Granting Your Accountant KSeF Access: Entity-Level Permissions Step by Step
KSeF permissions are not automatic. Your biuro needs explicit grants per entity. Grant by NIP, enable delegation, and never give full permission management. Here is the step-by-step.
Granting Your Accountant KSeF Access: Entity-Level Permissions Step by Step
Your accounting office has no default access to your KSeF. Even if they have been doing your accounting for twenty years, KSeF requires explicit permission grants. The biuro cannot issue invoices, view your invoices, or check session history until you grant access.
The Correct Grant Procedure
Step 1: Grant by entity NIP
In KSeF, grant permissions to the biuro's NIP, not to an individual employee's PESEL. This makes the biuro the authorised entity, and the biuro can then delegate internally to its own staff.
Step 2: Enable dalsze przekazywanie
Check the "dalsze przekazywanie" (further delegation) flag when granting. This allows the biuro to grant access to its own employees without coming back to you for each new hire. Without this flag, every staff change at the biuro requires a new grant from you.
Step 3: Grant issuing and access rights
Grant the rights the biuro needs:
- Issuing: So the biuro can issue invoices on your behalf
- Access: So the biuro can view your invoices and session history
Step 4: Do NOT grant permissions-management rights
The biuro should not be able to grant access to your KSeF to third parties. The permissions-management right is unrevocable for the owner and should be granted only to trusted internal administrators. The official KSeF podręcznik is explicit: a biuro should never receive the permissions-management right.
Step 5: Repeat per entity
If you have a JDG and a spółka, grant the biuro access to both NIPs separately. Each entity is a separate permission grant in KSeF.
Step 6: Set a quarterly review reminder
Review who has access to your KSeF every quarter. Remove anyone who should no longer have access. The 10-year session history means every action is logged and auditable.
What the Biuro Can and Cannot Do
| Action | With issuing + access | With permissions management |
|---|---|---|
| Issue invoices on your behalf | Yes | Yes |
| View your invoices | Yes | Yes |
| View session history (10 years) | Yes | Yes |
| Grant access to others | No | Yes |
| Revoke access | No | Yes |
| Change owner | No | No (unrevocable) |
Revoking Access
When you change accounting offices or an employee leaves:
- Revoke in KSeF immediately. Log in to e-Urząd Skarbowy, navigate to KSeF permissions, and revoke the biuro's or individual's access.
- Regenerate your token. If the biuro was using a token, revoke it and generate a new one. Old tokens remain valid until they expire or are explicitly revoked.
- Check session history. Review the 10-year log for any unusual activity in the period before revocation.
- Notify the biuro. Inform them in writing that access has been revoked, so they do not attempt to use stale credentials.
Common Mistakes
Granting permissions-management to the biuro. This gives the biuro the ability to grant access to anyone, including third parties you do not know. The official podręcznik recommends against it.
Granting to an individual PESEL instead of the biuro NIP. If the individual leaves the biuro, you need to revoke and re-grant to the new person. Granting to the biuro NIP with dalsze przekazywanie avoids this.
Not revoking when changing biuro. Former accounting offices retain access until you explicitly revoke. There is no automatic expiry.
Using Profil Zaufany for the biuro's access. Profil Zaufany is a personal login. Token-based auth is more reliable and does not depend on the Profil Zaufany infrastructure, which collapsed under load during the KSeF launch.
This material is information of a general nature and does not constitute legal or tax advice. For a specific situation, verify the current rules or consult a qualified adviser.