Users & security
Every company file has its own separate list of users — logging into one company doesn't give access to another.
Roles
| Role | Typical use |
|---|---|
| Administrator | Full access, including managing users and other administrators |
| Accountant | Full accounting access, typically for an outside CPA or bookkeeper |
| Advisor | Broad read/advise access without full administrative control |
| Staff | Day-to-day data entry, scoped by permissions |
| Read Only | View and report access with no editing rights |
Manage all of this from Company → Users & Security: add users, assign roles, reset passwords, or deactivate accounts. An Administrator can never remove their own Administrator access — only another active Administrator can do that, and LedgerDesk will never let a company be left with zero administrators.
For finer control than the five built-in roles, create a named permission profile with action-level permissions and, where relevant, dollar approval limits. This is also where Branch-specific permissions live — see Dimensions & Branches.
Login behavior
- LedgerDesk remembers the last successfully authenticated username per company — never the password — and prefills it at your next login.
- Repeated failed logins are throttled to slow down guessing attempts.
- Every meaningful action is written to the audit history, searchable from Reports.
Single-user vs. shared mode
By default, a company file is single-user: one person, one editing session. An Administrator can turn on shared mode from the File menu, which allows one editing session plus additional read-only viewers at the same time, without compromising the integrity of the encrypted file.
Closing dates
Set a closing date (Company → Set Closing Date) once a period is finalized — after your accountant files a quarter, for example. Any attempt to add, edit, or void a transaction dated on or before the closing date requires the closing-date password. The last 20 closing-date changes are kept in a dedicated history view.
Recovery keys
If an administrator password is forgotten, the recovery key generated at company creation is the only way back in. There is no other recovery path — this is by design, since the company file is encrypted. Keep it somewhere separate from the file itself.
