Xero User Roles and Permissions: A 2026 Reference
A current reference to Xero user roles, the access matrix by area, the extra permissions you can add, and exactly where Viewer access stops.
On this page +
See it live
Ask Kipper about your Xero data.
Invoices, supplier bills, purchase orders and credit notes.
Schedule free onboardingNo signup. Runs in your browser.
If you search for Xero user roles, a lot of what comes back names roles that are not in the product any more. Adviser, Read Only, and Invoice Only turn up constantly in older articles and forum answers, which makes it hard to tell what you are actually choosing from when you invite someone.
This is a current reference for Xero’s roles: what exists now, what each one can do, which additional permissions you can layer on top, and where Viewer stops. It is descriptive on purpose. If you want the argument about why none of these roles gives you safe read-only access for a wider team, that is a separate post.
Last verified: September 2026.
The roles, as of September 2026
Xero’s user roles article describes eight roles. Its compare-roles table covers seven of them, with Employee documented in the role list but left out of the table.
| Role | What it is for |
|---|---|
| Administrator | Full access to all areas of Xero |
| Standard | Almost full access, with a few things optional |
| Draft sales and purchases | Entering transactions without approving them |
| Sales | The customer side, including approvals |
| Purchases | The supplier side, including approvals |
| Sales and purchases | Both sides, including approvals |
| Employee | Expenses, projects, leave, timesheets, document upload |
| Viewer | Looking, not touching |
Xero treats the four middle roles as one family, described as four variations of the sales and purchases user role. That framing matters when you read the compare table, because the four are listed as separate columns.
One thing you cannot do is build your own role. Xero is direct about this: you can’t fully customize the areas you want to open up to a user. What you can do is add task-specific permissions to a role, which is covered further down.
Xero does not publish a mapping from the older role names to these, so if you are working from documentation that says Adviser or Read Only, treat the role names as a fresh decision rather than translating them across.
One caution on editions. Xero publishes a separate version of this article per region, and they do not use identical wording. The matrix below follows Xero’s Rest of world edition, which is the version that lays the seven roles out side by side. The US edition splits the same capabilities under different names for the four sales and purchases variations, and it lists Documents where the Rest of world table says Files. Treat this as a September 2026 reference point and check the labels in your own organization before writing them into a policy or an onboarding doc.
Each role in detail
Administrator
Full access to all areas of Xero. The one carve-out is billing: an administrator who is not the subscriber cannot change the pricing plan or payment details.
Administrators also get several additional permissions automatically, including user management, pay bills, and broad access to reports and inventory/products and services.
Standard
Almost full access, with cash coding, manual journals, and reports optional rather than automatic. In practice Standard is the working role for most finance staff, and the difference from Administrator is mostly about who manages users and subscription settings.
Standard users have bank account access by default, though someone with the edit users permission can turn that off.
The four sales and purchases roles
These are the roles people reach for when they want to give someone a limited slice of Xero. All four can create records in Xero, which is the detail that catches people out, so it is worth reading the difference carefully.
| Role | What the user can do |
|---|---|
| Draft sales and purchases | Create draft invoices, bills, quotes, and purchase orders, but not approve them |
| Sales | Create, approve, and send invoices, quotes, and customer credit notes, and record payment on invoices |
| Purchases | Create and approve bills, supplier credit notes, and purchase orders, and pay bills |
| Sales and purchases | Create and approve invoices, quotes, credit notes, bills, and purchase orders, record payment on invoices, and pay bills |
Three of the four can approve. The fourth still creates records that someone else has to deal with. None of them is a view-only role, and there is no variation that keeps the narrow area and drops the write access.
Employee
A limited role for people who are in Xero for their own admin rather than the company’s books: expenses and projects, submitting leave requests and timesheets, and uploading documents. Employee users get the Xero Me mobile app.
Employee is the role that can be given upload-only access to documents, covered in the permissions section below.
Viewer
Viewer can view most areas of Xero, but cannot create or edit transactions, or run new reports. It is the closest thing Xero has to a read-only user.
What Viewer can see is broader than most people expect, so it gets its own section below.
The area-by-area matrix
This is Xero’s compare-roles table, as published in the Rest of world edition of the article. Optional means the access can be granted as an additional permission rather than coming with the role. The US edition covers the same capabilities under some different labels, so read this for the access split rather than for exact naming.
| Area | Administrator | Standard | Draft sales and purchases | Sales and purchases | Sales | Purchases | Viewer |
|---|---|---|---|---|---|---|---|
| Bank accounts, transactions and statements | Yes | Yes | No | No | No | No | Partial* |
| Contacts | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
| Classic expense claims | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
| Files (Documents in the US edition) | Yes | Yes | No | No | No | No | No |
| Fixed Assets | Yes | Yes | No | No | No | No | Yes |
| Inventory | Yes | Yes | Optional | Optional | Optional | Optional | Optional, view only |
| Multicurrency | Yes | Yes | Yes | Yes | Yes | Yes | No |
| Online bill payments | Optional | Optional | No | Optional | No | Optional | No |
| Purchases | Yes | Yes | Yes | Yes | No | Yes | Yes |
| Reports, budgets and manual journals | Yes | Optional | No | Optional** | Optional** | Optional** | Yes |
| Sales | Yes | Yes | Yes | Yes | Yes | No | Yes |
| Settings | Yes | Yes | No | No | No | No | No |
* Viewer can access bank balances, balance in Xero, and account transactions in Xero. It cannot access imported bank statements.
** Sales and purchases users can be given permission to view relevant sales or purchases reports, depending on which of the four roles they have.
Two rows are worth pausing on. Contacts is available to every role in the table, so there is no role that hides your customer and supplier list. And Settings is limited to Administrator and Standard, which is what keeps the sales and purchases roles out of the organization’s configuration.
Where Viewer access stops
Viewer is the closest thing Xero has to a read-only role, so the boundary is worth stating precisely.
Viewer can:
- View sales, purchases, contacts, classic expense claims, and fixed assets
- View reports, budgets, and manual journals
- See bank balances, balance in Xero, and account transactions in Xero
- Be given view-only access to products and services
Viewer cannot:
- Create or edit transactions
- Run new reports
- Access imported bank statements
- Access documents, multicurrency, or settings
Read the reports row carefully, because it surprises people. Xero’s compare table marks Viewer as having access to reports, budgets and manual journals, while the role description says a Viewer cannot run new reports. Those are consistent if you read the second as being about creating a new report rather than opening an existing one, but the distinction is fine enough that it is worth confirming in your own organization before you rely on it for an access decision.
The other thing Viewer does not do is narrow. There is no way to give someone Viewer access to one customer, one tracking category, one project, or one bank account. Xero’s permissions are organized by functional area, and the area is as small as it gets. Where Xero does go below that level, in Projects and Expenses, it narrows by who created the record rather than which account it belongs to.
Additional permissions
These are the task-specific permissions you add on top of a role.
Bank accounts. View and edit bank accounts, account transactions, and bank statements, and reconcile transactions. Administrators and standard users have it by default, and someone with edit users can turn it off for a standard user.
Edit users. Add users, update roles for existing members, and remove people. Add it to standard users. The subscriber and administrators have it automatically.
Edit contact bank details. Only users with this permission can add or edit bank account details on a contact. Add it to standard, sales and purchases, or purchases users. This one is worth treating as sensitive, since contact bank details are a common target for payment fraud.
Reports. Gives standard users reports, budgets, and manual journals via the Journal report, plus saving custom layouts, viewing reports others have saved or published, and printing or exporting. Administrators have full report access already. Sales and purchases users can be given the relevant sales or purchases reports for their role.
Inventory (products and services). View lets a user open the Products and services screen and view and export items without changing anything. Edit items only allows creating, editing, and deleting items. Edit items and stock adds adjusting quantity or value. Assignable to the sales and purchases roles and to Viewer. Administrator and Standard have full access by default.
Projects. Edit own only covers a user’s own time entries, projects, and tasks. Edit all covers all projects and time entries and projects reports, but not staff cost rates or cost data in reports. Edit staff cost rates adds those.
Expenses. Submitter enters, edits, and submits their own expenses. Approver can also approve or decline, see other employees’ expenses, pay them out, and run reports. Admin adds expenses settings.
Pay bills. Process online bill payments. Assign it to standard, sales and purchases, or purchases users. Administrators have it by default.
Documents. Called Files in the Rest of world edition. Administrator and standard users can view, upload, and delete documents by default. An Employee user can be given upload-only access, where they can upload files to the file library and view their own files, and nothing else.
Picking a role
A few practical notes that follow from the matrix.
If someone needs to enter transactions but should not commit them, Draft sales and purchases is the role, and you need a second person with approval rights.
If someone should never write anything, Viewer is the only role that guarantees it. Accept that they will see most of the organization, including bank balances and account transactions in Xero.
If you want narrow and read-only at the same time, Xero does not have a role for that. That gap, and what to do about it, is the subject of why Xero still has no safe read-only role.
Worth knowing if you are connecting software: Xero’s user roles govern the Xero interface, and an API connection is governed separately by its scopes and by the access of the person who authorized it. Xero requires that person to be a Standard, Adviser, or Administrator level user, so a Viewer cannot authorize an app. Xero MCP Scopes Explained covers the scope side.
For questions that keep landing on finance because the asker has no Xero seat, Kipper answers them read-only in Slack, Microsoft Teams, SMS, and chat, with access configured per person. It can return the supported Xero reports, but it does not read Xero bank data: no bank account balances, bank feed transactions, imported bank statements, or reconciliation status. For the wider picture on connecting AI to Xero, see the complete guide to Xero MCP.
FAQ
What user roles does Xero have?
As of September 2026, Xero’s article on user roles describes Administrator, Standard, four sales and purchases variations (Draft sales and purchases, Sales, Purchases, and Sales and purchases), Employee, and Viewer. Xero’s compare-roles table covers seven of them; Employee is documented separately in the role list.
What can the Viewer role see in Xero?
Viewer can view most areas of Xero, including sales, purchases, contacts, classic expense claims, fixed assets, and reports, budgets and manual journals. It can also see bank balances, balance in Xero, and account transactions in Xero, but not imported bank statements. It cannot create or edit transactions, or run new reports.
What is the difference between Draft sales and purchases and Sales and purchases?
Approval rights. Draft sales and purchases can create draft invoices, bills, quotes, and purchase orders but cannot approve them. Sales and purchases can create and approve invoices, quotes, credit notes, bills, and purchase orders, and can record payment on invoices and pay bills.
Can you customize Xero user roles?
Not the roles themselves. Xero says you can’t fully customize the areas you open up to a user. What you can do is add task-specific permissions on top of a role, covering areas such as bank accounts, editing users, contact bank details, reports, inventory, projects, expenses, paying bills, and documents.
Sources
- Xero Central, “User roles and permissions in Xero,” Rest of world edition. The compare-roles matrix comes from here, read 15 September 2026. Xero Central renders client-side and its articles carry no publication date, so this one is cited by title and read date rather than by link.
- Xero Central: User roles and permissions in Xero (US Business edition). The additional permissions list comes from here. Xero publishes region-specific versions of this article, so confirm role and permission labels against the version your organization sees.
- Xero API permissions FAQ