Skip to main content

Free CRM for accountants & bookkeepersFree for two months (60-day trial) · no per-user fees

Team & capacity

Roles and Permissions: Control Who Sees Client Data

Give every team member exactly the access they need, and no more.

Built by a practising Chartered Accountant · Unlimited users · Free for 60 days

app.remindoo.co · Roles and permissions
  • Premier Books Consultancy
  • Cranleys Chartered Accountants
  • CJM Accountants
  • Towpath Accounting Solutions
  • Auditax International
  • RS

Quick answer

Roles and permissions let a firm control exactly which client records and functions each team member can see and edit, based on their role rather than trusting broad, shared access. This matters for confidentiality, GDPR compliance and reducing the risk of accidental changes, and is far easier to manage in one system than through scattered spreadsheet permissions.

What are roles and permissions and why do they matter for UK practices?

Roles and permissions determine exactly which client data and functions a given team member can see or change within your practice systems.

Many small firms operate on trust: everyone can see everything, because it's simpler to set up and the team is small enough to know each other. That works fine until the firm grows, a temporary contractor needs limited access, or a client insists on knowing exactly who can see their records.

Under UK GDPR, firms are expected to apply appropriate access controls to personal data, which includes client financial information. Broad, undifferentiated access across the whole team is harder to justify and harder to audit than a system where access is tied to role.

Why do most firms give everyone broad access by default?

It's the path of least resistance

Setting up individual permissions takes a bit of upfront thought, so many firms default to giving everyone full access rather than deciding deliberately who needs what.

Spreadsheets don't really support restricted access

Shared spreadsheets and drives are difficult to lock down selectively, so firms relying on them often end up with all-or-nothing access by necessity.

Junior staff and contractors see everything

New joiners, part-time staff or outsourced contractors often get the same access as a partner simply because nobody set up anything more limited.

Leavers retain access for too long

Without a proper process, former staff can retain access to client systems well after they've left, which is a clear data protection risk.

What does poor access control cost an accounting firm?

Beyond the confidentiality risk, poor access control makes it harder to investigate mistakes, and raises questions in a client or regulatory conversation about who could have seen sensitive data.

If every team member can edit every client record, an accidental change is harder to trace, and a client asking who has access to their file doesn't have a clean answer. That's an uncomfortable position in a regulated profession that handles sensitive financial and personal information.

It also complicates onboarding contractors or part-time staff, since firms without proper role controls tend to either restrict them from the system entirely (losing efficiency) or grant full access anyway (increasing risk).

How do you set up roles and permissions properly? Step by step

  1. 1

    List the roles in your practice

    Partner, manager, senior, junior, payroll specialist, contractor — write down the actual roles that exist, rather than assuming everyone needs the same access.

  2. 2

    Decide what each role genuinely needs

    Be specific: does a junior need to see every client's full financial history, or only the ones they're actively working on?

  3. 3

    Apply the principle of least access

    Grant the minimum access needed to do the job, and expand it deliberately if a genuine need arises, rather than starting broad and never narrowing it.

  4. 4

    Set permissions per role, not per person

    Assigning permissions to a role rather than individually makes it far easier to onboard new staff consistently and adjust access as people change roles.

  5. 5

    Review access when someone changes role or leaves

    Build a simple checklist into your leaver and role-change process so access is updated the same day, not weeks later.

  6. 6

    Audit access periodically

    Once or twice a year, review who has access to what and check it still matches their current role and responsibilities.

  7. 7

    Document the policy

    A short written policy on who gets what access and why is useful evidence of good practice if a client or regulator ever asks.

How does Remindoo help control who sees client data?

Remindoo's roles and permissions let you define exactly what each team member can see and edit, based on their role rather than giving everyone the same broad access by default. This works alongside teams and team leads, so a payroll bureau team or a specific office can be scoped to only the client data relevant to their work. Centralised client information means access is controlled in one place rather than scattered across spreadsheets and shared drives that are difficult to lock down selectively. Because Remindoo is unlimited users, you can add contractors or part-time staff with genuinely limited access rather than either excluding them from the system or granting full access out of convenience. This makes it straightforward to apply the principle of least access consistently as the practice grows.

Spreadsheets vs Remindoo: what changes?

AreaSpreadsheets & emailWith Remindoo
Default access levelBroad, everyone sees everythingSet by role, minimum needed
Contractors and part-time staffFull access or none at allAccess scoped to their specific work
Leaver processAd hoc, sometimes delayedAccess removed with the role change
Auditing accessHard to establish who can see whatClear record by role and permission
Client confidenceCannot confirm who has accessClear, role-based access to point to
Managing this at scaleGets harder as staff numbers growRoles apply consistently as the team grows

See it with your own clients

A 30-minute walkthrough using your services and deadlines.

Book a Demo

Is access control a GDPR requirement?

UK GDPR expects appropriate technical and organisational measures to protect personal data, and access control is one of the clearest ways to demonstrate that.

The ICO doesn't mandate a specific access model, but firms are expected to limit access to personal data to those who need it for their role. Role-based permissions are a straightforward, demonstrable way to meet that expectation, and to answer a client or regulator's question about who can see their data.

“Automated reminders and task templates save countless hours each week.”
Shaz Israr, Director, BNW Accountants

Frequently asked questions

Do small firms really need role-based access?

Even a two or three-person practice benefits, particularly once part-time staff, contractors or bookkeeping support are involved, since it's easier to set boundaries early than to retrofit them later.

Does this replace a data protection policy?

No, role-based access is one practical control that supports a wider data protection policy; it doesn't replace the need for a documented approach to handling personal data generally.

How quickly should access be removed when someone leaves?

Ideally the same day their employment ends, which is why building it into a standard leaver checklist matters more than remembering it case by case.

Can permissions be set at team level as well as individually?

Yes, combining teams with roles lets you scope access both by group (such as an office or specialism) and by individual responsibility.

Is this covered in the free trial?

Yes, roles and permissions are available to configure during Remindoo's 60-day free trial, so you can set up your access structure before deciding to continue.

Does restricting access slow the team down?

Not if roles are set up sensibly — the aim is removing unnecessary access, not blocking staff from the client data they actually need for their work.

Ready to run a calmer practice?

See Remindoo with your own clients, or start free for 60 days with unlimited users.

Sources

Comparing options? Read our guide to accounting practice management software.

Last updated: . General guidance, not regulatory advice. Check with your professional body.

Why knowing what each employee is working on matters

In a growing practice, the partner can no longer hold every job in their head. Clear ownership and visible workload are what stop deadlines slipping when someone is on leave, busy or new.

Clear ownership

Every client and task has a named person, so nothing sits unassigned and clients get consistent answers.

Balanced workload

Seeing tasks per person helps managers move work before one person is overloaded and another is waiting.

Cover for absence

When work, notes and history live in one system, a colleague can pick up a job without starting from scratch.

Controlled access

Roles and permissions keep sensitive client and AML data visible only to people who need it.

Practical tips from UK practice

  • Group people into teams around services or client portfolios, and name a Team Lead for each.
  • Review the employee task breakdown weekly, not only when a deadline is missed.
  • Give new starters a limited role first, then widen access as they are trained.
  • Use bulk reassignment when someone leaves or goes on holiday, rather than moving tasks one by one.

Written and reviewed by Waqas Sagar ACA FCCA FMAAT, Chartered Accountant with 18+ years in practice. Founder and MD of Accotax, an ICAEW, ACCA and AAT regulated London practice that has served over 5,000 clients, and founder of Remindoo. Guidance is general; check current GOV.UK and professional body guidance for your firm.

What UK practices say about Remindoo

Read all reviews on Trustpilot
“With Remindoo, everything from the first enquiry to onboarding and ongoing client management is tracked in one place… It saves us hours and gives me, as a practice owner, complete visibility of where the firm stands.”
Shaz Israr
“The biggest benefit is having clients, tasks, deadlines, workflows, proposals and communication all organised in one place.”
Taxaccolega Chartered Accountants
“During my trial, the team were absolutely amazing. They helped onboard my clients, set up my settings and made sure everything was ready for me to use… they made the whole process completely stress-free.”
Afia Begum
“It brings client information, tasks, recurring deadlines, workflows and reminders together in one place, giving us much better visibility across the team.”
Premier Books Consultancy Ltd

Trusted by firms regulated by the following professional bodies