Back to Insights
Operations7 min read

Granting Your Accountant KSeF Access: Entity-Level Permissions Step by Step

KSeF permissions are not automatic. Your biuro needs explicit grants per entity. Grant by NIP, enable delegation, and never give full permission management. Here is the step-by-step.

Granting Your Accountant KSeF Access: Entity-Level Permissions Step by Step

Your accounting office has no default access to your KSeF. Even if they have been doing your accounting for twenty years, KSeF requires explicit permission grants. The biuro cannot issue invoices, view your invoices, or check session history until you grant access.

The Correct Grant Procedure

Step 1: Grant by entity NIP

In KSeF, grant permissions to the biuro's NIP, not to an individual employee's PESEL. This makes the biuro the authorised entity, and the biuro can then delegate internally to its own staff.

Step 2: Enable dalsze przekazywanie

Check the "dalsze przekazywanie" (further delegation) flag when granting. This allows the biuro to grant access to its own employees without coming back to you for each new hire. Without this flag, every staff change at the biuro requires a new grant from you.

Step 3: Grant issuing and access rights

Grant the rights the biuro needs:

  • Issuing: So the biuro can issue invoices on your behalf
  • Access: So the biuro can view your invoices and session history

Step 4: Do NOT grant permissions-management rights

The biuro should not be able to grant access to your KSeF to third parties. The permissions-management right is unrevocable for the owner and should be granted only to trusted internal administrators. The official KSeF podręcznik is explicit: a biuro should never receive the permissions-management right.

Step 5: Repeat per entity

If you have a JDG and a spółka, grant the biuro access to both NIPs separately. Each entity is a separate permission grant in KSeF.

Step 6: Set a quarterly review reminder

Review who has access to your KSeF every quarter. Remove anyone who should no longer have access. The 10-year session history means every action is logged and auditable.

What the Biuro Can and Cannot Do

ActionWith issuing + accessWith permissions management
Issue invoices on your behalfYesYes
View your invoicesYesYes
View session history (10 years)YesYes
Grant access to othersNoYes
Revoke accessNoYes
Change ownerNoNo (unrevocable)

Revoking Access

When you change accounting offices or an employee leaves:

  1. Revoke in KSeF immediately. Log in to e-Urząd Skarbowy, navigate to KSeF permissions, and revoke the biuro's or individual's access.
  2. Regenerate your token. If the biuro was using a token, revoke it and generate a new one. Old tokens remain valid until they expire or are explicitly revoked.
  3. Check session history. Review the 10-year log for any unusual activity in the period before revocation.
  4. Notify the biuro. Inform them in writing that access has been revoked, so they do not attempt to use stale credentials.

Common Mistakes

Granting permissions-management to the biuro. This gives the biuro the ability to grant access to anyone, including third parties you do not know. The official podręcznik recommends against it.

Granting to an individual PESEL instead of the biuro NIP. If the individual leaves the biuro, you need to revoke and re-grant to the new person. Granting to the biuro NIP with dalsze przekazywanie avoids this.

Not revoking when changing biuro. Former accounting offices retain access until you explicitly revoke. There is no automatic expiry.

Using Profil Zaufany for the biuro's access. Profil Zaufany is a personal login. Token-based auth is more reliable and does not depend on the Profil Zaufany infrastructure, which collapsed under load during the KSeF launch.

This material is information of a general nature and does not constitute legal or tax advice. For a specific situation, verify the current rules or consult a qualified adviser.