Every ITR season, freelancers repeat the same scramble: dig out invoices from email, copy bank statements to Excel, export GSTR-1 CSVs, screenshot expense receipts, zip everything up, send it to the CA on WhatsApp. The CA replies asking for one specific invoice from October. Repeat five times. HourSlip's Accountant Access exists to skip that cycle entirely — your CA gets a read-only cockpit that mirrors your own data, with full audit log, magic-link login, no password sharing, no exports needed.
Why CAs Need Access (Not Just Exports)
Three things break the email-and-CSV workflow at scale:
- Reconciliation needs the source. A summarised CSV hides the underlying invoices. When your CA spots a Rs. 7,300 mismatch between your books and your annual tax statement (Form 26AS, or Form 168 from tax year 2026-27), they need to drill into the actual invoice — not ask you to send it.
- Forms 16A, GSTR-1 CSV, P&L, and ITR worksheets all change shape during ITR season. Re-exporting every time the CA finds an inconsistency means re-emailing 5-10 attachments weekly between April and August.
- Live access means one version of the truth. When your CA reads the same data you see, rather than a Dropbox link from March, questions get answered from the source and you are less likely to file on stale numbers. The return and its accuracy remain your responsibility.
The hidden cost of CSV-based collaboration with your CA is the back-and-forth: one new question per week, three new exports per question. Read-only cockpit access drops that weekly tax to zero.
The Magic Link + OTP Flow
HourSlip's accountant access uses passwordless login — your CA never gets your account password, and you never have to rotate one. The flow:
- You add your CA's email from Settings → Accountant Access. One click, one email field.
- We send your CA a one-time magic link by email. Clicking it opens HourSlip in their browser and triggers a 6-digit OTP sent to the same email.
- The OTP is entered to confirm device identity — a second-factor step that prevents email forwarding attacks.
- After OTP verification, the CA gets a 7-day session tied to that device, which also expires after 72 hours of inactivity — whichever comes first. The idle timeout is the one most CAs actually meet, because compliance work runs in bursts around each deadline rather than continuously.
- Expiry ends the session, never the access. Your invitation has no end date: the CA re-opens the same link, gets a fresh 6-digit code by email, and is back in. You are not involved and nothing needs re-inviting. Access stops only when you revoke it.
- The session is per-device. CAs working from office laptop and home laptop are treated as two devices, two sessions.
What CAs See (the 12 Pages)
The CA cockpit is read-only and scoped to 12 specific pages:
- Dashboard — Income, expenses, P&L summary at a glance.
- Clients — Client list with GSTIN and total revenue.
- Invoices — All invoices with status, line items, taxes.
- Time entries — Logged hours by client and project.
- Expenses — Categorised expenses with receipts.
- Platform income — Upwork/Fiverr/Toptal/Direct aggregations.
- TDS tracker — Section-wise TDS log with 26AS reconciliation.
- Tax planner — Old vs new regime, advance tax schedule.
- GST reports — GSTR-1 source data, monthly summary.
- P&L — Drill-down profit-and-loss for the selected period.
- Reports — Tally XML, ITR worksheet, GSTR exports.
- Audit log — Every action the CA has taken in the cockpit.
Pages the CA cannot access: settings, billing, integrations, profile editing, workflow rules. They cannot edit any data anywhere — every form is rendered read-only.
The 5 Exports CAs Can Pull
Even with full read access, CAs prefer downloadable artifacts for their own working files. The cockpit ships 5 one-click exports:
- GSTR-1 CSV — Pre-formatted in the exact 8-section layout the GST portal accepts (B2B, B2CS, B2CL, EXP, CDNR/CDNUR, NIL, HSN, DOCS).
- GSTR-3B summary — Section-by-section numbers ready to type into the portal, including 3.1(d) RCM rows.
- Tally XML — Direct import into Tally Prime / ERP 9 for CAs running Tally workflows.
- ITR worksheet — Pre-computed gross receipts, 44ADA-eligible deemed profit, TDS by section, 80C/80D summary — formatted for ITR-4 line items.
- P&L statement — Period-bounded P&L with category drill-down, downloadable as CSV or PDF.
The Audit Log
Every action the CA takes inside the cockpit is logged: page visited, export downloaded, invoice viewed, search query run. The log is visible to you on the Audit Log tab, with:
- Timestamp (UTC + IST)
- CA email + device fingerprint
- Action category (view, export, search)
- Resource accessed (e.g., "Invoice INV-2026-1024 viewed")
The audit log retains 90 days by default; HourSlip Pro keeps it indefinitely. (Your tax records have their own rules: for GST-registered freelancers, CGST Act s.36 requires keeping books and records for 72 months from the due date of the annual return for that year.)
When to Add Your CA
Most freelancers benefit from CA access in three windows:
- Quarter-end (April, July, October, January) — TDS reconciliation, GSTR-1 review before it is due (the 13th for quarterly filers, the 11th for monthly); advance-tax review before 15 June, 15 September, 15 December and 15 March.
- Pre-ITR season (April-August) — Annual books cleanup, regime selection, deduction planning, ITR draft review.
- Year-round if your CA charges retainer — Add once, leave permanently. The invitation never expires; only the session does, and a new one is one emailed code away.
Revoking Access
Revocation is one click from Settings → Accountant Access → Revoke:
- Active sessions immediately invalidated — any in-progress browser tab gets a 401 on the next request.
- The CA's email is removed from the allowed list — new magic links will not be sent.
- Audit log entries remain (revocation does not erase history; it gates new access).
- If you reinstate the same CA later, they have to complete the OTP flow again.