Security & governance
Clear permissions. Controlled actions. Traceable records.
Manage access to business information, control who can prepare and approve supported actions, and retain the records needed to review what happened.

Controls
Authority model
See, prepare, approve and execute.
These are different responsibilities. Where a workflow supports and requires it, they can be held by different people — not every process needs four different people.
- 01
See
Access information permitted for your role and company.
- 02
Prepare
Assemble a proposed action and its supporting information.
- 03
Approve
Review and authorise the action where approval is required.
- 04
Execute
Carry out the authorised action through the supported process.
Separation of duties
Separate preparation from approval.
In supported workflows, the person who prepares or submits an action cannot also approve it. Some separations are mandatory; others are configurable to suit the size of the organisation.
- Mandatory: purchase requisitions and purchase orders are approved by someone other than their submitter, unless the company explicitly allows self-approval
- Mandatory: purchase orders need two distinct approvers — Procurement, then Finance
- Mandatory: payment preparation, approval and release, and payee bank-detail changes, need different people
- Configurable: other combinations, such as goods receiver and invoice preparer, can be allowed in smaller teams
Prepared by
Assembles the action and its supporting evidence.
Approved by
A different person accepts the consequence.
Example · same person, both roles
Declined. In workflows where separation is mandatory, the approval is refused when the approver is the person who prepared or submitted the action.
Company access
Access stays within authorised companies.
Each user is given access to specific companies, and may be permitted in several. Records outside those companies are not available to them in enquiries, operations or reporting. Choosing a company changes what you are working on; it does not grant access. Group-level reporting across companies needs its own, separately granted access.
- A user can be authorised for one company or several
- Access is checked by the system, not by what is shown on screen
- Group reporting access is granted separately
- Authorised
UK trading company
Authorised for this user
- Authorised
Distribution company
Also authorised for this user
- Not authorised
European subsidiary
Not authorised for this user
- Not authorised
Group reporting
Needs separately granted group access
Sensitive information
Sensitive information, restricted by role.
People and payroll information is permissioned separately from finance. Access comes from the permissions a person is given, not from their job title. Workforce-cost reporting can be permitted without granting access to individual pay records.
- EmployeeTheir own details and requests
- ManagerTeam information they are permitted to see, without individual pay detail
- PayrollPay calculation detail for the people they are permitted to process
- FinanceEmployment cost in the accounts, without individual pay records
- ExecutiveWorkforce-cost reporting where that access is granted
Examples of how permissions can be arranged. Access depends on the permissions granted, not the job title.
Financial record integrity
Correct the record without erasing what happened.
Posted accounting entries are not edited or deleted. A correction is recorded as a separate, dated entry — such as a reversal — linked to the original, so both remain in the ledger.
- The original posted entry is retained
- The correction records who made it, when and why
- The current position can be traced back through the corrections
Original
What was recorded at the time, and remains recorded.
Controlled correction
A separate, dated entry linked to the original.
Current position
The result of both, traceable back to each entry.
The original posted entry is kept alongside its correction.
Period control
Control changes to closed periods.
Closing a period is itself prepared and approved. Once closed, the period refuses new postings. Closed periods are not reopened: a later correction is posted as a dated adjustment in an open period, so the change is visible rather than rewriting the closed month.
- Closed periods refuse new postings
- Later corrections are dated adjustments in an open period
- Changes to reported figures remain traceable
- Period 01Closed
- Period 02Closed
- Period 03Closed
- Period 04Open
Closed periods refuse new postings. Corrections are dated adjustments in an open period.
Audit evidence
Trace who acted, what changed and who approved.
Controlled actions are recorded as they happen. The record shows the user, the action, the approval where one is required, the date and time, the affected record, the outcome and supporting evidence where it is available. Not every action needs an approver or an attachment.
- User
- The signed-in person who acted
- Action
- What they did
- Approval
- Who approved it, where approval is required
- Date and time
- When it happened
- Affected record
- The transaction or record concerned
- Outcome
- Completed, or refused with the reason
- Evidence
- Supporting document or source, where available
Recorded for controlled actions. This is not a record of every activity in the application.

Payment governance
Payment controls before execution.
Outgoing payments are prepared, reviewed and approved by authorised people before release. Payee bank-detail changes need a second person's approval. Available in Sandbox — live money movement is not enabled.
Across the platform
Controls across your business.
The same approach to access, approval and records applies in each area.
Intelligence
Intelligence explains and suggests. People decide and act.
Intelligence answers business questions, explains results, helps investigate them and writes proposed action plans for people to review — using only the records the person asking is permitted to see. It works within their existing permissions and company access; group analysis needs separately granted group access.
- Intelligence cannot post journals, approve actions, move money or change business records.
- Written recommendations are for review; actions are carried out by authorised people
Intelligence, read-only
- Answer questions
- Explain results
- Investigate
- Write proposed plans
Authorised people
- Decide
- Approve
- Post and pay
Uses only records the person asking is permitted to see.
See how your controls work in SynqLedger.
Bring your access and approval requirements. We’ll walk through the supported controls and show how actions and their supporting records can be reviewed.