Access follows the record.
Every role has a defined view of the operating record, every document moves through a controlled request, and every change in responsibility triggers a review. The controls below describe how Institution actually works.
- Full view of every entity record they own
- Approve requests and reporting release
- Grant or remove team access
- Read and update the recurring operating record
- Provide documents in response to a request
- See open requests and their state
- See records for the accounts they are staffed on
- Post reconciliations, journals, and review notes
- Route requests and log completion
- Receive a bounded evidence package for the engagement
- Return work into a defined request
How access, requests, and review actually operate.
Every access decision starts from the record and the role, not the person. A team member staffed on an account gains scoped access on onboarding; when they rotate off, access is removed the same day. Ownership is a role that a person occupies for a period, not a permanent attribute.
Client documents arrive through a request record with a named owner, a purpose, and a completion state. A document that arrives outside a request is either attached to one or returned. This is how a supporting document ends up findable a year later instead of buried in an email thread.
A staffing change, a client-side role change, or a professional handoff triggers an access review before the next recurring cycle. Requests in flight are reassigned to a named owner; nothing sits without one. Continuity of the operating record survives the personnel change.
When a licensed tax professional, counsel, or specialist is engaged, they receive a bounded evidence package built for that engagement, delivered through the client's approved channel, and returned into a defined request. There is no standing access to the live operating record.
Request history, review records, and reporting packs persist independently of the individuals who created them. The record is the durable artifact; anyone reading it a period later can see who acted, when, and against what evidence.
Operating posture.
We describe how we operate rather than publishing certifications we do not hold.
Access is granted to people staffed on your account. Onboarding and offboarding are documented events, not a change in a shared login.
We prefer delegated access and provider-issued invitations over shared passwords. Where shared credentials are unavoidable, they are stored in a business password manager, not in email or shared documents.
Client records and workpapers are held in the accounting software of record (QuickBooks Online or Xero) and in Institution's internal systems, which encrypt data in transit and at rest.
Bank, card, and payroll integrations use each provider's official read-only mechanisms whenever available. Write access is limited to the specific tasks it is granted for.
Commitments.
- We do not sell client data.
- We do not use client financial data to train third-party AI models.
- We do not store bank credentials outside sanctioned provider integrations or a business password manager.
- We do not send financial statements or credentials over unencrypted channels.
Security questions or a specific control request: security@institutionhq.com.