Administration
Giving access to someone outside
Your accountant, an auditor or a client who wants to look: scoped access with an end date.
Sooner or later someone outside needs in: the accountant, an auditor, the client who wants to see their file, the lawyer handling a matter. The temptation is to email the files or hand out an ordinary account. Both end badly.
The three ways, and when to use each
| Way | When | What it leaves |
|---|---|---|
| Sending the files | A one-off, small delivery | Nothing: outside here there is no control and no record |
| Scoped, time-limited access | Accountant, auditor, collaborator | A record of what they saw and when, plus an expiry |
| The recipient portal | A client or supplier who only sees their own | They see their part without entering the organisation |
Important
The third is the most overlooked. A supplier or client does not need an account in your organisation to see and sign their own: they reach their document by their link and see nothing else, with nothing for you to administer.
If real access is needed
- 1
Their own account, never a shared one
If three people at the firm log in with the same credentials, the record stops meaning anything.
- 2
The lowest permission that works
Almost always read-only. Start there and widen if needed.
- 3
Scoped to their remit
A quality auditor has no business seeing payroll or invoicing.
- 4
And a review date in the calendar
External access lingers for years. Set the reminder yourselves.
Watch out
The real risk is not that they do something improper: it is that access stays alive after the relationship ended. Review the outsider list twice a year; there is almost always someone left over.
When it ends
Worth knowing
Everything an outsider does lands in the activity log exactly like anyone on the team. That is the main difference from emailing files: you can answer "who saw this?" a year later.
›Do they count as a team member?
They take a seat like any user; what changes is what they see, not how they log in.
›Can they download?
Depending on the permission you grant. Assume anything visible can be copied.
›Is it right for a client following their case?
The portal is usually enough there, with no account at all.
A real case
The situation
A company emails its invoices to the accountancy firm every month.
What you do
- Grants scoped read access to invoicing with an annual review
- Withdraws it when changing firms
What you get
Documents stop circulating by email and there is a record of what was consulted and when.
The situation
Full access is granted to an occasional external party.
What you do
- Grants access only to what they need
What you get
They see theirs and nothing more.
The situation
The external party finishes and their access stays active.
What you do
- Revokes access on completion
What you get
Access reflects who is collaborating today.
The situation
Somebody who only provides one paper is invited as a user.
What you do
- Sends them a link
What you get
No licence is consumed.
The situation
Nobody knows which external parties have access.
What you do
- Checks the list of external access
What you get
The picture exists without asking.
The situation
The external party asks for more access than planned.
What you do
- Extends only what is justified
What you get
The scope stays matched to the work.
This article answers
- give my accountant access
- access for an external auditor
- sharing with someone outside the team
- invite an outsider without giving everything