People and access

Your account

Your books are yours, and access to them is explicit: nobody sees a company's books unless they were given that company, at a level you chose.

Inviting someone

In a company's Books Settings, under Access, press Invite your accountant or bookkeeper. Type their email address and press Continue: if they already use the platform we recognise them and they keep the password they have; if not, give their name and we create their sign-in and a link for them to set their own password. They land only in what you granted. An invitation that was never accepted can be withdrawn at any time.

Roles that match real life

Per company, pick the role that fits the person:

  • Accountant (free, no seat): reviews everything, asks you for receipts, suggests corrections for you to approve and prepares the tax lines. Changes no money on their own.
  • Bookkeeper (uses a paid seat): does the bookkeeping - bank lines, entries, invoices, bills, reconciliations. Cannot change who else gets in.
  • Viewer (free, no seat): looks, prints and exports - a banker, an investor, a family member. Changes nothing.
  • Partner (uses a paid seat): everything, including deciding who else gets in - a co-owner.

Each role is one access level, shown under its name, and you can change it from the access list at any time. The books and nothing else, ticked by default for an accountant or bookkeeper, keeps them inside the books: no dashboard, sales, payroll or any other page. Access ends stops their sign-in after a day you choose; it is set on their sign-in, so it ends every company in the account they were given, and the list says Access ended once the day has passed (they stop using a seat then too).

Someone who only adds documents

Somebody who brings in your mail, or drops off receipts, can file paper into a company without seeing its books. In the invite window pick Adds documents only (free, never a seat). Their sign-in opens the scanner and nothing else: they choose the company and what kind of paper it is, take the picture, and see a short list of what they added themselves - never the books, the documents or anyone's money. What they add waits for you in Needs review.

It is a permission on its own, not a role: a person who already has a role here can be given it too, by inviting their email the same way. Everyone who holds it is listed under Can add documents on the access card, where Remove takes it away at once and New invite link sends a fresh sign-in link. Giving a documents-only person a role later opens the books to them in the ordinary way.

The accountant's manual walks your accountant through what their role lets them do. Revoking access takes effect immediately, and what they did while they had it stays in the history, attributed to them by name.

One person, one session

An account can require that each sign-in is the only live one: signing in on a second computer signs the first one out. It is the simplest honest guard against a password being quietly shared, and it is on by default.

Signing in with Google

If your sign-in email is a Google account, you can connect it once and skip the password from then on. The first time you press Sign in with Google, we ask for your password one time to prove the account is yours; after that, Google alone signs you in. Your email and password keep working exactly as before - connecting Google adds a door, it never closes one. You can see and disconnect connected sign-ins any time from Preferences.

You can also sign up with Google in the first place: press the Google button at the top of the signup form and your books open right away - no confirmation email to wait for, and no password at all. Google is your one way in, so the connection cannot be removed until you add another (for example by setting a password later). If your address already signs in here, the same button simply signs you in.

A way back in: your recovery email

From Preferences, add a recovery email: a second address, different from the one you sign in with, used only if you ever lose access to your sign-in mailbox. It is not a login - it is where the way-back-in email goes. It starts working after you click the confirmation link we send there, and we notify your sign-in address whenever it changes.

If you are locked out of your sign-in mailbox, use Forgot password and choose to have the link sent to your recovery email instead.

When the mailbox itself is lost

If the sign-in mailbox is gone for good, an Owner on your account can change your sign-in email from Users & Access - pick the user, press Change email, type the new address. Nothing happens immediately: the old address (and the recovery email, if confirmed) gets a letter saying what will change and when, the change waits about three days, and one click from either letter stops it. The pending change shows on the user's card, where an Owner can also stop it.

If no other Owner can help, contact support - the same careful process runs there, with identity checks first. While a support-led recovery is being reviewed, the account's full export is paused as a safety measure; it comes back the moment the recovery resolves.

Two-step sign-in

After your password, a second proof that it is you: something you hold, not something you know. A stolen password alone then opens nothing.

  • An authenticator app on your phone shows six digits that change every thirty seconds. Google Authenticator, Microsoft Authenticator, Authy and 1Password all work, they are free, and nothing is ever sent to you: the app and kBooks share one key, made when you scan the QR code.
  • A passkey uses your face, fingerprint or device PIN through the device itself. Nothing to type, and it cannot be phished.
  • Recovery codes are shown once when you turn two-step on. Each works once, typed where the six digits go, if you ever lose your phone. Keep them away from the phone; make a new set any time, which retires the old.

Turn it on under My preferences, or on the phone under Security. On the sign-in screen you can trust a browser for a while so a device that is yours is not asked every time; forget every browser if one is lost. An account owner can require two-step for everyone from Users & Access, in which case anyone who has not set it up is walked through it at their next sign-in, before anything else opens.

Watching the door

The user menu's Recent sign-ins shows every sign-in to your account: who, when, from where, including the failed attempts. If something there surprises you, change your password and review who holds access; both are two clicks from the same menu.

Letting support look

Nobody at kBooks can open your books on their own. When you ask support for help and they need to see what you see, you let them in, for a set time, from Plan > Support access:

  1. Pick the companies support may look at (All and None help with a long list).
  2. Pick how long: 1 day, 3 days or 7 days.
  3. Optionally say what to look at, then press Let support look.

Support can only look: they cannot add, change or delete anything, whatever else is set. They must type a reason every time they open your books, and the list under the card shows every time support was let in, every time they looked, who it was and why. It prints and downloads like any other list.

Press End now to end it early; anyone from support who is looking is signed out at once. When the time runs out it ends by itself. Support sees only the companies you picked, never your Plan, your people or your other companies, and never counts as one of your paid users.