Give an outside auditor view-only access
Goal
Let an auditor or outside bookkeeper see your accounts, payments and counterparties, without being able to change anything or move money.
How it works
You create a group that holds only view permissions, then invite the auditor into that group and nothing else. They see what the group can see. When the engagement ends, you take them out of the group.
Before you start
Section titled “Before you start”- You’re an Owner or Admin. Creating groups, changing permissions and inviting people all need that. (Who can use it)
- You have the auditor’s email address.
- You know what they need to see. The list in Part B covers a typical financial audit.
Part A: Create the group
Section titled “Part A: Create the group”- In the sidebar, click System Controls → Groups.
- Click Actions at the top right, then New group.A window opens titled New group.
- Under Group name, type a name, e.g.
Auditors
. - Leave Start from on Start from scratch. Copying another group would bring its edit permissions with it.
- Optionally, add a Description, e.g.
External audit, read only
. - Click Create group.You see
Created group “Auditors
.” and the new group opens on the right. Its Permissions tab readsNo permissions yet. Add some in Permissions.
Part B: Give the group view permissions
Section titled “Part B: Give the group view permissions”- In the sidebar, click System Controls → Permissions.
- Type the first permission from the table below into Search permissions, then click it.Its details open on the right, under Who has this.
- Click Add group or person, then click your group under Groups.The group appears under Who has this.
- Click Done.
- Repeat steps 2–4 for each permission the auditor needs.
| Permission | What the auditor can then see |
|---|---|
| View entities | Your entities, accounts, balances and asset pages: All Accounts, Balance Sheet and Entities |
| View outgoing transfers | The payment list under Send Money and each payment’s details |
| View recurring payments | Your recurring payment series under Recurring Payments |
| View contacts | Your contacts and the accounts saved on them: Contacts and 3rd Party Accounts |
| View wallet verification | Wallet verification history and the bypass log. Needs View contacts too |
Add these only if the audit needs them:
| Permission | What it adds |
|---|---|
| View sensitive organization details | Tax IDs and account numbers on your organization’s own records |
| View sensitive contact details | Tax IDs, account numbers and other sensitive fields on contacts and their accounts |
| View team | Who is in your organization |
| View groups | Your groups and who belongs to each |
| View permissions | Who holds which permission. Useful if they’re reviewing your access controls |
With View contacts, View entities or View team, they can also open OFAC Screening.
Don’t add anything that starts with Manage, Propose, Start, Add, Install or Edit. Those let someone change things.
- When you’ve added them all, click Save changes in the bar at the bottom.A window opens titled Save these changes?, listing each change, e.g.
Auditors added
. - Check the list, then click Save changes.The bar disappears. Each permission you changed now lists your group under Who has this.
Part C: Check nothing broader applies
Section titled “Part C: Check nothing broader applies”Anything open to Everyone is held by every member, including your auditor.
- Stay on System Controls → Permissions and look down the list for rows showing Everyone.
- If a permission that changes things shows Everyone, click it and decide whether it should be limited to specific groups. Adding a group switches Everyone off. Then Save changes.
Part D: Invite the auditor
Section titled “Part D: Invite the auditor”- In the sidebar, click System Controls → Our Team.
- Click Actions at the top right, then Invite Teammate.A window opens titled Invite Teammate to Workspace.
- Under Email, type the auditor’s email address.
- Under Add to groups, click your auditors group only. Don’t pick Finance, Operations or Legal. By default each of those can change things.
- Click Continue, check the summary, then click Send invitations.The window changes to Invitations Sent. The auditor appears on the Invites tab as Pending.
The auditor accepts the same way as any invitee. You can forward them Part B of Invite teammates. Their link works for 3 days.
Part E: Confirm what they can do
Section titled “Part E: Confirm what they can do”- Once they’ve accepted, go to System Controls → Our Team and click the auditor’s row.
- Click the Permissions tab.You see every permission they hold. Each one shows your auditors group or Everyone as its source. Check there’s nothing you didn’t intend.
When the audit ends
Section titled “When the audit ends”Go to System Controls → Groups, open your auditors group, and click the Members tab. Click the × next to the auditor and confirm with Remove Member. They lose everything the group gave them. They stay listed on Our Team, and keep anything open to Everyone.
Good to know
Section titled “Good to know”- Company files aren’t on the Permissions page. If the auditor needs your company documents, they can open Company Files, click Request Permission, and ask for View company files. You review the request in Requires Action.
- Payment pages need the Approve Payments app. If your organization hasn’t installed it, Approve Payments shows as Not installed on the Permissions page, and its view permissions can’t be granted until it’s installed from the App Library.
If something goes wrong
Section titled “If something goes wrong”| You see | Why | What to do |
|---|---|---|
New group is greyed out, with Only Owners and Admins can create groups |
You aren’t an Owner or Admin | Ask an Owner or Admin to do this, or to add you to the Admin group |
A message ending Maximum of 20 custom groups per organization reached |
Your organization already has 20 groups of its own | Delete a group you no longer use, or reuse an existing view-only group |
Copy from options are greyed out, with Only Owners and Admins can copy permissions from another group |
You don’t hold Edit permissions | Use Start from scratch, which is what you want here anyway |
Clicking Add group or person says You do not have permission to change who has… |
You don’t hold Edit permissions | Ask an Owner or Admin |
Those changes could not be saved. Try again. |
The save failed | Click Save changes again |
| Your group isn’t offered under Groups in the picker | It already holds that permission | Nothing to do |
The auditor sees You do not have permission to view…on a page |
The group doesn’t hold that page’s view permission | Add it in Part B, or have the auditor click Request Permission and approve it in Requires Action |
| The auditor can open Send Money but not Bill Pay | Bill Pay is where payments are created, so it needs Propose bill payments | Nothing to do. Send Money lists the payments |