Wave has two access layers that organizations often blur together. The account owner controls the Wave login and owner profile, while collaborators receive roles on particular business profiles. A trusted bookkeeper may need accounting access to one client but no visibility into another; a payroll specialist may need payroll without purchases or reports; an external reviewer may need read-only financial access. Start with a person-by-profile register that records the relationship, approved role, optional payroll or invoice capability, business owner, start date, review date, and termination trigger.
The role name alone is not an adequate control. Wave's current permission table says role permissions cannot be customized, certain sensitive pages are unavailable to invited users, and only Pro subscribers can invite Admins, Editors, and Viewers. Admin, Editor, Payroll Manager, and Viewer do not form a simple ladder. For example, an Admin has broad accounting, reporting, integration, user-management, and export capabilities but cannot delete the Wave account, archive a business, or edit the owner's user profile; a Payroll Manager can manage payroll without general accounting access. Review the full capability set and any optional access before approval.
Login security also belongs to each person. Wave recommends collaborators use their own credentials instead of sharing the owner login, and 2FA can use an authenticator app or text code with one-time recovery keys. Current Wave guidance says collaborators do not have to activate 2FA unless they have payroll-management access, although they may choose it. A sound policy can be stronger than the platform minimum: require individual logins, protect recovery material, prohibit shared codes, and document how ownership and access will be recovered without turning a secondary owner email into an informal group account.
Key decisions at a glance
- Use individual collaborator logins for ongoing work and reserve the account owner identity for decisions that genuinely require owner-level authority.
- Wave collaborator permissions are preset and cannot be customized, so compare the complete role table with real duties before inviting anyone.
- Only Pro subscribers can invite Admins, Editors, and Viewers, while payroll-related access has separate availability and stronger 2FA implications.
- Assume invited users can see sensitive bank and card transaction histories even though they cannot see online-banking passwords.
- Offboarding must cover each invited profile, owner email state, 2FA recovery material, payroll authority, integrations, exports, and retained evidence.
Separate the Wave owner identity from collaborator duties
Document which human being and managed mailbox own the Wave account, then distinguish that authority from day-to-day work on each business profile. The owner should control primary-email changes, account-level recovery, high-impact business lifecycle decisions, and the invitation policy. Routine invoice entry, bookkeeping, payroll, review, and reporting should use individual collaborator accounts wherever a suitable role exists. This preserves attribution, reduces dependence on one credential, and avoids exposing every profile tied to the owner login when a person only needs one business.
Treat additional owner email addresses as a transition item, not a durable multi-user design. Wave's current help article states that sign-in using additional email addresses will end on August 19, 2026, and also explains that multiple owner emails tied to a password share that password. Inventory every additional owner address now, identify who actually uses it, move ongoing workers to appropriate collaborator roles, and establish the intended primary owner email. Do not assume deleting an extra email transfers ownership; follow the documented add, verify, select-primary, and old-address removal sequence.
Invite collaborators separately to every business they are authorized to use. Wave says an invited user can see only the business or personal profile to which that invitation applies, which is valuable segmentation only if administrators resist broad convenience access. Require a named request, business owner approval, role justification, optional-capability decision, expiry or review date, and acceptance confirmation. Pending invitations should be monitored and cancelled when the recipient, email domain, or engagement changes before acceptance.
- Maintain one authoritative owner record and a separate person-by-business collaborator register.
- Migrate ongoing work away from additional owner-email sign-in before the documented Wave transition date.
- Prohibit shared owner credentials, shared one-time codes, and recovery keys stored in general bookkeeping folders.
- Require a fresh invitation and approval for each business profile rather than cloning access across clients.
Test preset roles against real accounting and payroll duties
Build a role test from Wave's current table rather than from role names. Admin has full sales, purchases, accounting, payroll, reports, integrations, collaborator management, and data export, subject to documented bank and owner-setting limits. Editor has broad purchases, accounting, and reporting access, with optional invoice-sending and payroll capabilities, but no integrations, user management, or data export. Viewer can see sales, purchases, accounting, and reports with documented restrictions and may receive optional payroll access. Payroll Manager focuses on payroll and lacks general accounting, bank, and reporting access.
Make optional access an explicit risk decision. Giving an Editor invoice-sending access can let that person send from connected owner email addresses, and enabling payroll for an Editor or Viewer changes the sensitivity of the role. Wave's table also says an Admin can update bank accounts used for online payments and payroll but cannot connect a new bank for transaction imports. Test the exact subscribed business with harmless sample activity and capture allowed and denied results, because plan, country, payroll enrollment, online payments, and role options influence what the user sees.
Do not describe collaborator access as harmless because online-bank passwords are hidden. Wave explicitly warns that invited users can see sensitive bank and credit-card transaction histories. That can reveal payroll amounts, suppliers, customer payments, travel, healthcare, legal matters, or owner activity even when the user cannot access banking credentials. Minimize profiles and roles, restrict exports and local downloads, define approved devices and storage, and make confidentiality expectations part of the invitation and periodic review process.
- Test Admin, Editor, Payroll Manager, and Viewer with the exact plan and optional toggles used by the business.
- Treat payroll, invoice sending, integrations, user management, and data export as separately approved capabilities.
- Record both allowed and denied test cases so reviewers understand the practical boundary of each role.
- Classify transaction history and downloaded reports as sensitive even though bank passwords remain inaccessible.
Protect individual logins, recovery paths, banks, and integrations
Require every user to activate and maintain a security method appropriate to the risk, even where Wave does not mandate it. Wave 2FA supports an authenticator app or text messages and prompts for a one-time code at login. Recovery keys are displayed during setup, can each be used once, and should never be shared. Store owner recovery material in a controlled vault with documented emergency access; collaborators should protect their own recovery keys under the organization's policy. Test recovery without exposing the actual code or key in tickets, screenshots, chat, or workpapers.
Account for Wave's payroll distinction. Current guidance says collaborators are required to activate 2FA when they have payroll-management access, while other collaborators may activate it voluntarily. Include 2FA status in the access register, make payroll enablement contingent on an individual protected login, and remove payroll before or with access termination. When recovery keys are regenerated, Wave says the prior set becomes invalid, so update the custody record and destroy superseded copies instead of leaving multiple uncertain emergency sets.
Extend the review beyond the login screen. Wave describes connected transaction-import access as read-only through its bank-connection provider, but transaction data remains sensitive. Admins may also have integration and export authority, and Wave's developer portal supports applications, tokens, and webhooks for custom workflows. Inventory connected banks, active integrations, developer applications, token owners, export locations, verified email addresses, and devices. Remove or rotate each path when its owner changes, and avoid placing secrets or financial payloads in screenshots and support records.
- Require individual 2FA for owners and privileged collaborators and enforce Wave's payroll-access requirement.
- Vault owner recovery keys, prohibit sharing, record tests, and invalidate superseded sets when keys are regenerated.
- Inventory connected banks, integrations, developer applications, webhooks, tokens, verified emails, and export destinations.
- Keep codes, recovery keys, bank data, payroll details, and customer information out of tickets and visual evidence.
Review access periodically and execute evidence-backed offboarding
Reconcile access with employment, contractor, client-engagement, and owner records on a defined schedule. Review active and pending collaborators for every business; assigned roles and optional payroll or invoice access; owner and additional email state; 2FA status; bank, integration, developer, and export privileges; and the last business need. Ask the profile owner to attest to exceptions. Pay special attention to outside accountants with many client invitations, seasonal payroll staff, generic mailboxes, dormant Admins, and users whose role changed without an updated request.
Use a coordinated termination checklist. Remove the collaborator from each business profile, verify pending invitations are gone, revoke payroll and invoice capabilities, reassign recurring work and close tasks, change the primary owner email when ownership legitimately transfers, remove obsolete owner addresses, rotate exposed recovery material, and revoke integration or developer credentials the departing person controlled. Preserve necessary reports and exports before removal through an authorized Owner or Admin, since Editors and Viewers do not have data-export access under the current role table.
Treat business archiving as a lifecycle operation, not a shortcut for one user's removal. Wave says archiving removes invited users and hides the business without deleting its data, but connected banks, integrations, active subscriptions, online payments, and recurring invoices may have to be addressed first. If the business remains active, remove the person rather than archive the profile. Close with a second-person verification, time-stamped evidence, open exception list, and confirmation that the former user cannot reach the business through another invitation, owner email, integration, or retained secret.
- Compare Wave users and privileges with authoritative people, engagement, and owner records at least quarterly.
- Remove access from every business profile and terminate related payroll, integration, export, email, and recovery paths.
- Preserve authorized continuity evidence before removing a person who owns recurring close or export duties.
- Require independent verification that no invitation, owner address, token, or delegated workflow remains usable.
Vendor documentation and ALLMSP resources
- Wave: User types and permission levels
- Wave: Invite or remove collaborators
- Wave: Use two-factor authentication
- Wave: Generate new 2FA recovery keys
- Wave: Additional owner email addresses
- Wave: Change the owner email address
- Wave: Change or update password
- Wave: Archive or restore a business
- Wave: Accounting and read-only bank connections
- Wave: Download account data
- Wave: Developer portal
- ALLMSP Cybersecurity Services
- ALLMSP Software Support
- ALLMSP Managed IT Services
- ALLMSP IT Consulting
- ALLMSP Data Backup and Recovery
- ALLMSP Cloud Services
Frequently Asked Questions
Can Wave collaborator permissions be customized?
No. Wave's current role guidance says collaborator permissions cannot be customized. Select the closest preset role, decide any optional invoice or payroll capability explicitly, and test the resulting access. If the preset role exposes more than the person should have, change the operating process or keep that duty with a more appropriate authorized user.
Which Wave plans can use Admin, Editor, and Viewer collaborators?
Wave currently limits Admin, Editor, and Viewer invitations to Pro Plan subscribers. Payroll Managers are available on all plans, and United States owners may have a separate Block Advisors tax-pro role. Verify the active plan, country, subscribed services, and role options in the specific business before approving an access design.
Can Wave collaborators see bank information?
Invited users can see sensitive bank and credit-card transaction histories within an authorized business profile, but Wave says they cannot access online-banking passwords. Treat the transaction history as confidential financial data. Restrict profiles and roles, control downloads and screenshots, and include transaction visibility in the user's confidentiality and device requirements.
Does every Wave collaborator have to enable 2FA?
Wave says collaborators do not have to activate 2FA unless they have payroll-management access, although they may enable it themselves. An organization can set a stronger standard. Requiring individual 2FA for owners, Admins, payroll users, and other sensitive roles reduces reliance on password-only access and improves accountable recovery.
Should several people share the Wave owner login?
No. Wave recommends that people use individual collaborator accounts instead of sharing login credentials, and a 2FA code can be delivered through only one method and device at a time. Shared owner access weakens attribution, complicates recovery, and exposes every linked profile. Reserve the owner identity for owner-only responsibilities.
What is the difference between a Wave owner and an Admin?
The owner controls the Wave account and primary profile identity. An Admin has broad business access, including accounting, reports, integrations, user management, and export, but Wave documents owner-level limits such as no account deletion, business archiving, owner-profile editing, or new bank connection for transaction imports. Preserve that distinction in approvals and recovery plans.
What should businesses do about Wave additional owner email addresses?
Wave's current article says sign-in through additional owner email addresses ends on August 19, 2026. Inventory those addresses, identify real users, move ongoing workers to suitable collaborator roles, and establish the correct primary owner email. Do not use additional owner addresses as a replacement for individual, profile-specific access.
How should Wave payroll access be controlled?
Approve payroll separately from the base role, require an individual login with 2FA, and test which payroll actions and data the user can reach. Review payroll access whenever duties or employment change. Remove it during offboarding and keep payroll exports, employee details, codes, and recovery material out of general accounting folders and support screenshots.
Who can export data from a Wave business?
Wave's current permission table gives data-export access to the Owner and Admin, while Editor and Viewer roles do not have it. Treat export permission as a high-impact capability because files may contain transactions, vendors, customers, bills, receipts, and region-dependent payroll data. Control the destination, retention, encryption, and approved purpose.
What should a Wave offboarding checklist verify?
Remove the person from every business profile, cancel pending invitations, revoke optional payroll and invoice access, reassign close work, address owner email changes, rotate exposed recovery material, and revoke integration or developer credentials they controlled. A second reviewer should confirm that no invitation, owner address, token, export path, or retained secret still provides access.


