Firm access
4 operations. All areas
- POST /v1/firm-access
- GET /v1/firm-access
- POST /v1/firm-access/{id}/revoke
- POST /v1/firm-access/{id}/update
POST/v1/firm-access
Grant an accounting firm access to this company (the company's own people only): scopes are the ceiling for every firm member and agent here; billing is recorded only. Audited here and in the firm's log.
- Operation
grantFirmAccess - Scope: admin
- Write: needs Idempotency-Key (or dry_run)
- Request body
firm_idstring, requiredscopesarray of "read" | "propose" | "approve" | "admin", requiredbilling"firm" | "client", required Who pays for the company file (ADR-0009): firm-billed wholesale or client-billed. Recorded only.reasonstring
- Responses
201Granted (object)- Errors
400,401,403,409,422,429,500(Error:error.type,message)
GET/v1/firm-access
Firms with access to this company (and revoked grants)
- Operation
listFirmAccess - Scope: read
- Read
- Responses
200Grants (object)- Errors
400,401,403,429,500(Error:error.type,message)
POST/v1/firm-access/{id}/revoke
Revoke a firm's access (effective on its next request; its agents are unassigned here). A firm may also give up its own access. Final.
- Operation
revokeFirmAccess - Scope: admin
- Write: needs Idempotency-Key (or dry_run)
- Parameters
idpath, string, required
- Request body
reasonstring, required
- Responses
200Revoked (object)- Errors
400,401,403,404,409,422,429,500(Error:error.type,message)
POST/v1/firm-access/{id}/update
Change the billing flag of a live grant (record only; scopes are fixed: revoke and grant again)
- Operation
updateFirmAccess - Scope: admin
- Write: needs Idempotency-Key (or dry_run)
- Parameters
idpath, string, required
- Request body
billing"firm" | "client", required Who pays for the company file (ADR-0009): firm-billed wholesale or client-billed. Recorded only.
- Responses
200Updated (object)- Errors
400,401,403,404,409,422,429,500(Error:error.type,message)