Evenbead docs

Firm access

4 operations. All areas

POST/v1/firm-access

Grant an accounting firm access to this company (the company's own people only): scopes are the ceiling for every firm member and agent here; billing is recorded only. Audited here and in the firm's log.

  • Operation grantFirmAccess
  • Scope: admin
  • Write: needs Idempotency-Key (or dry_run)
Request body
  • firm_id string, required
  • scopes array of "read" | "propose" | "approve" | "admin", required
  • billing "firm" | "client", required Who pays for the company file (ADR-0009): firm-billed wholesale or client-billed. Recorded only.
  • reason string
Responses
  • 201 Granted (object)
  • Errors 400, 401, 403, 409, 422, 429, 500 (Error: error.type, message)

GET/v1/firm-access

Firms with access to this company (and revoked grants)

  • Operation listFirmAccess
  • Scope: read
  • Read
Responses
  • 200 Grants (object)
  • Errors 400, 401, 403, 429, 500 (Error: error.type, message)

POST/v1/firm-access/{id}/revoke

Revoke a firm's access (effective on its next request; its agents are unassigned here). A firm may also give up its own access. Final.

  • Operation revokeFirmAccess
  • Scope: admin
  • Write: needs Idempotency-Key (or dry_run)
Parameters
  • id path, string, required
Request body
  • reason string, required
Responses
  • 200 Revoked (object)
  • Errors 400, 401, 403, 404, 409, 422, 429, 500 (Error: error.type, message)

POST/v1/firm-access/{id}/update

Change the billing flag of a live grant (record only; scopes are fixed: revoke and grant again)

  • Operation updateFirmAccess
  • Scope: admin
  • Write: needs Idempotency-Key (or dry_run)
Parameters
  • id path, string, required
Request body
  • billing "firm" | "client", required Who pays for the company file (ADR-0009): firm-billed wholesale or client-billed. Recorded only.
Responses
  • 200 Updated (object)
  • Errors 400, 401, 403, 404, 409, 422, 429, 500 (Error: error.type, message)