Finance & admin

Xero and MYOB permissions for an offshore bookkeeper

Looking for VA work yourself? Apply at staffingsolutions.ph — this article is written for businesses hiring.
The short answer

Split the job into preparing and authorising. Everything that prepares the books can sit with an offshore bookkeeper on their own named login; anything that moves money stays with you. In Xero that means a Standard user rather than an Adviser, and in MYOB a restricted user rather than the administrator one, with payroll added later once the rest is running clean. They build the payment batch, and you upload and release it from your internet banking, which they never touch.

The question almost everyone arrives with is "what access level do we actually give them?" In Xero it is a Standard user, with Payroll admin added only when payroll is handed over, and never Adviser. In MYOB it is a restricted role rather than the administrator one, with payroll granted separately.

The second question matters more: does that person need the ability to move money? No. None of the work an offshore bookkeeper does requires payment authority, in either system, ever. Once you accept that, the rest of the permission design gets simple.

Preparation and authority are two different permissions

The useful split is not "bookkeeping versus not bookkeeping". It is preparation versus authority. Coding the bank feed, entering bills, raising invoices, chasing debtors, drafting a pay run and reconciling a GST control account are all preparation. Approving a payment run, lodging a BAS, signing off financials and making the Single Touch Payroll declaration are authority.

The first list travels offshore. The second does not. We set out the full task-by-task version in the Xero handover guide, and the boundary is identical in MYOB. What changes between the two platforms is only how cleanly the software lets you enforce it.

Xero: what to grant and what to withhold

Invite them as a named user on their own email address. Never share a login. A shared login destroys the one thing that makes offshore access safe, which is that every action in the record history has a name attached to it.

Grant Standard. A Standard user codes and reconciles the bank feed, enters and approves bills and raises invoices, which is the day-to-day work. Withhold Adviser. Adviser access lets someone change the chart of accounts, edit locked periods and adjust conversion balances. That is history editing rather than bookkeeping, and a new starter has no business there. Read the whole invitation screen rather than the role name alone, because Xero handles payroll access separately from the role and the remaining options vary with your plan.

Payroll should stay separate for a while. Add Payroll admin only when you actually hand payroll over, which is after two or three clean cycles of everything else. Where Xero lets you withhold the ability to authorise a superannuation payment, withhold it, because that step moves money out of a bank account and belongs with someone authorised on that account.

Set your lock dates before the first day rather than after the first mistake. Xero gives you two of them: one that stops all users, and one that stops everyone except advisers. Use both. And if you are a practice, invite them into each client organisation individually. Do not add them to a practice-level staff list that hands over the entire client base in one click. The practice version of this role is on the client bookkeeper page, and the general scope sits on the Xero VA page.

MYOB: coarser roles, so the control sits elsewhere

MYOB's access model varies by product, and it is generally coarser than people expect. AccountRight lets you build a role from a list of individual permissions. MYOB Business gives you less to work with. Open the user settings on your own file and look at what you can actually restrict before you promise anyone anything.

The rule holds regardless. The default administrator role lets someone change the accounts list, edit closed periods and adjust opening balances, so it is the wrong starting point. Create a restricted user, keep your period lock on, and make sure the audit trail is running.

MYOB's Pay Super flow has its own authorisation step, and that authoriser should be someone on your side who is authorised on the bank account. If you run AccountRight from a local server rather than in the cloud, access becomes a hosting question before it is a permissions question, and it deserves a proper answer rather than a remote desktop session and optimism. The MYOB handover guide has the task split, and the MYOB VA page has the role.

Bank feeds are not bank access

This is where most of the anxiety sits, and it is misplaced. A bank feed is a one-way pipe. Transactions flow from the bank into the ledger, and reconciling them is a labelling exercise. Nothing done in the reconcile screen moves a cent.

What moves money is your internet banking, which is a separate system with separate credentials. Set the feed up yourself with your own banking login, and never hand over that login, a security token or a physical authenticator. If a provider asks for internet banking credentials so their team can "handle payments", that is the end of the conversation.

Batch payments work the same way. Your bookkeeper prepares the batch and generates the payment file. You upload it and you release it. Approving a bill inside Xero or MYOB does not pay it, which means the control that actually matters lives outside the accounting software, and it is already there.

The exception worth naming is supplier bank details. Payment redirection is the fraud that genuinely happens, and it happens to businesses with local staff as well, so treat it as a control problem rather than an offshore one. Make it a written rule that your bookkeeper never edits a supplier's bank account details. They flag the request, you verify it by phone on a number from your own records, and you make the change. Say out loud that delaying a payment to verify will never be held against them. That risk and four others are covered in is it safe to hire offshore.

Making the review step real rather than a rubber stamp

Everyone who sets this up says there will be a review step. Most reviews decay into opening the file, seeing nothing obviously on fire and clicking approve. A rubber stamp is worse than no review at all, because it manufactures a feeling of control you do not have.

A review becomes real when the reviewer is checking something specific against something external. Three things make that happen.

Give the reviewer a list to work from. The habit that makes offshore bookkeeping safe is the query list: anything unclear gets parked and flagged, never guessed. Your review starts there. If the list is empty two weeks running on a file you know is messy, that is a reason to look harder, not a reason to relax.

Write down what must be escalated. A new supplier. Any bank detail change. Any manual journal. Any transaction over a threshold you choose. Anything coded to an account outside the usual set. Anything that would touch a locked period. Hand those rules over before day one and the review has a shape instead of a vibe.

Check the file against something outside the file. The closing balance against the actual bank statement. A supplier statement against aged payables. The super batch against the clearing house receipt. The pay run against the roster. Reviews that compare the file to itself find nothing, because the file always agrees with the file.

A short review every week will do more for you than a long one once a month. And read the audit trail properly once in the first fortnight, not because you expect a problem, but because that is how you learn what normal looks like on your own file.

Lodging a BAS for a fee, or advising on one, requires registration with the Tax Practitioners Board, and that is not something an offshore team member can hold. They prepare the numbers and hand your registered agent a reconciled pack. The BAS prep handover guide walks through that split, and the boundary map covers the equivalent line in other regulated professions.

If you are a registered agent doing this for clients rather than a business doing its own books, there is a consent step before any access is granted. Code item 6 of the Code of Professional Conduct in the Tax Agent Services Act 2009 stops you disclosing a client's information to a third party without their permission, and the TPB's outsourcing guidance names offshore contractors as third parties. Permission has to come before the disclosure, not after. A general third-party consent in your engagement letter is acceptable to the TPB, and it should name what is disclosed, to whom and where.

Where the Privacy Act 1988 applies to your business, your obligations under the Australian Privacy Principles follow the data regardless of where the person handling it sits, which is another reason to work inside your own systems with scoped access rather than sending files out. The OAIC is the regulator to check if you are unsure. This is general information, not legal or financial advice. Confirm your own position with your accountant or adviser, and check your licensee or professional body's outsourcing policy before you hire rather than after.

What to do next

Before their first day: create the named user, choose the role, set the lock dates, turn on multi-factor authentication, write down the escalation rules and the query list process, and diarise a permission review ninety days out. That is roughly an hour of work, and it decides how the rest of this goes.

If you would rather map the permissions against your actual file before you hire anyone, that is a good use of a call. Book a 30-minute discovery call, bring your file structure, your approval chain and whatever your licensee requires, and we will scope the role around it.

How we would staff this

What we would hire for this file, and what we would never give them

If you have read this far you already know the shape of the role: someone doing the daily bookkeeping inside your own Xero or MYOB file, on their own named login, with no ability to move a cent. That is exactly what we hire for. We find, hire and manage the person in the Philippines on your behalf, and on the discovery call we map that permission split against your actual file, so it is settled before anyone starts rather than after the first mistake.

Dedicated bookkeeper (Xero or MYOB)
What they do
  • Works the bank feed every day as a named Standard user in Xero, or a restricted user in MYOB, coding and reconciling and parking anything unclear on a query list rather than guessing.
  • Enters bills, raises and chases invoices, prepares the weekly payment batch and generates the payment file, then hands it to you to upload and release from your own internet banking.
  • Flags every new supplier, bank detail change, manual journal, out-of-pattern coding and over-threshold transaction against escalation rules agreed before day one, and never edits a supplier's bank account details.
  • Produces the checks your review needs against something outside the file — closing balance to the bank statement, supplier statements to aged payables, the super batch to the clearing house receipt — so you are not left comparing the file to itself.
  • Prepares the quarter's numbers into a reconciled pack for your registered agent, and, once two or three clean cycles are behind them, drafts the pay run for you to post.
What stays with you
  • Payment authority. Internet banking logins, bank security tokens and bank authenticators stay with you, and you upload and release every batch.
  • Lodgement and declaration. The BAS is lodged by you or your registered agent, and the Single Touch Payroll declaration is made on your side.
  • The review itself. A short weekly look at the query list, the escalations and one check against a document from outside the file. Nobody offshore can do that part for you.
  • Consent and permissions. If you act for clients, their consent comes before access, and the user list, the lock dates and the ninety-day permission review remain yours.
From A$14/hr + GST · full-time and dedicated · about two weeks from brief to first day · no placement or exit fees
See the role →

Frequently asked questions

Can I just share my Xero login with my bookkeeper?
No. Xero records who made each change and MYOB keeps an audit trail, and a shared login strips the name off all of it, so you cannot tell who coded what or who altered a supplier record. You also cannot switch one person off without locking everyone out, and you hand over whatever else that login can reach. Invite them as a named user on their own email address. Every other control you set up depends on that one step.
Can an offshore bookkeeper run payroll and pay super?
They can prepare it, not authorise it. An offshore bookkeeper can enter timesheets, draft the pay run, calculate leave and superannuation and leave the whole thing sitting ready. You post the pay run, make the Single Touch Payroll declaration to the Australian Taxation Office and authorise the super payment, because that step moves money out of a bank account. Hand payroll over only after two or three clean cycles of the ordinary bookkeeping, and grant the payroll permission then rather than on day one.
What happens if my offshore bookkeeper makes a mistake in Xero?
You find it and fix it, and the file tells you who did it. Xero keeps a history against the transaction and MYOB keeps an audit trail, so a named user turns an error into something traceable rather than mysterious, and your lock dates stop it reaching a period you have already reported on. The responsibility does not move, though. A wrong tax code, a mis-coded expense or a missed reconciliation is still yours to correct and yours to answer for.
How do I remove an offshore bookkeeper's access when they leave?
Remove the user in the accounting file first, then everywhere else the same day: email, the document store, the receipt capture tool, any client or practice portal, and the password manager. If they used a credential that cannot be split by person, change it rather than trusting the departure. Then read the audit trail for their last fortnight so you know the file was left clean, and bring forward the ninety-day permission review for whoever is still there.
Does my offshore bookkeeper need two-factor authentication if they are overseas?
Yes, on every user, including you. Use an authenticator app on that person's own device rather than text-message codes, which depend on a mobile number you cannot see and cannot control. Never let two people share one authenticator and never pass a code by chat message, because that is a shared login wearing a disguise. Set it up before you grant access to the file, not after, and keep it separate from anything that touches your bank.
How much does an offshore bookkeeper cost in Australia?
A dedicated, full-time bookkeeper starts at A$14 an hour plus GST for Australian clients and from US$9 an hour for US clients, with specialist roles higher. There are no placement, recruitment, setup or exit fees. The engagement is an initial three-month contract and then month to month, and it takes roughly two weeks from your brief to their first day. Budget a little of your own time each week for the review step, because that is what makes the arrangement safe.
Sources & further reading
  • Tax Agent Services Act 2009 (Cth), Code of Professional Conduct, item 6 (confidentiality of client information) — A registered agent needs the client's permission before disclosing their information to an offshore contractor.
  • Tax Practitioners Board — registration requirements and guidance on outsourcing and offshoring — Lodging or advising on a BAS for a fee requires registration, and an offshore contractor counts as a third party.
  • Privacy Act 1988 (Cth) and the Australian Privacy Principles, Office of the Australian Information Commissioner — Where the Act applies to your business, your obligations follow the data regardless of where the person handling it sits.
  • Australian Taxation Office — Single Touch Payroll employer reporting guidelines — The pay run declaration is made by the business or its registered agent, not by the offshore preparer.
  • Xero Central — user roles and lock dates — What Standard and Adviser access each allow, and the two lock date settings available.
  • MYOB help centre — managing users and user access — The default administrator role can change the accounts list, edit closed periods and adjust opening balances.
  • ACCC Scamwatch — payment redirection scams — Why supplier bank detail changes are verified by phone on a number from your own records.
Alfie Quiming
Alfie QuimingAccount manager, Manila

Alfie is a natural facilitator with a passion for building meaningful relationships. A true people person, he thrives on creating genuine connections and bringing people and businesses together, and he excels at fostering collaboration and teamwork. At StaffingSolutions.io he is usually the first person you speak to: he maps the role, writes the brief the recruiters work from, and stays on the account long after the placement.

Meet the team