Quickbooky

Accounting News

User Access & Permissions

QuickBooks Online Advanced custom roles: how access control is meant to work

QuickBooks Online Advanced users struggling with broad default user roles can fix it by building custom roles that limit access area by area.

COMMUNITY ISSUESQUICKBOOKY

Access control is a recurring pain point for QuickBooks Online Advanced subscribers. The complaint arrives the same way each time: the stock user roles are too blunt for a growing team. Someone gets near-total reach, or loses the ability to do routine work. The feature that resolves it, custom roles, is built into the Advanced tier, and it works once you know the exact path.

The symptom behind most complaints

Someone needs to reconcile the bank feed but must not see payroll. Another user should manage sales for one branch and nothing else. The built-in options, such as Company admin or Standard all access, cannot express either restriction. So whoever configures users hands over wide access and hopes for the best.

Two quirks add confusion. Some fields inside a role are read-only; the software includes them automatically for reference, and no setting removes them. Finer permissions, meaning View, Create, Edit, or Delete, exist only in selected areas of the product.

Custom roles work by area, not by trust

When you build a custom role, you decide which areas of the books the role can reach: banking, sales, payroll, expenses, reports, budgets, inventory. You do not have to start from an empty page. Predefined custom roles, such as Sales manager or Expense manager, give you a working base to adjust. The standard QuickBooks roles remain available if one of those fits after all.

Building a role from scratch

Open Settings and select Manage users. Switch to the Roles tab and select Add role. Enter a role name and a short description, then tick the areas this role may access. Select Save Role, and the role appears in your list, ready to assign. That is the entire workflow; the difficulty is deciding the scope, not finding the screens.

Can one role cover sales for a single location?

It can, and multi-location businesses lean on it. Set up your locations first if you have not, because the role builder reads them from company settings. Then repeat the basic steps: Settings, Manage users, Roles tab, Add role. Name the role, select Sales, and open the All locations dropdown. Pick one location or several, choose what the user can access within sales, and save. A person assigned this role handles sales transactions for the chosen locations only.

Giving a role to a new user

New staff still enter through the Users tab. Go to Settings, select Manage users, and open the Users tab. Select Add user and enter the person’s first name, last name, and email address. Under Assign roles, pick the role from the dropdown. Review the permissions listed, then select Send invite.

The invitee receives an email and follows it to sign in. Forgotten passwords are the user’s own to reset, which spares the admin a support chore. Nothing in the invite flow requires the administrator to handle credentials on the new user’s behalf.

Custom permissions at the invite screen

Sometimes you want to tune access for one person rather than maintain a saved role. At the Add user screen, select View all permissions under Assign roles. Set the custom permissions you want, review them, and select Send invite. The software then prompts you to name a custom role, because custom permissions must live inside one. Name it and continue.

This is the step that surprises people. What began as a one-off adjustment becomes a saved role, one you can assign again later or audit when questions come up. Treat it as a feature rather than a detour.

Limits to keep in mind

Read-only fields will stay in every role; they are included for your information and cannot be switched off. The granular View, Create, Edit, and Delete choices apply only where the product currently offers them. Elsewhere, access is granted or withheld at the level of the whole area. Custom roles belong to the Advanced tier of QuickBooks Online, so teams on lower plans will not find these screens at all.

Our read of the fix is simple: stop adjusting trust and start adjusting scope. Map what each person must touch, build a role that covers exactly that, and invite them into it. The tooling already sits inside the Advanced tier. Most of the frustration comes from not realizing the door is there, not from anything the software refuses to do.

← Back to Community Issues