Team & Task Management

Role-Based Access for CA Firms — Owner, Staff, and Client Permissions

TEAM & ACCESS MANAGEMENT ROLE-BASED ACCESS CONTROL

Running a CA firm means handling some of the most sensitive financial data in your clients' lives — ITR filings, bank statements, PAN details, GST records, TDS workings, and company incorporation documents. The question of who gets to see what is not just a matter of convenience. It is a matter of professional responsibility. Yet many Indian CA firms still operate with a single shared login or an ad hoc approach to access — everyone can see everything, which creates real risks around confidentiality, data integrity, and accountability. Setting up role-based access control correctly is one of the most impactful structural changes a growing firm can make.

Why "Everyone Can See Everything" Is a Problem

In a small, two-person practice, open access feels harmless. You and your partner know each other, trust each other, and there is no reason to restrict anything. But even in that scenario, there are problems. If a client's documents are visible to your Article Assistant who is also handling their family member's accounts, confidentiality walls break down. If a contractual bookkeeper working part-time can download any file in your system, your data security posture is weaker than you realize. And if a client can browse your full client list — even accidentally through a shared link — the damage can be severe.

As firms grow, the risks multiply. A practice with a Partner, three Chartered Accountants, four Article Assistants, and two administrative staff has very different access needs across those roles. A new Article joining the firm should not have the same access as the Partner who has been managing a client relationship for eight years. A client who uses your upload portal to submit their Form 16 should not be able to see billing notes, internal task comments, or other clients' documents. The absence of role boundaries creates operational confusion as much as it creates security risk.

Beyond internal considerations, the ICAI's guidelines on client confidentiality and the emerging obligations under India's Digital Personal Data Protection Act 2023 make it necessary for firms to demonstrate that they have controls in place over who accesses what data. Role-based access is the practical mechanism that makes those controls real and auditable.

The Three Core Roles: Owner, Team Member, and Client

A well-structured CA firm permission model needs at least three distinct roles, each with a clearly scoped set of capabilities. Getting these boundaries right from the start saves significant confusion later.

The Firm Owner role carries full administrative control. The owner — typically the principal CA or managing partner — can see all clients, all documents, all tasks, all team members, and all system settings. This includes the ability to invite and remove team members, configure billing, access audit logs, and modify firm-wide settings. The owner role should be assigned only to those who genuinely need and are accountable for full system access. In most Indian CA firms, this is one to three people — the partners or principal.

  • View and manage all client records and documents
  • Add, edit, or remove team members and their role assignments
  • Access audit logs and activity history across all clients
  • Configure firm-wide settings, integrations (such as Google Drive sync), and billing
  • Create and assign tasks to any team member across any client
  • Delete documents and close client records

The Team Member role — which in Practivo corresponds to the Staff or Assignee tier — should cover most of the day-to-day work done by CAs, semi-qualified staff, and Article Assistants. Team Members can work on assigned clients and tasks, upload and download documents within their scope, update task statuses, and communicate through internal notes. What they should not be able to do is modify billing settings, access clients they have not been assigned to, view other team members' salary or performance data, or export bulk data from the system.

  • Access clients and tasks specifically assigned to them
  • Upload documents on behalf of clients or from their own machine
  • Update task status and priority within assigned work
  • View document checklists and mark items complete
  • Add internal comments and notes on tasks and documents
  • Cannot view firm-wide settings, billing, or unassigned clients

The Client role is the most restricted — and appropriately so. Clients interact with your firm's platform for one primary purpose: to submit the documents you have requested. They should be able to see their own upload checklist, upload files against specific requests, view the status of their own submissions, and download documents the firm has shared back with them (such as filed ITR acknowledgements or GST registration certificates). Clients should never be able to see other clients' data, internal task notes, team member information, or billing records.

  • Access only their own client record and document checklist
  • Upload files against specific document requests (via guest link or login)
  • View the status of their own document submissions
  • Download firm-shared documents (e.g., acknowledgements, reports)
  • Cannot see other clients, internal notes, task details, or team structures
"The right permission model is not about distrust — it is about clarity. When everyone knows exactly what they can and cannot access, the firm runs more smoothly, clients feel safer, and accountability is built into the system rather than bolted on after something goes wrong."

Practical Scenarios: Where Role Boundaries Matter Most

Consider a firm managing both individual ITR clients and corporate clients with complex GST compliance needs. The team member handling individual ITR filings for salaried employees has no business accessing the working papers for a manufacturing client's GST audit. If access is unrestricted, there is no barrier preventing accidental — or deliberate — cross-contamination of data. With role-based assignment, team members see only the clients in their portfolio, and the ITR staff and the GST team operate in cleanly separated workspaces within the same platform.

Another common scenario is the departing Article. When an Article Assistant's articleship ends, you need to revoke their access cleanly and completely. With a role-based system, this is a single action — removing or deactivating the team member account — rather than a manual scramble to change passwords, revoke shared drives, and remove WhatsApp group memberships. The clean off-boarding is just as important as the clean on-boarding.

For multi-partner firms, role assignment also clarifies client ownership. Partner A handles the pharmaceutical sector clients; Partner B manages the hospitality and retail accounts. With proper role scoping, each partner's team members see only the relevant client portfolio, and cross-pollination of client data — which can create both legal and ethical complications — is structurally prevented rather than dependent on individual discipline.

Pro tip

When onboarding a new team member, assign them only the clients they are actively working on from day one — do not give blanket access to all clients "just in case." Access is easy to expand; the harm from overly broad access is often invisible until something goes wrong. Review access assignments quarterly as client portfolios shift between staff members.

The Client Upload Experience — Scoped and Friction-Free

One of the most common access design mistakes in CA firm tools is treating the client portal as an afterthought. Clients are given a login but then presented with an interface that is confusing, cluttered with internal information they should not see, or so locked down that they cannot figure out what to do. The ideal client-facing experience is narrow in scope but extremely easy to use.

This is where Practivo's guest upload link model is particularly well-designed for Indian CA practice. Rather than requiring every client to create an account and navigate a full portal, you can send a client a secure, scoped upload link that goes directly to a checklist of the documents you have requested — Form 16 here, bank statements here, investment proofs here. The client sees only what is relevant to them. They upload, you receive. The link can optionally be PIN-protected for additional security, which is especially useful for sensitive engagements such as income tax search and seizure assessments, FEMA compliance filings, or high-value company audit work.

For clients who prefer a persistent login — typically corporate clients with ongoing monthly compliance work — a proper client account with scoped access to their own records provides the continuity they need without the risk of overexposure. Whether your client is an individual filing a straightforward ITR or a GSTIN-registered business with quarterly compliance obligations, the access model adapts to fit the engagement structure.

Access Control and Google Drive Sync — Keeping It Consistent

Many CA firms use Google Drive as their primary document storage. Practivo's Google Drive auto-sync feature creates a dedicated folder for each client in the firm's Drive, and files uploaded through the platform are automatically organized there. But this raises an important question: if a team member has limited access within Practivo — seeing only their assigned clients — does their access to Google Drive respect those same boundaries?

The answer should ideally be yes, and the way to achieve this is to configure your Google Drive folder permissions to mirror your Practivo role assignments. Team members should have access only to the Drive folders corresponding to their assigned clients. The firm owner or a designated Drive administrator should be the only person with full access across all client folders. This mirroring ensures that bypassing the document management tool by going directly to Google Drive does not grant a team member access they would not have within the platform itself.

When a team member leaves the firm, revoke their Practivo access first, then remove their Google Drive access in the same off-boarding step. Doing both simultaneously eliminates the gap that often occurs when access is revoked in one system but forgotten in another. Tools like Practivo that surface all client and document access in a single interface make this process straightforward — there is no need to chase down access across five different systems.

Getting Started: Setting Up Roles in Your Firm

If your firm is new to structured role-based access, the best approach is to start with the ownership boundary and work outward. Begin by identifying who in your firm genuinely needs Owner-level access — the principals, managing partners, or firm administrators. Everyone else starts as a Team Member. Then, for each Team Member, explicitly assign the clients they are responsible for. Do not leave any team member with blanket access to the full client list by default.

For clients, decide early whether you will use the guest upload link model (no client login required) or the persistent client account model. For most individual ITR clients — salaried employees, small business owners, HUFs — the guest upload link is simpler and more user-friendly. For corporate clients on monthly retainers — GST-registered businesses, companies needing monthly TDS compliance, audit clients — a persistent client account with scoped access makes more sense. You can use both models within the same firm, client by client.

Finally, revisit your role assignments at least twice a year — once before ITR season and once at your firm's financial year-end. Staff changes, client additions, and expanding service lines all create access drift if roles are not actively maintained. A periodic access review is not just good security hygiene — it is the kind of professional governance standard that distinguishes mature, reliable CA practices from those flying by the seat of their pants. Practivo's built-in permission model, designed specifically for CA firms, gives you Firm Owner and Team Member roles, scoped client assignments, and guest upload links that give clients exactly the access they need and nothing more.

Frequently Asked Questions

How many permission levels does a typical CA firm need?

Most Indian CA firms operate well with three tiers: Firm Owner (full administrative access), Team Member (access to assigned clients and tasks only), and Client (scoped upload and view access for their own records). Larger firms with distinct practice verticals — for example, a dedicated statutory audit team and a separate direct tax team — may benefit from a senior team member tier that allows supervisors to manage sub-team client assignments without full firm-wide admin rights. Start with three roles and add complexity only when the operational need is clear.

Should every client have a login to the firm's document portal?

Not necessarily. For individual clients who submit documents only a few times a year — such as salaried employees uploading Form 16 and bank statements for ITR filing — a guest upload link is often more practical than a full login. Guest links require no account creation, work on any device, and can be PIN-protected for extra security. For corporate clients with ongoing monthly compliance work who regularly send and receive documents, a persistent client account provides better continuity. Many firms use both models simultaneously depending on the client type and engagement structure.

What should happen to a team member's access when they leave the firm?

Access should be revoked on the day of departure, not after. This means deactivating their account in your document management platform, removing their access to Google Drive client folders, removing them from any shared communication tools, and changing any shared passwords they may have known. With a proper role-based system, revoking platform access is a single action — the account is deactivated and all their assigned client access is immediately removed. The firm owner should also review any documents downloaded or accessed in the final days before departure, which is where audit logs become an essential tool.

Can role-based access help with ICAI peer review compliance?

Yes. ICAI's peer review process examines whether a firm has adequate controls over client confidentiality and working paper management. Being able to demonstrate that access to client files is limited to assigned team members, that all access events are logged, and that clients can only see their own data directly supports the confidentiality and quality control standards the peer review process assesses. While ICAI does not currently audit your software's permission settings directly, the ability to produce a clear account of who had access to what — and when — is exactly the kind of documentation that strengthens a firm's peer review standing.

Ready to streamline your CA practice?

Practivo helps CA firms collect documents, manage clients, and coordinate teams — without the WhatsApp chaos.

Start free trial Book a demo