Runs inside your tenant, under your IT policy.
FigsFlow is practice management software for large accounting firms. It signs in through Entra ID, keeps client documents in the firm’s own SharePoint under the firm’s retention policy, delegates permissions by office and team, and writes a full audit trail — so the practice system sits inside the tenant your IT function already governs.
Partner or COO, start with the firm view in the video below. IT or security, everything you need is in the Trust Center pack.
4.8 / 5 126 reviews on G2 and Capterra
- Identity Entra ID · conditional access · MFA
- Documents Your SharePoint · your retention
- Permissions 4 offices · 11 teams · delegated
- Audit Every action · exportable
- Sub-processors Published · with regions
nothing here lives in our storage
The walkthrough
The security review your IT function runs, walked through on screen
Where identity comes from, where documents actually live, what a delegated permission looks like across four offices, and what the audit export contains. Written for whoever has to sign off on this, not for the partner who wants it.
1 Sign in
2 Open a client document
3 Permissions across offices
4 Offboard a leaver
5 Filter and export the audit log
| User | Action | Time |
|---|---|---|
| D. Laurent | Override review gate | 08/18 16:04 |
| J. Moreau | Opened document | 08/18 11:22 |
| R. Tran | Changed permission | 08/15 09:47 |
6 The published sub-processor list
| Party | Region |
|---|---|
| Microsoft Azure | United States |
| Sterling Wells Nepal | Kathmandu, NP |
Six sections, in order
1 Entra sign-in
A partner signs in with the firm account. Conditional access is enforced by the firm's own policy and MFA is satisfied by the firm's own method. There is no FigsFlow password issued, rotated or audited.
2 A document in your SharePoint
A client folder is opened and the SharePoint path stays visible in the breadcrumb. The retention label on the file is the one the firm's IT function set. FigsFlow reads and writes; it does not hold.
3 Permissions across four offices
The permission model is shown against the firm's real shape — four offices, eleven teams — with access delegated through Entra groups. A seasonal preparer in one office cannot open a client in another.
4 A leaver offboarded in one action
A seasonal preparer is disabled in Entra ID. Session, documents, portal and mailbox access end in the same action, without anyone reconstructing a list of systems that person touched.
5 Audit log, filtered and exported
The log is filtered by office and date range, then exported. Every entry carries user, object and timestamp, and a review-gate override carries the reason the person recorded at the time.
6 The sub-processor list on screen
The published list is opened in the product, showing each party with its region and its role, including the offshore support team. Nothing on it is disclosed only on request.
Firms of fifty and up.
If your IT function has a veto, this page is written for them
You have more than one office, an identity policy that already exists, and a security review that happens before anything touches client data. You are not asking whether practice management would help. You are asking whether this one survives your security review.
Practice management for firms of fifty and up
What changes when practice management runs inside your own tenant
What should a large accounting firm look for in practice management software?
Firms your size don’t buy time back. You buy the ability to answer a question in front of someone else. Five questions a firm of fifty and up gets asked — and what practice management software for a large accounting firm should let you say back.
None of that is efficiency. It is defensibility — and it is the reason a firm of seventy-eight changes systems at all.
The obligation
You review everyone who touches client data. Try reviewing your own shelf.
What does the FTC Safeguards Rule require an accounting firm to know about its software?
The Safeguards Rule asks the firm to oversee its service providers — to know who holds client data, where, under what controls, and for how long. Here is that questionnaire, filled in for the systems a seventy-person firm is running right now.
Click any cell you could answer right now, without asking anyone.
01The obligation is the firm’s, not the software company’s.
02Every blank cell is a question a client, an insurer or a peer reviewer is entitled to ask.
Every blank cell is a question a client, an insurer or a peer reviewer is entitled to ask.
The fix is not a better questionnaire. It is fewer places the answer can be unknown.
The answer sheet
One column, filled in — what “inside your tenant” actually means
Can practice management software use our existing Entra ID single sign-on?
Six answers, in the order a security review asks for them.
Nothing on this sheet lives in our storage.
Identity you already govern
Sign-in: Entra ID · conditional access enforced · no separate user list
There is no FigsFlow password to manage, rotate or audit. Your conditional access policy applies because it is your identity provider. A leaver disabled in Entra is disabled here, in the same action.
Documents that never left
Documents: Northfield Keyes tenant · SharePoint · your retention labels
Client documents live in the firm’s own SharePoint, in a defined folder structure per client, under the retention policy IT already set. FigsFlow reads and writes; it does not hold. If the firm leaves, the documents never moved in the first place.
Permissions shaped like the firm
Access: 4 offices · 11 teams · delegated
Partners see their offices. Teams see their clients. A seasonal preparer in the Denver office cannot see a Boise client, because the permission model knows what an office is.
An audit trail that answers questions
Audit: every action · user, object, timestamp · exportable
Who opened it, who changed it, who overrode a review gate and why. Filterable by office, exportable for peer review or an insurer, without a support ticket.
Sub-processors, published
Sub-processors: named, with regions and roles — including offshore support
Every party that can touch data is listed publicly with its region and its function. You should not be discovering this in week three of a procurement, and neither should we make you.
An exit you can describe before you sign
Export: structured data + documents already in your tenant
Your documents are already yours. Structured records export in a documented format. The exit plan is a page, not a negotiation.
Five unknowns became one system your existing policy already covers.
Send this to whoever runs your security reviewOpen it yourself
Click through what seventy people, four offices and one policy actually looks like
No sales call. Open the permission model, the audit log and the firm view yourself.
Review readiness
What your security review can answer today, against what it could answer
How many systems hold your clients’ documents right now?
Tick what you run today
Your tax software still files the return, and it stays where it is. What changes is that everything around it — the documents, the identity, the audit trail, the permissions — moves inside a boundary your IT function already controls and already reviews.
Before you buy the whole thing
What we would tell you not to buy yet
Where should a large accounting firm start with practice management software?
Anyone who recommends the whole platform on day one has never rolled one out in a firm your size. Three things we would keep out of year one, and why.
Not every office at once.
One office, one service line, one season. A firm of seventy-eight cannot absorb a change on that scale in a single cycle, and an office that adopts a proven standard goes faster than one that adopts a promise.
Not capacity reporting in year one.
Capacity across offices only means something once the offices define the work the same way. Buy it when you have one standard, not before — otherwise you are comparing numbers that are not comparable, which is the problem you started with.
Not proposals and engagement letters first.
They are the easiest modules to switch on and the least urgent for a firm your size. Your pressure is on consistency and evidence, not on how quickly you can send a proposal. Come back to them in year two.
The eleven questions your IT function will ask, and where our answers are
These are the eleven your IT function will put to us. Our answers to all of them are written down and public — you do not have to book a call to get them.
-
Answered inArchitecture overview
-
Answered inSub-processor list
-
Answered inArchitecture overview
-
Answered inArchitecture overview
-
Answered inAudit log specification
-
Answered inData export and exit
-
Answered inTrust Center — security posture
-
Answered inPermission model
-
Answered inPermission model
-
Answered inAvailability matrix
-
Answered inRollout guide
Rollout
One office first. Never between January and April.
How do you roll out practice management software across multiple offices?
Seventy people cannot change systems at once, and no firm should try it in season. The order below is designed so that stopping halfway still leaves you better off than when you started.
Connect identity and storage
Entra application registered, conditional access applied, SharePoint sites mapped, retention labels confirmed. No end user touches anything at this stage — which is what lets IT approve it before the firm is committed.
One office, one service line
Pick the office with the most consistent process, and its highest-volume service. Build the template, run live engagements through it, and let the review gate hold for real. One office proves it; nobody else is disrupted.
Publish the standard
The template that worked becomes the firm’s. This is a partner-group conversation, and it is the step firms skip. The software is ready before the decision is.
Office by office
Each office adopts the published standard rather than inventing one. Every office after the first is faster, because the standard already exists and the questions have already been asked.
Everything else waits. Proposals, engagement letters, capacity and firm reporting switch on when the firm is ready for them, not because a rollout plan says so.
Your stack, not our feature list
Everything your firm already runs. And the parts we deliberately do not touch.
Does practice management software have to store client data on someone else’s servers?
Seventy-eight people, four offices, one Microsoft tenant. FigsFlow adds the practice layer inside it — it does not replace what your IT function already governs.
Yours — governed by your IT 10
FigsFlow — the practice layer 25
Third party — connected, not held 4
What is not in that grid
Your tax software is not in that grid, and will not be this year. There is no US tax-prep integration today — 1040s, 1120s and e-filing happen where they happen now, and FigsFlow runs the practice around them. If your evaluation depends on tax-software connectivity, we would rather you knew on this page than in week four.
- Google Workspace — mail and calendar depth is Microsoft-only. Documents can still live in your own storage; the identity and mail integration cannot.
- Gmail — supported for mail. No calendar, no contacts.
- Nothing in anyone else’s storage — every document tile above resolves to your tenant. If you leave, the files never moved.
Every US preparer is a financial institution under GLBA and subject to the FTC Safeguards Rule, with a Written Information Security Plan expected under IRS Publication 4557. The Safeguards Rule also asks the firm to oversee its service providers. FigsFlow does not provide your WISP and does not make the firm compliant — it narrows the number of service providers that plan has to describe, and gives your Qualified Individual answers rather than blanks.
Proof
Documents your IT team can read instead of a testimonial
FigsFlow was built inside two working practices — the workflows came from partners running real deadlines. Every module started as something a firm needed on a Tuesday.
What we can give you today
Architecture overview
Written for IT — identity, data flow, hosting regions
Request it 02Sub-processor list
Every party, with its region and its role
Request it 03Data processing agreement
Draft form, for your review
Request it 04Audit log sample
Exported and redacted, so you can read the fields
Request itA testimonial is nice. A sub-processor list is what unblocks procurement.
Founding-customer programme
We are taking on a small group of US firms this quarter — a direct line to the product team, your standards built into the template library, and pricing locked for as long as you stay.
Pricing and availability
Seventy seats, and the four answers procurement will ask for
How is practice management software priced across multiple offices?
Per user, per monthPublished on the pricing page
- No implementation fee
- No minimum seat count
- No separate charge per office
Not in the US version yet
Dated on the availability matrixResources
Everything your IT reviewer will ask for, before they ask
Two conversations
Two conversations, and they do not have to be the same one
The partner group wants to see the firm view. Your IT function wants the architecture and the sub-processor list. Both are available now, and neither requires the other to go first.
See the firm view — four offices, one dashboard, and what changes for the partner group.
Book a demoThe architecture, the permission model, the audit log fields and the sub-processor list.
Get the Trust Center packNot quite your firm?
- Ten to fifty and standardizing for the first time? That page is written for that moment
- Replacing three or four systems at once? Start here instead
- Already running a proposal tool and adding the practice side? This one
Start Smarter. Grow Faster.
From proposals to pricing, streamline every step with automation designed particularly for accountants, bookkeepers and tax advisers.