Quick answer

QuickBooks Online user permissions are controlled by the role assigned to each email on your plan. Go to Settings, then Manage users, to invite someone, assign a standard role, or build a custom role in QuickBooks Online Advanced. Most "you don't have permission" messages trace back to the wrong role, an invitation that was never accepted, or a change that requires the user to sign out and back in.

What QuickBooks Online user roles control

Every email on your QuickBooks Online plan carries exactly one role, and that role decides what the person can see and do: which transactions they can enter, which reports they can open, whether they can reconcile, and whether they can manage other users. Standard roles cover most teams. Custom roles exist only in QuickBooks Online Advanced and Intuit Enterprise Suite, and they grant view, create, edit, delete, or approve rights inside specific areas such as banking, sales, expenses, and reports.

RoleBest forImportant limits
Primary admin / Company adminOwner or office managerFull access, including user management. Only the primary admin can change company info or reassign the primary admin.
Standard all accessTrusted staff who run the booksFull transactions, banking, reconciliation, and reports. No user or billing management.
In house accountantInternal bookkeeper or accountantBookkeeping, banking, and financial reports, plus undo of completed reconciliations. No payroll or user management.
BookkeeperDay-to-day data entrySales, expenses, bills, and lists. No Profit and loss, balance sheet, or cash flow reports, and no payroll.
Standard no accessField or shop staffCan submit timesheets and nothing else.
View reportsOwners or investors who only readAll reports except payroll and contact details, with no transaction access.

Symptoms of a QuickBooks Online permissions problem

  • The user sees "Sorry! You don't have permission to access this information. Ask your QuickBooks Online admin to fix your permission, and then try signing in again."
  • A menu item, button, or report is missing or grayed out, or the screen returns the user to the dashboard.
  • Part of the data is blank — for example, an expense list with no vendors when vendors exist.
  • The Manage users page still shows the person as Invited instead of Active.
  • On the mobile app, the user sees "Using QuickBooks Windows or Mac", which means the account only has time tracking or reports access.

Common causes of "you don't have permission" in QuickBooks Online

  1. The role does not include that feature. A Bookkeeper cannot view financial reports, and Standard no access cannot open transactions. Check the role before you assume a bug.
  2. The invitation was never accepted, or the wrong email is signed in. One person can own several Intuit accounts; signing in with a personal email instead of the invited work email produces the same error.
  3. The session is stale after a role change. QuickBooks applies permission changes on the next sign-in, not instantly in an open tab.
  4. Only a primary admin can do that task. Changing company details, transferring the primary admin role, and some billing actions are reserved for the primary admin even when the user is a company admin.
  5. A custom role has a gap. A custom role can grant a report but not the transactions behind it, or sales access limited to one location.
  6. The user is on the mobile app. The QuickBooks mobile app supports admin and Standard all access only. Every other role needs the web app.
  7. The plan limit is reached or the subscription is inactive. A canceled or expired subscription becomes read-only, and actions such as inviting an accountant stop working until you resubscribe.

Check the exact screen. Ask the user for a screenshot with the page name. The wording differs between a missing role permission, an unaccepted invite, and a mobile-app limitation, and each has a different fix.

Before you change anyone's access

  • You need primary admin or company admin access to open Settings → Manage users. If you cannot see that page, you are not an admin.
  • List the two or three tasks the person must perform, then choose the smallest role that covers them.
  • Check your user limit. Billable roles count toward your plan's user count; View reports, Track time only, and Expense submitter do not.
  • Allow about five minutes per user. Role changes take effect only after the user signs in again.

Plan note. QuickBooks Online Advanced allows unlimited users and custom roles. Simple Start, Essentials, and Plus have fixed user counts, so confirm your plan under Settings → Account and settings → Billing & subscription before you promise a seat.

How to set up users and fix permissions step by step

1

Confirm your admin access and user count

Go to Settings → Manage users. The Users tab lists everyone with their role and status. If Manage users is missing, ask the primary admin to grant you admin access first — a Standard all access user cannot manage roles.

2

Invite a new user and assign a role

On the Users tab, select Add user, then enter the person's name and work email. Open the Roles dropdown, pick the standard role that matches their job, review the feature list, and select Send invitation. Names accept periods but no other special characters, and the email field accepts only periods and the @ symbol.

The user receives an email and must select the Let's go! link to create or link an Intuit account.

3

Confirm the user accepted the invitation

Return to Manage users and check the status column. Invited means the email was never accepted — ask the user to check spam. Active means the account is live. If the user accepted but still cannot get in, work through the QuickBooks Online login loop fixes before changing the role.

4

Edit a role when access is too broad or too narrow

Find the user, select Edit in the Action column, and change the Roles dropdown. Adjust any account management settings, then select Save. Tell the user to sign out and back in before testing. Time tracking roles cannot be edited; delete the user and re-invite them with the correct role instead.

5

Build a custom role (QuickBooks Online Advanced)

Open Settings → Manage users and select the Roles tab, then Add role. Give it a clear name and description, choose access area by area — banking, sales, expenses, accounting, reports — and set the action level (view, create, edit, delete, approve, or all access). Select Save role. Assign it during an invite with View all permissions, or apply it to an existing user with Edit. Sales access can be limited to one location.

6

Fix "you don't have permission" at the exact screen

Ask which page fails and compare it to the user's role on the Manage users page. If the role is wrong, fix it in step 4 and have the user sign in again. If the role is right, confirm the person is in the correct company and Intuit account, and is using a browser rather than the mobile app. For tasks reserved for the primary admin, sign in as the primary admin or transfer the role in QuickBooks Online Accountant.

If the whole account is read-only, check the subscription status described in QuickBooks Online billing errors.

7

Invite your accountant through the Accounting firms tab

Open Manage users, select the Accounting firms tab, then Invite firm. Enter your accountant's email or the firm's user ID and save. With two-step verification on, enter the code you receive. Accountant users do not count toward your regular user limit. If the code never arrives, work through the two-step verification problems before resending the invitation.

Removing access is permanent. Deleting a user cannot be undone, and anyone still signed in on a device loses access at the next check. Cover their work first: reassign open reconciliations, export any reports they own, and confirm no scheduled payments depend on their login.

8

Remove a user without losing the audit trail

On the Users tab, select the ellipsis next to the person, choose Delete, then confirm with Delete user. The login is removed permanently, but the transaction history stays visible in the audit log. If you only want to stop paying for a seat, change the role to a non-billable one such as View reports instead. Before deleting a custom role, reassign every user who holds it.

Verify the change worked

  1. Confirm the person shows as Active with the role you intended on the Manage users page.
  2. Have them sign out completely, sign back in, and open the screen that failed before.
  3. Ask them to complete one real task — enter a bill, run the report, or start a reconciliation — and confirm it saves.
  4. Open Settings → Audit log and confirm their name appears against the action.

If access still fails

Test in a private browser window to rule out a cached session, and make sure the user is not signing in with a second Intuit account. Accountants sometimes need to open the company from QuickBooks Online Accountant rather than the direct URL. In-house staff who need to undo a reconciliation must hold the In house accountant role or higher — see reconciliation problems in QuickBooks Online. If the account is on a billing hold or a canceled trial, no permission change helps until the subscription is active; plan changes that move user limits are covered in QuickBooks Online plan changes.

Security best practices for QuickBooks Online users

  • Grant the least access that works. Use custom roles in Advanced, or the narrowest standard role, instead of making everyone an admin.
  • One login per person. Shared credentials destroy the audit trail and make offboarding impossible.
  • Keep a second admin. Two admins mean one departure never locks the company out.
  • Invite accountants through Accounting firms. It grants accountant tools without a shared admin login.
  • Lock closed periods. Set a closing date under Account and settings → Advanced so past transactions need a password to change.

Frequently asked questions

How many users can I add to QuickBooks Online?

It depends on your plan. Simple Start, Essentials, and Plus include a set number of billable users, while QuickBooks Online Advanced allows unlimited users and custom roles. View reports, Track time only, and Expense submitter roles do not count toward the limit, and invited accountants do not count either.

What is the difference between the primary admin and a company admin?

Both can access everything and manage users, but only the primary admin can change business details in Company info and reassign the primary admin role. A company admin cannot remove or replace the primary admin.

Do accountant users count toward my user limit?

No. Accountant access is separate from your regular user count. You can invite up to two accountants on most plans, and up to three with QuickBooks Online Advanced, at no extra seat cost.

Why can't I edit a user's role?

Three things block editing: you are not an admin, the target holds a time tracking role that QuickBooks does not allow you to edit, or a custom role is still assigned to users. For time tracking roles, delete the user and re-add them. For custom roles, reassign the users first.