Use Case

Sharing HourSlip with Your CA: Read-Only Accountant Access

Skip the WhatsApp-and-CSV cycle with your CA. Read-only cockpit, magic-link login, full audit log — your CA sees what you see, with zero credential sharing.

On this page

Every ITR season, freelancers repeat the same scramble: dig out invoices from email, copy bank statements to Excel, export GSTR-1 CSVs, screenshot expense receipts, zip everything up, send it to the CA on WhatsApp. The CA replies asking for one specific invoice from October. Repeat five times. HourSlip's Accountant Access exists to skip that cycle entirely — your CA gets a read-only cockpit that mirrors your own data, with full audit log, magic-link login, no password sharing, no exports needed.

Why CAs Need Access (Not Just Exports)

Three things break the email-and-CSV workflow at scale:

  1. Reconciliation needs the source. A summarised CSV hides the underlying invoices. When your CA spots a Rs. 7,300 mismatch between your books and your annual tax statement (Form 26AS, or Form 168 from tax year 2026-27), they need to drill into the actual invoice — not ask you to send it.
  2. Forms 16A, GSTR-1 CSV, P&L, and ITR worksheets all change shape during ITR season. Re-exporting every time the CA finds an inconsistency means re-emailing 5-10 attachments weekly between April and August.
  3. Live access means one version of the truth. When your CA reads the same data you see, rather than a Dropbox link from March, questions get answered from the source and you are less likely to file on stale numbers. The return and its accuracy remain your responsibility.
The hidden cost of CSV-based collaboration with your CA is the back-and-forth: one new question per week, three new exports per question. Read-only cockpit access drops that weekly tax to zero.

HourSlip's accountant access uses passwordless login — your CA never gets your account password, and you never have to rotate one. The flow:

  1. You add your CA's email from Settings → Accountant Access. One click, one email field.
  2. We send your CA a one-time magic link by email. Clicking it opens HourSlip in their browser and triggers a 6-digit OTP sent to the same email.
  3. The OTP is entered to confirm device identity — a second-factor step that prevents email forwarding attacks.
  4. After OTP verification, the CA gets a 7-day session tied to that device, which also expires after 72 hours of inactivity — whichever comes first. The idle timeout is the one most CAs actually meet, because compliance work runs in bursts around each deadline rather than continuously.
  5. Expiry ends the session, never the access. Your invitation has no end date: the CA re-opens the same link, gets a fresh 6-digit code by email, and is back in. You are not involved and nothing needs re-inviting. Access stops only when you revoke it.
  6. The session is per-device. CAs working from office laptop and home laptop are treated as two devices, two sessions.

What CAs See (the 12 Pages)

The CA cockpit is read-only and scoped to 12 specific pages:

  1. Dashboard — Income, expenses, P&L summary at a glance.
  2. Clients — Client list with GSTIN and total revenue.
  3. Invoices — All invoices with status, line items, taxes.
  4. Time entries — Logged hours by client and project.
  5. Expenses — Categorised expenses with receipts.
  6. Platform income — Upwork/Fiverr/Toptal/Direct aggregations.
  7. TDS tracker — Section-wise TDS log with 26AS reconciliation.
  8. Tax planner — Old vs new regime, advance tax schedule.
  9. GST reports — GSTR-1 source data, monthly summary.
  10. P&L — Drill-down profit-and-loss for the selected period.
  11. Reports — Tally XML, ITR worksheet, GSTR exports.
  12. Audit log — Every action the CA has taken in the cockpit.

Pages the CA cannot access: settings, billing, integrations, profile editing, workflow rules. They cannot edit any data anywhere — every form is rendered read-only.

The 5 Exports CAs Can Pull

Even with full read access, CAs prefer downloadable artifacts for their own working files. The cockpit ships 5 one-click exports:

  1. GSTR-1 CSV — Pre-formatted in the exact 8-section layout the GST portal accepts (B2B, B2CS, B2CL, EXP, CDNR/CDNUR, NIL, HSN, DOCS).
  2. GSTR-3B summary — Section-by-section numbers ready to type into the portal, including 3.1(d) RCM rows.
  3. Tally XML — Direct import into Tally Prime / ERP 9 for CAs running Tally workflows.
  4. ITR worksheet — Pre-computed gross receipts, 44ADA-eligible deemed profit, TDS by section, 80C/80D summary — formatted for ITR-4 line items.
  5. P&L statement — Period-bounded P&L with category drill-down, downloadable as CSV or PDF.

The Audit Log

Every action the CA takes inside the cockpit is logged: page visited, export downloaded, invoice viewed, search query run. The log is visible to you on the Audit Log tab, with:

  • Timestamp (UTC + IST)
  • CA email + device fingerprint
  • Action category (view, export, search)
  • Resource accessed (e.g., "Invoice INV-2026-1024 viewed")

The audit log retains 90 days by default; HourSlip Pro keeps it indefinitely. (Your tax records have their own rules: for GST-registered freelancers, CGST Act s.36 requires keeping books and records for 72 months from the due date of the annual return for that year.)

When to Add Your CA

Most freelancers benefit from CA access in three windows:

  • Quarter-end (April, July, October, January) — TDS reconciliation, GSTR-1 review before it is due (the 13th for quarterly filers, the 11th for monthly); advance-tax review before 15 June, 15 September, 15 December and 15 March.
  • Pre-ITR season (April-August) — Annual books cleanup, regime selection, deduction planning, ITR draft review.
  • Year-round if your CA charges retainer — Add once, leave permanently. The invitation never expires; only the session does, and a new one is one emailed code away.

Revoking Access

Revocation is one click from Settings → Accountant Access → Revoke:

  • Active sessions immediately invalidated — any in-progress browser tab gets a 401 on the next request.
  • The CA's email is removed from the allowed list — new magic links will not be sent.
  • Audit log entries remain (revocation does not erase history; it gates new access).
  • If you reinstate the same CA later, they have to complete the OTP flow again.

FAQ

Can multiple CAs access my account simultaneously?
Yes. You can add up to 2 CA emails on the Pro plan. Each gets their own 7-day session, their own audit log entries, and their own magic-link flow. Useful for partner firms where the primary CA delegates GSTR-1 work to an associate.
Does my CA need their own HourSlip subscription?
No. Accountant Access is included in your Pro subscription. Your CA does not pay anything to access your data. If your CA wants to set up their own HourSlip workspace for other clients, that requires a separate Pro account.
What if my CA wants to make a correction to an invoice?
CAs cannot edit. They will message you with the correction needed; you make the edit in your own account; the change reflects immediately in the CA cockpit. This split is intentional — your data, your edits; their analysis.
Is the magic link secure if the CA's email is hacked?
The magic link is one-time and expires in 15 minutes. Even if an attacker intercepts the email, they need to claim it within 15 minutes, then pass the 6-digit OTP also sent to the same email. The OTP step is what prevents simple email forwarding attacks. For high-risk scenarios (CAs handling 50+ clients), they should use a hardware security key on their email account.
Can I see what my CA exported and when?
Yes. The Audit Log lists every export with timestamp, file type, and which CA pulled it. If your CA pulled the ITR worksheet on 18 July at 9pm, you see it. Useful for billing CAs by quarter activity and for compliance trails during scrutiny.
What happens to my CA's access if I cancel HourSlip Pro?
Their access is revoked immediately on downgrade. Your data continues to be visible on the free plan (with feature limits), but the Accountant Access feature itself is Pro-only. To restore CA access, resubscribe to Pro and re-add the email.

Every deduction, caught

Manage your freelance finances in one place.

HourSlip handles invoicing, GSTR-1 export, and TDS reconciliation — free to start.

Start free →

This guide is general information, not tax advice. Rates and dates are for FY 2026–27 and can change. Verify with your CA before you file.

HourSlip

We build GST invoicing and tax tooling for India’s independent services professionals. Every guide is written against the Act, the Rules and the CBDT/CBIC circulars, and cites its sources.

Built for Indian freelancers

Invoicing and compliance, in one place.

GST-correct invoices, TDS tracked to 26AS, and a tax position you can actually see — free to start.

• No card required• Export your data as CSV