The 2026 R2 release isn’t the flashiest update Sage Intacct has ever shipped—but for anyone who actually runs the system day to day, it’s quietly one of the more useful ones. Better admin tools, tighter security, and a few fixes for things that have been quietly annoying people for a while. Here’s what’s changed.
In this release:
- Roles Permissions Report — one consolidated view of role access
- Import Service — new AR Advances and Consolidation Beta imports
- External User Management — one record per user per console
- Console Email Domain Validation — validate once, covers all linked companies
- Restricted Attachment Types — executables and scripts now blocked
- Entity Logo for AP Remittance — correct entity branding on payment docs
- Roles Permissions Report
If you’ve ever tried to audit what a role can actually do in Intacct, you know the drill: open one screen, cross-reference another, make notes, repeat. It’s tedious and error-prone-especially when you’re doing it under time pressure for a compliance review.
The new Roles Permissions Report fixes that. Administrators now get a single report showing every permission tied to a role—standard and custom—at a specific point in time. Run it, review it, done.
A few things worth knowing:
- Covers both standard and custom permissions in one view
- Filter by role name, date range, or both
- Leave the date range blank and it shows all current permissions for that role
- Leave the role name blank and it returns every role created in that period
One important caveat: this isn’t an audit trail. It doesn’t log historical changes-it reflects how the role looks when the report runs. For periodic access reviews and role validation, though, it’s a genuine time-saver.
Where to find it: Company → Admin → History and Reports → Roles Permissions Report
- Import Service Expansion
The import service keeps getting broader. This release adds three new Beta imports:
- AR Advances (Accounts Receivable) — create and update
- Ownership Structure (Consolidation) — create and update
- Ownership Structure Periods (Consolidation) — create and update
The guided workflow itself hasn’t changed-you still map fields, preview results, and fix any errors before anything gets committed. What’s expanding is simply the range of data you can bring in that way.
One thing it handles particularly well is messy mapping: splitting a full name into separate fields, combining columns to create new values, that sort of thing. Not magic, but it does cut down the manual prep work considerably.
Beta imports require enrolment in the Beta programme. Early Adopter and GA imports are available to all users with the relevant permissions.
- Simplified External User Management
This one’ll matter most to partners managing access across multiple linked companies.
Previously, the same external user could end up with separate records depending on how they accessed each company. More records to track, more places to update permissions, more chances for things to drift out of sync. A known frustration.
This release consolidates all of that. Each external user now has one record, tied to the parent console. Permissions are managed there and apply across all linked companies from that single point.
When records are merged, permissions from each are combined—so nobody loses access. That said, it’s worth reviewing the results and adjusting anything that looks off.
To check your consolidated records: Switch to the relevant instance → Company → Admin → External Users. The User ID column shows the consolidated view.
- Console-Level Email Domain Validation
This one’s specifically for partners who send email on behalf of multiple client companies.
Until now, validating your email-sending domain meant creating a separate DNS TXT record for every company. Managing dozens of clients? That adds up fast—and plenty of DNS providers cap how many TXT records you can have. It was a mess.
Now you validate once at the console level, and it covers every linked company automatically. You’ll need to add four records to your DNS provider:
- Three CNAME records — for SPF and DKIM authentication. Same for all companies using the domain.
- One TXT record — your console’s ESK key. Replaces the per-company TXT records.
That’s it. No separate records per company.
Setup
- Start at the console: Console → More → Configuration → Security tab → Email Sender Domain Settings → Add a Domain
- Authenticate the domain—Intacct generates the exact DNS values to copy across
- Add those records to your DNS provider (copy-paste exactly; don’t type them manually)
- Return to Intacct and select Validate Domain once the records are live
DNS propagation can take up to 72 hours. If validation fails first time, check your records and try again later. Standalone companies still validate at the company level.
- Restricted File Types for Attachments
A security change, worth flagging: a defined list of file types can no longer be uploaded as attachments. We’re talking executables, scripts, disk images, and system files—things that have no business being attached to a vendor invoice anyway.
Blocked extensions: .bat, .cmd, .com, .dll, .dmg, .exe, .iso, .jar, .msi, .ps1, .sh, .sys, .vbs, .vhd
Existing attachments aren’t touched—this only applies to new uploads going forward. If your team currently attaches files in any of these formats for a legitimate reason, now’s the time to find an alternative.
- Entity-Level Logo for AP Bank Remittance
If your organisation runs multiple entities—subsidiaries, regional offices, different business units—you’ve probably hit this: a bank remittance document showing the parent company logo when it should clearly show the issuing entity’s. In some regions, that’s not just an aesthetic issue. It’s a compliance one.
You can now upload a logo at the entity level. It’ll appear on remittance documents when the applicable template is used. No entity logo on file? It falls back to the company logo automatically—no blank documents.
To set it up: Company → Setup → Entities → Edit → Upload Logo
File requirements: GIF, JPEG, or PNG — max 216×43 pixels, under 9KB. GIF prints most cleanly on forms.
About Us
Greytrix has a wide product range for Sage Intacct- a Cloud ERP. This includes migrations from QuickBooks | Sage 50 | Sage 100 | Sage 300 to Sage Intacct. Our unique GUMU™ integrations include Sage Intacct for Sage CRM | Salesforce | FTP/SFTP | Rev.io | Checkbook | Dynamics 365 CRM | Magento | Rent Manager | Treez | Avalara Avatax | Blackline SFTP. We also offer best-in-class Sage Intacct Development Services, Consulting services, integrated apps like POS | WMS | Payroll | Shipping System | Business Intelligence | eCommerce for Sage Intacct to Sage business partners, resellers, and Sage PSG worldwide. Greytrix constantly develops apps, products, and add-ons to enhance user experience. Sage Intacct add-ons include AR Lockbox File Processing.
Greytrix GUMU™ integration for Sage CRM – Sage Intacct, Sales Commission App for Sage Intacct, and Checkbook.io ACH/Digital Check Payments for Sage powered by GUMU™ are listed on Sage Intacct Marketplace.
The GUMU™ Cloud framework by Greytrix forms the backbone of cloud integrations that are managed in real-time for the processing and execution of application programs at the click of a button.
For more information on Sage Business Cloud Services, please contact us at sagecloud@greytrix.com. We will like to hear from you.