Client Email Access: A Security Checklist for Accountants

Viewed
times

TL;DR

  • Review the actual consent screen and distinguish reading from sending or modifying permissions.
  • Decide who can access collected documents and where copies will be exported.
  • Treat disconnecting a source, revoking provider access and deleting stored data as separate steps.

Before connecting client email to receipt collection software, review the permissions, the documents people will be able to see, and what happens when access ends. Let the authorized mailbox owner approve the connection. Start with a limited pilot and record the agreed source, users, accounting destination and offboarding steps.

This checklist is for evaluating a document-collection workflow. It helps you ask concrete questions rather than treating an “AI” label or a read-only connection as a complete security assessment.

1. Choose the Right Mailbox and Owner

Identify who owns the mailbox and who can authorize a third-party connection. A client employee's access to an inbox does not necessarily mean they can approve a new service under the organization's policy.

Prefer the business source that contains the relevant supplier documents. If receipts arrive in a mixed personal and business inbox, discuss that explicitly. Consider whether the client can provide selected documents or use a separate business collection address instead.

Record the client, mailbox, workspace, approver and purpose. This becomes useful when a staff member leaves or the engagement ends.

2. Read the Actual Permission Request

Separate three questions: what the provider allows the app to access, what the app processes, and what it retains. They are related, but not interchangeable.

A read-only permission does not mean “only receipts are accessible.” It means the permission is for reading rather than changing the mailbox. Likewise, selecting a date range in a scan is an application setting, not necessarily a restriction on the provider's underlying authorization.

For Receiptor AI's Google and Microsoft collection flow, review the consent screen for the reading permissions requested. Optional connected actions or earlier grants may affect the permissions shown. Do not promise a client that all possible configurations have identical access.

Google explains how to review and remove third-party account access. Ask the client's Microsoft administrator about tenant restrictions when using a managed Microsoft 365 account.

3. Keep Authorization With the Client

With a Google or Microsoft authorization flow, the client signs in with the provider and approves access. You should not need to collect their password in an email or spreadsheet.

Other connection methods, including IMAP, may use credentials or app passwords. Review those separately rather than applying an OAuth explanation to every provider.

Before sending an invitation, confirm the intended workspace and recipient. After connection, check that documents arrive in the agreed workspace, not an accountant's unrelated test environment. The first-client setup guide covers the operating sequence.

4. Review Who Can See Collected Documents

Mailbox authorization is only the first boundary. Once a receipt has been extracted, workspace members and downstream systems may have access to the resulting document.

Use separate workspaces for unrelated clients. Review invited members and their roles, and remove access that is no longer needed. Do not assume that assigning a document to a business entity restricts which workspace members can view it.

List the destinations you intend to use: accounting software, cloud storage, email exports or downloaded files. A copy exported elsewhere has its own access and retention controls.

5. Ask About Processing, Retention and Evidence

Ask the vendor for current information covering:

  • Which message content and document types are processed.
  • What source data, extracted documents and logs are retained.
  • Where processing and storage take place, including subprocessors.
  • Who can access customer data for support or operations.
  • Whether customer data is used for model training.
  • How deletion requests and backup retention are handled.
  • What security assessment evidence is available and what it covers.

For Receiptor AI, start with the privacy policy and request current supporting materials for your firm's requirements. Do not infer a certification, a deletion deadline or a geographic guarantee from this checklist. Use the applicable policy, contract and evidence to make that decision.

6. Test With a Defined Sample

Agree the sources and period before collection begins. Check a few expected documents and confirm that users see the correct workspace and that exports reach the correct client account.

For a client who has not approved mailbox access, selected document uploads can support an initial processing demonstration. They do not establish that the connected-mailbox workflow has been reviewed.

Keep a record of exceptions: an unexpected source, an incorrect destination, a person with unnecessary access, or a document that needs manual review. Resolve those before expanding the pilot.

7. Write the Offboarding Steps Now

Do not leave access removal until the relationship ends. Assign someone to carry out and record each relevant step:

  1. Stop collection and scheduled actions for the departing client.
  2. Disconnect the source in the application.
  3. Review and revoke the app's access at the email provider.
  4. Remove workspace members who no longer require access.
  5. Export the records the client is entitled to keep.
  6. Follow the agreed process for stored documents, account deletion and downstream copies.

Disconnecting a mailbox is not the same as deleting previously collected records. Confirm completion against your firm's policy rather than treating one disconnect button as the entire process.

Use this checklist alongside the client document collection workflow. In a practice demo, bring the client's source types and your access requirements so the proposed setup can be reviewed before rollout.

Frequently Asked Questions

Does read-only email access mean an app cannot read unrelated messages?

No. Read-only describes what actions a permission allows. It does not necessarily restrict access to receipts alone. Review the granted scope and the application's processing rules separately.

Should clients share their mailbox password with the accountant?

For Google and Microsoft connections, use the provider's authorization flow so the authorized mailbox owner approves access. Other connection methods may require credentials and need their own review.

Does disconnecting an inbox delete documents already collected?

Do not assume so. Disconnecting collection, revoking access at the email provider and deleting stored documents are different actions. Check the vendor's retention and deletion process.

What should we request before rolling out across a practice?

Request current permission details, access controls, processing and storage information, subprocessors, retention and deletion terms, and any assessment evidence your firm requires.

Romeo Bellon
By Romeo Bellon

Last update on September 29, 2026 · 3 min read

🤖

Subscribe to our newsletter

Get the latest on AI bookkeeping automation and save hours on financial admin.

Follow us on X!

Follow @ReceiptorAI on Twitter for the latest updates, tips on expense management, and insights into the future of AI in personal finance.