ALLMSP Blog

Melio Access and Approval Security: Roles, Permissions, Owners, and Offboarding

Melio access control is more than choosing a role name. This guide connects current plan-dependent permissions, scheduler and approver rules, owner/admin coverage, vendor-detail risk, account security, audit evidence, incident response, and offboarding.

Melio access-approval-security-roles-offboarding support for a Georgia business

A payment platform can have individual accounts and still concentrate incompatible authority. A user may be able to create a vendor, enter a bill, add a funding method, schedule a payment, or administer others depending on role and plan. A senior title does not automatically create separation of duties, and a narrow role name does not prove that a risky action is denied. Security begins with tested tasks and negative test cases.

Melio's current public permissions matrix lists six roles: Owner, Admin, Accountant, Contributor, Approver, and Viewer. It also distinguishes plan availability. Go permits access to the business owner only, while Core and above support team participation. The matrix shows detailed capabilities, but separate workflow guidance may describe who can manage a particular configuration surface. Verify the live tenant and subscription whenever delegating a control-sensitive task.

For CPA firms, access exists at both firm and client layers. Removing a person from a firm's team may not remove all client relationships or payment authority, and reassignment may be necessary. Build a current inventory of identities, assigned clients, entities, roles, approval steps, payment methods, vendor-change rights, accounting connections, and report access. That inventory becomes the basis for onboarding, periodic review, incident containment, and offboarding.

Key decisions at a glance

  • Confirm subscription eligibility before designing team access: current guidance limits Go to the business owner and enables team roles on Core and above.
  • Map Melio's Owner, Admin, Accountant, Contributor, Approver, and Viewer roles to tested allowed and denied actions.
  • Explicitly include Owner and Admin schedulers when approval policy requires their payments to receive independent review.
  • Treat vendor delivery-detail changes, payment-method changes, user administration, and ownership transfer as privileged events with evidence.
  • Offboarding must remove Melio access, replace workflow ownership, review recent financial activity, and preserve the audit trail.

Translate Melio roles and plan limits into tested duties

Melio support workflow: Translate Melio roles and plan limits into tested duties
Melio support workflow: Translate Melio roles and plan limits into tested duties

Start with a responsibility matrix for vendor creation, vendor edits, delivery methods, bill entry, bill edits, payment scheduling, funding-source use, cancellation, refunds, failed-payment recovery, accounting sync, workflow management, user administration, reports, and client assignment. For every duty, record the business owner, Melio role, allowed entities, approval requirement, backup, and expected denial. Test using representative users rather than an all-powerful setup account.

The current Melio matrix gives the Owner full access and limits ownership to one role. Admin access is broad but cannot change the Owner's role. Accountants and Contributors can perform payables work with different limits; Approvers review assigned items rather than create them; Viewers observe without modifying. Some actions depend on who created the object. Capture these nuances in the access matrix and verify them after plan, role, or product changes.

Protect the ownership layer. Document who can reach the Owner, how ownership transfer is authorized, and which Admins provide operational coverage without sharing credentials. The team-management guide explains that transferring ownership requires assigning the current Owner another role. Test that process in policy and evidence, but do not conduct an unnecessary live ownership transfer merely as a drill. A single-owner dependency needs an approved continuity procedure.

  • Use individual accounts and prohibit shared Owner, Admin, Accountant, or approver credentials.
  • Test both allowed and denied vendor, bill, payment, sync, report, and user-management actions.
  • Scope CPA firm personnel to only the clients and entities required for current engagements.
  • Review plan entitlements before inviting users or promising approval, reporting, or support features.

Engineer payment approvals for self-approval and scheduler coverage

Melio support workflow: Engineer payment approvals for self-approval and scheduler coverage
Melio support workflow: Engineer payment approvals for self-approval and scheduler coverage

Build approval logic from the financial authorization policy and Melio's current supported criteria. The current payment-workflow page describes amount, scheduler, and vendor conditions, along with specific or any approvers and plan-dependent multi-level options. Premium approval workflows are available on Core and above, while multi-level specifics depend on higher plans. Record the plan and interface observed when the rule is approved.

Two current rules deserve explicit tests. First, the person who scheduled a payment cannot approve that same payment. Second, an amount- or vendor-only workflow does not automatically make Owner or Admin scheduled payments require approval; those schedulers or roles must be selected under scheduler criteria. Create tests above, below, and exactly at thresholds for Accountant, Contributor, Admin, and Owner schedulers, then verify the expected approver path and denial behavior.

Control change timing. Current guidance says payments scheduled before a workflow is configured do not become subject to it. Before adding, editing, or deleting a workflow, inventory pending and future-dated payments and decide how they will receive equivalent review. Preserve the signed policy, configuration screenshots, affected-payment list, test evidence, effective time, and rollback decision. Never assume a saved rule retroactively repairs an in-flight exception.

  • Test self-approval denial with each scheduler who may also hold an approval-capable role.
  • Select Owner and Admin schedulers explicitly whenever policy requires independent authorization of their payments.
  • Define backup approvers, maximum coverage duration, and review of actions taken during an absence.
  • Recheck approval behavior after subscription, role, workflow, vendor, or organization changes.

Secure accounts, vendor changes, and audit evidence

Melio support workflow: Secure accounts, vendor changes, and audit evidence
Melio support workflow: Secure accounts, vendor changes, and audit evidence

Require the account-protection controls currently offered for each user and device. Melio's public security guidance describes multi-factor or two-step verification for account access. Pair that platform control with unique email identities, strong managed passwords, protected recovery channels, device security, and prompt review of unexpected sign-in or payment messages. Staff should never share verification codes or approve a challenge initiated by someone else.

Treat vendor and delivery-method changes as financial authority, not clerical maintenance. Current role documentation shows several roles may add vendors or delivery methods, while network vendors can control their own preset delivery preference. Require independent vendor verification, compare the prior and requested values, inspect scheduled payments, and preserve who requested, verified, entered, and approved the change. A message from the same mailbox requesting new bank details is not independent confirmation.

Use evidence that can answer who did what and when. Melio's current Audit Trail report is available to Owners and Admins and records activity such as bills, payments, users, roles, payment methods, vendors, delivery methods, login attempts, and sync events; current guidance notes monthly reports and masks sensitive banking detail. Retain appropriate reports, approval records, vendor-verification evidence, and bank results under the organization's audit and privacy policy.

  • Alert on unexpected user, role, payment-method, vendor-detail, approval, and accounting-connection changes.
  • Verify vendor bank or check-address changes through a trusted channel captured before the request.
  • Limit audit-report downloads and store them as sensitive financial and identity records.
  • Escalate suspicious login, mailbox compromise, vendor change, or payment activity under the incident plan.

Run access reviews, incident containment, and complete offboarding

Review access against authoritative employment, contractor, and engagement records on a schedule proportionate to payment risk. Compare active Melio users, firm membership, assigned clients, roles, approval assignments, workflow creators, Owner and Admin coverage, funding-source visibility, vendor-change rights, accounting sync authority, and recent activity. Investigate dormant identities, generic mailboxes, former client teams, temporary access without expiry, and users whose duties changed.

Contain urgent risk before normal offboarding when termination, compromise, an unauthorized vendor change, or a suspicious payment is involved. Remove or restrict access through the supported workflow, secure the person's email and devices, preserve audit evidence, review pending approvals and scheduled payments, validate vendor and funding changes, and contact Melio, the bank, insurer, counsel, or law enforcement when the incident plan requires it. Do not delete records simply to make the user list look clean.

Complete offboarding as an ownership transfer. Remove the person from relevant business and firm accounts; reassign clients, approval steps, reports, integrations, vendor communications, exception queues, and recurring duties; collect devices or keys; and test critical payment paths. The current team guide describes removing a user, while the accounting-firm guide warns that removing a firm team member does not itself affect clients. Record each layer checked, residual access, recent actions reviewed, and independent sign-off.

  • Trigger access removal from an authoritative HR, contractor, or client-engagement event with a defined deadline.
  • Review recent vendor edits, payments, approvals, exports, user changes, and sync activity before closure.
  • Replace approvers and exception owners before removing a user so payment operations do not stall.
  • Keep a signed checklist showing business account, firm account, client assignment, email, device, and evidence completion.

Frequently Asked Questions

Which team roles does Melio currently document?

Melio's current public permissions materials list Owner, Admin, Accountant, Contributor, Approver, and Viewer. Their permissions differ by action and sometimes by who created an item. Validate the live tenant and subscription, then test both allowed and denied duties before granting production access.

Can a Go plan invite multiple Melio team members?

Current Melio guidance says the Go plan allows access only to the business owner. Team roles and approval workflows require an eligible higher subscription. Confirm current commercial terms and entitlements before designing a staffing or control process around a feature.

How many Owners can a Melio account have?

Current role guidance says there is one Owner role. Document continuity, authorized ownership transfer, and Admin coverage without sharing the Owner credential. If ownership changes, preserve approval and verification evidence and assign the former Owner an appropriate new role.

Can a Melio scheduler approve the same payment?

Current payment-workflow guidance says no: a user cannot approve a payment they scheduled. Test the rule for every scheduler who also has approval-capable access, and prohibit shared accounts that would obscure the identity boundary.

Why might a Melio workflow miss Owner or Admin payments?

If a workflow uses only amount or vendor criteria, current guidance says it applies to Accountant and Contributor schedulers unless Owner or Admin users or roles are explicitly selected under scheduler criteria. Add those schedulers when policy requires independent review and test the resulting route.

Do new Melio workflows cover already scheduled payments?

No. Current guidance says payments scheduled before the workflow was created do not require approval under that new rule. Inventory in-flight and future-dated payments before configuration changes and provide equivalent documented review where necessary.

How should vendor delivery-detail changes be secured?

Separate request, verification, entry, and approval where practical. Confirm the vendor through a known independent channel, compare prior and proposed details, review scheduled payments, record the people involved, and retain appropriate evidence without exposing full bank data.

What evidence can a Melio Audit Trail report provide?

Current Melio guidance says Owners and Admins can download reports covering bills, payments, users, roles, payment methods, vendor and delivery changes, login attempts, and sync activity. Store these reports securely because they contain sensitive operational and identity information.

Does removing someone from a CPA firm's Melio team remove client access?

Do not assume so. Melio's current accounting-firm removal guide says removing a person from the firm's account does not affect clients. Review and reassign every client relationship and business account separately, then test that residual access is gone.

What must a Melio offboarding checklist include?

Remove relevant business and firm access, reassign client work and approval steps, review pending and recent payments, inspect vendor and role changes, transfer exception and reporting ownership, secure email and devices, preserve audit evidence, and obtain independent completion sign-off.

Facebook
LinkedIn
WhatsApp
X
Email
Print
Threads
Reddit

Related Articles