Xero has changed how user roles and permissions are presented, giving business owners greater control over who can view, edit and approve financial information. While the update offers clearer, more tailored access, it also increases the risk of sensitive data being exposed if permissions are not reviewed carefully.
Some Xero permission names have been updated. For example, the previous “Advisor” role has been renamed “Administrator”. Xero describes Administrators as having full access to all areas of Xero, unless they are not the subscriber, in which case they cannot change the pricing plan or payment details.
It is important to note that these name changes do not automatically mean existing users have been given different access. Existing users retain the same level of access they had before the name changes. The updated permission names and role table are most relevant when inviting new users or changing access moving forward.
Administrator and Standard users have broad access across key areas such as bank accounts, contacts, files, fixed assets, payroll, purchases, sales and settings, while more limited roles such as Sales, Purchases, Sales and purchases, Draft sales and purchases, and Viewer provide narrower access depending on the area.
The main benefit of the updated permissions structure is control.
For businesses with multiple staff, external bookkeepers, accountants, payroll administrators or department managers using Xero, permissions can help make sure each person has access to the information they need, without giving unnecessary access to sensitive data.
Xero recommends that each invited user has their own login details, rather than sharing logins, because shared access can create unreliable audit trails and make it difficult to see who entered or changed transactions.
While more granular permissions can be helpful, they can also create risk if they are not set up correctly.
If a user is given more access than they need, they may be able to view sensitive information such as payroll, bank transactions, reports or supplier details. In some cases, they may also be able to edit, approve or process transactions that sit outside their role.
This is particularly important with higher-access roles such as Administrator, who have full access to all areas of Xero. That means business owners should be careful when assigning this role, especially to staff or external users who may not need full visibility across the entire file.
A permission review is a good idea if:
It is also worth reviewing access before adding any new staff member, bookkeeper, accountant or external advisor to your Xero file.
The best approach is to give each user the access they need to do their job, and nothing more. Think about what the person needs to view, what they need to edit, and whether they should have approval authority over transactions, payroll, expenses or reporting.
If you are unsure about adding staff, changing permissions or inviting an external user into your Xero file, it is worth getting advice before making the change.
Incorrect permissions can create unnecessary risk, but the right setup can help protect sensitive information, improve accountability and make day-to-day financial management much smoother.
At Cutcher & Neale, we can help review your Xero users and advise on the most appropriate access levels for your team, your advisors and your internal processes.
If you are unsure whether someone should have access to your Xero file, or which permission level is most appropriate, please reach out to our team before making changes.