# Accountants: Let your accountant in. Safely.
> Invite your accountant to see the books and help with year-end. You pick what they can do and when it ends, and every action is on the record.
[Get started](https://app.getoatmilk.com/sign-up) · [Sign in](https://app.getoatmilk.com/sign-in) · [Docs](https://getoatmilk.com/docs.md) · [llms.txt](https://getoatmilk.com/llms.txt)
## How it works
1. Invite your accountant
2. Pick what they can do
3. Answer their questions
## What it does
- **Three levels, nothing more.** Read only, Read and comment, or Prepare year-end. Payments, invites, API keys, settings, signing and sending invoices are never allowed.
- **Access that ends on its own.** Access ends 60 days after the tax filing deadline by default, invite links work for 14 days, and revoking works on the next request.
- **Checked twice, every time.** Every request is checked in the app and again in the database, which reads the access level and end date fresh each time.
- **Every action on the record.** An append-only activity log keeps who did what, when and from where. A full SIN is shown only with a reason, and the reason is logged.
- **Questions land in Needs you.** Your accountant asks on the transaction itself, and you answer from Home. Changes they ask for wait for an admin to approve.
- **Every change can be undone.** History records every change by source, previews a rollback first, and the rollback can be undone too.
## How it works
1. An admin opens **Settings › People** and invites the accountant by name and email. Up to 10 people from one firm can be invited at once.
2. The admin picks an **access level** and **when access ends**. By default, access ends 60 days after the tax filing deadline.
3. The accountant gets a link that works for 14 days. Oatmilk stores only a hash of the link, never the link itself.
4. The accountant signs in and works in their own workspace. Their questions show up for the company as "Your accountant asked N questions" in Needs you on Home.
5. When the work is done, access ends on its own, or an admin revokes it. Revoking works on the accountant's next request.
## Access levels
| Level | Can | Notes |
| --- | --- | --- |
| Read only | See the books and download the year-end package. | |
| Read and comment | Also ask questions on transactions and receipts. | The default level. |
| Prepare year-end | Also confirm records and answers, and ask for a few changes. | Changes wait for an admin. |
Extra access, such as more periods, documents or email, is asked for and approved one at a time. The access level never grants it on its own.
## What an accountant can never do
At every level, an accountant can never:
- manage members or roles, or send invitations
- make API keys
- change settings or connectors
- make payments
- send invoices
- sign agreements
- upload files or match records
Accountants get no API keys. Over AI connectors (MCP), they can only view and comment.
## How access is checked
Every request is checked twice: once in the app, and again in the database. The database check reads the accountant's access and end date fresh on every call, so nothing carries over from an older sign-in.
Revoking access, or reaching the end date, works on the very next request. An open accountant workspace switches to an "Access ended" screen.
## The audit trail
- **Accountant activity log.** Append-only: rows are added, never changed or deleted. It records joining, sign-ins, downloads, exports and year-end packages, access requests and decisions, level and end-date changes, and questions asked and answered.
- **Sensitive numbers.** Full SINs are masked. An accountant can show one only by giving a reason, and the reason is logged.
- **History.** Every change is recorded with its source: web, Ask AI, AI connector, API or automation. A rollback shows a preview first, and the rollback can itself be undone.
## Questions and change requests
- **Questions.** With Read and comment or Prepare year-end, the accountant asks a question right on a transaction or receipt, for example "Is this Air Canada flight for a client trip?" The company sees "Your accountant asked 1 question" in Needs you and answers in place. The accountant sees the answer on the record.
- **Change requests.** With Prepare year-end, the accountant can ask for three kinds of change, one record at a time: attach a receipt, match a receipt, or check which contractor a payment was for. Only an admin can approve, and the database enforces that.
## The accountant workspace
The accountant works in their own workspace: **Overview**, **Transactions**, **Receipts**, **Statements**, **Downloads** (reports), **Year-end** and **Access**. Year-end shows the same checklist the company sees. Access shows what they can do, when it ends, and lets them ask for more.
## Several clients, one login
An accountant who works for several companies uses one login. They choose which client to open, and a **Switch company** button moves between them. Each company's access is separate: ending one doesn't touch the others.
## Ask AI for accountants
Accountants get Ask AI too, inside the client's workspace, to find records, explain totals and check what is missing. An Ask AI answer is separate from a question sent to the company.
## AI connectors (MCP)
An accountant can connect an AI app over MCP, but only to view and comment, and they name the company on every call. Access and the end date are read again on every MCP call, and downloads and questions from a connected AI app are kept in the activity log.
## More from Oatmilk
- [Classifier](https://getoatmilk.com/classifier.md): Each bank and card line runs through rules, memory, receipts and Jev. Oatmilk sorts it only when it's sure, and asks you one question when it isn't.
- [Evidence matching](https://getoatmilk.com/evidence.md): Oatmilk reads receipts from your company's inboxes and matches each one to its charge. It asks you when it isn't sure and keeps the original.
- [Bookkeeping](https://getoatmilk.com/bookkeeping.md): Bank, card, Wise and Stripe charges come in and get sorted. Oatmilk asks you only when it isn't sure.
- [Compliance](https://getoatmilk.com/stay-compliant.md): Ask any rules question and get an answer with official sources. Guides, deadlines and rule changes for your company, in one place.
- [Invoices](https://getoatmilk.com/invoices.md): Make an invoice in a minute, send it, and see when it's opened and paid.
- [Agreements](https://getoatmilk.com/agreements.md): Write an agreement, send it to sign on any device, and keep every signed copy with a full record.
- [Contractors](https://getoatmilk.com/contractors.md): Contractors send hours from their own portal. You approve with a tap, pay with Wise and get tax slips at year-end.
- [Tax](https://getoatmilk.com/tax.md): Year-end for Canadian companies, one plain question at a time. T2, GST/HST and T4A work, ready for your accountant.
- [Ask AI](https://getoatmilk.com/ask-ai.md): Ask a question about your company and get a straight answer. Ask AI reads your books and asks before it changes anything.
- [Run it locally](https://getoatmilk.com/local.md): Run Oatmilk on your own computer with the CLI and the web portal, or choose where each part runs: this computer, the cloud, or off.
- [Local models](https://getoatmilk.com/local-models.md): Run Ask AI, the classifiers and document reading on Ollama, LM Studio or any OpenAI-compatible server. Mix local and cloud by role.
- [CLI](https://getoatmilk.com/cli.md): Oatmilk in your terminal: every page one keypress away, Ask AI built in, and themes that work in light and dark terminals.
- [AI connectors](https://getoatmilk.com/mcp.md): Connect Claude, ChatGPT, Cursor, Codex and more to Oatmilk. Your AI can do what you can do, and nothing more.
Human version: https://getoatmilk.com/accountants