Account & security

This page covers how people sign in to Journey, what their role lets them do, and how your firm's data is kept safe and separate from everyone else's. Security in Journey isn't a single feature so much as a set of guarantees that run underneath everything. This is where they're spelled out.

Roles

What a member of your firm can do is set by their firm role (Owner, General Manager, Manager, Supervisor, or Staff), arranged as a hierarchy where each role includes the abilities of the ones below it. Roles are how sensitive controls stay with the right people while everyone still has what they need for their own work. For the full breakdown of exactly what each role unlocks and how the hierarchy is enforced, see Role structure.

Signing in

Staff and clients both sign in with an email and password. Team invites and client portal invites alike arrive as a secure one-time link to set a password, so credentials are never handled by anyone but the person they belong to, and a password reset is available from the sign-in screen if one is forgotten.

Sign-in is by email and password, or by a one-time link. Anyone stuck at the sign-in screen can choose "Email me a sign-in link" and Journey sends a link that signs them in without a password, which is usually the quickest way to help a client who cannot get in. Text-message codes and Google sign-in are on the roadmap.

Multi-factor authentication

For stronger protection, staff use multi-factor authentication (a second factor beyond the password), and this matters most for owners and managers performing sensitive actions. Those higher-stakes operations require an elevated, recently-verified session, so simply being logged in isn't enough to perform them; the account has to prove itself again at the moment it counts.

How your data is isolated

Journey is multi-tenant (many firms run on it), and every firm's data is strictly walled off from every other's. A firm's users can only ever see their own firm's clients, returns, and documents. Crucially, this isolation is enforced in the database itself through row-level security, not merely hidden in the interface, so there is no path by which one firm could reach another's data even if it tried.

Sensitive documents and privacy

The same principle of "enforce it, don't just hide it" runs through how sensitive material is handled. Internal staff notes are never exposed to clients. Signer audit details, like IP addresses, are kept in staff-only records. And client documents are stored privately and served through short-lived secure links rather than public URLs, so a document can't be reached by guessing an address or sharing a stale link.

Protecting your firm from scams

Most breaches at tax firms begin with a person being tricked rather than a system being broken: a phishing email, a fake "new client", or a request for W-2s that only looks like it came from the boss. Security and social engineering covers the common tactics, how to verify a request, a page to share with your clients, and a first-hour checklist if something goes wrong.

Can't find what you need? .