R&D COPILOT
ROLet’s talk

e-FacturaWorkflow

Scope e-Factura access and responsibilities for several companies

An accounting team working for several companies needs more than a company selector. The selected taxpayer must remain clear during preparation, authorization, submission and response review. A quiet context switch can affect a document long before anyone notices the wrong company name.

By R&D COPILOT5 min read

Make the taxpayer context unmistakable

Begin with the actual working arrangements: internal staff, external accountants and technical operators. List which companies each person may access and which actions they may perform. Reading an invoice, approving its preparation and operating an integration credential are separate permissions.

Separate business identity from technical access

Keep company records and official access configuration distinct. A user may work on several companies while each authorized connection has its own scope and lifecycle. Do not assume that access to a client workspace automatically establishes authority to submit through an official interface.

ANAF's OAuth documentation describes application access linked to authorization. Verify the current registration and supported operations for the intended setup. Record who maintains access and what happens when authorization changes. The business record should reference the connection used without exposing its secret material.

Carry company identity through every handoff

Attach taxpayer context to documents, jobs, responses and exports. The context should be validated at the boundary between systems, not inferred from whichever company a user happens to have open. Background work may continue after the user switches screens.

Display the company prominently before an approval or submission action. If a record belongs to another company, require a deliberate move through an authorized workflow rather than silently changing its owner. Preserve the previous association and explanation where a correction is appropriate.

Design onboarding and access removal

A new client connection needs a documented setup and a verification step using the agreed official workflow. Check the identity presented by the connection, the permissions available and where responses will be stored. Record the responsible contact before regular processing begins.

When an employee leaves or a client engagement ends, review both user access and integration authorization. Removing a screen login may leave a background connection active. Provide a controlled suspension procedure and identify outstanding submissions that another authorized person must continue to monitor.

Protect company boundaries in ordinary work

Test search, downloads, notifications and saved links with a user assigned to only one company. A correct screen filter is insufficient if an export endpoint returns a wider dataset. Company identifiers also need to survive support and retry operations.

Keep credential administration limited to the appropriate role and exclude secrets from logs. An external reviewer may receive invoice and response access without control over authorization settings. Audit history should identify the actor, company and action clearly enough to investigate an unexpected submission.

Rehearse mistakes before they become incidents

Test switching companies while a document is open, repeating a background job after access changes and following an old response link after a user loses permission. Include a suspended connection and an expired authorization so the recovery route is understandable.

Measure mismatched-context attempts, unresolved authorization failures and orphaned jobs without a current owner. Verify that each response maps back to the correct company and submission. The goal is dependable separation and traceability, not a claim that a single integration automatically supports every taxpayer situation.

Check company boundaries at each operation

The most revealing access tests cross normal workflow boundaries. A user can start work in one company, switch context and later receive a notification from the earlier task. Each operation must still resolve the intended company independently.

Prepare test users with different company assignments and inspect both successful and denied actions. A denied request should explain the operational problem without disclosing another client's invoice. Record the expected owner for recovery so technical staff do not solve access failures by granting broader permissions than the task requires.

Check company boundaries at each operation
SituationEvidence to inspectDecision or next action
A user switches companies mid-taskThe open invoice and pending action carry their original taxpayer identity independently of the current navigation selection.Require an explicit action in the correct context and prevent the screen switch from changing the stored submission target.
A notification is opened laterThe saved link identifies its invoice and company, while current permissions may differ from those at notification time.Recheck access when the link is opened and show only the information the person is currently permitted to retrieve.
A connection is suspendedOutstanding attempts and response checks identify the disabled connection and their current operational owners.Pause affected operations, assign continuity decisions and preserve historical evidence without silently choosing another company's connection.
An external accountant leavesThe user account, delegated tasks and authorized background connections show separate access relationships that may require separate actions.Remove the agreed permissions, transfer unresolved work and verify that unattended access is handled by the responsible owner.
A cross-company export is requestedThe requesting role and selected companies can be checked against the dataset before any document archive is generated.Generate only authorized contents and keep the export decision traceable, including the period and companies represented.
Support investigates an errorThe ticket identifies the company and attempt but does not include authorization secrets or unrelated client documents.Provide narrowly scoped evidence and a named connection owner; broader access requires its own justified authorization.

Scope a multi-company implementation

RDC can build company-scoped workspaces, action permissions, authorized connection handling and a reviewable submission history. We define these around your engagement model and the current official interfaces.

Bring a list of roles, company relationships and current access arrangements without sharing credentials. A scoped proposal can specify onboarding, suspension, recovery and acceptance tests. That gives accountants and technical operators a shared operating model, with explicit responsibility for the connections that move each company's documents.

Follow the references

Sources & inspiration

InvoiceFlow AI

Devpost project by Coolieo Bowley

Invoice checks and approval routing.

This independently created project is credited as inspiration. The workflow and implementation guidance in this article are RDC’s analysis.

Put the guide to work

Start with your workflow.

Tell us what your team needs to do, which systems are involved and where the current process slows down.