Zato Onboarding Readiness Checklist

Please have the following ready so we can complete setup quickly and spend the session getting your team into Zato.

Before the onboarding session: complete the onboarding form and make sure the people who can authorise your accounting, document and tax systems are available.

1. Before Onboarding

  • Pilot Agreement signed

  • Onboarding Form completed

  • Primary onboarding contact and first users confirmed

2. Have Your System Access Ready

  • Accounting system: A user who can authorise the firm connection (e.g. Xero admin)

  • Practice management: Access is ready when connecting to XPM or another supported practice management system

  • Document system: An admin or authorised user available for FYI Docs, SharePoint, OneDrive, Google Drive or Dropbox

3. Tax Access

  • New Zealand firms: Have the Tax Agency's own IRD number, a myIR user with Owner access, and an authorised signatory (usually a director) available for IRD authorisation

  • Australian firms: Have an authorised user available for the ATO or tax agent connection, where applicable

4. Training

  • Choose the people attending the training session: Ideally your internal champion plus the first users who will run pilot jobs

  • Have 1 to 2 real pilot jobs in mind: We will use real work in training so your team can learn the workflow end to end

That's it. Zato will guide the connection, configuration and first jobs during onboarding. You do not need to prepare client-by-client setup in advance.

Questions before the session? Send them to your Zato contact so we can resolve any access issues beforehand.


Connecting Your Integrations (ZIP)

ZIP is the option under Firm Settings that connects Zato to the other systems your firm already uses. Once a connection is set up, every client and job benefits from it, you do not need to reconnect for each new client.

Zato never asks for your password to any of these systems. Each connection is completed through that provider's own sign in screen.

Accounting and Finance

Xero

Xero brings your clients (organisations) into Zato. Connecting Xero is what allows you to import clients directly, rather than adding them one by one.

  1. Go to Firm Settings, then ZIP.

  2. Locate Xero and select the Settings icon.

  3. Select Connect.

  4. Log in with your Xero credentials.

  5. Select the organisation, or organisations, you want to connect.

  6. Confirm to authorise the connection.

Once connected, your Xero clients are available to import from the Clients screen.

XPM (Xero Practice Manager)

XPM is connected separately from Xero. Xero alone is enough to bring your clients across, XPM is only needed if you also want jobs to import automatically.

  1. Go to Firm Settings, then ZIP.

  2. Locate XPM and select the Settings icon.

  3. Select Connect and follow the same sign in steps as Xero.

Documents and Storage

Google Drive, SharePoint, OneDrive, and Dropbox all connect the same way, with two options: a one click connection, or bringing your own app.

Google Drive, SharePoint, OneDrive, and Dropbox

  1. Go to Firm Settings, then ZIP.

  2. Locate the provider you want to connect and select the Settings icon.

  3. Select the OAuth app tab.

  4. Choose Continue with [Provider] for the one click option. This is the recommended option for most firms, Zato never sees your password.

  5. Alternatively, expand Use your own app to enter a Client ID and Client Secret from an app registered in that provider's own developer console.

  6. Select Connect.

Here are screenshots showing where to locate the credentials on each platform:

1. Azure Portal / Microsoft Entra ID (OneDrive & SharePoint)

In the Microsoft Azure Portal under App Registrations > Overview, you can locate your Application (client) ID and Directory (tenant) ID:

Azure portal app registration overview client id tenant id screenshot, AI generated

2. Google Cloud Console (Google Drive)

In the Google Cloud Console under APIs & Services > Credentials, creating an OAuth 2.0 Client ID displays the Client ID and Client Secret:

Google Cloud Console OAuth credentials client id secret screenshot, AI generated

3. Dropbox Developers Console (Dropbox)

In the Dropbox App Console under the Settings tab of your app, you will find the App Key and App Secret:

Dropbox App Console App Key App Secret settings screenshot, AI generated

Once connected, files from these providers can be browsed and linked alongside ZBox's own storage.

FYI Docs

FYI Docs connects differently, using account details from FYI rather than a sign in screen. Once connected, FYI Docs is read only within Zato, edits still need to be made in FYI Docs itself.

  1. Go to Firm Settings, then ZIP.

  2. Locate FYI Docs and select the Settings icon.

  3. Enter your FYI Region, FYI Access ID, and FYI Access Secret.

  4. Select Connect.

Here is the FYI Docs screenshot showing where the Access ID and Access Secret are generated under Automation > Apps:

If you do not have these details to hand, they can be found within your own FYI Docs account under its integration or API settings.

Tax Authority

IRD (New Zealand)

Unlike the integrations above, IRD is not connected firm wide. It is a single firm level connection, followed by a mapping step that links individual clients to it.

Before connecting, your firm's myIR account needs to already be linked as the client's tax agent, or hold delegated access. Zato cannot create this link on your behalf, it has to be arranged directly with IRD or the client first.

  1. Go to Firm Settings, then ZIP.

  2. Locate IRD and select the Settings icon.

  3. Select Connect, and sign in through myIR.

  4. Once connected, open the client mapping wizard to map individual clients to the connection.

In the myIR portal dashboard, the 8 or 9 digit IRD Number is visible on the top right / top banner of the main account summary page next to your account name:

myIR account summary page showing IRD number NZ screenshot, AI generated

This connection is also visible per client, under Client Setup, then Integrations, where you can see whether that particular client has been mapped.