If you have hesitated to hand a stranger access to your business bank accounts, good. That instinct is doing its job. Your books are connected to real money, real customer data, and often your Social Security number or EIN. Caution here is not paranoia, it is reasonable.
But it also should not stop you from getting your books cleaned up. The good news is that legitimate remote bookkeeping access looks nothing like handing someone the keys to your accounts. It is narrower, more structured, and more limited than most business owners assume.
Here is how it actually works, and what you should watch for.
How Legitimate Access Actually Works
When a bookkeeper needs to see your QuickBooks Online or Xero file, they do not ask for your username and password. They should not, and if they do, that is a red flag on its own.
Instead, both platforms have a built-in accountant-invite feature. You send an invitation to the bookkeeper’s own email address, they accept it, and they get their own separate login tied to their own credentials. Your login never changes hands. You can see exactly when they are in the file, and you can revoke their access at any time from your own account settings, instantly, without changing a single password.
The access itself is typically scoped, not full account control. In many cases it can be limited to specific areas of the file rather than opened up entirely, and it never grants the ability to move money.
Banks and card issuers work the same way. Most business banking platforms offer a view-only or read-only user role, separate from full online banking credentials, built specifically for accountants and bookkeepers who need to see transaction history and statements without being able to initiate a transfer or payment. If your bank offers this, it is worth using instead of sharing your actual banking login, even with someone you trust.
The pattern across all of it is the same: separate credentials, scoped visibility, and no ability to touch money. That is what a normal, professional bookkeeping engagement looks like.
What a Legitimate Bookkeeper Should Never Ask For
A few requests should stop you cold, no matter how reasonable the explanation sounds.
Your actual banking password. There is no bookkeeping task that requires it. If a bookkeeper asks for your online banking username and password directly, rather than requesting view-only access through your bank’s own accountant or read-only role, decline and ask for the alternative.
Your Social Security number over unencrypted email. Your bookkeeper may legitimately need your SSN or EIN at some point, most commonly for payroll or tax-related work. How it is collected matters. A plain email is not the way. It should come through a secure portal, a password-protected document, or a method your CPA or payroll provider already uses.
Permission to move money. This is the one that matters most. Bookkeeping is the work of recording and reconciling what has already happened in your accounts. It has nothing to do with initiating payments, transfers, or approvals. A bookkeeper does not need transaction or payment authority to categorize expenses and reconcile a bank statement, and asking for it is asking for more than the job requires.
If any of these come up, it is fair to pause the conversation and ask why.
Questions Worth Asking Before You Grant Access
A legitimate bookkeeper will have straightforward answers to all of these. If they don’t, or if the answers feel vague, that tells you something too.
- How is access structured? You want to hear about the accountant-invite feature or a read-only role, not a shared login.
- What happens to my access if the engagement ends? You should be able to revoke it yourself, immediately, from your own account. If the answer depends on the bookkeeper doing something on their end, that is worth clarifying.
- Is my data shared with anyone else? Ask directly whether your file is viewed by subcontractors, other staff, or third parties, and under what circumstances.
- Can I see when you are in the file? Both QuickBooks and Xero log accountant activity. You should be able to check it.
None of these are unusual or aggressive questions. A bookkeeper worth hiring will expect them and answer plainly.
Why Read-Only Access Is a Real Protection, Not Just a Reassurance
It is worth sitting with why this structure matters, beyond the fact that it sounds safer.
A properly scoped bookkeeping engagement means the bookkeeper genuinely cannot move your money, not because they have promised not to, but because the access they were given does not include that capability. If a login were somehow compromised, or if something in the engagement went sideways, there is no transaction to authorize because that permission was never granted in the first place.
That is a meaningful difference from trust alone. Trust is necessary in any working relationship, but it should not be the only thing standing between your bank account and someone with access to it. The structure of the access itself should be doing real work, so that the worst-case scenario is limited by design rather than by good intentions.
This is also, frankly, in your bookkeeper’s interest as much as yours. Nobody doing this work well wants transaction authority over a client’s accounts. It is unnecessary risk for them and unnecessary exposure for you. The engagements that work well are the ones where the scope of access matches the scope of the job.
Bringing This Up on a Call
You do not need to feel awkward asking about any of this. Any bookkeeper who has done this work for a while has answered these questions before, and a firm that works entirely remotely should be able to walk you through exactly how access is granted, scoped, and revoked before you agree to anything.
Being cautious about who touches your financial accounts is not a barrier to working with a remote bookkeeper. It is exactly the conversation a good one wants to have with you.
Have questions about how access works before you commit to anything? Book a free consultation and ask us directly. We would rather you feel informed than just reassured.