User Role - Restrict access to specific Settings
Ability to customise user roles to restrict some access in Xero.
Purpose: Some staff should only have limited access in Xero.
Hey everyone, we've been following the conversation closely and we want to acknowledge how important this is for many of you.
Atm, we’re on a long journey to provide more controls within Xero features that our customers need. Being such a broad idea that touches many areas of our platform, we’d like to encourage adding your votes to specific user permissions that matter most to you, such as:
- Bank Accounts: For more control over who can see bank account balances and access specific accounts, please see the idea here: User Role - Restrict access to individual bank accounts
- Sales and Invoicing: If you’d like to see changes to permissions around sales reporting and editing invoice templates, you can follow that conversation here: User roles: Restrict access to Invoice Settings
- Reports: To have your say on restricting access to specific reports, the relevant idea is here: User permissions - Assign user access to specific reports
This change will allow us to focus on the more specific requests to explore. If you don’t see the user permission you’re after, raise a new idea here.
We're thankful for the time and effort you've put into sharing your thoughts on this. Your feedback is valuable, and helps us better understand the priorities and needs of the community as we continue to evolve Xero.
-
Amoré Muller
commented
Our company has a creditor clerk, that needs to process bills payable. They are not supposed to see the bank accounts which is fine. But they must be able to have access to reports to recon their accounts. At the moment this is not possible and very frustrating. There must be a possibility to 'tick' or 'untick' levels of accessibility to the system? Please urgently look into your permissions settings.
-
Chevon Bauer
commented
The ability to restrict certain reports for example having office team members being able to generate debtor reports for credit control without having access to view the banking details. someone below mentioned a tick box to all user to view bank is critical and I agree if we could remove the bank accounts and just allow certain reports far more users would be able to access Xero and do their jobs as normal.
-
Rob Nobel
commented
Developing a simple option to allow/disallow access to sensitive parts within XERO is certainly necessary.
My concern is primarily to do with authorisation when 2 or more signatures are required, such as with Direct Payments where an ABA file is produced. Currently, one user is all that's required which could contravene policy. If the bank accepts the ABA file having been signed by one user only, also leaves the organisation open to theft by any user who has access to producing ABA files. -
T est
commented
Hi Kelly.
As other mentioned, one of the most important additions must be the ability to disable bank accounts/balances etc for all user levels. Simple tick box should suffice.
Do you have a time line for how long before we start to see changes ? -
Izhar Groner
commented
I need to add an employee to do the bank reconciliations for me. I don't want to give him any other authorization.
You current system is too rigid. Other software provides allow their clients to pick and choose authorizations for their added users. Can you adopt this feature too? -
Maria Lis
commented
Hello, Ability to be read only profile (meaning no changes to TB activity but with ability to authorize teams POs and see reporting using the same profile.
Authorizations levels for staff (basic PO input, no other access), team leader (PO input and PO authorisation for the allocated team), Line manager(PO input and PO 2nd level of authorisation over certain value, plus access to reporting)
-
Michelle Westle
commented
Ability to refine access to view, or not, bank accounts, separate to other access. Read only view also needs the ability to scale access to everything i.e auditors, to limited to specific areas.
-
Matthew James Mifsud
commented
Quotes only role - this is a critical function - just the ability to issue, send quotes via email and send to invoice (to be approved) once quote is confirmed.
-
Brandy Wilde
commented
Thank you Kelly, do you have any kind of timeline? I am in the process of switching to quickbooks because they already have the users so that you can customize their rolls. I have been with Xero for 4 years, and finally decided I can't keep waiting. I will fill out the survey and hopefully help with the process. I would really appreciate someone reach out to me. Maybe I don't have to switch, that would be awesome! I would need to know in the next couple days!
-
Eileen Cotton
commented
I agree with everyone's comments, this is great! It's would be important to block access to certain reports. Such as allowing access to the accounts payable and receivable reports, issuing payments, and reports pertaining to those areas but blocking access to the financial reports such as Profit & Loss, Balance Sheet. Trial balance, etc. Also not allowing the user to have to certain financial data on the "Dashboard".
-
Charlotte Woodbridge
commented
I completely agree that Bank Accounts would be a great place to start when adding restricted access to users. I am so glad this is being looked at by xero! Great news!
-
Tracy Hunt
commented
Just remove view of bank accounts should be first critical need.
How many companies have you worked for where you know what in the business bank accounts!
-
Gemma Papp
commented
This is great news. I think even just a tick box option in the first instance to hide/unhide bank accounts from a specific user regardless of their other permissions (including reconcile, account transactions, & Statement lines) would be a massive step forward. Perhaps further research could be undertaken to drill down further once you implement the main issue.
-
Eileen Cotton
commented
Wonderful news!
-
Eileen Cotton
commented
Xero - this is wonderful news!
-
Stuart Mohamed
commented
Like many who have commented before, our requirement would be for users to be able to process purchase and sales ledger invoices without being able to see bank account details.
-
Jason Abbott
commented
Allowing team members to view items relevant to their department budget would allow better workflows and accountability
-
Kyle Angloher
commented
It would be great to limit account creation / create a password to create / delete accounts, as this just adds structure having standard chart of accounts. extremely important if you have multiple companies.
Also, would be great, if you are running a group of companies, to be able to lock chart of accounts, so all your entities share same set of accounts (ie, global chart of acccounts), NetSuite has this functionality, and makes sense for group companies
-
Rochelle Sowman
commented
We need our receptionist who has invoice only + approve & pay user to be able to create batch payments and export the payment file and send remittance to clients.
At the moment it is super messy as she is able to enter invoices etc then pass them onto me to have to create batch payments export the file drag it into the bank and pay.We would like her to still have the invoice only + approve & pay user as we do not need her to see our bank accounts.
I have set her up in our bank and she has access to transact an imported file but she can not see our accounts and she can not authorize the payment.Was so much easier when batch payments went directly to the bank (she was able to do that!) I would just have to authorize the payment.
Hopefully this can get sorted soon!
-
Dinay Jansen
commented
Restricting user access to Invoice Only permissions should definitely not allow them to see any financial information, including You Owe data. Maybe have the contacts as restricted, but only visible to create invoices and quotes when drafting them.