KSeF permissions for an accountant and accounting firm in Poland in 2026
How to give an accountant or accounting firm access to KSeF, separate roles, enable delegation, and securely end the cooperation.
An accounting firm’s access to KSeF should be based on permissions granted in the system, not on giving the accountant the business owner’s private login, Trusted Profile, or electronic signature. KSeF lets you specify who may issue invoices, who may view them, and who may manage further access.
Accounting office access to KSeF in Poland
Grant permissions — never share your private login
1. Define tasks
Receiving, issuing or viewing invoices, or managing permissions.
2. Select a person or entity
Verify the identifier and access scope before approval.
3. Test access
The accountant should confirm access before the first deadline.
4. Revoke when finished
Changing offices does not remove earlier access automatically.
UPL-1 and PEL do not replace KSeF permissions.
Move your accounting without disruptionMatch the permission scope to actual tasks and current KSeF functions.
A JDG owner receives access automatically
A natural person conducting business and holding a NIP, the Polish tax identification number, automatically receives owner permissions in KSeF. They do not need to file ZAW-FA merely to obtain basic access to their own business.
The owner authenticates using an accepted method, such as a Trusted Signature or qualified electronic signature. If the qualified signature contains neither a NIP nor a PESEL number, its details must be reported using ZAW-FA so that KSeF can link it to the taxpayer. This is a special technical case, however, rather than the standard way to activate KSeF for a JDG.
Initial access works differently for a company or another entity that is not a natural person. Such an entity can act using a qualified seal containing its NIP. If it does not have one, it names the first authorized person on the ZAW-FA form. This article focuses on a typical JDG, but it is important to understand the distinction rather than copying the procedure for a company into a sole proprietorship.
A broader introduction to the system is available in the guide KSeF for a JDG in Poland in 2026.
An individual or the entire accounting firm
A business owner can grant access to a specific natural person or to an entity, such as an accounting firm identified by its NIP. These models have different organizational consequences.
Granting permissions to a specific accountant is straightforward when one person is responsible for the engagement and only that person will handle the business. Any change of account manager, however, requires the owner to revoke the old access and grant new access.
When permissions are granted to the accounting firm as an entity, the firm can be allowed to delegate access to its employees. The business owner then authorizes the firm, and the firm identifies the people who actually serve the client. Staff changes do not require the owner’s involvement each time, provided that the scope of the entity-level permission still corresponds to the agreement.
This does not mean giving the firm unlimited control. The scope of activities must be defined deliberately, and the owner must decide whether the entity should have the right to grant further permissions. The right to issue or access invoices should not automatically be equated with the right to manage every user.
How to divide the scope of access
Before granting permissions, describe the actual process. A person who only downloads purchase invoices needs different access from an accountant who issues sales invoices, while an administrator responsible for employee access needs something different again.
In practice, you should answer several questions:
- will the firm only receive and view purchase invoices,
- will it issue sales invoices on the client’s behalf,
- will it download UPO confirmations and verify submission status,
- may it grant permissions to its employees,
- should access cover the whole business or a specific organizational model,
- who is responsible for corrections and handling documents rejected for technical reasons?
The safest rule is to grant the minimum scope required to perform the agreed activities. If the firm only records expenses, permission to issue invoices may be unnecessary. If it is to handle the complete sales process, document viewing alone will be insufficient.
How to give the firm access
The JDG owner should open the relevant KSeF tool, authenticate in their own name, and select their business context. They then identify the person or entity and select the appropriate scope of permissions.
For an accounting firm, check in particular:
- the firm’s correct NIP,
- the scope of access under the agreement,
- whether the firm may delegate permissions to its employees,
- the service start date,
- how you will verify that access actually works.
After granting permissions, a confirmation screenshot is not enough. The firm should run a test in the correct context by checking access to documents or performing an agreed test operation. Do not experiment by submitting a fictitious invoice to the production environment.
KSeF is not UPL-1 or PEL
Permissions in KSeF are a separate mechanism. They must not be confused with the UPL-1 power of attorney for signing tax declarations or the PEL power of attorney used in dealings with ZUS, Poland’s Social Insurance Institution.
Filing UPL-1 does not automatically give the accountant access to invoices in KSeF. Conversely, granting KSeF access does not mean that the firm may sign all of the business owner’s tax returns. PEL is not a substitute for permission to act in KSeF either.
In practice, one accounting firm may need several independent authorizations. Each serves a different process and should be granted, monitored, and revoked separately. This is particularly important when changing accounting firms: ending the agreement does not always remove every existing permission across different systems automatically.
A certificate and accounting software do not replace permission
A permission answers the question what a person or entity may do. Authentication answers the question how the system confirms the identity of a user or application. The concepts are not interchangeable.
An accountant may use an accepted authentication method, but without the correct permission they should not gain access to the client’s business. Conversely, granting permission does not mean that a certificate, signature, or login credentials can be freely shared among employees.
If the firm uses software integrated with KSeF, establish who manages the certificates, how long they are valid, where they are stored, and how they will be revoked after a provider change. A business owner should not hand over personal authentication tools for the firm’s routine use.
Changing accountants or ending the cooperation
The access revocation procedure should form part of the agreement and the offboarding checklist. First, establish whether the permission was granted to a specific person, the entire firm, or both.
When the service ends, you should:
- revoke unnecessary person-level and entity-level permissions,
- check delegations created by the firm,
- revoke unneeded certificates and integration access,
- download UPO confirmations and a list of documents in progress,
- agree who will submit invoices issued offline,
- give the new firm information about corrections and rejected files.
Pay particular attention to invoices issued outside the system that are still awaiting submission. The deadlines depend on the procedure used; they are covered in the article KSeF offline24, unavailability, and outages.
A short checklist for business owners
Before starting the cooperation, confirm the firm’s NIP, scope of activities, and right to delegate. Do not share your Trusted Profile or private signature. Once access has been granted, request a technical test and record who is responsible for monitoring rejections and downloading UPO confirmations.
Review active permissions every few months. This review is particularly important after a change of account manager, the end of a contract, or the implementation of new accounting software. KSeF makes it easier to separate roles, but only when access reflects the business’s current organization.
Sources
Questions about accounting?
I run accounting for sole proprietors from 49 zł + VAT per month.
Get in touch