Security

Users, Roles and Audit Trail: Letting Staff Bill Without Showing Them Everything

Users, roles and an audit trail let your staff make bills and receive payments without seeing or changing everything. Each person has their own login, the role decides which screens open, and the audit trail records who did what and when.

Why should each employee have their own login?

Because a shared login makes everyone anonymous. If three people use one password, a wrong bill belongs to nobody. With one login per person, every invoice, payment and reversal carries a name.

What is a role?

A role is a set of permissions given to a kind of user. Three roles cover a small trading business:

RoleTypical personTypical access
AdminThe ownerEverything, including users and settings
ManagerA trusted senior employeeAll daily work and reports, not settings
StaffCounter or billing clerkCustomers, products, sales, purchases, payments, stock

What each role can open should be yours to decide, area by area.

Which areas should staff not see?

Most owners keep four areas from billing staff: profit and loss and other reports, cash and bank balances, expenses and owner drawings, and settings. A clerk needs the customer's balance to make a bill; he does not need the purchase rate or the month's profit.

What is an audit trail?

An audit trail is an automatic list of every action: who signed in, who created, finalized, reversed or edited what, the time, and for edits the old and the new value. Nobody writes it and nobody can skip it.

How does an audit trail prevent loss?

It prevents loss in two ways. First, mistakes are found fast: when a customer's balance looks wrong you can see every entry on his account and who made it. Second, it removes temptation. A bill made for cash and then removed is visible forever, because invoices are reversed, not deleted, and the reversal is recorded with a name and a reason.

What should you check in the audit trail?

  • Reversals: who reverses often, and why.
  • Edited masters: changes to rates, credit limits and opening balances.
  • Sign-ins at odd hours.
  • Stock adjustments: each should have a believable reason.

What makes a login safe?

  • A password of at least eight characters that is not shared.
  • Passwords stored as one-way hashes, so nobody can read them, not even the software company.
  • A lock after repeated wrong attempts.
  • Automatic sign-out after a period without activity.
  • Switching a login off the day an employee leaves.

In M-Tech Logistics: each user has a login and a role (admin, manager or staff); you tick which areas managers and staff can open; five wrong passwords lock a login for 15 minutes; and the audit trail records every action with user, time and old and new values, with filters and export. The number of users depends on the package. See users and security in the software or compare packages.

Questions people also ask

Can staff make bills without seeing profit?

Yes. Give them the sales area and keep reports for the owner or manager.

Can an admin delete the audit trail?

No. The audit trail has no delete or edit function.

What happens to a user's entries when he leaves?

They stay, with his name. Only his login is switched off.

See it with your own products

Tell us your business on WhatsApp. We set up your account for your trade and you try it free.

WhatsApp