Hiring a VA to Manage Your Budget? Delegate the Work, Not the Login

The thread starts the way these always do. Someone is three weeks behind in YNAB, the uncategorised pile keeps growing, and they have found an assistant who will keep it current for a weekly fee. Send over the bank login, they import and categorise, everything stays green. The assistant is probably fine. The plan is the problem.

Hiring a VA to manage your budget is a reasonable idea with one wrong step in the middle of it. The task is delegable. The access almost never is. Categorising transactions is someone else’s work. Your banking credentials are not, and the consumer protections you quietly assume will catch a bad outcome read differently once you have handed over an access device on purpose.

So: hand over the categorising through the budgeting app or a file, never through your bank; keep anything that moves money or edits account details on your side of the line, permanently; write the rules down before week one. And before paying anyone weekly, spend an evening on automation rules, which for most individuals is the whole answer.

What you are actually hiring a VA to manage

“Manage my budget” sounds like one job. It is five, and they are not the same shape.

  • Getting transactions in. Already automatic if your accounts are linked. YNAB’s security page describes its bank connection as read-only: “The connection is read-only, so transactions import but no one can move money through YNAB.” Paying a person to do what a feed does is the most common waste here.
  • Categorising and splitting. The real work. That the $312 at a building supplier was the rental and not the house, that the $184 supermarket run included $40 of birthday presents, that the March charge is insurance rather than a subscription to cancel. High volume, rule-following, occasional judgement. The one part that genuinely benefits from another person.
  • Reconciling to the statement. Matching the app’s cleared balance to the bank’s, to the cent, then finding the difference. Mechanical, but it needs sight of the statement, which is exactly the data you were trying not to scatter.
  • Flagging anomalies. A duplicate charge, a new fee, a subscription up 30%, a payee you do not recognise. Useful, and mostly replicable by switching on your bank’s own alerts.
  • Deciding what the money does. Assigning dollars, covering an overspend, choosing what gets funded next month. Not delegable, and not for security reasons: that decision-making is the budget. Hand it over and you have bought a spending report with a nicer interface.

Why the bank login is the request to refuse

Most people refuse on instinct, then talk themselves out of it, because the assistant is nice and the work is boring and it is only read access, really. The instinct was right.

Federal protection for consumer electronic transfers turns on a definition. The Consumer Financial Protection Bureau’s Regulation E defines an unauthorised electronic fund transfer as one “initiated by a person other than the consumer without actual authority to initiate the transfer and from which the consumer receives no benefit,” and the definition expressly excludes a transfer “by a person who was furnished the access device to the consumer’s account by the consumer, unless the consumer has notified the financial institution that transfers by that person are no longer authorized.” The official interpretation adds that where someone given an access device exceeds the authority granted, the consumer is fully liable unless the institution has been told that person’s transfers are no longer authorised.

That inverts the model most people carry. The liability caps half-remembered from somewhere, $50 if you report a lost card within two business days and up to $500 later, sit on top of a transfer being unauthorised in the first place, and handing credentials over deliberately is not the fact pattern they were built around. The CFPB separately notes you must tell your bank within 60 days of the statement showing the problem.

None of that predicts what your bank would do in your case, and I will not pretend otherwise. Two things beat assuming: read the account agreement your bank actually gave you, which usually has its own language about disclosing credentials, and read the CFPB’s pages rather than forum summaries of them. Your online banking credentials are the one thing here with no safe sharing design, so they never leave your hands, and anyone who asks for them has told you something about how they work.

The access designs that work, best first

All three hand over the categorising and keep your bank out of it. The third is what I would pick first time.

1. Access inside the budgeting app, not the bank. An app login is a different object: a credential you created, rotatable in ten seconds, sitting on a read-only connection that cannot initiate a transfer. If your app supports a genuine second user or a read-only role, use it, and give the assistant their own account so the activity is theirs and revocation is one click.

Be honest about the limits. These apps were built for couples, not staff, so “sharing” usually means the whole budget rather than a permission tier you can shape: sight of every transaction and balance, plus the ability to rearrange your categories. That may be acceptable. It should be a decision, not a surprise.

2. Export the transactions and let them work on the file. Pull the uncategorised rows to CSV, keep four columns (date, amount, payee, account nickname), delete the rest, account numbers included. The assistant returns it with a category column filled and a query column for anything they could not place. Ten minutes a week slower than option one, and nobody outside your household holds a credential to anything.

3. A shared sheet as the working surface, with the app updated by you. One spreadsheet you own. Each week you paste in the unresolved transactions, the assistant fills category and notes, you spend fifteen minutes applying it. Applying pre-decided categories is fast, so it costs less than it sounds, and what you get is complete: no shared logins, a record of who decided what, revocation in one click, and a sheet that becomes your rules document as the same payees reappear.

The line that does not move for convenience

Nobody but the account holder moves money. Not a transfer between your own accounts, not a card payment, not a scheduled bill, not “I noticed the electricity was due so I paid it.” Nobody but the account holder adds or edits a payee, changes routing details on a saved one, sets up bill pay, links or unlinks a bank connection, or touches the email address, phone number or two-factor settings on the bank or the app. If a feed breaks and needs re-authenticating, that involves your bank credentials, so you do it, even at 11pm when the assistant has offered.

Absolute, not a preference, because every request to cross it will be helpful, small and urgent. A categorisation error costs a corrected row. A payee with altered account details costs the payment.

Your transaction history is a dossier, so treat it like one

Individual rows look boring. A year of them is not. Read together, a transaction export tells a stranger where you live, where you work and roughly what you earn, which bank and card issuers you use, your landlord or mortgage servicer, your children’s school, your pharmacy, your donations, and the exact dates the house was empty because the charges moved 400 miles.

The Federal Trade Commission’s description is plain: identity theft “is when someone uses your personal or financial information without your permission,” and the information used includes name, address, card and bank account numbers. A transaction history hands over much of that, plus the context that makes impersonation convincing and the detail that answers a bank’s security questions. The CFPB’s fraud glossary also names the version specific to this arrangement, fraud by fiduciaries: someone managing another person’s money spending it for their own benefit.

So the hygiene follows:

  • No exports as email attachments, none pasted into a chat thread. Those copies live in two mailboxes and every backup behind them, and you control none of them.
  • One folder you own, shared to one named account, access removed when the work ends. Redact first: if the job needs date, amount and payee, do not send account numbers and balances just because the export had those columns.
  • A unique password and two-factor authentication on the app and on the email address that can reset it.
  • Data terms in writing, even for one person: what they may keep, where, deletion on request, no sub-contracting. Their laptop is now part of your exposure.
  • Keep reading your own statements monthly. You are the one with a 60-day clock running.

Write the rules before somebody guesses at 2am

Ambiguity does not stay ambiguous. It becomes someone’s guess, made quickly, without your context, then repeated forty times before you notice. Half a page prevents most of that.

Start with the ten cases that actually recur: multi-item online orders, warehouse shops mixing groceries with household goods, delivery versus restaurants versus groceries, cash withdrawals, peer-to-peer payments in and out, refunds needing matched to an original charge, annual renewals that look like one-offs, fuel stations where half the spend is not fuel, pharmacy and copays, reimbursable work expenses. Write the default for each, and name your split thresholds.

Then the two that cause the most damage, both structural rather than a matter of taste. Transfers between your own accounts are transfers, never spending. Credit card payments are transfers, never expenses. Code either as spending and your reports double-count the same money, which is the most common reason a budget quietly stops being true.

Then the unknown transaction, which needs a written default, because the alternative is a plausible guess that hides a problem. Mine: never guess, never skip silently, park it in a holding category with one line on what is unclear.

Finally, define an anomaly with numbers, not adjectives. Any transaction over an amount you choose. Any first-time payee. Two identical amounts to the same payee in a day. Any fee, interest charge, returned or declined payment. A recurring charge whose amount changed. “Flag anything odd” gets you nothing or everything, depending on the person.

The honest alternative, which most people should try first

If the backlog is the problem rather than a real shortage of hours, a weekly service treats a setup failure as a staffing one. Two hours, in this order:

  • Link every account that supports it, so importing stops being manual.
  • Clean up payee names first. Rules match on payee, and messy names are why they fail. Merge the four spellings of the same supermarket.
  • Build rules for your top 20 payees by count, not by value. A short list of merchants usually covers most rows.
  • Set up the two or three split templates you need, usually the warehouse shop and the marketplace.
  • Switch on the bank’s own alerts above a threshold, plus low balance. Anomaly detection, free.
  • Book the habit: ten minutes twice a week, half an hour at month end to reconcile.

Then the arithmetic: the quoted rate, times hours a week, times 52, against one evening of your time plus a couple of hours a month. For one person with two accounts and a card, paying weekly usually buys a habit you could have built, and it tends not to hold, because a budget somebody else maintains stops changing your behaviour. Paying earns its place when volume exceeds what rules absorb, when the backlog wants a one-off reconstruction rather than a subscription, or when what stops you is a real constraint on your week rather than dislike of the task.

When paying someone does make sense

Four situations where I stop arguing.

Business and personal money in the same accounts. Common for sole traders and single-member LLCs, and painful because every split now carries a tax consequence, so a guess costs more than a corrected row. The real fix is separating the accounts, which removes more mess than any amount of help.

Managing a relative’s finances. A parent’s bills, a sibling’s accounts after an illness. Different from delegating your own, because a formal role and duties attach. The CFPB publishes its Managing Someone Else’s Money guides for exactly these roles: agents under a power of attorney, court-appointed guardians and conservators, trustees under revocable living trusts, and government-appointed fiduciaries. Start with the role and the paperwork, not the app.

High volume across many accounts. Several cards, two banks, a brokerage, rental income. Past a few hundred transactions a month, rules stop absorbing the exceptions and a person genuinely helps.

A time constraint money can solve. A new baby, two jobs, a medical stretch, a business in its first year. A legitimate purchase, usually with an end date, which is a good way to frame it.

One note on who to hire. At that volume you probably want a bookkeeper rather than a general assistant. Categorising money with tax or reporting consequences is a trained skill, and someone who does it daily produces a cleaner file in fewer hours than a generalist learning your categories on your time.

General information only, not financial, tax or legal advice. Your rights depend on your own facts, your bank’s account agreement and where you live. Use the sources linked below and a licensed adviser for your own situation.

Straight about the fit, since this is written for an individual: AB7 Solutions does not sell a personal-budget service to consumers, and if you emailed asking us to run your household budget in YNAB we would point you at the two-hour setup above and tell you to keep your money. The business-side version is what we work on. We place trained remote finance and bookkeeping support for owners whose personal and business transactions run through the same accounts and need untangling and coding against written rules; we build the automation that turns categorisation into rules instead of weekly labour; and our security practice designs the access model so nobody in the process ever needs a banking credential. Same principle as above, applied where the volume justifies paying a person. If that is nearer your situation than a household budget is, call +1 321 341 7733, email ab@ab7solutions.com or director@ab7solutions.com, or see www.ab7solutions.com.

Questions that come up next

My app has no read-only option. Is a shared login acceptable? It can be, as long as you know you are granting full read and edit access to the budget, and as long as it is the app’s login and not the bank’s. Unique password, two-factor authentication where supported, password changed the day the arrangement ends. If that feels like too much, use the shared-sheet design: no credential at all.

What about a read-only login at the bank itself? Some institutions offer view-only additional users, and where that exists it beats sharing your own credentials. Ask your bank what its option actually permits, in writing, and read the account agreement on additional authorised users first. Do not assume “read-only” means the same thing at every bank.

Should I ask them to sign something? Yes, one page: what they may access, that they may not initiate any transaction, how files are stored and deleted, no sub-contracting. It will not stop a determined bad actor. It does set expectations with the far more likely person, the well-meaning one who would otherwise pay your electricity bill to help.

Sources: Consumer Financial Protection Bureau, Regulation E §1005.2(m) and official interpretation, Ask CFPB: unauthorized transfers from your bank account, Fraud and scams key terms and Managing Someone Else’s Money; Federal Trade Commission, What To Know About Identity Theft; YNAB, Security.

Leave a Comment

Your email address will not be published. Required fields are marked *