02Start here

Users & security

Every company file has its own separate list of users — logging into one company doesn't give access to another.

Roles

RoleTypical use
AdministratorFull access, including managing users and other administrators
AccountantFull accounting access, typically for an outside CPA or bookkeeper
AdvisorBroad read/advise access without full administrative control
StaffDay-to-day data entry, scoped by permissions
Read OnlyView and report access with no editing rights

Manage all of this from Company → Users & Security: add users, assign roles, reset passwords, or deactivate accounts. An Administrator can never remove their own Administrator access — only another active Administrator can do that, and LedgerDesk will never let a company be left with zero administrators.

For finer control than the five built-in roles, create a named permission profile with action-level permissions and, where relevant, dollar approval limits. This is also where Branch-specific permissions live — see Dimensions & Branches.

Login behavior

  • LedgerDesk remembers the last successfully authenticated username per company — never the password — and prefills it at your next login.
  • Repeated failed logins are throttled to slow down guessing attempts.
  • Every meaningful action is written to the audit history, searchable from Reports.

Single-user vs. shared mode

By default, a company file is single-user: one person, one editing session. An Administrator can turn on shared mode from the File menu, which allows one editing session plus additional read-only viewers at the same time, without compromising the integrity of the encrypted file.

Closing dates

Set a closing date (Company → Set Closing Date) once a period is finalized — after your accountant files a quarter, for example. Any attempt to add, edit, or void a transaction dated on or before the closing date requires the closing-date password. The last 20 closing-date changes are kept in a dedicated history view.

Recovery keys

If an administrator password is forgotten, the recovery key generated at company creation is the only way back in. There is no other recovery path — this is by design, since the company file is encrypted. Keep it somewhere separate from the file itself.