Enjoy complimentary data migration when switching from your existing bookkeeper or CPA to Institution.
Security

Access follows the record.

Every role has a defined view of the operating record, every document moves through a controlled request, and every change in responsibility triggers a review. The controls below describe how Institution actually works.

Role-to-record view
Business owner
  • Full view of every entity record they own
  • Approve requests and reporting release
  • Grant or remove team access
Cannot: Modify Institution's internal review records
Finance operator (client-side)
  • Read and update the recurring operating record
  • Provide documents in response to a request
  • See open requests and their state
Cannot: See records for entities they are not staffed on
Institution team member
  • See records for the accounts they are staffed on
  • Post reconciliations, journals, and review notes
  • Route requests and log completion
Cannot: See client records outside their staffed accounts
External professional
  • Receive a bounded evidence package for the engagement
  • Return work into a defined request
Cannot: Browse the client's live operating record

How access, requests, and review actually operate.

Access follows responsibility, not seniority.

Every access decision starts from the record and the role, not the person. A team member staffed on an account gains scoped access on onboarding; when they rotate off, access is removed the same day. Ownership is a role that a person occupies for a period, not a permanent attribute.

Documents move through controlled requests.

Client documents arrive through a request record with a named owner, a purpose, and a completion state. A document that arrives outside a request is either attached to one or returned. This is how a supporting document ends up findable a year later instead of buried in an email thread.

Access is reviewed when responsibility changes.

A staffing change, a client-side role change, or a professional handoff triggers an access review before the next recurring cycle. Requests in flight are reassigned to a named owner; nothing sits without one. Continuity of the operating record survives the personnel change.

External providers receive only what the engagement requires.

When a licensed tax professional, counsel, or specialist is engaged, they receive a bounded evidence package built for that engagement, delivered through the client's approved channel, and returned into a defined request. There is no standing access to the live operating record.

Operational continuity survives personnel changes.

Request history, review records, and reporting packs persist independently of the individuals who created them. The record is the durable artifact; anyone reading it a period later can see who acted, when, and against what evidence.

Operating posture.

We describe how we operate rather than publishing certifications we do not hold.

Named access only

Access is granted to people staffed on your account. Onboarding and offboarding are documented events, not a change in a shared login.

Delegated over shared

We prefer delegated access and provider-issued invitations over shared passwords. Where shared credentials are unavoidable, they are stored in a business password manager, not in email or shared documents.

Encryption in transit and at rest

Client records and workpapers are held in the accounting software of record (QuickBooks Online or Xero) and in Institution's internal systems, which encrypt data in transit and at rest.

Provider-official integrations

Bank, card, and payroll integrations use each provider's official read-only mechanisms whenever available. Write access is limited to the specific tasks it is granted for.

Commitments.

  • We do not sell client data.
  • We do not use client financial data to train third-party AI models.
  • We do not store bank credentials outside sanctioned provider integrations or a business password manager.
  • We do not send financial statements or credentials over unencrypted channels.

Security questions or a specific control request: security@institutionhq.com.