Security & Roles

Only the right people, and a record of everyone

Role-based access, an audit trail on every change, and bank-level security.

One board year, and what the books remember of it

Turnover, shared laptops and a president who needs to approve one check. Access control for a PTA is a people problem before it is a software one.
  1. A new board is elected in May

    A treasurer, a president, a secretary, two vice presidents, and whoever chairs the fall festival. Six people who need six different amounts of access to the same set of books.

  2. You invite each one with the role they need

    By name and email, at admin, editor, viewer or reviewer. A reviewer is not a weaker viewer: they see only the items they were personally asked to sign, with no ledger, no reports and no chart of accounts. That is how a president approves a check without being handed the books.

  3. They work through the year

    Entries, reconciliations, expense reports, checks. Nobody can hand themselves more access than they were given, and nobody can change their own — the role you hold is the role somebody else put you in.

  4. Every change writes down who and when

    Expense reports, checks, journal entries, individual lines, vendors and reconciliations keep an append-only history. Nothing in the application can edit or delete one of those rows. The name is stamped on at the time, so it still reads correctly after that person leaves in July.

  5. The bank connection only ever reads

    BeeKeeper asks your bank for two things: balances and transactions. There is no permission to move money, because there is no feature that moves money. A connection that goes quiet for thirty days is flagged rather than silently forgotten.

  6. The numbers that must not leak do not

    A vendor's EIN or SSN is encrypted in the database, and the change log keeps an allowlist of fields specifically so an encrypted number can never be written into it in plain text. Review links are thirty-two random characters, stored only as a hash, and dead after seven days.

  7. When support has to fix something, the log says we did it

    A duplicated import, a check that will not void. The correction is written as FutureFund Support, with the name of the person who approved it and the ticket number beside it. It is never written as you. An audit trail that makes your own history claim you did something you did not do is the one thing it must never do.

  8. A year later, it still answers the question

    The audit committee asks why that check was voided in March. The record says who, when, and why — not because anybody remembered to write it down, but because there was never a way not to.

The risk to a PTA's books is almost never a hacker.

Everyone is an admin, because that was easiest

The president, last year's treasurer, whoever set it up, and one email address nobody at the table can identify.

The board wants to approve, not to browse

Asking a busy parent to sign off on one check should not mean handing them the general ledger.

Nobody can prove who changed the number

The amount is not what you remember it being. There is no other version of the truth to check it against.

Four roles, and one of them is not a weaker version of the others

Admin

The whole application, plus the things only a treasurer or president should touch: who else has access, the bank connections, and closing the fiscal year.

Editor

Works the books day to day — entries, reconciliation, expenses, checks. Cannot change who has access.

Viewer

Reads, and nothing more. Deliberately left out of the operational email too: a read-only role does not need the queue in their inbox.

Reviewer

Sees only the items they were personally asked to sign. No ledger, no reports, no chart of accounts. It exists so a president can approve an expense without being handed the books.

PTA accounting that runs itself

Built for school groups. Free for 30 days, no credit card required.

Start free trial

What is protected, and how

Bank connections are read-only

BeeKeeper asks your bank for two things: balances and transactions. There is no permission to move money, because there is no feature that moves money.

Tax IDs are encrypted at rest

A vendor's EIN or SSN is encrypted in the database. The change log records an allowlist of fields specifically so an encrypted number can never be written into it in plain text.

History is append-only

Expense reports, checks, journal entries, individual lines, vendors and reconciliations keep a record the application cannot edit or delete.

Prior values are kept

Accounts, budgets, permissions, reconciliations, fiscal year closes, vendors and more keep a full version history, so what a number used to be is always answerable.

Tokenized links expire

A review link is thirty-two random characters and only a hash of it is stored, so a copy of our database could not be used to manufacture a signature. Each one dies after seven days.

US and Canada only

Requests from outside the United States and Canada are refused before they reach the application. Hosting is Google Cloud, behind Cloud Armor.

The part most software does not put on a page

Access control is easy to claim. These are the specific decisions underneath it, including the one about what happens when our own support team touches your books.
And so much more
Automatic bank imports
AI receipt scanning
AI transaction coding
Duplicate detection
Bank reconciliation
Expense reports
Mobile apps
Two-signature Sign-Off
Check printing
Check register
Budgets
Budget vs. actual
Custom chart of accounts
Vendor management
W-9 collection portal
1099 reporting
Form 990 mapping
Treasurer's report
Annual financial report
Balance sheet
Profit and loss
General ledger
Audit Kit
Treasurer Transition Kit
Fiscal year close
Role-based permissions
Permanent audit trail
English and Spanish
MCP server
FutureFund sync

Frequently Asked Questions

Keep your books where school groups keep theirs

Accounting built for PTAs, PTOs, booster clubs and ASBs. Free for 30 days, no credit card, cancel anytime.