Split the job into preparing and authorising. Everything that prepares the books can sit with an offshore bookkeeper on their own named login; anything that moves money stays with you. In Xero that means a Standard user rather than an Adviser, and in MYOB a restricted user rather than the administrator one, with payroll added later once the rest is running clean. They build the payment batch, and you upload and release it from your internet banking, which they never touch.
The question almost everyone arrives with is "what access level do we actually give them?" In Xero it is a Standard user, with Payroll admin added only when payroll is handed over, and never Adviser. In MYOB it is a restricted role rather than the administrator one, with payroll granted separately.
The second question matters more: does that person need the ability to move money? No. None of the work an offshore bookkeeper does requires payment authority, in either system, ever. Once you accept that, the rest of the permission design gets simple.
Preparation and authority are two different permissions
The useful split is not "bookkeeping versus not bookkeeping". It is preparation versus authority. Coding the bank feed, entering bills, raising invoices, chasing debtors, drafting a pay run and reconciling a GST control account are all preparation. Approving a payment run, lodging a BAS, signing off financials and making the Single Touch Payroll declaration are authority.
The first list travels offshore. The second does not. We set out the full task-by-task version in the Xero handover guide, and the boundary is identical in MYOB. What changes between the two platforms is only how cleanly the software lets you enforce it.
Xero: what to grant and what to withhold
Invite them as a named user on their own email address. Never share a login. A shared login destroys the one thing that makes offshore access safe, which is that every action in the record history has a name attached to it.
Grant Standard. A Standard user codes and reconciles the bank feed, enters and approves bills and raises invoices, which is the day-to-day work. Withhold Adviser. Adviser access lets someone change the chart of accounts, edit locked periods and adjust conversion balances. That is history editing rather than bookkeeping, and a new starter has no business there. Read the whole invitation screen rather than the role name alone, because Xero handles payroll access separately from the role and the remaining options vary with your plan.
Payroll should stay separate for a while. Add Payroll admin only when you actually hand payroll over, which is after two or three clean cycles of everything else. Where Xero lets you withhold the ability to authorise a superannuation payment, withhold it, because that step moves money out of a bank account and belongs with someone authorised on that account.
Set your lock dates before the first day rather than after the first mistake. Xero gives you two of them: one that stops all users, and one that stops everyone except advisers. Use both. And if you are a practice, invite them into each client organisation individually. Do not add them to a practice-level staff list that hands over the entire client base in one click. The practice version of this role is on the client bookkeeper page, and the general scope sits on the Xero VA page.
MYOB: coarser roles, so the control sits elsewhere
MYOB's access model varies by product, and it is generally coarser than people expect. AccountRight lets you build a role from a list of individual permissions. MYOB Business gives you less to work with. Open the user settings on your own file and look at what you can actually restrict before you promise anyone anything.
The rule holds regardless. The default administrator role lets someone change the accounts list, edit closed periods and adjust opening balances, so it is the wrong starting point. Create a restricted user, keep your period lock on, and make sure the audit trail is running.
MYOB's Pay Super flow has its own authorisation step, and that authoriser should be someone on your side who is authorised on the bank account. If you run AccountRight from a local server rather than in the cloud, access becomes a hosting question before it is a permissions question, and it deserves a proper answer rather than a remote desktop session and optimism. The MYOB handover guide has the task split, and the MYOB VA page has the role.
Bank feeds are not bank access
This is where most of the anxiety sits, and it is misplaced. A bank feed is a one-way pipe. Transactions flow from the bank into the ledger, and reconciling them is a labelling exercise. Nothing done in the reconcile screen moves a cent.
What moves money is your internet banking, which is a separate system with separate credentials. Set the feed up yourself with your own banking login, and never hand over that login, a security token or a physical authenticator. If a provider asks for internet banking credentials so their team can "handle payments", that is the end of the conversation.
Batch payments work the same way. Your bookkeeper prepares the batch and generates the payment file. You upload it and you release it. Approving a bill inside Xero or MYOB does not pay it, which means the control that actually matters lives outside the accounting software, and it is already there.
The exception worth naming is supplier bank details. Payment redirection is the fraud that genuinely happens, and it happens to businesses with local staff as well, so treat it as a control problem rather than an offshore one. Make it a written rule that your bookkeeper never edits a supplier's bank account details. They flag the request, you verify it by phone on a number from your own records, and you make the change. Say out loud that delaying a payment to verify will never be held against them. That risk and four others are covered in is it safe to hire offshore.
Making the review step real rather than a rubber stamp
Everyone who sets this up says there will be a review step. Most reviews decay into opening the file, seeing nothing obviously on fire and clicking approve. A rubber stamp is worse than no review at all, because it manufactures a feeling of control you do not have.
A review becomes real when the reviewer is checking something specific against something external. Three things make that happen.
Give the reviewer a list to work from. The habit that makes offshore bookkeeping safe is the query list: anything unclear gets parked and flagged, never guessed. Your review starts there. If the list is empty two weeks running on a file you know is messy, that is a reason to look harder, not a reason to relax.
Write down what must be escalated. A new supplier. Any bank detail change. Any manual journal. Any transaction over a threshold you choose. Anything coded to an account outside the usual set. Anything that would touch a locked period. Hand those rules over before day one and the review has a shape instead of a vibe.
Check the file against something outside the file. The closing balance against the actual bank statement. A supplier statement against aged payables. The super batch against the clearing house receipt. The pay run against the roster. Reviews that compare the file to itself find nothing, because the file always agrees with the file.
A short review every week will do more for you than a long one once a month. And read the audit trail properly once in the first fortnight, not because you expect a problem, but because that is how you learn what normal looks like on your own file.
Where the line sits, and the consent step
Lodging a BAS for a fee, or advising on one, requires registration with the Tax Practitioners Board, and that is not something an offshore team member can hold. They prepare the numbers and hand your registered agent a reconciled pack. The BAS prep handover guide walks through that split, and the boundary map covers the equivalent line in other regulated professions.
If you are a registered agent doing this for clients rather than a business doing its own books, there is a consent step before any access is granted. Code item 6 of the Code of Professional Conduct in the Tax Agent Services Act 2009 stops you disclosing a client's information to a third party without their permission, and the TPB's outsourcing guidance names offshore contractors as third parties. Permission has to come before the disclosure, not after. A general third-party consent in your engagement letter is acceptable to the TPB, and it should name what is disclosed, to whom and where.
Where the Privacy Act 1988 applies to your business, your obligations under the Australian Privacy Principles follow the data regardless of where the person handling it sits, which is another reason to work inside your own systems with scoped access rather than sending files out. The OAIC is the regulator to check if you are unsure. This is general information, not legal or financial advice. Confirm your own position with your accountant or adviser, and check your licensee or professional body's outsourcing policy before you hire rather than after.
What to do next
Before their first day: create the named user, choose the role, set the lock dates, turn on multi-factor authentication, write down the escalation rules and the query list process, and diarise a permission review ninety days out. That is roughly an hour of work, and it decides how the rest of this goes.
If you would rather map the permissions against your actual file before you hire anyone, that is a good use of a call. Book a 30-minute discovery call, bring your file structure, your approval chain and whatever your licensee requires, and we will scope the role around it.
What we would hire for this file, and what we would never give them
If you have read this far you already know the shape of the role: someone doing the daily bookkeeping inside your own Xero or MYOB file, on their own named login, with no ability to move a cent. That is exactly what we hire for. We find, hire and manage the person in the Philippines on your behalf, and on the discovery call we map that permission split against your actual file, so it is settled before anyone starts rather than after the first mistake.
- Works the bank feed every day as a named Standard user in Xero, or a restricted user in MYOB, coding and reconciling and parking anything unclear on a query list rather than guessing.
- Enters bills, raises and chases invoices, prepares the weekly payment batch and generates the payment file, then hands it to you to upload and release from your own internet banking.
- Flags every new supplier, bank detail change, manual journal, out-of-pattern coding and over-threshold transaction against escalation rules agreed before day one, and never edits a supplier's bank account details.
- Produces the checks your review needs against something outside the file — closing balance to the bank statement, supplier statements to aged payables, the super batch to the clearing house receipt — so you are not left comparing the file to itself.
- Prepares the quarter's numbers into a reconciled pack for your registered agent, and, once two or three clean cycles are behind them, drafts the pay run for you to post.
- Payment authority. Internet banking logins, bank security tokens and bank authenticators stay with you, and you upload and release every batch.
- Lodgement and declaration. The BAS is lodged by you or your registered agent, and the Single Touch Payroll declaration is made on your side.
- The review itself. A short weekly look at the query list, the escalations and one check against a document from outside the file. Nobody offshore can do that part for you.
- Consent and permissions. If you act for clients, their consent comes before access, and the user list, the lock dates and the ninety-day permission review remain yours.
Frequently asked questions
Can I just share my Xero login with my bookkeeper?
Can an offshore bookkeeper run payroll and pay super?
What happens if my offshore bookkeeper makes a mistake in Xero?
How do I remove an offshore bookkeeper's access when they leave?
Does my offshore bookkeeper need two-factor authentication if they are overseas?
How much does an offshore bookkeeper cost in Australia?
- Tax Agent Services Act 2009 (Cth), Code of Professional Conduct, item 6 (confidentiality of client information) — A registered agent needs the client's permission before disclosing their information to an offshore contractor.
- Tax Practitioners Board — registration requirements and guidance on outsourcing and offshoring — Lodging or advising on a BAS for a fee requires registration, and an offshore contractor counts as a third party.
- Privacy Act 1988 (Cth) and the Australian Privacy Principles, Office of the Australian Information Commissioner — Where the Act applies to your business, your obligations follow the data regardless of where the person handling it sits.
- Australian Taxation Office — Single Touch Payroll employer reporting guidelines — The pay run declaration is made by the business or its registered agent, not by the offshore preparer.
- Xero Central — user roles and lock dates — What Standard and Adviser access each allow, and the two lock date settings available.
- MYOB help centre — managing users and user access — The default administrator role can change the accounts list, edit closed periods and adjust opening balances.
- ACCC Scamwatch — payment redirection scams — Why supplier bank detail changes are verified by phone on a number from your own records.
