For Tom and Miles

QMax Access Model.

Max cannot write to your systems today, and QuickBooks is not connected. This document is the gate on both. Once you confirm who sees what and who approves what, we connect QuickBooks and turn writing on — with your rules in place from day one.

Your instruction, from Miles on July 29:

"We want to make sure employees have the same access rights that they currently have in Quickbooks."

That is what this does. Every tier maps to a QuickBooks role you already grant.

Where you start from

What your QuickBooks shows.

Nine users on your QuickBooks Advanced account.

PersonQuickBooks roleSees financialsSees payroll
Thomas PerryPrimary adminYesYes
Miles AndrewsCompany adminYesYes
Vanessa BergvistCompany adminYesYes
Josh LayneStandard all accessYesYes
Kim PerryStandard all accessYesYes
Michele FronzagliaStandard limitedYesReports only
Daniel PaigeBill approverNoNo
Zach RumphBill approverNoNo
Matt BabsonBill approverNoNo

Kim is a QuickBooks user but not a Max user, so no profile applies to her.

Two things worth knowing, separate from this project

The role names understate the access. "Standard limited — customers and vendors" still grants Company and Financial Reports, Payables, Receivables and payroll reports. Six of your nine can pull company financials. Only the three Bill approvers cannot.

"Standard all access" includes payroll — Intuit's words: "full access without admin privileges, plus access to Payroll." That is Josh and Kim, alongside Tom, Miles and Vanessa. Five people, plus Michele on payroll reports.

Your rule was that people should have the same access in Max as in QuickBooks. Payroll access in QuickBooks is wider than that sentence suggests. It changes nothing for us — salaries are unreachable through Max for everyone — but it is worth your attention as a QuickBooks question.

How access works

Seeing and approving
are separate.

01

What someone can see

One of three profiles.

02

What someone can approve

Set separately, by type of work.

They are not linked. Carson needs the scorecard without gaining the ability to approve a bill. Vanessa needs to approve bills without gaining anything extra to look at.

Access is enforced on our servers, not by asking the assistant to behave. If someone is not cleared, the request is refused before any data is fetched. Every request is logged against the person who made it.

What someone can see

The three profiles.

Finance

Everyone who already pulls financial reports in QuickBooks.

Sees everything below, plus cash position, AR and AP aging, and vendor bills.

Operations

For people on your July 29 list who have no QuickBooks account.

Sees the KPI scorecard and admin portal, plus everything below. No cash position, no AR/AP aging, no bill amounts.

General

Day-to-day lookups.

Sees customers, contacts, CRM health, Project Hunter, and the sales pipeline. No scorecard, no admin portal, no QuickBooks financials.

Nobody sees salaries or payroll. Not even Finance. That data is not reachable through Max at all.

What someone can approve

Six kinds of change.

Approval is granted per kind — someone trusted with bills is not automatically trusted with sales orders. Approval rights carry the matching queue with them.

Kind of change
Vendor bill entry
Bill date correction
Customer invoice
Collections email
Sales order entry
Scorecard publish to Smartsheet

Who holds what

This is the table
to mark up.

PersonRole at QMaxSeesCan approve
Thomas PerryPresidentFinanceEverything
Miles AndrewsCOOFinanceEverything
Vanessa BergvistA/P, A/R, HRFinanceBills · bill dates · invoices · collections · sales orders
Josh LayneOperations leadFinanceBills, including the second approval above $15,000
Michele FronzagliaCompliance, MarketingFinanceNothing
Carson HannahProject DevelopmentOperationsNothing
Matt BabsonEngineered PMGeneralBills and invoices on his own orders
Daniel PaigeJacket PMGeneralBills and invoices on his own orders
Zach RumphPattern ManagementGeneralBills on his own POs
Kent SnelsonEstimatingGeneralNothing
Davey ScismEstimatingGeneralNothing
Noah GranitoProduction, ShippingGeneralNothing

The "Sees" column matches your July 29 list exactly — Finance plus Operations is the six you named and nobody else.

The "Can approve" column follows your Bill Approval form where the form covers it. Matt, Daniel and Zach are your PO creators and hold Bill approver in QuickBooks. Josh is your second approver above $15,000.

Four places we made a call and want your eye

  • Invoices, collections and sales orders are not in your Bill Approval form. We put invoices with the PMs who own the orders, collections and order entry with Vanessa.
  • Michele and Carson see financials but approve nothing. They need visibility, not write power.
  • Scorecard publish sits with Tom and Miles. Should Miles hold it alone?
  • Michele sits in Finance because her QuickBooks role grants financial reports. Miles mentioned she does not use QuickBooks much — tell us if practice should govern instead of permission.

Anyone not on this list gets nothing beyond General.

One thing we found

Credentials in plain text.

Your Fishbowl customer records have a free-text Customer Notes field. It holds invoicing instructions — and for customers who require portal upload, the portal login and password.

Those credentials sit in plain text where every Fishbowl user can read them. Worth fixing regardless of this project.

On our side, customer lookups return name and account identifiers only, not that field.

Next

Turning QuickBooks on.

Once you approve this model, one of your QuickBooks admins connects Max. Tom can do it as Primary admin. Vanessa may be able to from her Company admin seat — worth checking her permissions before someone sits down to it.

Mark up the table and send it back.

Back to the table The nine workflows