Saltar al contenido

Administration

Giving access to someone outside

Your accountant, an auditor or a client who wants to look: scoped access with an end date.

Updated on 13/08/2026

Sooner or later someone outside needs in: the accountant, an auditor, the client who wants to see their file, the lawyer handling a matter. The temptation is to email the files or hand out an ordinary account. Both end badly.

The three ways, and when to use each

WayWhenWhat it leaves
Sending the filesA one-off, small deliveryNothing: outside here there is no control and no record
Scoped, time-limited accessAccountant, auditor, collaboratorA record of what they saw and when, plus an expiry
The recipient portalA client or supplier who only sees their ownThey see their part without entering the organisation

Important

The third is the most overlooked. A supplier or client does not need an account in your organisation to see and sign their own: they reach their document by their link and see nothing else, with nothing for you to administer.

If real access is needed

  1. 1

    Their own account, never a shared one

    If three people at the firm log in with the same credentials, the record stops meaning anything.

  2. 2

    The lowest permission that works

    Almost always read-only. Start there and widen if needed.

  3. 3

    Scoped to their remit

    A quality auditor has no business seeing payroll or invoicing.

  4. 4

    And a review date in the calendar

    External access lingers for years. Set the reminder yourselves.

Watch out

The real risk is not that they do something improper: it is that access stays alive after the relationship ended. Review the outsider list twice a year; there is almost always someone left over.

When it ends

Worth knowing

Everything an outsider does lands in the activity log exactly like anyone on the team. That is the main difference from emailing files: you can answer "who saw this?" a year later.

Do they count as a team member?

They take a seat like any user; what changes is what they see, not how they log in.

Can they download?

Depending on the permission you grant. Assume anything visible can be copied.

Is it right for a client following their case?

The portal is usually enough there, with no account at all.

A real case

The situation

A company emails its invoices to the accountancy firm every month.

What you do

  1. Grants scoped read access to invoicing with an annual review
  2. Withdraws it when changing firms

What you get

Documents stop circulating by email and there is a record of what was consulted and when.

The situation

Full access is granted to an occasional external party.

What you do

  1. Grants access only to what they need

What you get

They see theirs and nothing more.

The situation

The external party finishes and their access stays active.

What you do

  1. Revokes access on completion

What you get

Access reflects who is collaborating today.

The situation

Somebody who only provides one paper is invited as a user.

What you do

  1. Sends them a link

What you get

No licence is consumed.

The situation

Nobody knows which external parties have access.

What you do

  1. Checks the list of external access

What you get

The picture exists without asking.

The situation

The external party asks for more access than planned.

What you do

  1. Extends only what is justified

What you get

The scope stays matched to the work.

This article answers

  • give my accountant access
  • access for an external auditor
  • sharing with someone outside the team
  • invite an outsider without giving everything