Everyone who works in your books — bookkeeper, treasurer, board members — gets their own login. Shared passwords are how audit trails die; accounts are how you can always answer "who entered this?"
Where: Settings → Users. Your plan sets how many active users you can have (Free: 2, Foundation: 4, Core: 10, Pro: unlimited) — deactivated users don't count.
Adding a user
Click Add User and enter their name, email, and role/title. You never type a password — the new user gets an email with a secure link to set their own (the link is good for 7 days; you can re-send from their page).
Before saving, check the Permission Groups that apply. In practice most organizations decide just two things:
- System Administrator — full access to everything, including Settings, users, and billing. Give this to the people who actually run the books. (Turning it on also enables two-factor login codes for that user automatically — administrators are worth protecting.)
- Approver — on plans with two-person approval, members of this group are the ones who can approve outgoing payments.
Everyone belongs to the Everyone group automatically; the remaining groups offer narrower day-to-day access.
The two-administrator rule (Policy 5.2)
GoodBooks requires every organization to keep at least two active System Administrators. It's not bureaucracy — it's what keeps your books reachable when the treasurer moves away, and it's a condition of keeping online donation processing active (organizations without a second admin see a warning banner, and processing is suspended after 180 days without one). The setup wizard's last step exists precisely to satisfy this.
Managing users over time
- Someone leaves: open their account and click Deactivate Account. They can't log in, their history is preserved, and they stop counting toward your user limit. Reactivate any time. (You can't deactivate yourself — someone else does the honors.)
- Forgotten password: their page has a Send Reset Link button (link valid 24 hours). There's also "Forgot Password?" on the login page.
- Stale passwords: accounts with passwords older than 90 days are asked to choose a new one at their next login, automatically.
- Two-factor codes: each user's page has a Require MFA at Login toggle and a cell phone field — see Two-Factor Login Codes.
- Donation notifications: the per-user toggle "Receive Donation Notifications" sends that administrator a copy of each donor receipt as gifts come in — nice for the pastor or development director.
Your outside accountant doesn't need a user seat
If an accountant or bookkeeper from outside your organization helps with your books, don't add them as a user — connect them through Accountant Access instead. They work under their own GoodBooks account, don't count toward your user limit, can't touch your settings or users, and you can remove their access with one click.
Good to know
- Add real people, not shared mailboxes like
treasurer@— role accounts defeat the audit trail and strand MFA codes when the role changes hands. - When someone with money access leaves, deactivate them the same day. It's one click, and it's reversible.
Comments
0 comments
Please sign in to leave a comment.