Invite an Accountant using a link
Give one Accountant access to a Workspace using a secure invitation link.
Before you begin
- You must be the Workspace Owner.
- Know the Accountant's exact sign-in email address.
- A Workspace may have only one active Accountant.
Create the invitation
- Open Settings > My Accountant.
- Enter the Accountant's email address.
- Choose a permission:
- View only allows Workspace reading.
- Can edit transactions allows supported operational transaction changes.
- Select Invite.
- Select Copy Invite Link.
- Send the copied link to the Accountant using your own communication method.
xBoox currently generates the link but does not send an invitation email.
Accountant acceptance
The Accountant opens the link, reviews the Workspace, invited email, permission, and expiry, then signs in with the invited verified email and accepts.
An invitation cannot be accepted with a different email address. The Accountant must also have a valid Auth0 session and verified email.
If the invitation page says that a different account is signed in, compare Currently signed in with Invitation sent to. Select Switch Account, then choose the exact invited email address. xBoox preserves the invitation URL through the secure sign-in redirect, so the Accountant returns to the same invitation after authentication.
If the Owner needs to remain signed in at the same time, open the invitation in a separate browser profile, private window, or another browser. This keeps the Owner and Accountant authentication sessions separate.
After acceptance, the invitation link is no longer required. The Accountant can sign in directly with the invited verified email. xBoox discovers the active Workspace membership and loads the permitted workspace data. A View only Accountant can review Banking, Bank Transactions, Expenses, Income, and Reports, but cannot use owner-only Accounting or Settings actions.
Expiry and refresh
Invitation links expire after seven days. While an invitation is pending, the Owner can refresh it to generate a new link valid for another seven days. Send the new link because the prior token is replaced.
The seven-day expiry controls acceptance of a pending invitation. It does not expire an already active Accountant membership. The Owner must use Revoke Access to end accepted access.
Replace or revoke
- A pending invitation may be replaced.
- The Owner may revoke a pending invitation or active Accountant access.
- To invite a different Accountant when one is active, revoke the existing access first.
When Revoke Access succeeds, the Accountant immediately loses backend access to the Workspace. If the Accountant already has the Workspace open, xBoox checks access again when that page regains focus and periodically while it remains open. The old Workspace is then cleared from the Accountant's browser, normally immediately on return to the tab and within approximately 30 seconds while the tab stays visible. Revocation does not sign the person out of every Auth0 or xBoox Workspace they may legitimately use.
Sign-in activity
My Accountant shows two security-awareness timestamps:
- Your Previous Sign-In is the Workspace Owner's preceding recorded xBoox sign-in.
- Accountant Last Sign-In is the most recently active or revoked
Accountant's latest recorded xBoox sign-in. Revoking access does not erase this security history.
New timestamp tracking begins with the first successful sign-in after this feature is available. Not recorded yet does not mean the account has never been used; it means xBoox does not yet have two recorded Owner sign-ins or a recorded Accountant sign-in for the new tracking field.
Permission boundary
View Only and transaction-edit behavior are enforced by the backend. Structural actions such as Workspace, Category, tax, Business Profile, Accountant Access, Bank Rule, and Journal Entry changes remain Owner-controlled in the current implementation.
For View Only access, operational buttons keep their original action labels so the Accountant can understand the workflow. Buttons such as Post, Undo, and Save Changes appear in a gray disabled state and cannot submit a change. Their disabled appearance is informational; backend permission checks remain authoritative.
The final boundary for certain advanced Year End Review and controlled-posting actions remains a pending product decision; this article does not make a permanent promise for those actions.
Troubleshooting
The link expired
Ask the Workspace Owner to refresh the pending invitation and send the new link.
The invitation email does not match
Sign out and use the exact verified email shown on the invitation, or ask the Owner to replace the invitation with the correct address.
Another Accountant is active
The Owner must revoke the current Accountant before inviting a replacement.
Revoke Access reports an error
The Accountant being signed in on another browser does not prevent revocation. Refresh My Accountant once and try again. If the error remains, do not send a new invitation; contact Support with the Workspace name and approximate time of the failed revoke so the access record and Audit Log can be checked.