Updated By Faubix

Who should own IRIS credentials

The coordination and access decisions that hold up FBR digital invoicing projects: who registers, who holds credentials, and why sharing a personal login creates avoidable risk.

Start with people and access, not screenshots

Most IRIS friction is organisational, not technical. Before anyone clicks through menus, decide:

  • Who holds the NTN login for the authorized person (and who covers leave)
  • Whether finance, IT, or an external firm will complete registration steps
  • How credentials will be stored securely once sandbox or production tokens appear
  • Which licensed integrator path your advisor says you need (if any)

Handing a software vendor a personal password, or sharing tokens in a group chat, creates avoidable risk. Good partners ask for the minimum access required to configure their product — they should not impersonate FBR portals.

What teams usually prepare before IRIS work

Use this as a kickoff checklist. Portal labels change; the underlying requirements rarely do:

  • NTN access for the right authorized person, with 2FA habits your firm already trusts
  • Clarity on mode — API-oriented integration vs more manual paths where FBR offers them
  • Integrator decision — which FBR-approved gateway path applies for your entity
  • Invoice inventory — the real document types you will issue in the next 30–90 days
  • Environment plan — sandbox credentials first; production only after representative tests pass

If buyer master data is still messy, fix that in parallel. Registration alone does not make bad NTN/CNIC values submit cleanly.

How registration typically connects to software

Think of IRIS (and related official steps) as the compliance front door. Day-to-day invoicing tools sit behind that door:

  1. Complete official registration / enablement steps in IRIS as guided by FBR and your advisor
  2. Obtain sandbox credentials and confirm they work with your licensed integrator path
  3. Configure invoicing software or API mapping against sandbox
  4. Prove representative invoices (including failures)
  5. Promote to production credentials with controlled live volume

eInvoicePro focuses on day-to-day invoicing, validation, bulk, and API connection. It does not replace IRIS or FBR portals — registration and portal steps stay with your team and advisor. Vendors who blur those roles create false expectations and stalled projects.

Coordination tips that save weeks

  • One owner per environment — sandbox and production credentials should not bounce between three WhatsApp groups
  • Written field mapping — ERP or POS fields to FBR invoice fields, reviewed by finance and IT together
  • Named failure owner — who retries a rejected invoice during peak hours
  • Advisor checkpoints — especially before production cutover, not only at project kickoff
  • Evidence pack — keep sandbox confirmation samples so go-live is a decision, not a guess

Screenshots of last year’s IRIS menus go stale quickly. Prefer current official help pages and your advisor’s guidance for the exact click path.

Step-by-step IRIS orientation

Read our modular IRIS registration guide, then book a demo for the eInvoicePro product path alongside your official portal steps.

Common mistakes to avoid

  • Treating a vendor demo as proof that registration is complete
  • Jumping to production tokens before sandbox covers real tax patterns
  • Leaving POS and ERP teams out until “after IRIS is done”
  • Assuming software can invent missing buyer identifiers at submission time
  • Skipping credit/debit note patterns because “we rarely use them” (until the first live correction)

Ready to simplify your FBR digital invoicing?

Join 2000+ businesses using eInvoicePro for real-time FBR integration and automated tax compliance.

Chat with us