QuickBooks Online User Management Constraints Trip Up Accountants
QuickBooks Online's Add and manage users workflow imposes role and character limits that catch users off guard when inviting across multiple companies.

QuickBooks Online’s redesigned user management screen promises one-stop provisioning across multiple companies, but accountants and admins regularly hit friction when the interface quietly blocks certain roles, rejects names with special characters, or refuses to edit time-tracking assignments after the fact.
Adding a Single User
The entry point lives under Settings > Manage users. Clicking Add user opens a form requesting the person’s name and email address. What the form does not tell you upfront is that it is picky about what characters it will accept. In the name field, only a standard period is permitted alongside letters — no hyphens, apostrophes, or accented characters. In the email field, only a period and the @ symbol pass validation. Anything else produces an error that, by community reports, is not always clearly tied back to the offending character.
After the name and email clear validation, the next step is role assignment via a dropdown. The system displays a summary of what each role grants access to, with expandable sections for finer detail. Certain roles also surface Account management settings — checkboxes that control whether the user can manage other users, billing, or subscription-level changes. Once everything looks right, Send invitation fires off an email inviting the user to accept access.
The Multi-Company Shortcut — and Its Limits
For firms managing several QuickBooks Online companies under a single sign-in, the Manage users page defaults to whichever entity you logged into. A Company access dropdown lets you select additional companies to add the user to simultaneously, and each selected company appears in a list where you assign a role individually.
A batch-action shortcut exists: check the boxes next to multiple companies, then use Assign role from the actions bar to apply the same role everywhere at once. This works well for firms onboarding a bookkeeper across a portfolio of clients where the access level is identical.
The catch is that multi-company invitations only support a subset of preset roles. Custom roles are not available in this flow. If you need to assign a user to a custom role — or to preset roles like project manager, sales manager, bill clerk, bill approver, bill payer, expense manager, payroll manager, or inventory manager — you must select the role from the dropdown next to each individual company on the list.
Time-Tracking Roles Require Extra Steps
Roles such as Track time only and Track time and submit expense claims cannot be assigned from the multi-company screen at all. To provision these, you must sign in to the specific company where the user needs access, add them there, and link their user record to an existing employee or vendor entry before sending the invitation. This requirement catches users off guard because the standard add-user flow does not prompt for the employee or vendor link — it only becomes apparent when the role selection fails or the invitation will not send.
Editing Existing Users — and the Wall You Hit
Changing a user’s role after they have been invited is straightforward in most cases. Open Manage users, find the person, click Edit in the Action column, and pick a new role from the dropdown. Account management settings can be adjusted at the same time.
The exception is time-tracking roles. Once a user is assigned a time-tracking role, that assignment is locked — the role dropdown is effectively read-only for that user. The only workaround is to delete the user entirely and re-add them from scratch with the correct role. There is no in-place edit path, and the community reports indicate this is by design rather than a bug.
Managing Permissions Per Company
For users who need different access levels across different companies, the Users and roles for dropdown lets you switch context to any company you manage. Within each company’s view, you can adjust the role independently.
A separate option — Manage consolidated view permissions — controls finer-grained access to list management and intercompany transactions. This screen lets you toggle view, create, edit, and delete permissions for those specific areas. Changes here save back to the main Edit screen, where a final Save commits everything.
What to Take Away
The user management interface is functional but carries enough conditional logic — character restrictions, role availability tied to the entry point, and the hard lock on time-tracking edits — that admins provisioning access for the first time should expect at least one round of trial and error. Planning role assignments before starting, and knowing which roles require signing into the individual company, saves a measurable amount of frustration.