Security best practices for administrators
Protect your Usystems account and sensitive financial data with essential security practices.
Security best practices for administrators
As an administrator, you control access to your organization's financial records, inventory, and customer data in Usystems. The security decisions you make directly affect the safety of your business and your team members' privacy.
Why security matters
Weak account security exposes your business to financial fraud, data theft, and unauthorized changes to critical records. A compromised admin account can lead to:
- Unauthorized financial transactions — fake invoices, payments, or inventory adjustments that damage your bottom line.
- Data loss or corruption — accidental or malicious deletion of customer, inventory, or transaction records.
- Compliance violations — breaches that may violate local business laws or data protection rules.
- Reputation damage — customers losing trust if their personal data is exposed.
Implementing security best practices is the simplest way to prevent these scenarios.
Key security practices
1. Use strong, unique passwords
- Create passwords with at least 12 characters combining uppercase, lowercase, numbers, and special characters.
- Never reuse passwords across multiple services — use a different password for Usystems than for your email, banking, or other accounts.
- Change your password periodically (every 60–90 days) and immediately if you suspect compromise.
- Never share your password with anyone, not even other administrators or vendors.
2. Protect your login credentials
- Keep your email secure — your email is the key to resetting your Usystems password and receiving account notifications. Secure it with a strong password and two-factor authentication if your email provider offers it.
- Use a secure connection — always log in to Usystems over a trusted internet connection. Avoid public WiFi for sensitive work when possible.
- Log out when finished — do not leave your session open on shared computers or public devices.
- Never leave your device unattended while logged in — anyone with access to your computer during your session can make changes to critical records.
3. Limit user access with roles and permissions
- Assign roles carefully — give each user only the roles and permissions they need to do their job (principle of least privilege).
- Review roles regularly — at least quarterly, check which users have which roles. Remove roles from staff who no longer need them.
- Use role restrictions — if available, limit users to specific products (e.g., Pharmacy only) or locations (e.g., one warehouse) to reduce the blast radius if a lower-privilege account is compromised.
- Separate sensitive duties — assign invoice approval, payment authorization, and financial reporting to different users where possible.
4. Monitor and audit user activity
- Review the user list regularly to ensure all listed users are current staff. Deactivate accounts for employees who have left (do not delete them; deactivation maintains the audit trail).
- Watch for unusual activity — if you notice transactions at odd times or from unexpected users, investigate immediately.
- Keep audit logs — Usystems maintains a record of changes. Review transaction history and change logs periodically to catch fraud early.
5. Secure your account recovery method
- Use a personal email for your admin account — do not use a company-wide email that multiple people can access, as it becomes a backdoor to resetting your password.
- Keep your phone number up to date — if Usystems ever implements SMS-based account recovery, a current number is critical.
6. Plan for admin succession
- Designate a backup administrator if your organization is large enough. This person should also follow these security practices.
- Document critical procedures in a secure location (e.g., a password manager accessible only to authorized staff) so another admin can take over if needed.
- Test the succession plan by having the backup admin perform key tasks under supervision, so you know they can do it.
Where to manage security in Usystems
You manage users, roles, and access settings in the Settings area:
- Users & Roles → Users: Add, edit, and deactivate user accounts. Open in Usystems
- Users & Roles → Groups (Roles): View and manage the roles available in your system. Open in Usystems
- Settings → General: Configure basic account and organization information. Open in Usystems
Start by reviewing your current user list and roles to ensure they match your organization's current structure.
هل كان هذا مفيدًا؟