Earlier quoted context omitted.
I'm curious, if you don't store usernames and passwords for banking credentials, how do know if the ACH transfer will NSF? Do you ask the account holder for their bank credentials each time you want to pull money from their account?
No - so we risk rate for recurring payments and get a bunch of info from online banking that helps us determine how large of a recurring payment and at what interval we can allow. We've never been wrong, but we will be someday I'm sure. Recurring payments right now are not fully guaranteed against NSF risk only the first one and all one time payments. So for ZenPayroll I suppose that's particularly relevant. Someday…
Usernames and passwords are generally an all-or-nothing proposition, and will be for the foreseeable future. Is getting major banks to adopt a application-specific-password scheme [0] (maybe even with maybe-fine-grained permissions!) such a lost cause that it makes what you're proposing a vaguely reasonable thing to do?