Accountant Access Overview
Accountant access lets a workspace owner give an external accountant the business and financial visibility they need without making them an Administrator or Manager.
Accountants sign in with their own Keito account. Access is granted separately by each client workspace, so the same accountant can work with several clients while each owner remains in control of their own workspace.
The accountant joins each client’s existing Business workspace. Accepting an invitation does not create a separate accountant subscription or trial.
Accountant access is currently available to selected Business workspaces during a controlled rollout. Contact Keito support if the option is not visible.
Choose the right level
Every accountant starts with one of two access profiles:
| Capability | Audit | Operational |
|---|---|---|
| View workspace business records and reports | Yes | Yes |
| View rates, costs, financial totals, and profitability | Yes | Yes |
| Download permitted business CSV/PDF files and attachments | Yes | Yes |
| Edit existing time and expenses | No | Optional owner grant |
| Approve time and expenses | No | Optional owner grant |
| Create and edit draft invoices | No | Optional owner grant |
| Send invoices, record payments, delete records, or run bulk imports | No | No |
| Use or configure integrations | No | No |
| Manage people, permissions, ownership, security, or subscriptions | No | No |
Choose Audit when the accountant only needs to inspect, reconcile, report, or download records. Choose Operational Accountant only when they need one or more of the three supported local actions.
Operational access does not automatically enable any action. The owner must turn on each grant separately.
What accountants can see
Both profiles can see workspace-wide business information covered by the workspace’s plan, including:
- clients, projects, tasks, time, expenses, invoices, and reports;
- billable rates, costs, totals, and profitability;
- ordinary uploaded receipts and invoice attachments; and
- permitted CSV and PDF downloads.
This visibility does not include integration settings, provider configuration, credentials, API keys, database backups, security administration, billing administration, or subscription controls.
Permanent safety boundaries
Accountant access is deliberately narrower than administrator access:
- An accountant cannot invite people, change roles, transfer ownership, or change another person’s permissions.
- An accountant cannot connect, reconnect, configure, or operate Xero, QuickBooks, Stripe, Slack, Basecamp, Jira, or another integration.
- An accountant cannot send invoices, record payments, delete records, create public links, or run imports.
- A previously issued browser session or machine credential does not override a later downgrade or revocation.
- If stored accountant permissions are inconsistent, Keito blocks access until the owner corrects them.
Operational grants apply only to local Keito records. If an affected record came from an integration, was previously synced, or can currently sync through an active connection, Keito blocks the change before saving and asks the owner to make it.
Accountant access versus other access types
| Access type | Best for | Scope |
|---|---|---|
| Accountant | External finance and bookkeeping work | Workspace-wide business visibility with fixed administrative and integration restrictions |
| Member | A teammate recording their own work | Their own work and assigned projects |
| Manager | A delivery lead responsible for selected people or projects | Assigned people/projects plus specific manager grants |
| Administrator | A trusted internal workspace administrator | Workspace-wide operational and administrative control |
| Client | A customer stakeholder | Selected client projects and client-facing information |
Do not make an accountant an Administrator just to provide financial visibility. Use the Accountant profile so the permanent restrictions remain enforced.