cancel
Showing results for 
Search instead for 
Did you mean: 
kevinamfs
Level 2

Sensitive Payroll Data is visible to every user

If you are on QBO Advanced, I found out that any user can see payroll information, even when they are not given payroll viewing access. If you simply create a custom report and select Transaction Type, Transaction Name, and Transaction Memo, you can see everyones payroll checks (Screenshot attached). We are on QBO payroll but I have not enabled payroll data access for any of my employees.

 

This is a HUGE flaw on behalf of Intuit and should be addressed immediately. I am just praying my staff doesn't realize this loophole exists and everyone starts looking at each others' pay information.

3 Comments 3
MadelynC
Moderator

Sensitive Payroll Data is visible to every user

Thanks for sharing your thoughts with us, @kevinamfs. I’ll make sure this payroll data access for all your employees will immediately get disabled.


Before anything else, what type of role or access you‘ve given to these users? Please know that Workers have the ability to view payroll reports, paycheck lists, payroll settings, etc. If you created custom roles for them, make sure the permission to see your payroll files isn’t included.


You can go to your Manage Users section under the Gear icon to review all assigned roles. Then, edit if necessary. Here’s how:

 

  1. In the Users tab, find the user you want to modify.
  2. Choose Edit from the Action column.
    SSS.png
  3. Change the role.
  4. Press Save after.


You can read this article to learn more about managing custom roles for your QuickBooks Online Advanced users: Add and manage custom roles.


On the other hand, if everything is correct and doesn’t have the option to access your payroll data, I’d recommend contacting our support team. Our representatives can check the issue further and can find more solutions to ensure all sensitive data like payroll will no longer be visible to everyone.


In case you need resources and tips to handle your employee records, accounting preferences, and items, you can visit these websites anytime for more details:

 


Safeguarding your account information is our top priority. If you find any odd behavior or have concerns about your company files, feel welcome to reach out or mention me in your comments. I’d be more than happy to help. Take care always!

kevinamfs
Level 2

Sensitive Payroll Data is visible to every user

I tested it with out-of-box roles:

- Expense Mgr

- Sales Mgr

- Std limited customers & vendors

 

And all can see via this backdoor.

MadelynC
Moderator

Sensitive Payroll Data is visible to every user

Thanks for getting back and trying it with out-of-the-box roles, @kevinamfs. It helped me determine that this situation needs to be checked further.


Since your users or employees still have access even though their roles aren’t related to payroll, it would be great to contact our support team, as I've suggested. Only our phone and chat representatives have the tools to verify its cause and help you resolve this. Let me show you the steps:

 

  1. Sign in to your QuickBooks Online account.
  2. Go to the Help (?) menu, then the Search tab.
  3. Click Contact Us.
  4. Enter your brief concern, then select Continue.
  5. Choose a way to connect with us:
    • Start a chat with a representative
    • Get a callback from the next available expert

 

I'm adding this reference to get more information about customizing roles and providing individual permissions for specific tasks: User roles and access rights in QuickBooks Online.


If you have any other concerns besides managing users' permission. You can always get back on this thread anytime. I’ll make sure everything is taken care of. Keep safe!

Need to get in touch?

Contact us