How to Safely Give Your Clients "Drill Down" Access
A lot of firms invite their clients directly into Retriever so they can refresh their own reports and drill down into the transaction detail behind any number — without picking up the phone or opening QuickBooks. The key is doing it so each client sees only their own business, and never your other clients, users, or companies. Here's exactly how to set that up, what your client will see on their end, and the one setting to stay on top of as you grow.
Watch the walkthrough
This short video walks through the whole thing end to end — inviting a client as a viewer, choosing which company they can see, and what the client experiences on their side.
Start with the right role: Viewer
Before you invite anyone, it helps to know how roles work. Retriever offers more permissive roles for your own team, but for clients you want the Viewer role. A viewer can do the useful things — refresh reports and drill down — but nothing that could change your setup or expose other clients.
A viewer can
- Open and refresh their own company's reports so the numbers stay current
- Drill down on any cell to see the underlying transaction detail — without opening QuickBooks
- View the reports and companies you've granted them — and nothing else
A viewer cannot
- Create or edit reports
- Reach the Create, Configure, Access, or Account tabs — a viewer's app only shows Drill down and Manage
- See your other users, or any company you haven't explicitly shared with them
How to invite a client (step by step)
- Open Access
From your Retriever workspace, go to the Access section. This is where you manage everyone who can see your reports and which companies they can reach.
- Click "Invite users" and enter the client's email
Enter the email address of the client you want to invite. You can add several people at once here if a client has more than one person who needs access.
- Choose the "Viewer" role
Set the role to Viewer. This is the role built for clients: they can refresh reports and drill into transaction detail, but they cannot edit or create reports, or manage other users.
- Select only the company (or companies) they should see
Deselect everything first, then check only the specific company that client should have access to. If they own two businesses, select both — but nothing else.
- Grant access
Click Grant access. Retriever emails the client an invitation with instructions on how to install Retriever and open their reports. That's it — they're scoped to just their own company.
In short: client email, Viewer role, one company (or two, if they have two) — then Grant access. Retriever sends them an email with instructions to install and open their reports.
What your client sees — and what they don't
Once the client accepts, they open a pared-down version of Retriever built around exactly what they need. The app shows just two tabs — Drill down and Manage — and viewers land straight on Drill down:
- Drill down — where they land. Whenever a viewer opens Retriever, they go straight to Drill down, where they can select any cell and inspect the transaction detail behind it — without opening QuickBooks.
- Manage — refresh, but not edit. On the Manage tab they can refresh their reports to pull the latest numbers, but they can't click into a report to edit it — there are no edit controls.
- Only their own reports. Even when reports live in a shared firm workbook alongside other clients', a viewer's list is filtered to just their own company — other clients' rows never show up.
- Everything else is hidden. The Create, Configure, Access, and Account tabs don't appear for viewers — no report builder, no user list, no company roster, no settings to wander into. If a client ever opens one of those pages from an old link, Retriever sends them straight back to their own reports.
The result is a clean client portal: two tabs, their own business, and nothing in the interface that points to anyone else's.
The one thing to watch: connecting new companies
This is the setting worth being intentional about. When you connect a new company, Retriever shows a pop-up listing everyone in your organization — both your team members and your other clients — so you can choose who gets access. New companies are not shared with anyone automatically.
The one thing to be careful with here is Select All: checking it would grant every client access to the new company — which could hand one client a window into another client's business. Instead, leave your clients unchecked, select only the people who should see the company, and click Grant Access.
And if you ever need to change it, access is a single click to grant or revoke, company by company — so it's easy to adjust later without redoing the invite.
Note: There's an extra layer of security here: even if you granted the wrong company, a client can only read data from Google Sheets you've shared with them — and you'd never share another client's sheet.
A quick note on the email-domain warning
When your client opens the invitation, they may see a red caution line if your email domain and theirs don't match. That's a security precaution, not a problem — it simply flags the domain mismatch, and your client will still recognize your name, profile picture, and email address on the invitation before they accept. It's worth giving clients a heads-up that the invite is coming from you so they know to expect it.
Frequently asked questions
Which role should I give a client?
The Viewer role. It lets clients refresh and drill down into their own reports while keeping them out of anything that could change your setup — they can't edit or create reports, and they can't manage users. Reserve the more permissive roles for your own team.
Can a client see my other clients or companies?
No. A viewer only sees the companies you grant them, and the tabs that would expose anyone else — Create, Configure, Access, and Account — are hidden for viewers entirely. Even when reports share a single firm workbook, the Manage view is filtered to just that client's own company, so other clients' reports never appear.
What happens when I connect a new company later?
New companies are not shared automatically. When you connect a company, you decide who gets access on the spot. If you don't want an existing client to see the new company, simply leave them unchecked when you grant access — they'll never see it appear.
My client saw a red warning about email domains. Is something wrong?
No. When the inviter's and invitee's email domains don't match, Retriever shows a caution line on the invitation as a security precaution — it's just flagging that the domains differ. Your client will still see your name, profile picture, and email address on the invitation, so they can confirm it's you and accept.
What does the client actually see when they open Retriever?
A streamlined version of Retriever with just two tabs — Drill down and Manage. They land on Drill down, where they can inspect the transaction detail behind any number, and on Manage they can refresh their reports (but not edit them). The report list is filtered to only their own reports, and the Create, Configure, Access, and Account tabs are hidden. If they open one of those pages from a stale link, they're sent back to their reports.
Give every client a live window into their own numbers
Retriever pulls your QuickBooks Online reports into Google Sheets and refreshes them on a schedule — then lets you invite each client as a view-only user who can drill down into their own detail, and only their own. No exports, no back-and-forth, no risk of one client seeing another.
See how Retriever worksSee also
Questions about inviting clients? Reach out — aubrey@retrieverhq.com.