Jump to section
Key takeaways
- Three properties make access permissioned: it is scoped, it is attributable to a named person, and it is revocable.
- Sharing a login is the opposite of permissioned access: it is unscoped, unattributable, and can only be revoked by changing the password for everyone.
- Revocability is what makes it safe to grant access generously in the first place.
- An access log matters as much as the permission itself: who saw what, and when.
How Olomon thinks about this
Permissioned access is the collaboration model Olomon is built around: the household holds the record and decides who reads which part of it. The practical consequence is that granting access stops being a decision the household has to be nervous about, because it is scoped to begin with and reversible afterward.
In-depth definition
The default way households share financial information with their professional team is not really sharing at all. It is emailing a PDF, exporting a spreadsheet, or handing over a password. Each of those produces a copy that is stale the moment it is sent, that lives outside the household's control, and that cannot be taken back. A CPA who received a statement in March still has that statement in November, and the household has no record of it.
Permissioned access inverts that. The record stays in one place and each professional is granted a view of the part of it their work requires: the attorney sees entity and document structure, the CPA sees what matters for the return, an adult child named as successor trustee sees what a trustee needs. Nobody holds a copy, every grant is attributable to a person, and when a relationship ends the access ends with it rather than persisting in an inbox.
The idea has a regulatory analogue, though not one that binds anyone today. The CFPB's Personal Financial Data Rights rule sets out requirements for authorized third parties at 12 CFR 1033.401 and following, resting on the same premise: a third party has access because the consumer authorized it, and that authorization can be withdrawn. A federal court stayed the rule's compliance dates in October 2025 and the Bureau has reopened it for revision, so the parallel describes where the thinking is heading rather than an obligation in force.
Frequently asked questions
A shared login grants everything to everyone who has it, leaves no trace of who actually looked, and can only be revoked by changing the credential, which cuts off every other person at the same time. Permissioned access is granted per person, limited to a defined scope, logged, and withdrawn individually.
Not by default. Viewing and editing are separate permissions, and most professional access is read-only. The point of scoping is that each grant carries only what that person's work actually requires.
It is revoked, and because they were reading from the household's record rather than holding their own copy, revoking it is sufficient. That is the practical difference from a document-sharing workflow, where every file you ever sent stays where you sent it.
Sources
Primary, authoritative references.
- 1
Consumer Financial Protection Bureau
Personal financial data rightsCited for: The rule's authorized-third-party requirements (12 CFR 1033.401 and following) and the October 2025 stay of its compliance dates
Continue exploring
Cite this page
APAOlomon Editorial Team. (2026). Permissioned access. Olomon Financial Glossary. https://olomon.com/financial-glossary/permissioned-access