Sharing HourSlip with Your CA: Read-Only Accountant Access
Skip the WhatsApp-and-CSV cycle with your CA. Read-only cockpit, magic-link login, full audit log — your CA sees what you see, with zero credential sharing.
Every ITR season, freelancers repeat the same scramble: dig out invoices from email, copy bank statements to Excel, export GSTR-1 CSVs, screenshot expense receipts, zip everything up, send it to the CA on WhatsApp. The CA replies asking for one specific invoice from October. Repeat five times. HourSlip's Accountant Access exists to skip that cycle entirely — your CA gets a read-only cockpit that mirrors your own data, with full audit log, magic-link login, no password sharing, no exports needed.
Why CAs Need Access (Not Just Exports)
Three things break the email-and-CSV workflow at scale:
- Reconciliation needs the source. A summarised CSV hides the underlying invoices. When your CA spots a Rs. 7,300 mismatch between your books and 26AS, they need to drill into the actual invoice — not ask you to send it.
- Forms 16A, GSTR-1 CSV, P&L, and ITR worksheets all change shape during ITR season.Re-exporting every time the CA finds an inconsistency means re-emailing 5-10 attachments weekly between April and July.
- Compliance liability shifts when the CA has live access. A CA looking at read-only data they can re-pull whenever needed is much harder to challenge in scrutiny than a CA who got a Dropbox link in March.
The hidden cost of CSV-based collaboration with your CA is the back-and-forth: one new question per week, three new exports per question. Read-only cockpit access drops that weekly tax to zero.
The Magic Link + OTP Flow
HourSlip's accountant access uses passwordless login — your CA never gets your account password, and you never have to rotate one. The flow:
- You add your CA's email from Settings → Accountant Access. One click, one email field.
- We send your CA a one-time magic link by email. Clicking it opens HourSlip in their browser and triggers a 6-digit OTP sent to the same email.
- The OTP is entered to confirm device identity — a second-factor step that prevents email forwarding attacks.
- After OTP verification, the CA gets a 30-day session tied to that device. Within those 30 days, they log in passwordlessly with the same email (we send a one-tap link each session).
- The 30-day session is per-device. CAs working from office laptop and home laptop are treated as two devices, two sessions.
What CAs See (the 12 Pages)
The CA cockpit is read-only and scoped to 12 specific pages:
- Dashboard — Income, expenses, P&L summary at a glance.
- Clients — Client list with GSTIN and total revenue.
- Invoices — All invoices with status, line items, taxes.
- Time entries — Logged hours by client and project.
- Expenses — Categorised expenses with receipts.
- Platform income — Upwork/Fiverr/Toptal/Direct aggregations.
- TDS tracker — Section-wise TDS log with 26AS reconciliation.
- Tax planner — Old vs new regime, advance tax schedule.
- GST reports — GSTR-1 source data, monthly summary.
- P&L — Drill-down profit-and-loss for the selected period.
- Reports — Tally XML, ITR worksheet, GSTR exports.
- Audit log — Every action the CA has taken in the cockpit.
Pages the CA cannot access: settings, billing, integrations, profile editing, workflow rules. They cannot edit any data anywhere — every form is rendered read-only.
The 5 Exports CAs Can Pull
Even with full read access, CAs prefer downloadable artifacts for their own working files. The cockpit ships 5 one-click exports:
- GSTR-1 CSV — Pre-formatted in the exact 8-section layout the GST portal accepts (B2B, B2CS, B2CL, EXP, CDNR/CDNUR, NIL, HSN, DOCS).
- GSTR-3B summary — Section-by-section numbers ready to type into the portal, including 3.1(d) RCM rows.
- Tally XML — Direct import into Tally Prime / ERP 9 for CAs running Tally workflows.
- ITR worksheet — Pre-computed gross receipts, 44ADA-eligible deemed profit, TDS by section, 80C/80D summary — formatted for ITR-4 line items.
- P&L statement — Period-bounded P&L with category drill-down, downloadable as CSV or PDF.
The Audit Log
Every action the CA takes inside the cockpit is logged: page visited, export downloaded, invoice viewed, search query run. The log is visible to you on the Audit Log tab, with:
- Timestamp (UTC + IST)
- CA email + device fingerprint
- Action category (view, export, search)
- Resource accessed (e.g., "Invoice INV-2026-1024 viewed")
The audit log retains 90 days by default. For long-term retention (Section 36 mandates a 6-year minimum for tax records), HourSlip Pro stores the log indefinitely on your account.
When to Add Your CA
Most freelancers benefit from CA access in three windows:
- Quarter-end (April, July, October, January) — Advance tax review, TDS reconciliation, GSTR-1 review before the 11th-of-next-month deadline.
- Pre-ITR season (April-July) — Annual books cleanup, regime selection, deduction planning, ITR draft review.
- Year-round if your CA charges retainer — Add once, leave permanently. The 30-day session auto-renews on each login.
Revoking Access
Revocation is one click from Settings → Accountant Access → Revoke:
- Active sessions immediately invalidated — any in-progress browser tab gets a 401 on the next request.
- The CA's email is removed from the allowed list — new magic links will not be sent.
- Audit log entries remain (revocation does not erase history; it gates new access).
- If you reinstate the same CA later, they have to complete the OTP flow again.
Frequently asked
A few things readers always ask.
Yes. You can add up to 2 CA emails on the Pro plan. Each gets their own 30-day session, their own audit log entries, and their own magic-link flow. Useful for partner firms where the primary CA delegates GSTR-1 work to an associate.
No. Accountant Access is included in your Pro subscription. Your CA does not pay anything to access your data. If your CA wants to set up their own HourSlip workspace for other clients, that requires a separate Pro account.
CAs cannot edit. They will message you with the correction needed; you make the edit in your own account; the change reflects immediately in the CA cockpit. This split is intentional — your data, your edits; their analysis.
The magic link is one-time and expires in 15 minutes. Even if an attacker intercepts the email, they need to claim it within 15 minutes, then pass the 6-digit OTP also sent to the same email. The OTP step is what prevents simple email forwarding attacks. For high-risk scenarios (CAs handling 50+ clients), they should use a hardware security key on their email account.
Yes. The Audit Log lists every export with timestamp, file type, and which CA pulled it. If your CA pulled the ITR worksheet on 18 July at 9pm, you see it. Useful for billing CAs by quarter activity and for compliance trails during scrutiny.
Their access is revoked immediately on downgrade. Your data continues to be visible on the free plan (with feature limits), but the Accountant Access feature itself is Pro-only. To restore CA access, resubscribe to Pro and re-add the email.
HourSlip is the cockpit for Indian freelance work — time tracking, GST invoicing, advance tax, TDS reconciliation, and ITR-ready exports. Built by a small team that files its own taxes and got tired of spreadsheets.
Read next
Use Case
Import Bank CSV and SMS as Expenses — 7 Indian Banks Supported
Stop typing every expense. HourSlip Pro parses CSVs from 7 Indian banks and SMS notifications from any sender. Android share target makes it one-tap.
ReadUse Case
GSTR-2B Reconciliation for Freelancers: A Practical Monthly Workflow
Every claimed rupee of ITC must trace to GSTR-2B. Here is the monthly workflow, the 4-state reconciliation model, and how to do it in minutes — not hours.
Read