The safest setup is a separate, named login for your accountant with view-only or role-scoped permissions, instead of sharing your primary login. This lets them reconcile transactions and pull statements while you keep control of the password, payments, and account settings.
Sharing the primary login gives whoever's helping with the books more power than reconciliation requires, and it makes every action look like it came from you. That extra power is also unneeded for most reconciliation work. Most business banking platforms, Relay included, let you assign each accountant their own login with role-based permissions. Accounting software like QuickBooks Online and Xero can also pull a read-only bank feed when separate bank roles aren't available.
What secure accountant bank access should accomplish
Secure access lets your accountant see what they need while you keep the password and the power to move money. They can view transactions and pull statements for reconciliation while you keep control over payroll, operating cash, settings, and payments.
When one login does everything, the person reconciling last month's expenses also has the technical ability to send a wire. The audit trail gets messy because every action points back to the same credential.
The Association for Financial Professionals (AFP) 2025 payments fraud survey found that 79% of respondents reported their businesses were victims of attempted or actual payments fraud in 2024. Every extra credential is another way in, especially when that credential can do more than the person needs.
Before you grant access, confirm these four controls:
Your accountant uses a named login, so the audit log ties activity to a real person.
They see the transactions and statements they need without the ability to move money.
You can see what they accessed and when.
You can pull that access back instantly, without changing your own password.
If your current bank can't tick all four, that's the real gap to fix. Separation of duties matters more as your transaction volume grows. The person reviewing transactions should not also approve payments. Separate credentials and alerts, plus revocation controls, are also part of how you keep finances secure as more people touch the books.
Permission settings matter more than convenience
The permission level you assign determines whether accountant access stays secure. Sharing one login may feel easy, but it's the least secure choice. Scoping your accountant to exactly what their work requires takes a few more minutes and closes almost every gap.
Common permission levels
Give the minimum access that lets the work happen, and nothing more. A bookkeeper who reconciles monthly needs to read transactions and pull statements, so view-only access covers the job. An accountant who also runs bill pay needs a payment role, paired with approval controls.
Common permission levels usually fall into four buckets:
View or read-only: Sees transactions and statements, but can't move money. This fits most reconciliation and bookkeeping work.
Bill-pay or payment-initiator: Can queue or send payments. Use it only when the accountant handles disbursements, ideally with a second approval.
Administrator: Can add users and change settings. This is owner-level control that rarely belongs to an outside advisor.
Deposit-only: Can record or view deposits without broader access. This fits narrow, specific deposit tasks.
Start with the lowest permission level that lets the accountant do the work, then add more only when the role clearly requires it. Relay's advisor permissions follow this same logic: every advisor login is scoped to one of five roles—Read-only, Bill Payer, Manager, Administrator, or Super Administrator—so reconciliation access doesn't include the ability to send payments. Note that Administrator is Relay's default role when a firm invites a new client, so it's worth downgrading to Read-only or Bill Payer if the advisor only needs reconciliation access.
Handling full-access requests
When an accountant asks for "full access is easier," slow the decision down. Full access may make reconciliation faster, but it also gives the accountant permissions they may not need. Ask which task requires each permission before you approve the role. If the answer is "in case we need it later," leave the permission off and add it later if the work changes.
After you assign the role, turn on login and settings-change alerts before the accountant starts work. Those alerts are a basic part of online banking security while advisor access is active.
Set up separate logins or read-only feeds
Assign the accountant their own login through your bank's user settings, or connect a read-only bank feed through your accounting software. Authorized signer status works differently: it's a legal role with money-movement power, not a way to share visibility. The setup you choose should match the work, not the accountant's preference for convenience.
The three access pathways
Two options keep the accountant out of your primary login. One option gives far more power than most reconciliation work requires.
Bank portal sub-user: Your accountant gets a named login with a role you scope. This is the strongest option when your bank supports it. Relay is one example that gives every advisor their own login with role-based permissions, though not every bank offers granular roles.
Bank feed via accounting software: Connecting your bank to QuickBooks Online or Xero gives your accountant read-only transaction data with no bank-portal access. You can revoke the feed independently of your banking login. The tradeoff is that it shows transaction data, not the live portal.
Authorized signer: An authorized signer can move money and legally act on behalf of the business. Use this role only when the accountant genuinely needs that authority, and not as a shortcut for read-only access.
Choose the path that gives the accountant the narrowest workable access. If they need statements and transaction data, a sub-user or bank feed usually solves the problem. If they need to sign checks, approve transfers, or act for the business legally, put that authority in writing before you grant it.
When your bank lacks roles
If your bank doesn't support separate users, avoid turning that limitation into a shared-password habit. Start with the accounting software feed, then confirm whether the feed gives your accountant enough data for the close. If it doesn't include statements, download statements yourself and share them through your document tool instead of broadening bank access.
A missing role feature is also a useful signal. If you now need outside advisors, payment approvals, and a clean user history, your banking setup has to support more than one owner login. Business banking platforms with per-user role-based access make the safer setup easier to maintain. Relay was built for this, with named advisor logins, scoped permissions, and QuickBooks Online and Xero sync in the same place.
When to remove or update accountant access
Remove or update your accountant's access whenever the engagement changes, someone leaves, or a scheduled review comes due. Assign one person to manage accountant access, because a login granted for one reason can remain active after the work changes. Keep the user list on the same schedule as your other close-of-month controls so it gets reviewed regularly.
Review triggers
A handful of trigger events should prompt a review or removal:
The engagement ends or you terminate the accountant.
A staff member at the firm who had access leaves that firm.
You switch accounting firms.
You sell, merge, or restructure the business.
A scheduled quarterly review comes due, whether or not anything changed.
Quarterly reviews catch stale access before it becomes a liability. The login nobody remembered to pull after a project wrapped can sit open for months unless a scheduled review forces the check. A recurring review date removes the need for a specific reason to check access.
Review scope
Make the review practical. Open the user list, confirm each accountant still needs access, and compare the permission level against the work they do now. If a role changed from bill pay to reconciliation, reduce the permission instead of leaving it in place. Document the date, the person who reviewed it, and any changes made.
The review should also check whether access still belongs to the right person. If the accounting firm changes who handles your file, invite the new person under their own name and remove the old login. Don't let a shared firm inbox or generic advisor account become the workaround.
Review every system the accountant touched, including the bank. Over the life of an engagement, your accountant likely accumulated access across the bank, your accounting software, payroll, and the document-sharing tool you use to pass statements and receipts. Pulling their bank login while leaving payroll access active leaves the revocation unfinished.
Security checklist before you invite your accountant
A short checklist before you send an invite prevents the most common access mistakes. Treat it as the final check before month-end pressure turns into a shared-password workaround. It also gives you a record to use later, when you need to review or remove access.
Run through this before you grant access:
Use the invite tied to the accountant, not your own login.
Match the role to the work.
Turn on activity alerts for logins and setting changes.
Confirm which menu removes the access later.
Record the other systems you're opening, including accounting software and payroll, plus document sharing, so a future revocation is complete.
For each invite, write down the accountant's name, the firm, the permission level, and the reason for access. If the bank lets you add notes to the user record, use them. If not, keep the notes with your close checklist. The record should be findable later, so anyone asking who currently has access can get an answer quickly.
Use that list later to remove access from each system. Keep it with your close checklist so removing an advisor doesn't depend on memory.
Control accountant access on your terms
Accountant access starts with permissions you can scope, track, and revoke. Reconciliation needs visibility. Payment work needs a deliberate payment role, and every role needs a review date on the calendar.
Relay makes that easier to maintain with role-based advisor access and separate advisor logins that keep reconciliation out of your primary bank credentials.
Give the accountant only the access they need and review it on a set cadence. Make that routine easier by opening a Relay account that gives each advisor a role-based login across the checking accounts your plan supports, with QuickBooks Online and Xero sync so reconciliation never depends on your owner credentials.
Frequently asked questions
Should I give my accountant access to my bank account or send Portable Document Format (PDF) statements?
It depends on your transaction volume and how current your books need to be. If your accountant reconciles frequently and you have real transaction volume, view-only access is less work than exporting and emailing PDFs every close. If they only handle periodic, tax-focused work, exported statements may be enough.
Can my accountant move money if I give them access?
Only if you assign a permission level that allows it. View-only or read-only access lets your accountant see transactions and pull statements without any ability to move money. Money movement requires a payment or bill-pay role that you grant deliberately; visibility alone doesn't include it.
What if my bank doesn't offer separate logins for my accountant?
Connect a read-only bank feed through your accounting software, such as QuickBooks Online or Xero, which gives your accountant transaction data without any portal access. If the lack of user roles is a recurring problem, it's worth reconsidering whether your bank fits how you operate.
Is sharing my bank login with my accountant against the rules?
Often, yes. Sharing a primary login commonly violates your bank's terms of service, and it removes any audit trail because every action shows up as you. A named, scoped accountant login is the compliant path and keeps activity traceable.
How do I remove my accountant's access when the engagement ends?
Revoke access through the user-management settings on every system you gave them access to. That includes your bank, accounting software, payroll, and any document-sharing tools. Pulling one login while leaving others active is a partial revocation, so work from a list of every system they could access.





