---
id: KB-ET-008
url: https://app.codecontract.io/help/your-workspace/inviting-an-outsider-into-your-account
idioma: en
categoria: espacio-de-trabajo
subcategoria: cuenta
audiencia: usuario
nivel: intermedio
actualizado: 2026-08-13
tambienEn: [es]
relacionados: [KB-ET-005, KB-AD-002]
citadoPor: [KB-CL-001, KB-CL-008]
---

# Inviting someone from outside

_Accountants, auditors and advisers: what to give them and what not to._

**Responde a:** give my accountant access · invite an external auditor · temporary access for a collaborator · share with someone outside the company

Sooner or later someone outside needs to see something: the accountants, an auditor, a lawyer, a one-off collaborator. The temptation is to make them an administrator so they stop asking; it is also the costliest mistake.

## What to give them, by role

| Who | What they need | What they do NOT need |
| --- | --- | --- |
| Accountants or advisers | Read access to their scope, and downloads | Creating processes, deleting, seeing other clients |
| Auditor | Read access limited to the audited scope | Anything more, and only for a limited time |
| Lawyer | The specific case for the matter | The rest of the organisation |
| One-off collaborator | The team or project they work on | Organisation settings |

## Three rules

- Never administrator. An outsider must not be able to change your permissions or settings.
- Scoped to their part, not everything. "Read-only" across the whole organisation is still too much.
- With an end date. When the engagement finishes, access goes that day, not when someone remembers.

> [!IMPORTANT]
> If you hold documentation for clients who compete with each other, a badly scoped external access is not an internal slip: it is a third party's information seen by someone they never authorised.

> [!NOTE]
> Scoped read access usually beats emailing the documents: it leaves no loose copies and it records what was looked at and when.

> [!WARNING]
> Review external accesses once a quarter. They are the most forgotten because they are not part of your team and nobody misses them.

**Can I grant access for a few days only?**

Yes, and it is recommended for audits.

**Does an external user consume anything?**

Viewing and downloading do not consume.

**Do they know I am watching?**

Their accesses are logged like anyone else's; it is not surveillance, it is the same treatment.

## Ejemplos

**A company gives its accountants administrator access to avoid emailing documents.**

- Changes it to read access scoped to tax matters
- Reviews external accesses each quarter

→ The accountants work exactly as before and can no longer change the company's configuration.

**Somebody who only had to provide one paper is invited as a user.**

- Sends them a link instead of an invitation

→ No licence is consumed for a one-off contribution.

**An external party needs to see several files for months.**

- Grants limited access to what they need

→ They work without seeing the rest.

**The external party finishes and their access stays active.**

- Revokes access on completion

→ Access reflects who is collaborating today.

**Nobody knows which external parties have access.**

- Checks the list of external access

→ The picture exists without asking.

**An external party asks for more access than they need.**

- Grants the minimum for their task

→ The scope matches the work.
