrison
commented
Is there any update if the bank account settings has been changed to restrict user access please
-
Noel McKenney
commented
This request for limited access to bank accounts has been going on for a significant number of years and Xero has zero interest in listening to users comments. I think it will take a user suing Xero for negligence if their business gets defrauded by an employee having full operating access to bank accounts when this restrictive feature has been requested so many times by so many users. Absolute gross negligence by Xero.
-
Joy Lorraine Ford
commented
I have a staff member, I believe another commentator called it a "CashBook Clerk" which is HUGE due to the nature of the company.
Happy for her to see the bank account called: "PETTY CASH"
However, I am far from keen to have her see the general bank account balance of the company, which I believe is sensitive and confidential in may aspects.
Xero - puts itself out there as a Premium product - I surprised there are not more user friendly pathways within the software. -
Rachael Harrison
commented
This is critical for our business atm as we have had a confidentiality breach , and if this was a option to hide bank account from certain staff levels would never have happended, please let me know if you are able to change this feature
-
Rachael Harrison
commented
This is critical for our business atm as we have had a confidentiality breach , and if this was a option to hide bank account from certain staff levels would never have happened, please let me know if you are able to change this feature
-
Linda De Beer
commented
Good day this is really a huge problem for us. Now our creditors and debtors controllers have access to all our bank account balances because they need to print reports. Bank accounts should be a separate role so that it can be taken off from certain users. Please Xero - my CEO just informed me we have to change to another system if Xero cannot comply with this
-
Wesley Nicolaai
commented
Good day,
I have been reading the threads of user concerns with regards to the lack of issuing users with limited access to certain bank accounts. Our company is now in the same position as many others where we have delegated certain tasks to employees and different staff performing different roles have user access to specific modules in Xero, for example debtors and creditors clerks having role specific access. We now have an issue with a cashbook clerk, who needs to allocate transactions off the main bank account only, having access to all bank accounts. Because of the limitations of Xero, we are unable to restrict her from seeing sensitive information in the salaries account other bank accounts. Xero needs to allow businesses to customize the user rights of the staff since, in our situation, the accountant will now need to do the work that the cashbook clerk needs to do so that confidential information remains confidential.