Who it should be
Someone with the standing to bind the business:- A director
- The company secretary
- The owner, for a business name or sole trader
- A partner, for a partnership
Setting one up
1
Open the regulator workspace
Go to the regulator, then Authorisation.
2
Enter the representative's details
Full name as it appears on their identification, their role at your business, email address
and phone number.
3
Upload the letter of authority
A signed letter on your letterhead authorising that person to act for the business with that
regulator. Some regulators have their own prescribed form — the page tells you if so.
4
Set the validity period
A start date and an end date. Keep the period sensible — a year is common. An open-ended
authorisation is harder to control if the person leaves.
5
Save and wait for approval
The authorisation is created as Pending and reviewed. Once approved it becomes active.
Authorisation statuses
Keeping it valid
Bumara warns you before an authorisation expires. Renew it before the date, not after — an expired authorisation discovered on a deadline day is a bad afternoon.Changing your representative
1
Revoke the existing authorisation
Open it and choose Revoke. It stops being valid immediately.
2
Create a new one
Enter the new person’s details and upload a new letter of authority naming them.
3
Check for in-flight submissions
Anything already with the Bumara team may need to wait for the new authorisation to be
approved. Raise a message on the affected filing if a deadline is close.
Which regulators require it
Where a regulator does not require one, the Authorisation page still exists but is optional.
What it does not do
An authorisation is about the regulator, not about Bumara. It does not:- Give that person any additional access inside Bumara — that is controlled by their role
- Allow them to approve payments or run payroll
- Replace the need for proper director resolutions where the regulator requires those separately
If a submission is blocked by authorisation
You can still request submission with a missing or expired authorisation — that gate is not checked at request time. The block happens later, when the team goes to lodge with the regulator, and you receive a message telling you so. This costs days. Check your authorisation status at the start of any period where you expect to file, rather than discovering the problem mid-submission.Related: Submitting to a regulator and
Team and roles.