QuickBooks Enterprise lets the admin user assign role-based permissions across more than 115 individual activities, controlling exactly what each team member can see and do — set to None, Full, or Partial access per area. Set this up from Company > Users > Set Up Users and Roles, either using Intuit's predefined roles as a starting point or building fully custom roles from scratch. This is the primary tool for securing client data across a bookkeeping team with staff at different experience and trust levels.
Why Role-Based Permissions Matter for a Bookkeeping Team
A bookkeeping firm typically has staff with very different needs: senior staff who need full access to reconcile and adjust client books, junior staff who should be limited to specific data entry tasks, and sometimes external contractors or payroll specialists who need narrow, task-specific access. QuickBooks Enterprise is built to support this — Intuit's own documentation notes it offers more individual permission controls (over 115 distinct activities) than QuickBooks Pro or Premier, since it's specifically designed for larger teams with more complex access needs.
Setting Up Roles: Step by Step
Only the admin user of a company file can create and manage roles.
- Go to the Company menu, then select Users
- Select Set Up Users and Roles
- Enter the admin password, then select OK
- Select the Role List tab
From here, you have two paths: use a predefined role, or build a new one from scratch.
Using a Predefined Role
Intuit provides predefined roles as a starting point, covering common positions:
- On the Role List tab, select an existing role, then select Edit to review its permissions
- In the Area and Activities section, review each area of the accounts
- For each area, select None, Full, or Partial access
- Select OK to save
Important: Editing a predefined or existing role changes permissions for every user currently assigned to that role — if you need different access for a specific person, create a new role rather than editing a shared one.
Creating a Custom Role From Scratch
- On the Role List tab, select New
- Give the role a name and description — naming it based on its permission level (e.g., "Junior Bookkeeper — Data Entry Only") makes it easier to manage as your team grows
- In the Area and Activities section, go through each area of the accounts and select None, Full, or Partial access
- Select OK to save the new role
Adding Users and Assigning Roles
- Go to Company > Users > Set Up Users and Roles
- Enter the admin password
- Select the User List tab, then New
- Enter a username and optional password
- In the Available Roles section, select the appropriate role(s) for that user, then select Add
- Select OK
A single user can be assigned multiple roles if their responsibilities span more than one area — common for smaller firms where staff wear multiple hats.
Reviewing Existing Permissions
Before making changes, it's worth reviewing what's currently assigned:
- Go to Company > Users > Set Up Users and Roles
- Select the Role List tab, then View Permissions
- This generates a Permission Access by Roles report, showing exactly what each role can access across the file
Running this report periodically — not just when first setting up roles — helps catch permission creep, where a role has accumulated broader access over time than it actually needs.
Practical Role Structures for a Bookkeeping Firm
A few common structures worth considering as starting points, then adjusted to your specific team:
Senior Bookkeeper / Reviewer: Full access to most areas, including the ability to reconcile accounts, adjust journal entries, and review other staff's work.
Junior Bookkeeper / Data Entry: Partial access limited to specific transaction entry (bills, invoices, expense categorization) without access to bank reconciliation, payroll, or the ability to delete transactions.
Payroll Specialist: Access scoped specifically to payroll areas, without broader access to unrelated financial data — useful if payroll is handled by a specialist separate from general bookkeeping staff.
External Contractor / Temporary Access: Narrow, task-specific access granted for a defined period, reviewed and removed once the specific task is complete rather than left active indefinitely.
Securing Client Data: Beyond Just Role Setup
Role-based permissions are the core tool, but a few additional practices strengthen data security across a multi-client bookkeeping practice:
- Avoid shared logins. Each staff member should have their own user account, not a shared login — this preserves the audit trail role-based access is meant to provide
- Review roles when staff responsibilities change, not just when they're hired — a promotion or role shift should trigger a permissions review, not just an assumption that old access still fits
- Remove access promptly when someone leaves the firm or a specific client relationship ends, rather than letting inactive accounts linger with standing access
- Combine with QuickBooks File Manager's Password Vault (available in Accountant Edition) to manage credentials securely across your growing client file list
Frequently Asked Questions
Who can create and manage user roles in QuickBooks Enterprise?
Only the admin user of the company file can create, edit, and assign roles.
What's the difference between "Full" and "Partial" access in a role?
Full grants complete access to that specific area's functions; Partial allows limited access, letting you fine-tune exactly what a role can view or do within that area rather than an all-or-nothing setting.
Can one user have more than one role?
Yes — a user can be assigned multiple roles if their work spans more than one functional area.
How do I check what permissions a role currently has without changing anything?
Use the "View Permissions" option on the Role List tab, which generates a Permission Access by Roles report you can review without editing the role itself.
Bottom Line
- QuickBooks Enterprise supports role-based access across more than 115 individual activities, set to None, Full, or Partial per area.
- Only the admin can create and manage roles, via Company > Users > Set Up Users and Roles
- Creating distinct custom roles (rather than editing shared predefined ones) avoids unintentionally changing access for multiple staff at once.
- Periodically reviewing the Permission Access by Roles report catches permission creep before it becomes a security gap.
- For firms wanting to design role-based access for accounting teams that scales properly as staff and clients grow, getting the structure right from the start avoids a messy cleanup later.
- A specialist can help with securing client data in Enterprise by reviewing your current role setup for gaps or overly broad access you may not have noticed.
