A FreshBooks account can expose billing, payments, expenses, bank connections, accounting, reports, clients, projects, staff time, connected apps, and settings. Giving someone access because they are a manager, accountant, or contractor is not precise enough. FreshBooks' current permission matrix includes several roles with materially different reach, and some roles can be modified by client access or project-manager settings. A role should be selected from documented tasks and tested behavior.
FreshBooks changed its login security during 2025. Current official guidance says two-factor authentication is mandatory for all FreshBooks accounts that sign in with an email and password, uses email verification by default, supports an authenticator app, and cannot be permanently turned off. It also says Apple and Google sign-ins do not require FreshBooks' own 2FA. Those distinctions must appear in the firm's access inventory and recovery plan.
This guide gives Georgia CPA and financial firms a current model for roles, accountant and client access, mandatory 2FA, remembered devices, audit evidence, data protection, joiner-mover-leaver controls, and incident recovery. ALLMSP can coordinate identity, endpoint, access-review, documentation, and vendor-support work while firm ownership and compliance advisers decide financial authority, professional obligations, retention, and client notification.
Key decisions at a glance
- Use FreshBooks' current Owner, Admin, Manager, Employee, Accountant, Accountant – Full Access, Contractor, and Unassigned roles from the official permission matrix rather than relying on old role names.
- FreshBooks currently requires 2FA for accounts signing in with an email and password; email verification is the default, an authenticator app is supported, and the control cannot be permanently disabled.
- Sign in with Apple or Google does not use FreshBooks' own 2FA prompt, so the firm must govern the external identity and its recovery instead of assuming the FreshBooks code protects that route.
- Client accounts, team Client Access, accountant roles, full-access accountant roles, and connected applications are distinct paths with different plan, billing, and permission consequences.
- The FreshBooks Audit Log covers invoice and expense changes within documented date limits; offboarding must also address projects, client ownership, apps, processors, devices, sessions, email, exports, and external identity systems.
Choose Current FreshBooks Roles From Tasks and Plan Boundaries
Build an access matrix around actions: manage clients, estimates, invoices, payments, expenses, projects, time, accounting, reports, apps, team members, items, bank connections, payroll, settings, subscription billing, and refunds. FreshBooks' current documentation lists Owner, Admin, Manager, Employee, Accountant, Accountant – Full Access, Contractor, and Unassigned. Record the approved role, client or project scope, sponsor, start and end date, device, login method, and financial limits for every person.
Do not treat Accountant and Accountant – Full Access as synonyms. The standard Accountant role has limited access to specified financial sections and notable restrictions, while Accountant – Full Access can reach most of the account but still has documented limits around online-payment settings, refunds, payroll, tax and financial information, and billing circumstances. FreshBooks currently allows up to ten standard accountants at no extra cost on Plus, Premium, and Select plans; verify the subscribed plan and current pricing before designing the staffing model.
Managers, employees, and contractors also differ. Contractors use their own separate FreshBooks account and can see shared project and time information; Unassigned stores a team profile without account access. Client Access for managers and employees is available only for certain users and Select plans according to current help text. Project Manager adds project-level authority. Test required and prohibited actions from each user's actual session instead of assuming a title conveys the intended boundary.
- Give each person an individual identity; prohibit shared owner, administrator, accountant, client, and contractor credentials.
- Test invoice, payment, refund, bank-connection, accounting, report, app, team, settings, and subscription actions that matter to the role.
- Use client and project scope only after confirming eligibility and verifying which records and actions the user can actually reach.
- Time-limit temporary support, seasonal staff, contractors, and external accountants, with a named sponsor who reviews renewal.
- Reassess permissions after plan changes because a feature becoming available does not mean every existing role should inherit its use.
Operate Mandatory 2FA, Remembered Devices, and Login Recovery Precisely
For direct FreshBooks email-and-password sign-in, current documentation says 2FA is required and cannot be permanently disabled. Email verification is automatically active by default, and a compatible time-based authenticator app can be configured instead. The six-digit code is valid for ten minutes. Require every user to identify the email mailbox or authenticator device that controls the factor, protect that system separately, and never read or send a code through support chat.
FreshBooks can remember a device for thirty days, while a session without that choice may remain active for several days. The Account Profile includes an option to log out of FreshBooks on all devices, which also removes remembered devices for that identity. Build checks for shared browsers, browser profiles, managed phones, device replacement, and remote support. A remembered workstation in a departed employee's possession can remain an access path even when nobody knows the password.
Handle Apple and Google sign-ins as separate authentication routes. FreshBooks says those sign-ins do not require its own 2FA prompt, so the firm's security depends on the Apple or Google account, its factors, device and session controls, and recovery. If an authenticator phone is lost, FreshBooks directs the user to Support for a 2FA reset. Document verified support contact, identity proof, mailbox continuity, owner availability, and a safe replacement-device exercise before an emergency.
- Inventory whether each person uses FreshBooks credentials, Apple sign-in, Google sign-in, or more than one usable route.
- Prefer an authenticator application over mailbox-only verification when it fits the firm's risk decision and recovery capability.
- Protect the email account used for verification with its own strong authentication, session review, forwarding controls, and recovery owner.
- Prohibit screenshots of QR setup secrets, verification codes, passwords, recovery correspondence, and client or payment screens.
- Review remembered devices and sign out all devices for the affected identity after loss, suspicious access, role change, or departure.
Separate Client, Accountant, Card-Data, App, and Audit Boundaries
A client does not need a full business-user role to receive and pay an invoice. FreshBooks says clients can view and pay shared documents without creating an account, while a free client account lets a primary client save and view documents, comment, collaborate on invited projects, save payment information, and pay multiple outstanding invoices. Treat the client account, client contacts, shared links, saved payment choices, and the firm's team-member Client Access feature as different controls.
Keep cardholder data inside the payment fields designed for it. FreshBooks states that it is PCI compliant and that payment data is handled through the appropriate payment paths; it also warns against entering card information in notes or other account fields. Do not paste card data into client internal notes, invoice terms, project discussions, screenshots, tickets, or exports. Restrict Advanced Payments and online-payment administration according to current role and add-on eligibility.
Use the Audit Log for the evidence it actually provides. FreshBooks documents invoice changes beginning May 24, 2024 and expense changes beginning September 11, 2024, with user and system changes, filters, and CSV export. It is not described as a universal login, role, bank, project, app, or report audit trail. Combine it with team records, project membership, processor evidence, app ownership, managed-device and identity logs, approvals, and exports according to the firm's retention policy.
- Document who may invite client contacts, share project access, change saved-payment behavior, and answer client account support requests.
- Use Accountant or Accountant – Full Access only after reviewing current section-level permissions, limitations, plan, billing, and payroll needs.
- Review connected apps as separate access paths because an app can retain data or capability after a person's team role changes.
- Export Audit Log evidence only when needed, protect the CSV, preserve filter and time-zone context, and do not claim it covers unlogged sections.
- Align FreshBooks records with professional confidentiality, privacy, payment, tax, legal, insurance, and client-agreement requirements.
Offboard Every FreshBooks and External Dependency, Then Verify
Prepare offboarding before the end date. Identify the person's FreshBooks role, projects, clients, time and expense approvals, accountant status, reports, connected apps, payment or payroll authority, support relationship, login method, email, managed devices, browser sessions, password manager, shared files, exports, and ownership duties. Assign successors and complete pending billing or accounting review under normal approval; do not preserve access merely because a workflow lacks an owner.
FreshBooks instructs owners to change a team member to Unassigned to remove access. Verify the change from the user's identity and review whether the subscription still includes an unused paid team seat that should be removed through the appropriate billing process. Separately transfer projects and client duties, disconnect or reassign apps, change processor and bank contacts, recover devices, close email and external identity sessions, protect exports, and use the identity's logout-all-devices control where available and appropriate.
Treat owner transfer as a high-risk exception. FreshBooks notes that all businesses associated with an owner's login transfer together, subscription billing must be updated, and payment-gateway ownership must be addressed with the gateway; Support may be required to separate businesses or billing first. After any departure or transfer, review relevant Audit Log evidence, test denied access and required successor actions, watch invoices and payments, and record completion without retaining passwords or codes.
- For movers, compare old and new roles, client scope, projects, apps, reports, payment rights, and external identities side by side.
- For leavers, set FreshBooks access to Unassigned and separately remove email, Apple or Google, devices, browsers, apps, processors, and shared storage.
- Reassign unbilled time, expense review, client communication, invoice approval, payment exceptions, reconciliation, payroll, and support cases.
- Verify both denial and continuity: the former user cannot enter, and the successor can complete required work without using the old identity.
- Run a post-offboarding review for suspicious changes, unowned apps, remembered devices, failed billing jobs, missing client communication, and exported data.
Vendor documentation and ALLMSP resources
- FreshBooks: Team member permissions
- FreshBooks: Invite and manage team members
- FreshBooks: Two-factor authentication
- FreshBooks: Log in and manage remembered devices
- FreshBooks: Account profile and login
- FreshBooks: Client accounts
- FreshBooks: Audit Log report
- FreshBooks: PCI compliance
- FreshBooks: Apps
- ALLMSP FreshBooks Software Support
- ALLMSP Software Support
- ALLMSP Managed IT Services
- ALLMSP Cybersecurity Services
- ALLMSP Cloud Computing and Migrations
- ALLMSP CPA and Financial Firm Resources
- Contact ALLMSP
Frequently Asked Questions
Which team roles does FreshBooks currently document?
FreshBooks currently documents Owner, Admin, Manager, Employee, Accountant, Accountant – Full Access, Contractor, and Unassigned. Each has section-level permissions and limitations. Choose from verified tasks, client or project scope, plan eligibility, financial authority, and required prohibited-action tests.
Is a FreshBooks Accountant the same as Accountant - Full Access?
No. The standard Accountant role has limited access to specified financial areas, while Accountant – Full Access reaches most of the account but still has documented restrictions. Review current permissions, payment, payroll, tax, billing, and plan implications before inviting either.
Does FreshBooks require two-factor authentication?
Current FreshBooks guidance says 2FA is mandatory for accounts logging in with an email and password and cannot be permanently disabled. Email verification is active by default, and users can configure a compatible time-based authenticator application instead.
Does FreshBooks 2FA apply to Sign in with Apple or Google?
FreshBooks says its own 2FA prompt is not required for Apple or Google sign-in. The firm must govern the external Apple or Google identity, its factors, sessions, devices, recovery, and offboarding rather than assuming a FreshBooks verification code protects that route.
How long can FreshBooks remember a device?
A user can choose Remember this device for thirty days according to current FreshBooks guidance. Without that option, a session may still remain active for several days. Review managed browsers and use the logout-all-devices control for that account after risk events or departures.
What should happen if a FreshBooks authenticator phone is lost?
FreshBooks directs users who lost access to the authenticator app to contact Support for a 2FA reset. The firm should protect the verification mailbox, know the support path, verify identity safely, remove remembered devices, and document replacement without sharing codes.
What is the difference between a FreshBooks client account and Client Access?
A client account is the separate client path for viewing, paying, commenting, and collaborating. Team-member Client Access limits eligible managers or employees to selected clients and is available only for certain users and Select plans. Test and document them separately.
What does the FreshBooks Audit Log cover?
The Audit Log records invoice and expense changes by users and FreshBooks system actors, with documented history beginning May 24, 2024 for invoices and September 11, 2024 for expenses. It is not a universal log of every login, role, app, bank, or project action.
How is access removed for a departing FreshBooks team member?
Change the team member to Unassigned, then verify denial. Separately transfer projects and client work, remove paid-seat needs, apps, email and external identity sessions, devices, browsers, processor or bank authority, reports, exports, shared storage, recovery contacts, and support ownership.
How can ALLMSP strengthen FreshBooks access for a Georgia financial firm?
ALLMSP can map roles, test permissions, coordinate mandatory 2FA and managed-device controls, document client and accountant paths, review connected apps and audit evidence, execute offboarding, and coordinate recovery with FreshBooks and external identity or payment providers.


