Skip to content

QuickBooks Online

QuickBooks Permissions and Current Writeback Availability

Configure QuickBooks mapping and organization writeback policy, then distinguish supported reviewed grant writes from blocked legacy writers.

GrantLink separates how records map to QuickBooks from whether GrantLink may write company data. Use Settings > QuickBooks Mapping to describe and import relationships. Use Settings > Permissions to save the organization-wide writeback policy.

Current availability: QuickBooks remains the accounting source of truth. Supported, rollout-enabled workflows can create or update grant and funder tracking entities and can apply or clear linked grant tracking on eligible transactions. Every such write requires an organization Admin's explicit Preview → Apply review and must pass policy, capability, provider-account, and rollout checks. Legacy journal-entry, claim, custom-field, and other transaction writers remain blocked.

Before You Start

  • Connect and sync QuickBooks first. See Connecting QuickBooks Online and QuickBooks Connection and Sync Troubleshooting.
  • Use an organization Admin role to change Settings > Permissions. The server verifies the Clerk admin or owner role; hiding or showing a control is not the authorization boundary.
  • Treat mapping and permission changes as organization-wide configuration, not as a replacement for accounting approval.
  • Keep making required accounting changes in QuickBooks, then sync GrantLink.

Choose a Source-of-Truth Mode

Open Settings > Permissions. The page shows three modes:

Mode shown in GrantLinkSaved policy behaviorCurrent operational result
Read-only reportingClears every write category. GrantLink can sync, link existing entities, and report without changing QuickBooks.Denies every QuickBooks writeback.
Selected writebacksLets an Admin select individual categories; unselected categories remain denied.Supported grant entity and transaction-tracking workflows may run after separate review when all other gates pass.
Full writeback / automationSaves all visible categories as allowed; grant-level toggles may still narrow intended behavior.Does not bypass workflow review, capability, provider-account, or rollout gates, and does not enable blocked legacy writers.

If no explicit policy has been saved, the page displays a notice. The effective backend default is fail-safe read-only. Select the intended policy and choose Save changes. A successful save records the policy and audit event; it does not test or perform a QuickBooks write.

Review Every Selected-Writeback Category

In Selected writebacks, Allowed writebacks displays eight categories:

Master data

  • Create or update QuickBooks Online grant entities: a Class, Customer, or Project representing a grant.
  • Create or update QuickBooks Online funder customers: the Customer representing a funder.

Transactions

  • Update QuickBooks Online transaction grant tags: Class, Customer, or Project tags on synced transactions.
  • Create allocation journal entries: journal entries associated with expense allocations.
  • Create reversing journal entries: reversals associated with released allocations.

Billing & overhead

  • Post indirect cost journal entries: indirect-cost allocation journal entries.
  • Create claim invoices: QuickBooks invoices from Claims Builder.
  • Write approved QuickBooks Online custom fields: approved fields such as a budget category code.

These controls express policy, not proof that a writer exists, is rollout-enabled, or completed. Create or update QuickBooks Online grant entities and Update QuickBooks Online transaction grant tags have supported reviewed workflows for eligible records. The other listed categories still use blocked legacy writers. In particular, do not infer that an ordinary Ledger allocation changed a transaction tag or posted a journal entry.

Configure QuickBooks Mapping Separately

Open Settings > QuickBooks Mapping. The page links back to QuickBooks Permissions and explicitly treats mapping as separate from writeback.

Current mapping surfaces include:

  • Mapping configuration: describes how GrantLink entities map to QuickBooks. Funders map to Customer. Shared settings do not relink existing grants; grant links are selected on each grant. Projects require QuickBooks Projects capability.
  • Restriction release accounts: when this feature is available, identifies release and offset accounts used to recognize reclassifications.
  • Functional expense tracking: selects the QuickBooks dimension used for Program, Administration, and Fundraising reporting: Class, Department, or None.
  • Class visibility in GrantLink: hides or restores synced classes in GrantLink only. It does not hide, deactivate, or edit them in QuickBooks.

Mapping configuration saves GrantLink organization metadata and does not grant permission to mutate QuickBooks company data.

Understand the Administration Boundary

Settings > Permissions is Admin-only at the API: all members may read the effective policy, but only an Admin can save it. The page states that changes apply to every organization member.

The current QuickBooks Mapping implementation is more granular:

  • An authenticated organization member can currently save the shared mapping configuration.
  • Class visibility changes and the class import plan's scan/draft, approval, and apply operations are Admin-only at their APIs.
  • Therefore, do not describe the entire Mapping page as uniformly Admin-only. Organizations that require tighter review should restrict who changes mapping configuration through their own operating procedure until the UI/API boundary is aligned.

Know the Fail-Closed Execution Boundary

The saved policy evaluator understands read_only, selected, and full, but policy alone never authorizes a provider write. The new durable workflows support eligible Class, Customer/Job, Project, funder Customer, and linked transaction grant-tracking changes. Each one prepares the exact effect for an Admin to review, then rechecks authorization, policy, QuickBooks capability, provider-account identity, source state, and organization rollout before dispatch.

Legacy custom-field, claim, allocation-journal-entry, reversal-journal-entry, indirect-cost-journal-entry, and other transaction mutation paths still fail closed. There is no fallback from a denied durable operation to a legacy writer.

This produces an important distinction:

  1. Policy configuration is necessary but not sufficient: an Admin can allow only the write categories the organization has approved.
  2. Read and local workflows are available: syncing, linking existing entities, importing into GrantLink, reports, notes, budget categories, and local reporting allocations can proceed.
  3. Supported grant writes require explicit review: an eligible, rollout-enabled grant entity or transaction-tracking workflow must show the exact change before an Admin applies it.
  4. Other writers remain unavailable: selecting or saving their policy category does not make a blocked legacy path operational.

If a workflow is unavailable or reports a failed or uncertain outcome, do not repeatedly retry or assume no effect. Read the displayed status, verify QuickBooks directly, and follow the workflow's recovery guidance.

Verify a Safe Configuration

  1. In Settings > Permissions, confirm the displayed mode and save only if you are an Admin.
  2. Reopen the page and confirm the saved badge and categories.
  3. In Settings > QuickBooks Mapping, verify dimensions, links, and visibility without expecting QuickBooks changes.
  4. Sync, then inspect the relevant grant or Ledger source details.
  5. Verify accounting state in QuickBooks itself. A GrantLink success message for a local report, mapping, or allocation is not evidence of a QuickBooks write.

For transaction-level effects, see The Ledger Workflow. For allocation accounting boundaries, see Allocating Transactions to Grants.

Search docs

Type to search documentation pages and sections.