Security & governance

Clear permissions. Controlled actions. Traceable records.

Manage access to business information, control who can prepare and approve supported actions, and retain the records needed to review what happened.

Abstract architectural composition of layered glass planes and aligned gateways with a single line of gold light

Controls

Authority model

See, prepare, approve and execute.

These are different responsibilities. Where a workflow supports and requires it, they can be held by different people — not every process needs four different people.

Illustrative control modelSeparated where the workflow requires it
  1. 01

    See

    Access information permitted for your role and company.

  2. 02

    Prepare

    Assemble a proposed action and its supporting information.

  3. 03

    Approve

    Review and authorise the action where approval is required.

  4. 04

    Execute

    Carry out the authorised action through the supported process.

Separation of duties

Separate preparation from approval.

In supported workflows, the person who prepares or submits an action cannot also approve it. Some separations are mandatory; others are configurable to suit the size of the organisation.

  • Mandatory: purchase requisitions and purchase orders are approved by someone other than their submitter, unless the company explicitly allows self-approval
  • Mandatory: purchase orders need two distinct approvers — Procurement, then Finance
  • Mandatory: payment preparation, approval and release, and payee bank-detail changes, need different people
  • Configurable: other combinations, such as goods receiver and invoice preparer, can be allowed in smaller teams
Separation of duties · illustrative

Prepared by

Assembles the action and its supporting evidence.

Approved by

A different person accepts the consequence.

Example · same person, both roles

Declined. In workflows where separation is mandatory, the approval is refused when the approver is the person who prepared or submitted the action.

Purchase requisitionsPurchase ordersPayment approval and releasePayee bank detailsPeriod close

Company access

Access stays within authorised companies.

Each user is given access to specific companies, and may be permitted in several. Records outside those companies are not available to them in enquiries, operations or reporting. Choosing a company changes what you are working on; it does not grant access. Group-level reporting across companies needs its own, separately granted access.

  • A user can be authorised for one company or several
  • Access is checked by the system, not by what is shown on screen
  • Group reporting access is granted separately
Company access · illustrative
  • UK trading company

    Authorised for this user

    Authorised
  • Distribution company

    Also authorised for this user

    Authorised
  • European subsidiary

    Not authorised for this user

    Not authorised
  • Group reporting

    Needs separately granted group access

    Not authorised

Sensitive information

Sensitive information, restricted by role.

People and payroll information is permissioned separately from finance. Access comes from the permissions a person is given, not from their job title. Workforce-cost reporting can be permitted without granting access to individual pay records.

Illustrative permission arrangement
  • EmployeeTheir own details and requests
  • ManagerTeam information they are permitted to see, without individual pay detail
  • PayrollPay calculation detail for the people they are permitted to process
  • FinanceEmployment cost in the accounts, without individual pay records
  • ExecutiveWorkforce-cost reporting where that access is granted

Examples of how permissions can be arranged. Access depends on the permissions granted, not the job title.

Financial record integrity

Correct the record without erasing what happened.

Posted accounting entries are not edited or deleted. A correction is recorded as a separate, dated entry — such as a reversal — linked to the original, so both remain in the ledger.

  • The original posted entry is retained
  • The correction records who made it, when and why
  • The current position can be traced back through the corrections
Posted accounting entries · illustrative
  1. Original

    What was recorded at the time, and remains recorded.

  2. Controlled correction

    A separate, dated entry linked to the original.

  3. Current position

    The result of both, traceable back to each entry.

The original posted entry is kept alongside its correction.

Period control

Control changes to closed periods.

Closing a period is itself prepared and approved. Once closed, the period refuses new postings. Closed periods are not reopened: a later correction is posted as a dated adjustment in an open period, so the change is visible rather than rewriting the closed month.

  • Closed periods refuse new postings
  • Later corrections are dated adjustments in an open period
  • Changes to reported figures remain traceable
Reporting periods · illustrative
  • Period 01Closed
  • Period 02Closed
  • Period 03Closed
  • Period 04Open

Closed periods refuse new postings. Corrections are dated adjustments in an open period.

Audit evidence

Trace who acted, what changed and who approved.

Controlled actions are recorded as they happen. The record shows the user, the action, the approval where one is required, the date and time, the affected record, the outcome and supporting evidence where it is available. Not every action needs an approver or an attachment.

Recorded fields · illustrative
User
The signed-in person who acted
Action
What they did
Approval
Who approved it, where approval is required
Date and time
When it happened
Affected record
The transaction or record concerned
Outcome
Completed, or refused with the reason
Evidence
Supporting document or source, where available

Recorded for controlled actions. This is not a record of every activity in the application.

Two colleagues reviewing a payment approval on screen

Payment governance

Payment controls before execution.

Outgoing payments are prepared, reviewed and approved by authorised people before release. Payee bank-detail changes need a second person's approval. Available in Sandbox — live money movement is not enabled.

Available in Sandbox

Live money movement is not enabled.

Explore Payments

Intelligence

Intelligence explains and suggests. People decide and act.

Intelligence answers business questions, explains results, helps investigate them and writes proposed action plans for people to review — using only the records the person asking is permitted to see. It works within their existing permissions and company access; group analysis needs separately granted group access.

  • Intelligence cannot post journals, approve actions, move money or change business records.
  • Written recommendations are for review; actions are carried out by authorised people
SynqLedger IntelligenceAvailable in preview

Intelligence, read-only

  • Answer questions
  • Explain results
  • Investigate
  • Write proposed plans

Authorised people

  • Decide
  • Approve
  • Post and pay

Uses only records the person asking is permitted to see.

See how your controls work in SynqLedger.

Bring your access and approval requirements. We’ll walk through the supported controls and show how actions and their supporting records can be reviewed.