ObraLedger

Type to search.

Your accountant doesn't need your password

Most small businesses hand their accountant a login, and nobody ever decided to. Here is what that quietly costs you, and what you are giving up to avoid ten minutes of setup.

The ObraLedger team ·

Ask a few small businesses how their accountant gets into the books, and most of the answers involve a password. Usually the owner’s own, handed over in January and still working in November.

Nobody chose that. It’s what the software left them with, and because it works on day one, it never gets revisited until something forces it.

It costs you the answer to “who did this?”

Every entry made on a shared login carries the owner’s name. Including the ones the owner didn’t make.

That sounds like an accounting-department problem until the first time a figure looks wrong. You’re looking at a number you don’t recognize, on a record that says you put it there, eight months ago. Nobody is being dishonest. There is simply no longer a fact of the matter about who typed it, and no amount of asking around at this distance will recover one.

A year later that’s the only question you ever actually ask about access, and a shared password can never answer it. It couldn’t even in principle - it was the same password for everyone who used it.

It costs you any say in what they can touch

A login is all or nothing. The firm you hired to file one return can also edit payroll, delete an invoice and see what you pay yourself, because nobody ever built a way to say otherwise.

Most of the time that’s fine, right up until it isn’t: a junior at the firm who is new to your file, a temp covering January, a relationship that ends badly. You didn’t choose to extend that much trust. You just had no smaller unit to hand over than “everything”.

It costs you a clean ending

Ending a shared-login arrangement means changing your own password. Then the payment provider that used it, the bank feed, the thing your website signs in with, and whatever you’ve forgotten.

So it gets postponed. Which is how a firm you stopped working with two years ago still has a working route into your books, not through anybody’s bad intent, but because revoking it was a chore with no deadline attached.

What you’re avoiding is about ten minutes

Access you grant is not a complicated idea, and it undoes all three.

You invite the firm, or they ask and you approve - either side can start it. You say what they can reach, per area and per action, which is how “can see everything, can post nothing” becomes an ordinary arrangement rather than a special favor. Tighten it later and everyone already working in your books tightens with them, including whoever is mid-reconciliation this afternoon. Take it all back whenever you like, without touching a password of your own. And whatever you set, you can’t lock yourself out of your own company, which is the one thing you want to be true on the day an access change goes wrong.

Their staff is their business. What they can touch is yours

You don’t know which of their people is on your file, and choosing them was never your job. What you should get is the list: everyone at that firm who can open your books right now, by name.

That’s the right seam. Their hiring stays theirs. What any of those names can reach stays yours. A shared password gets this exactly backwards - you have no idea who is using it, and no way to treat one of them differently from another.

And taking access away doesn’t erase the work

The entries a firm posted are still the entries that happened. Ending the relationship closes the door; it doesn’t reach back and unpick the year.

That’s the point of doing it this way. You’re not protecting the books from your accountant. You’re making sure that in eighteen months, when somebody asks where a number came from, the system can still tell you.

Users, roles and companies walks through both sides of this, including what each role preset starts with, and the separate screen for a practice managing its own clients.