---
id: KB-AD-011
url: https://app.codecontract.io/help/administration/giving-access-to-someone-outside
idioma: en
categoria: administracion
audiencia: administrador
nivel: intermedio
actualizado: 2026-08-13
tambienEn: [es]
relacionados: [KB-AD-006, KB-IC-010]
citadoPor: [KB-AD-014, KB-ET-016, KB-AD-017]
---

# Giving access to someone outside

_Your accountant, an auditor or a client who wants to look: scoped access with an end date._

**Responde a:** give my accountant access · access for an external auditor · sharing with someone outside the team · invite an outsider without giving everything

Sooner or later someone outside needs in: the accountant, an auditor, the client who wants to see their file, the lawyer handling a matter. The temptation is to email the files or hand out an ordinary account. Both end badly.

## The three ways, and when to use each

| Way | When | What it leaves |
| --- | --- | --- |
| Sending the files | A one-off, small delivery | Nothing: outside here there is no control and no record |
| Scoped, time-limited access | Accountant, auditor, collaborator | A record of what they saw and when, plus an expiry |
| The recipient portal | A client or supplier who only sees their own | They see their part without entering the organisation |

> [!IMPORTANT]
> The third is the most overlooked. A supplier or client does not need an account in your organisation to see and sign their own: they reach their document by their link and see nothing else, with nothing for you to administer.

## If real access is needed

1. **Their own account, never a shared one** — If three people at the firm log in with the same credentials, the record stops meaning anything.
2. **The lowest permission that works** — Almost always read-only. Start there and widen if needed.
3. **Scoped to their remit** — A quality auditor has no business seeing payroll or invoicing.
4. **And a review date in the calendar** — External access lingers for years. Set the reminder yourselves.

> [!WARNING]
> The real risk is not that they do something improper: it is that access stays alive after the relationship ended. Review the outsider list twice a year; there is almost always someone left over.

## When it ends

**En corto**

- Access is withdrawn the day the engagement ends, not when someone remembers.
- The record of what they saw remains, and is not erased by withdrawal.
- And if they return next year, grant it again: cheaper than leaving it open.

> [!NOTE]
> Everything an outsider does lands in the activity log exactly like anyone on the team. That is the main difference from emailing files: you can answer "who saw this?" a year later.

**Do they count as a team member?**

They take a seat like any user; what changes is what they see, not how they log in.

**Can they download?**

Depending on the permission you grant. Assume anything visible can be copied.

**Is it right for a client following their case?**

The portal is usually enough there, with no account at all.

## Ejemplos

**A company emails its invoices to the accountancy firm every month.**

- Grants scoped read access to invoicing with an annual review
- Withdraws it when changing firms

→ Documents stop circulating by email and there is a record of what was consulted and when.

**Full access is granted to an occasional external party.**

- Grants access only to what they need

→ They see theirs and nothing more.

**The external party finishes and their access stays active.**

- Revokes access on completion

→ Access reflects who is collaborating today.

**Somebody who only provides one paper is invited as a user.**

- Sends them a link

→ No licence is consumed.

**Nobody knows which external parties have access.**

- Checks the list of external access

→ The picture exists without asking.

**The external party asks for more access than planned.**

- Extends only what is justified

→ The scope stays matched to the work.
