Skip to content
Goals/Getting set up
Task

Give an outside auditor view-only access

Goal
Let an auditor or outside bookkeeper see your accounts, payments and counterparties, without being able to change anything or move money.
How it works
You create a group that holds only view permissions, then invite the auditor into that group and nothing else. They see what the group can see. When the engagement ends, you take them out of the group.
  • You’re an Owner or Admin. Creating groups, changing permissions and inviting people all need that. (Who can use it)
  • You have the auditor’s email address.
  • You know what they need to see. The list in Part B covers a typical financial audit.
  1. In the sidebar, click System Controls → Groups.
  2. Click Actions at the top right, then New group.
    A window opens titled New group.
  3. Under Group name, type a name, e.g. Auditors.
  4. Leave Start from on Start from scratch. Copying another group would bring its edit permissions with it.
  5. Optionally, add a Description, e.g. External audit, read only.
  6. Click Create group.
    You see Created group “Auditors.” and the new group opens on the right. Its Permissions tab reads No permissions yet. Add some in Permissions.
  1. In the sidebar, click System Controls → Permissions.
  2. Type the first permission from the table below into Search permissions, then click it.
    Its details open on the right, under Who has this.
  3. Click Add group or person, then click your group under Groups.
    The group appears under Who has this.
  4. Click Done.
  5. Repeat steps 2–4 for each permission the auditor needs.
Permission What the auditor can then see
View entities Your entities, accounts, balances and asset pages: All Accounts, Balance Sheet and Entities
View outgoing transfers The payment list under Send Money and each payment’s details
View recurring payments Your recurring payment series under Recurring Payments
View contacts Your contacts and the accounts saved on them: Contacts and 3rd Party Accounts
View wallet verification Wallet verification history and the bypass log. Needs View contacts too

Add these only if the audit needs them:

Permission What it adds
View sensitive organization details Tax IDs and account numbers on your organization’s own records
View sensitive contact details Tax IDs, account numbers and other sensitive fields on contacts and their accounts
View team Who is in your organization
View groups Your groups and who belongs to each
View permissions Who holds which permission. Useful if they’re reviewing your access controls

With View contacts, View entities or View team, they can also open OFAC Screening.

Don’t add anything that starts with Manage, Propose, Start, Add, Install or Edit. Those let someone change things.

  1. When you’ve added them all, click Save changes in the bar at the bottom.
    A window opens titled Save these changes?, listing each change, e.g. Auditors added.
  2. Check the list, then click Save changes.
    The bar disappears. Each permission you changed now lists your group under Who has this.

Anything open to Everyone is held by every member, including your auditor.

  1. Stay on System Controls → Permissions and look down the list for rows showing Everyone.
  2. If a permission that changes things shows Everyone, click it and decide whether it should be limited to specific groups. Adding a group switches Everyone off. Then Save changes.
  1. In the sidebar, click System Controls → Our Team.
  2. Click Actions at the top right, then Invite Teammate.
    A window opens titled Invite Teammate to Workspace.
  3. Under Email, type the auditor’s email address.
  4. Under Add to groups, click your auditors group only. Don’t pick Finance, Operations or Legal. By default each of those can change things.
  5. Click Continue, check the summary, then click Send invitations.
    The window changes to Invitations Sent. The auditor appears on the Invites tab as Pending.

The auditor accepts the same way as any invitee. You can forward them Part B of Invite teammates. Their link works for 3 days.

  1. Once they’ve accepted, go to System Controls → Our Team and click the auditor’s row.
  2. Click the Permissions tab.
    You see every permission they hold. Each one shows your auditors group or Everyone as its source. Check there’s nothing you didn’t intend.

Go to System Controls → Groups, open your auditors group, and click the Members tab. Click the × next to the auditor and confirm with Remove Member. They lose everything the group gave them. They stay listed on Our Team, and keep anything open to Everyone.

  • Company files aren’t on the Permissions page. If the auditor needs your company documents, they can open Company Files, click Request Permission, and ask for View company files. You review the request in Requires Action.
  • Payment pages need the Approve Payments app. If your organization hasn’t installed it, Approve Payments shows as Not installed on the Permissions page, and its view permissions can’t be granted until it’s installed from the App Library.
You see Why What to do
New group is greyed out, with Only Owners and Admins can create groups You aren’t an Owner or Admin Ask an Owner or Admin to do this, or to add you to the Admin group
A message ending Maximum of 20 custom groups per organization reached Your organization already has 20 groups of its own Delete a group you no longer use, or reuse an existing view-only group
Copy from options are greyed out, with Only Owners and Admins can copy permissions from another group You don’t hold Edit permissions Use Start from scratch, which is what you want here anyway
Clicking Add group or person says You do not have permission to change who has… You don’t hold Edit permissions Ask an Owner or Admin
Those changes could not be saved. Try again. The save failed Click Save changes again
Your group isn’t offered under Groups in the picker It already holds that permission Nothing to do
The auditor sees You do not have permission to view… on a page The group doesn’t hold that page’s view permission Add it in Part B, or have the auditor click Request Permission and approve it in Requires Action
The auditor can open Send Money but not Bill Pay Bill Pay is where payments are created, so it needs Propose bill payments Nothing to do. Send Money lists the payments