A login is not "KSeF access"
Sharing your Profil Zaufany login does not grant anything inside KSeF. It simply lets that person into your entire digital identity: the tax portal, ePUAP, social security, official filings. An accountant needs none of that to issue an invoice.
KSeF works differently. Permissions attach to a specific person or entity, identified by their NIP (tax ID) or PESEL (personal ID number). The authorized person signs in with their own Profil Zaufany, a qualified electronic signature, or a KSeF certificate, and the system knows they are acting on your behalf. A PESEL number alone is not enough to log in; one of those authentication methods is required (podatki.gov.pl).
The payoff: you get a clear record of who did what, and removing access is one action instead of changing a password and hoping nobody wrote it down.
Who holds KSeF permissions by default
Before you grant anything, it helps to know your starting point. It depends on your legal form.
Sole proprietorship (JDG). You hold owner permissions automatically, assigned by the system to your NIP. No forms to file. You sign in with your Profil Zaufany or qualified signature and can immediately issue invoices, view them, and grant access to others (podatki.gov.pl).
Companies and other entities. There is one extra step. If the company has a qualified seal, it authenticates with that and the first person then grants permissions electronically. If there is no seal, the company files a one-time paper notification called ZAW-FA with the tax office, designating one individual to use KSeF. That person then adds further permissions electronically (podatki.gov.pl).
In short: ZAW-FA is filed once to open the door. You do not grant your accountant access through ZAW-FA, you do it inside the system.
The four permission types you can grant
KSeF is not a single on/off switch. Permissions are split, so you hand over exactly what is needed:
Owner permissions – the broadest, assigned by default to the taxpayer's NIP. You do not grant these to an accountant.
Permission management – the right to grant, change, and revoke access for others. The strongest grantable right. Hand it out carefully.
Invoice issuing – the right to issue structured invoices on your behalf.
Invoice access – viewing and downloading invoices held in KSeF.
Issuing and access are independent. You can grant view-only, issue-only, or both (podatki.gov.pl). For a typical accounting-office relationship, issuing plus invoice access is usually enough, without permission management.
Granting your accountant access, step by step
Since 1 February 2026 you do this directly in the free Taxpayer Application (Aplikacja Podatnika KSeF) or in software integrated with KSeF. The path looks like this:
Sign in to KSeF with your Profil Zaufany (or qualified signature). Since April 2026, sign-in via the mObywatel app is also available.
Open the "Permissions" (Uprawnienia) section and choose to grant a new permission.
Enter the authorized party's details: your accountant's NIP or PESEL, or the accounting office's NIP and name.
Select the scope: for example, invoice issuing and invoice access. For an office running the whole process, you may add permission management.
Save. From then on, your accountant signs in to KSeF with their own Profil Zaufany and works within the scope you set (podatki.gov.pl).
Revoking is just as simple: return to the "Permissions" section and withdraw the granted rights. Keep that in mind especially when you change accounting offices or an employee leaves.
If your accountant works in the system daily, it is more practical to connect through a KSeF certificate rather than signing in with Profil Zaufany every time. The certificate is an access file valid for two years, with renewal. We cover it in more depth in our piece on KSeF tokens vs. certificates.
Where Biurko fits in
Everything above is the state layer: you grant it inside KSeF, and it applies no matter which software you use. Biurko sits one level up, exactly where login chaos usually starts.
In Biurko every team member has their own account, and you assign a role: owner, admin, accountant, or member. You do not hand over your panel login, just as you never hand over your Profil Zaufany. The accountant role can view and issue invoices and send them to KSeF, but cannot touch connection settings, the team, or the subscription.
For accounting offices there is a multi-company panel: one accountant serves many clients from a single place, with a separate KSeF connection per company. It is the same logic as KSeF, laid out more comfortably for daily work. More in our article on managing multiple companies in Biurko.
To be fair: you can grant KSeF permissions in the free Taxpayer Application too. Biurko earns its place when you want roles, an activity history, and many companies in one panel, without a password circulating around the firm.
Checklist: safe access for your accountant
Never share your Profil Zaufany login. It is both unacceptable and unnecessary.
Check your legal form: a JDG has owner permissions immediately; a company without a seal files ZAW-FA once.
Sign in to KSeF and open the "Permissions" section.
Grant your accountant a precise scope: usually issuing plus invoice access.
Give permission management only to a trusted office running the whole process.
Ask your accountant to sign in with their own Profil Zaufany or a KSeF certificate.
Set a calendar reminder to review permissions, especially after staffing changes.
Summary
Giving your accountant KSeF access does not require handing over a login or risking your whole digital identity. You grant specific permissions by NIP or PESEL, your accountant signs in with their own Profil Zaufany, and you can revoke access whenever you want. It is five minutes in KSeF and a year of calm, which matters more now that penalties for e-invoicing failures apply from 1 January 2027 (podatki.gov.pl).
If you want your accountant's and your team's access organized with roles and history instead of a shared password, create a free Biurko account and connect your company to KSeF in minutes. Running an accounting office? Book a short demo and we will show the multi-company panel on your own case.
FAQ
Can I give my accountant my Profil Zaufany login? No. Poland's Ministry of Finance treats this as unacceptable. Your Profil Zaufany is your full digital identity, not just invoicing. Instead, grant your accountant permissions in KSeF by their NIP or PESEL, and they sign in with their own Profil Zaufany.
How do I grant an accounting office access to KSeF? Sign in to KSeF, open the "Permissions" section, choose to grant a permission, enter the office's NIP and name, select the scope (for example issuing and invoice access), and save. You can revoke the permissions at any time.
Does my accountant need their own login to issue invoices in KSeF? Yes. They need their own Profil Zaufany, a qualified electronic signature, or a KSeF certificate tied to the authorized person. A PESEL number alone is not enough to authenticate in the system.
Does a sole proprietor (JDG) need to file ZAW-FA to use KSeF? No. A sole proprietor holds owner permissions assigned automatically to their NIP. ZAW-FA is typically filed by companies without a qualified seal, to designate their first authorized person.
What is the difference between owner permissions and invoice-issuing permissions? Owner permissions are the broadest, assigned by default to the taxpayer's NIP, and include granting access to others. Invoice-issuing permissions are narrower: they only allow creating invoices in KSeF, without managing anyone else's permissions.
