Expense data combines employee identity, client allocation, receipts, card activity, payment status, bank relationships, and accounting output. In a CPA firm, excessive Expensify access can expose more than a list of reports: it can permit role changes, card issuance or limits, payment configuration, exports, or broad visibility across client-coded expenses. Shared admin logins and informal handoffs make it impossible to prove which person approved a change or whether a departing user still controls a critical dependency.
Expensify permissions span more than one layer. New Expensify documents workspace roles such as Member, Workspace admin, Card admin, People admin, Payments admin, Auditor, and in some plans Editor. Domain administration governs separate company-wide controls, while a connected business bank account, billing ownership, and accounting integration add their own effective authority. Plan and interface matter, so verify the current official role description in the firm's tenant instead of assigning a familiar title by name alone.
Pair this lifecycle with ALLMSP's [Expensify software support library](https://www.allmsp.com/category/software-support/software-support-expensify/), [CPA and Financial Firms guidance](https://www.allmsp.com/category/cpa-and-financial-firms/), and [Cybersecurity resources](https://www.allmsp.com/category/cybersecurity/). The practical goal is not the smallest possible member list; it is enough access to perform an approved duty, no unowned authority, and a tested way to remove access without interrupting reimbursement or month-end close.
Key decisions at a glance
- Distinguish New Expensify workspace roles from domain-level administration and document which surface, plan, and owner controls each privilege.
- Use the narrowest current workspace role that fits the duty, then govern Domain Admin, bank ownership, billing, and integration authority as separate high-impact paths.
- Current Expensify 2FA guidance uses authenticator-app TOTP and recovery codes; domain-required 2FA has a documented relationship with SAML that must be reviewed before configuration.
- Offboarding is a dependency transfer: reassign workspace, domain, billing, bank, reimbursement, card, and accounting responsibilities before access is closed.
Map Workspace Roles, Domain Authority, and Hidden Dependencies
Build an access register from live configuration. For every person and service relationship, record company-controlled identity, employment or vendor status, sponsor, Expensify workspace membership, assigned workspace role, approval duties, domain group, Domain Admin status, card responsibilities, bank-account access, reimbursement authority, billing ownership, preferred-exporter status, accounting-administrator relationship, start and review dates, and removal trigger. Do not store passwords, one-time codes, recovery codes, card data, or bank details in the register.
Use current role definitions to split duties. A Member can submit or approve assigned expenses; a Workspace admin can manage broad workspace settings; Card admin, People admin, Payments admin, and Auditor provide narrower capabilities on eligible Control workspaces; Editor applies to documented Submit-workspace use. Validate the exact scope in the firm's plan. A person who only issues cards should not automatically receive bank-payment or accounting-configuration authority, and a read-only reviewer should not need an approval or payment role.
Treat Domain Admin as a separate, high-impact assignment rather than a synonym for Workspace admin. Domain controls can affect members, groups, company-wide rules, card feeds, and other settings documented on the current surface. A bookkeeper or external support provider may have a valid business need, but that access needs an internal sponsor, explicit scope, independent approval, and an end condition. Maintain at least two qualified owners for continuity without multiplying standing broad access.
- Filter the live workspace member list by role and compare it with the approved access register.
- Separate people, card, payment, audit, workspace, domain, billing, bank, and accounting duties in the review.
- Use individual company-controlled identities; never share an owner, admin, payer, or authenticator account.
- Time-limit vendor access and review it again when the engagement, plan, workspace, or assigned duty changes.
- Record why broad access remains necessary and which narrower role or compensating review was considered.
Govern Company Identity, Domain Groups, TOTP 2FA, and Recovery
Use a verified company domain and current Domain Group controls where they fit the firm's operating model. Expensify's current New Expensify guidance describes group options that can set a default group, strictly enforce workspace rules, require a company email as the primary contact method, restrict workspace creation or removal, set a preferred workspace, and route Expensify Card transactions to that workspace. Test group assignment for new employees, transfers, vendors, and exceptions rather than assuming every account joins the intended group automatically.
Current Expensify Classic documentation describes two-factor authentication as time-based one-time password authentication through an authenticator app. An individual can enable it, and a Domain Admin can require it for domain members. Recovery codes are generated during setup and must be copied to an approved secure location; they do not belong in a help-desk ticket, shared drive, chat, or manager's email. Test enrollment, a normal login, clock-skew troubleshooting, and controlled recovery before requiring 2FA at scale.
Do not invent an authentication stack that the current product documentation does not support. Expensify states that domain-level 2FA cannot be enabled for domains using SAML, so a firm using or planning SAML should review the current vendor guidance and design one coherent access path. Current reset guidance also places conditions on a Domain Admin reset, including company-domain identity and the resetting admin's own 2FA. Verify identity independently and record the reset event without collecting the user's authenticator secret or recovery code.
- Require company-controlled primary contact information when the domain-group design supports it.
- Store recovery codes in the firm's approved secret or recovery process with access logging and separation from the everyday device.
- Keep at least two trained Domain Admins, but review both for continuing business need and strong authentication.
- Treat a 2FA reset as a security event with identity verification, authorization, timestamp, owner, and post-reset confirmation.
- Re-check official Expensify guidance before combining SAML, domain requirements, or a changed login surface.
Control Cards, Limits, Spend Rules, Payments, and Administrative Changes
Card authority is financial access. Record who may issue, assign, freeze, deactivate, or replace Expensify Cards and who may manage other connected company cards. For every issued card, record the business owner, cardholder, workspace, limit type, approved amount, merchant or category spend rule when used, purpose, start and end condition, and exception approver. Do not reproduce the primary account number, security code, or full card image in the control record.
Current Expensify guidance describes Smart Limit, monthly limit, and fixed-amount behaviors on relevant card surfaces, plus workspace spend rules that can allow or block transactions based on merchant, spend category, and amount. Choose a control from the real purchasing pattern. A recurring software subscription, one-time filing fee, and travel card should not inherit the same limit merely because the users share a department. Test a permitted transaction, a controlled decline, limit refresh behavior where applicable, and the escalation path without weakening the rule to solve one urgent purchase.
Separate card administration from payment and bank control. A Card admin can manage documented card functions on eligible workspaces; a Payments admin can manage payment settings, but paying still depends on access to the relevant shared bank account. High-impact changes such as bank sharing, authorized payer, reimbursement account, settlement ownership, broad card limits, or automatic payment thresholds should require a ticket, independent approval, and post-change evidence. Review activity and report history after the change rather than relying only on the request.
- Review unused, dormant, excessive, temporary, and exception-based cards and limits on a defined cadence.
- Freeze or deactivate a card promptly for loss, suspected fraud, departure, or ended business purpose using the current supported workflow.
- Investigate pending expenses, unsubmitted reports, disputes, settlement, and reconciliation before declaring a card closed.
- Require independent confirmation for bank, payer, settlement, and broad-limit changes.
- Preserve the non-secret card identifier, owner, approval, change history, and financial follow-up needed for audit.
Review Access and Offboard Without Breaking Finance Operations
Perform a documented access review at least on the firm's risk-based schedule and after a role change, vendor change, incident, plan migration, merger, or administrator departure. Compare the approved register with workspace members and roles, approvers, domain members and groups, Domain Admins, 2FA status where visible, cards and limits, bank sharing, payer and reimburser duties, billing ownership, connected accounting configuration, preferred exporter, and outstanding reports. Resolve every unexplained or unowned path.
Sequence administrative offboarding around dependencies. Expensify's current admin checklist emphasizes assigning a new Workspace admin and, when applicable, Domain Admin; sharing and verifying the business bank account; transferring billing and payment responsibilities; updating reimbursement and card settlement ownership; and preserving accounting integration continuity before removing the former administrator. Validate the successor's access and a real low-risk operational task before revoking the departing person's authority.
Then close the individual's remaining paths: freeze or deactivate assigned cards, reassign approvals and open reports, remove workspace membership, close domain access when appropriate, revoke bank sharing, remove admin and integration duties, recover managed devices, and preserve audit evidence. Use [Software Support guidance](https://www.allmsp.com/category/software-support/) and [Contact ALLMSP](https://www.allmsp.com/contact-us/) when identity, devices, accounting integrations, or administrator continuity require coordinated technical work.
- Use an HR-triggered checklist with named owners, deadlines, verification evidence, and exception escalation.
- Do not remove the only admin, bank owner, settlement owner, reimburser, billing owner, or preferred exporter before a successor is proven.
- Reconcile open expenses, reimbursements, card activity, exports, and disputes that belong to the departing person.
- Review recent role, bank, card, payment, and integration changes for unusual activity before closure.
- Confirm access removal from an independent administrator view and retain only policy-required evidence.
Vendor documentation and ALLMSP resources
- Expensify: Managing Workspace Members
- Expensify: Two Factor Authentication
- Expensify: Add Domain Members and Admins
- Expensify: Create and Manage Domain Groups
- Expensify: Workspace Rules
- Expensify: Admin Card Settings and Features
- Expensify: Cardholder Settings and Features
- Expensify: Admin Offboarding Checklist
- Expensify: Login Troubleshooting
- ALLMSP: Expensify Software Support
- ALLMSP: CPA and Financial Firms
- ALLMSP: Software Support
- ALLMSP: Cybersecurity
- ALLMSP: Contact
Frequently Asked Questions
What Expensify workspace roles should a CPA firm review?
Review Member, Workspace admin, and every scoped role available to the firm's plan, including Card admin, People admin, Payments admin, Auditor, or Editor where the current official description applies. Map each role to concrete duties and validate it with a test account. Also review approver status, because approval authority can exist alongside a basic member role. Domain, bank, billing, card-feed, and accounting authority require separate review even when the same person holds them.
Is an Expensify Domain Admin the same as a Workspace admin?
No. A Workspace admin manages broad settings for a workspace, while Domain Admin functions apply to company-wide domain controls documented on the relevant Expensify surface. Cards, domain groups, SAML, member closure, or card feeds can create domain-level dependencies. Record the roles separately, grant each only for a current business need, and ensure succession for both. A person may legitimately hold both, but one title should never be used as proof of the other.
Who should be allowed to issue or change Expensify Cards?
Limit card issuance, assignment, limits, spend rules, freeze, deactivation, and replacement to the narrowest current role and approved administrators. Require a business owner, cardholder, purpose, workspace, limit type and amount, start and end condition, and exception approver. Separate routine card administration from bank, payer, and settlement ownership where practical. Review dormant or excessive cards and preserve non-secret change evidence without storing full card details.
What kind of two-factor authentication does Expensify currently document?
Current Expensify Classic help documents authenticator-app, time-based one-time password authentication. The user enters a six-digit code generated by an authenticator app, and recovery codes are created during setup. Train users on enrollment, secure recovery-code storage, device-clock troubleshooting, and the approved reset path. Do not describe push approval, SMS, passkeys, or hardware keys as Expensify's TOTP behavior unless current official documentation for the firm's surface explicitly adds them.
Can a firm enable Expensify domain 2FA and SAML together?
Expensify's current two-factor-authentication article states that domain-level 2FA cannot be enabled for domains using SAML. Treat that as a design constraint to verify against the current tenant and documentation before changing either control. Do not attempt to stack settings by assumption. Document the chosen authentication path, identity owner, recovery process, test cases, and rollback, then validate normal and recovery access with pilot users.
How should Expensify recovery codes and 2FA resets be governed?
Recovery codes should go directly into the firm's approved secure recovery process, separate from the everyday device, with access logging and restricted custodians. Never paste them into chat, email, tickets, or shared documents. For a reset, independently verify the user, require authorized approval, confirm the resetting administrator meets Expensify's current conditions, record non-secret evidence, and require immediate re-enrollment. Review the event for suspicious access or recent administrative changes.
How should Expensify card limits be selected and reviewed?
Choose the documented limit type and amount from the real purchasing purpose, transaction pattern, approval cadence, and financial exposure. Current guidance describes Smart Limit, monthly, and fixed-amount behaviors on relevant card surfaces, plus spend rules by merchant, category, and amount. Test permitted and denied scenarios, define an escalation path, and review unused, temporary, excessive, or frequently overridden limits. An urgent purchase is not a reason to remove a control permanently.
How often should Expensify access be reviewed?
Use a risk-based cadence and trigger additional reviews after hiring, departure, role or vendor changes, plan or interface migration, security incidents, bank changes, accounting changes, mergers, and administrator turnover. Compare live workspace, domain, card, bank, billing, approval, and integration state with the approved register. High-impact and temporary access may need more frequent review than ordinary members. Every unexplained owner, role, card, or dependency should receive a documented decision.
What is the safe order for offboarding an Expensify administrator?
First identify and transfer Workspace admin, Domain Admin, billing, bank sharing, default reimbursement, card settlement, card administration, preferred exporter, and accounting integration responsibilities. Verify the successor and perform a low-risk operational test. Then freeze or deactivate cards, reassign approvals and reports, remove workspace and domain access, revoke bank sharing, recover devices, and review recent activity. Removing the sole owner first can interrupt payments, billing, cards, or accounting access.
What evidence should an Expensify access review retain?
Retain the approved access register, live member and role snapshot, domain and group review, strong-authentication status where available, card and limit inventory, bank and payment ownership, billing owner, accounting and preferred-exporter ownership, open exceptions, decisions, approvers, timestamps, and confirmation of removals. Redact personal and financial details and never preserve secrets or recovery codes in the review file. Align retention with firm policy, client obligations, and applicable regulation.


