Typical responsibilities
These are examples, not fixed system roles. Your organization can define roles that match its segregation-of-duties policy.
Access rules users should expect
- A menu not assigned to your role does not appear.
- List views are filtered to the data scope permitted for your user.
- Create, edit, delete, approve, post, export, and report rights can be granted separately.
- Directly entering a restricted URL does not bypass authorization.
- Posted or period-locked records may remain visible but read-only.
Account security
- Use an individual account and never share credentials.
- Use a strong, unique password.
- Change the initial password when Change Password on First Logon is enabled.
- Sign out on shared devices.
- Protect exported data and downloaded reports.
- Report unexpected access immediately.
Administrator access review
1
Review active users
Confirm every active account belongs to a current staff member or approved service identity.
2
Review roles and scope
Confirm each user has only the modules, actions, offices, and data required for current duties.
3
Check privileged accounts
Limit administrator, approval, posting, and export permissions to authorized users.
4
Correct changes promptly
Deactivate leavers and update access when a person changes role, office, or responsibility.
5
Retain review evidence
Record who reviewed access, when it was reviewed, and which changes were approved.
