Users, roles and an audit trail let your staff make bills and receive payments without seeing or changing everything. Each person has their own login, the role decides which screens open, and the audit trail records who did what and when.
Why should each employee have their own login?
Because a shared login makes everyone anonymous. If three people use one password, a wrong bill belongs to nobody. With one login per person, every invoice, payment and reversal carries a name.
What is a role?
A role is a set of permissions given to a kind of user. Three roles cover a small trading business:
| Role | Typical person | Typical access |
|---|---|---|
| Admin | The owner | Everything, including users and settings |
| Manager | A trusted senior employee | All daily work and reports, not settings |
| Staff | Counter or billing clerk | Customers, products, sales, purchases, payments, stock |
What each role can open should be yours to decide, area by area.
Which areas should staff not see?
Most owners keep four areas from billing staff: profit and loss and other reports, cash and bank balances, expenses and owner drawings, and settings. A clerk needs the customer's balance to make a bill; he does not need the purchase rate or the month's profit.
What is an audit trail?
An audit trail is an automatic list of every action: who signed in, who created, finalized, reversed or edited what, the time, and for edits the old and the new value. Nobody writes it and nobody can skip it.
How does an audit trail prevent loss?
It prevents loss in two ways. First, mistakes are found fast: when a customer's balance looks wrong you can see every entry on his account and who made it. Second, it removes temptation. A bill made for cash and then removed is visible forever, because invoices are reversed, not deleted, and the reversal is recorded with a name and a reason.
What should you check in the audit trail?
- Reversals: who reverses often, and why.
- Edited masters: changes to rates, credit limits and opening balances.
- Sign-ins at odd hours.
- Stock adjustments: each should have a believable reason.
What makes a login safe?
- A password of at least eight characters that is not shared.
- Passwords stored as one-way hashes, so nobody can read them, not even the software company.
- A lock after repeated wrong attempts.
- Automatic sign-out after a period without activity.
- Switching a login off the day an employee leaves.
In M-Tech Logistics: each user has a login and a role (admin, manager or staff); you tick which areas managers and staff can open; five wrong passwords lock a login for 15 minutes; and the audit trail records every action with user, time and old and new values, with filters and export. The number of users depends on the package. See users and security in the software or compare packages.