Article

HMRC Agent Authorisation - 64-8: Workflow Configuration

A ready-to-build workflow for getting your firm authorised to act as a client's tax agent with HMRC. It runs from confirming the tax references you need, through submitting the authorisation request, collecting the code HMRC posts to the client, and activating the authorisation on your agent services account. Use it as a starting point and adjust the steps, roles, wording and timing to suit your firm.

Run one workflow per set of authorisations and name it for the services it covers, for example Agent Authorisation (Self Assessment), so a client with several tax requirements has one clear workflow each.

This version assumes the client uses Workiro for the steps that involve them, so those steps are written and addressed to the client, not to your team.

How to use this configuration

  1. In Settings → Workflows, create a recipe named HMRC Agent Authorisation - 64-8.
  2. Build the steps in order using the configuration blocks below. Each block gives you the participants, outcomes, guidance, the handover to the next step, and how to handle documents.
  3. You create each role the first time a step needs it (via Participants → Add → New Role), so roles come into being as you build. The roles table shows where each one first appears.
  4. Remember, a step's participants all see the task guidance, so put your internal owner on client steps but never put the client on an internal step. Do not default to a single participant: include whoever needs to receive the handover, sign off, or oversee.
  5. Any document attached carries forward between tasks automatically. The authorisation letter and the code itself are sensitive, so keep them off the flowing task and on the client record (via Relates To) instead.

Suggested timing is a guide for setting due dates when a workflow runs. It is not part of the recipe. The long gap between steps 4 and 5 is deliberate: HMRC posts the code to the client and that takes at least a week, so the client step sits open while you wait.

Roles

Create each role when you reach the step where it first appears.

RoleWho it representsFirst created at
Authorisation AdministratorThe team member who runs the authorisation request day to dayStep 1
Client Relationship OwnerThe person who owns the client relationship and confirms which services were agreedStep 1
Client ContactThe client's main point of contact, working in WorkiroStep 2
Practice Systems LeadThe senior team member who administers your agent services accountStep 3

The workflow at a glance

#Step / TitleForParticipantsDayOutcomes → next
1Confirm the scope and the details we needTeamAuthorisation Administrator, Client Relationship Owner0Details complete → 3 · Details needed → 2
2Confirm a few details for your HMRC authorisationClientClient Contact, Authorisation Administrator1Details provided → 3
3Submit the authorisation requestTeamAuthorisation Administrator, Practice Systems Lead3Request submitted → 4 · Details rejected → 2 (loop)
4Send us your authorisation code when it arrivesClientClient Contact, Authorisation Administrator5Code provided → 5 · Code not received → 3 (loop)
5Enter the authorisation codeTeamAuthorisation Administrator18Authorisation accepted → 6 · Code rejected → 3 (loop)
6Give the team access to the clientTeamPractice Systems Lead, Authorisation Administrator19Access in place → 7
7Confirm the authorisation and closeTeamClient Relationship Owner, Authorisation Administrator21Authorisation complete → End

Step-by-step configuration

Step 1: Confirm the scope and the details we need (internal)

ℹ️ This is where the Authorisation Administrator pins down which authorisations are being requested and checks the reference details HMRC will ask for are already on file.

Participants: Authorisation Administrator (assignee), Client Relationship Owner (confirms the services agreed)

Outcomes: Details complete → Step 3 · Details needed → Step 2

Guidance (shown to your team): copy and paste this...

Confirm which authorisations this workflow covers, then check the client record holds
what HMRC will ask for.

**Corporation Tax**
- Corporation Tax reference
- Registered office postcode
- Company registration number

**PAYE**
- Employer PAYE reference and Accounts Office reference
- Registered office postcode

**VAT**
- VAT registration number
- Postcode of the principal place of business
- Date of VAT registration
- Final month of the last return submitted, and the box 5 figure on it

**Self Assessment**
- Unique Taxpayer Reference
- National Insurance number
- Postcode

If everything is on file, choose **Details complete** and go straight to the request.
If anything is missing, choose **Details needed** to ask for it.
**IMPORTANT: ensure you update the list on the task that follows for the client.**

**Handover: the confirmed list of authorisations and the reference details pass to the request step.**

Documents: Nothing to attach here. Reference details stay on the client record rather than on this task.


Step 2: Confirm a few details for your HMRC authorisation (client-facing)

ℹ️ Only used when a reference or postcode is missing. What the client provides goes on the client record and the request continues.

Participants: Client Contact (assignee), Authorisation Administrator (requests the details and answers questions)

Outcomes: Details provided → Step 3

Guidance (shown to the client): copy and paste this...

**We need a few reference details before we can register as your tax agent.**

HMRC checks these against its own records, so they need to match exactly what HMRC holds for you.
Please add each one using the comments, or upload a document that shows it,
and complete the task when you're done.
 
Please confirm:

 - [List to be completed when Task sent]
 
 If you're not sure where to find any of these, leave a comment and we'll point you to it.

Step 3: Submit the authorisation request (internal)

ℹ️ The Authorisation Administrator raises the request with HMRC, which triggers HMRC to post an authorisation code to the client.

Participants: Authorisation Administrator (assignee), Practice Systems Lead (holds the agent services account)

Outcomes: Request submitted → Step 4 · Details rejected → Step 2 (loop)

Guidance (shown to your team): copy and paste this...

The client may upload a letter or return in the previous step that shows a reference. 
**Remove it from the task** once the details are captured,
so it does not travel through the rest of the workflow.

Sign in to HMRC online services for agents and request authorisation for each service:

- Open the option to be authorised by a client and start a new request
- Select the tax services agreed with the client
- Enter the client's reference details exactly as HMRC holds them
- Note the date submitted, so you can track the code's 30 day expiry

If HMRC rejects the details, choose **Details rejected** to go back to the client and
confirm the correct references before trying again.

Once the request is in, HMRC posts a code to the address it holds for the client, which
usually takes about a week.

**Handover: the submission date and the services requested should pass to the client step, 
so the client knows what to look out for in the post.**

Step 4: Send us your authorisation code when it arrives (client-facing)

ℹ️ Sits open while the client waits for the post. It also warns them about the code's expiry so it does not lapse unnoticed.

Participants: Client Contact (assignee), Authorisation Administrator (oversees and answers questions)

Outcomes: Code provided → Step 5 · Code not received → Step 3 (loop)

Guidance (shown to the client): copy and paste this...

**HMRC is sending you a code in the post, and we need it to finish setting up your authorisation.**

- We've asked HMRC for permission to act as your tax agent. 
- HMRC will not send that code to us, only to you, so this last bit needs your help.
- Look out for a letter from HMRC over the next week or so
- When it arrives, add the code as a comment below, or upload a photo or scan of the letter
- Please do this within **30 days** of receiving it, as the code stops working after that
- Nothing has arrived after two weeks? Leave a comment and we'll chase HMRC for you.

Complete this task after you've uploaded the code.

Step 5: Enter the authorisation code (internal)

ℹ️ The Authorisation Administrator activates the authorisation with HMRC using the code the client provided.

Participants: Authorisation Administrator (assignee)

Outcomes: Authorisation accepted → Step 6 · Code rejected → Step 3 (loop)

Guidance (shown to your team): copy and paste this...

Sign in to HMRC online services for agents and enter the code against the pending request.

- Check the code against what the client provided, character for character
- Confirm each service the code activates
- If HMRC rejects the code, or the 30 days have passed, 
choose **Code rejected** to submit a fresh request

Once accepted, the authorisation is live with HMRC, but the client may not appear in your agent services
list for another day or two.

**Handover: a live authorisation passes to the systems step, 
where the team is given access to the client.**

Documents: Remove the authorisation letter from the workflow before completing this step.

The code has served its purpose and does not need to travel any further.

Step 6: Give the team access to the client (internal)

ℹ️ Being authorised with HMRC is not the same as the team being able to see the client, so this step handles the access side.

Participants: Practice Systems Lead (assignee), Authorisation Administrator (needs access to work the client)

Outcomes: Access in place → Step 7

Guidance (shown to your team): copy and paste this...

Set the team's access to the client on your agent services account.
This needs an administrator level account, so it sits with the systems lead
rather than whoever ran the request.

- Find the client in the agent services client list
- Grant access to the team members who will work on the client's tax affairs
- Confirm the authorisation shows against the right services

The client can take 24 to 48 hours to appear in the list after the code is entered.
If they are not there yet **pause this task** to come back to this tomorrow.

**Handover: you have confirmed access, and the services now authorised,
choose *Access in place** to pass to the relationship owner so the client can be told.**

Step 7: Confirm the authorisation and close (internal)

ℹ️ Records the authorisation against the client and makes sure someone actually tells the client it is done.

Participants: Client Relationship Owner (assignee), Authorisation Administrator (records the authorisation)

Outcomes: Authorisation complete → End

Guidance (shown to your team): copy and paste this...

Close out the authorisation:

- Record on the client record which services are authorised, and the date they went live
- Tell the client the authorisation is in place, either on your next scheduled call or
 as a short note, and confirm what it lets us do on their behalf
- Check whether any other tax service still needs its own authorisation,
and start a separate workflow for it.

Keep the authorisation evidence on the client record rather than on this task.

Notes for whoever configures this

  • Waiting is part of this process. Most of the elapsed time in this workflow is HMRC posting a code to the client, which is why step 4 is a client step that sits open rather than an internal chase task. The suggested days reflect that: steps 1 to 4 happen in the first week, then there is a pause before step 5.
  • Two loops both go back to the request. Step 3 loops to step 2 when HMRC rejects the reference details. Steps 4 and 5 both loop back to step 3, because a code that never arrives and a code that has expired have the same fix: submit a fresh request.
  • Access is split from authorisation deliberately. Step 6 is separate because it usually needs an administrator level account that the person running the request may not have. If everyone in your team has administrator access, merge steps 5 and 6.
  • Participants are deliberate, not default. Step 5 includes a single participant because it is one person doing a short, focused job. Both client steps include their internal owner so someone is minding them. No internal step includes the client, because all participants see the guidance.
  • Sensitive material stays off the flowing task. The authorisation code is a credential. It should live on the client record and be removed from the task once used.
Powered by Zendesk