Banks use account permissions to let multiple people handle money without giving everyone full control

When more than one person needs to access a business checking account, the bank creates separate permission levels for each user. One owner might be able to see the balance and approve large transfers. A bookkeeper might only be able to view transactions and deposit checks. A payroll manager might be able to initiate payments but not change account settings. The bank's system tracks who did what, when, and how much money moved.

The account holder (usually the business owner or authorized officer) sets up these permissions through the bank's online platform or by visiting a branch. The bank then issues login credentials to each person—a username, password, and sometimes a security token or app-based verification. When someone logs in, the system checks their identity and then shows them only what their permission level allows.

Key Takeaways

  • Banks assign different permission levels to different users so a bookkeeper cannot do what a treasurer can do, even though you both access the same account.
  • The account owner sets up each user's access level through online banking or at the branch, and the bank stores those rules in its system.
  • Most banks require each user to have their own login credentials and often a second form of verification like a code from an app or text message.
  • The bank keeps a record of every transaction and who initiated it, so you can see which employee moved which money and when.
  • Removing someone's access is when ready—the bank disables their login as soon as you request it, though pending transactions they started may still process.

How permission levels work in practice

Banks typically offer a tiered system. The exact names and options vary by bank, but the structure is consistent. An owner or administrator can see all account activity, change other users' permissions, add or remove users, and approve or deny large transactions. A manager or approver can initiate transfers and payments up to a set dollar limit, but cannot change account settings or remove other users. A viewer can see the account balance and transaction history but cannot move money at all.

Some banks add a middle tier: a preparer can create a payment or transfer but cannot send it—an approver has to review and authorize it first. This two-person rule is common in larger businesses because it prevents one person from moving large sums without oversight. The preparer and approver are both tracked in the system, so the bank and the business owner know who created the transaction and who released it.

You set these levels when you add a user. Most banks let you do this through their online dashboard under a section called "User Management," "Team," "Permissions," or "Account Access." You enter the person's name, email, and phone number, choose their permission level from a dropdown menu, and the bank sends them an invitation. They accept it, create a password, and their access turns on.

How the bank verifies each person's identity

When a user logs in, the bank checks two things: that they know the password (something only they should know) and that they are physically the person they claim to be. The first check is the password itself. The second is usually multi-factor authentication—a second form of proof that happens after the password is entered.

Common second factors include a code texted to a phone number on file, a code generated by an authenticator app like Google Authenticator or Authy, or a push notification to a registered device that the user swipes to approve. Some banks use a physical security key—a small USB device that you plug in or tap to your phone. A few still use security questions, though this is less common now because the answers are often findable online.

The bank's system stores the password in encrypted form—the bank itself cannot read it, only check whether the one you type matches. If someone tries to log in with the wrong password three or more times, the account locks temporarily. If a login happens from an unusual location or device, the bank may send a verification code or ask security questions before allowing access.

How banks track who did what and when

Every transaction on a business account is logged with a timestamp, the user who initiated it, the amount, the recipient, and the status (pending, completed, or rejected). This record is called the audit trail or activity log. You can view it in your online banking dashboard, usually under "Transaction History," "Activity," or "Reports."

If a transfer was initiated by your bookkeeper at 2:47 p.m. on a Tuesday and approved by your manager at 3:15 p.m., both names and times appear in the log. If a payment failed because the account had insufficient funds, that is logged too. If someone tried to access the account and failed the security verification, that attempt is recorded.

This record serves two purposes. First, it lets you know what happened and who did it—useful if you need to investigate a mistake or dispute a transaction. Second, it protects the bank and the business. If an employee claims they never authorized a payment, the audit trail shows whether they logged in and initiated it. If someone outside the company gained access, the log shows the login location and device, which can help identify how the breach happened.

What happens when you remove someone's access

When you delete a user from the account, the bank disables their login when ready. They cannot log in again, and they cannot see the account balance or history. However, any transaction they started before you removed them may still process if it was pending approval.

For example, if your payroll manager initiated a payroll run at 4 p.m. and you removed their access at 4:30 p.m., the payroll run might still go through at 5 p.m. if it was set to auto-approve or if another approver signed off on it. To prevent this, some banks let you cancel pending transactions when you remove a user, but you have to do it manually—the system does not do it automatically.

The best practice is to notify the bank before you remove someone, especially if they have pending transactions. Call the account number on the back of your debit card or log into your online banking and start a find message. Tell the bank the person's name, the date you want access removed, and whether there are any pending transactions that should be cancelled. The bank will handle the removal and confirm it in writing.

How banks prevent unauthorized access to shared accounts

Banks use several layers of protection. The first is the login itself—each user has a unique username and password, so the bank knows who is accessing the account. The second is multi-factor authentication, which makes it much harder for someone to log in even if they steal a password. The third is IP monitoring—if a login happens from a country or city where that user has never logged in before, the bank may block it or ask for extra verification.

The fourth layer is transaction limits. If you set a user's permission level to allow transfers up to $5,000, they cannot move more than that in a single transaction, even if they try. If they attempt a larger transfer, the system rejects it and logs the attempt. Some banks also let you set daily limits—a user can move up to $50,000 per day but not more, even if they make multiple transfers.

The fifth layer is the audit trail itself. Because every action is logged and tied to a specific user, employees know their actions are traceable. This deters theft and mistakes. If money goes missing, you can see exactly who accessed the account and what they did.

What to do if you suspect unauthorized access

If you notice a transaction you did not authorize, or if a user reports that their login credentials were compromised, contact your bank when ready. Call the number on the back of your debit card or your account statement—do not use a number from an email or text, because those could be fake. Tell the bank what happened and ask them to freeze the account or disable all user logins except yours while they investigate.

The bank will review the audit trail to see who logged in and what they did. If the unauthorized transaction is recent (usually within 30 days), the bank may reverse it under the Electronic Funds Transfer Act, which protects business accounts in some cases. If the transaction is older, reversal is less likely, but the bank will still investigate and may be able to recover the money from the receiving bank.

After the investigation, change the passwords for all users and consider resetting multi-factor authentication settings. If an employee's credentials were compromised, remove their access and have them create a new password before restoring it. If the breach came from outside the company, ask your bank whether they recommend additional security measures, such as IP whitelisting (allowing logins only from specific addresses) or hardware security keys.

Frequently Asked Questions

Can I see what each employee did on the account without asking the bank?

Yes. Log into your online banking and look for "Transaction History," "Activity Log," or "Reports." Most banks show you the date, time, user name, transaction type, and amount for every action. You can usually filter by user, date range, or transaction type. Some banks let you read this as a spreadsheet or PDF.

What if two people need to approve every large payment?

Ask your bank whether they offer a "dual approval" or "two-person rule" feature. One user creates the payment, and it stays pending until a second user reviews and approves it. The bank logs both names. If your bank does not offer this, you can use a manual process: the preparer creates the payment and saves it as a draft, then emails the approver, who logs in separately and releases it.

Can an employee see other employees' login activity?

No, unless you give them permission to view the audit trail. Most banks let you restrict who can see the activity log. If you want employees to see only their own activity, tell your bank when you set up their permissions. If you want only the owner and one manager to see the full log, set it that way.

What happens if someone forgets their password?

They can reset it through the login page by clicking "Forgot Password" or "Reset Password." The bank sends a reset link to their email or a code to their phone. They use that to create a new password. If they cannot access their email or phone, they will need to visit a branch with a photo ID or call the bank and answer security questions to verify their identity.

Do I have to pay extra to add users to my business checking account?

Most banks do not charge a fee to add users or set up different permission levels. Some business account packages include a set number of users (like five) for free and charge a small monthly fee for additional users. Check your account agreement or call your bank to confirm what is included in your plan.