Security and access control

QuickBooks access is role-specific, not all-or-nothing.

Numbers Game can connect a firm to QuickBooks Online, but that does not give every teammate the same rights. Owners, Admins, Members, and Viewers have distinct capabilities for managing the firm, reading books, and working with connected data.

The short answer

Does Numbers Game have read and write access to QuickBooks?

A firm can authorize Numbers Game to connect to QuickBooks Online through Intuit’s OAuth flow. The connection’s approved scopes make it possible to support the bookkeeping workflows the firm chooses. That is not the same as giving every Numbers Game user unrestricted access to every QuickBooks action.

Access is governed at multiple levels: the QuickBooks connection, the firm role, and the action a person is attempting. A Viewer is explicitly read-only and cannot create or modify anything in QuickBooks. A Member can work with the firm’s connected QuickBooks data through the dashboard, Claude, ChatGPT, or another MCP client, but has no dashboard write access. Owners and Admins manage the firm account, its people, and its connected companies according to the limits below.

For workflows that propose a change to a connected book, Numbers Game shows the proposed action for review before it posts. QuickBooks remains the system of record. Read our security overviewfor the connection and approval model.

Role matrix

Four roles, clear boundaries.

Owner

Full control of the firm account.

Can do

  • Everything an Admin can do.
  • Choose a plan and manage billing through Stripe.
  • Change Owner and Admin roles.
  • Export firm data.

Cannot do

There is no higher role within the firm account.

Admin

Day-to-day firm management.

Can do

  • Invite and remove teammates, and cancel outstanding invitations.
  • Switch accounts between Member and Viewer.
  • Disconnect QuickBooks companies.
  • Edit firm settings, including the logo, Slack webhook, and per-realm client rules.

Cannot do

Admins cannot manage Stripe billing, change Owner or Admin roles, or export firm data.

Member

An accountant or teammate who works with the firm's connected books.

Can do

  • Read the Numbers Game dashboard.
  • Use Claude, ChatGPT, or another MCP client against the firm's QuickBooks data.
  • Generate analysis and reports from the connected books.

Cannot do

Members do not have write access in the Numbers Game dashboard.

Viewer

A report-only, read-only role for junior staff and outside collaborators.

Can do

  • Use Claude or another MCP client to read the firm's QuickBooks data and generate reports.
  • Review the dashboard without access to operational bank-feed information.

Cannot do

Viewers cannot create or modify anything in QuickBooks, connect new companies, see bank connections, or see bank-feed transactions.

How firms use the roles

Give people the access their job requires.

Firm principal

Make the principal an Owner. They retain control of billing, exports, and the small set of highest-impact role changes.

Operations lead

Use Admin for the person who onboards teammates, manages invitations, disconnects a client company, and maintains firm rules, without giving them billing or role-change power.

Accountant or manager

Use Member for a teammate who needs to ask Claude or ChatGPT about the firm’s QuickBooks data, use the dashboard, and produce analysis in their day-to-day work.

Junior staff or external reviewer

Use Viewer when someone needs reports and read-only answers, but must not create or modify anything in QuickBooks or access bank-feed information.

Why this matters

A connection is not a blank check.

An accounting firm may connect several client books, have a mix of partners, staff, and outside reviewers, and use AI clients such as Claude or ChatGPT to ask questions of those books. Treating everyone as a single generic user would make offboarding, delegation, and report-only work much harder to control.

  • Least-privilege access: a Viewer can generate a report without being able to change the underlying QuickBooks data.
  • Safer delegation: an Admin can manage invitations and connections without being able to alter Owner or Admin roles or billing.
  • Clear accountability: billing, firm-data exports, and top-level role changes remain with an Owner.
  • Bank-data separation: bank connections and bank-feed transactions are not visible to Viewers.
Common questions

Roles and QuickBooks access, answered plainly.

Can every Numbers Game user write to QuickBooks?

No. Viewers cannot create or modify anything in QuickBooks. Members have no write access in the Numbers Game dashboard. Firm role and the action being attempted determine what a person can do.

Who can make someone an Owner or Admin?

Only an Owner can change Owner and Admin roles.

Who can invite or remove teammates?

Owners and Admins can invite and remove teammates. Admins can also switch accounts between Member and Viewer.

Can a Viewer use Claude, ChatGPT, or another MCP client?

Yes. A Viewer can use Claude or another MCP client to read the firm’s QuickBooks data and generate reports. A Viewer cannot create or modify anything in QuickBooks.

Can a Viewer see bank-feed transactions?

No. Bank connections and bank-feed transactions are restricted to Owners, Admins, and Members.

Who manages billing and exports firm data?

Only an Owner can manage Stripe billing, choose a plan, and export firm data.

Need to assess the access model?

Bring your firm’s roles and a real client workflow to a walkthrough.

Book a walkthrough