System Administrator: daily workflow
Step-by-step tasks for user management, permissions, and system monitoring.
Each morning: Check system health
Start your day by verifying the system is running and all critical services are online.
- Navigate to Settings → System Status or Admin → Dashboard Open in Usystems
- Verify:
- Database: Connected and responding.
- Backup: Last backup completed without error.
- Integrations: Payment gateways, bank feeds, or external APIs are synced.
- If any service is down, log the issue and notify your team; escalate to IT if needed.
Onboard a new user
When someone joins the organization, create their account and assign permissions.
- Navigate to Settings → Users & Accounts or Admin → Users Open in Usystems
- Click Add User or Create User.
- Enter:
- Name: Full name.
- Email: Work email address.
- Role: Select from existing roles (Accountant, Sales Manager, HR Officer, Admin, etc.).
- Start date: When they begin.
- Click Send Invite. The system emails them a temporary password and login link.
- Ask them to log in, change their password, and confirm they can access the menus for their role.
Assign or modify permissions for a user
If a user needs different access (e.g., a junior accountant should now be able to approve invoices), update their role or permissions.
- Navigate to Settings → Roles or Admin → Permissions Open in Usystems
- Select the user or role you want to modify.
- Review the permissions list:
- ✓ Permissions the role can do.
- ✗ Permissions the role cannot do.
- Check or uncheck permissions as needed. Examples:
- Create invoices, Sales receipts, Bills — financial data entry.
- Approve invoices, Bills — authorization.
- View reports, Ledger — read-only reporting.
- Manage users, Export data — admin-only.
- Click Save.
- Ask the user to log out and log back in for permissions to take effect.
Deactivate a user (when someone leaves)
When an employee departs, disable their login to protect security.
- Navigate to Settings → Users & Accounts Open in Usystems
- Find the user.
- Click Deactivate or toggle Active off.
- Optionally, mark their data records (documents they created) as read-only or reassign them to another user.
- The user cannot log in; their old data remains for audit purposes.
Tip: Never delete a user entirely — deactivation preserves the audit trail of documents they created.
Weekly: Audit user access
Review who has access and whether permissions still align with their role.
- Navigate to Settings → Audit Trail or Admin → Activity Log Open in Usystems
- Filter by recent activity (last 7 days) and scan for:
- Unusual login times or locations.
- Bulk exports or data access outside normal scope.
- Deleted or modified documents (verify if intentional).
- If something looks wrong, investigate and document your findings.
Monthly: Review and export backups
Ensure your data is being backed up and accessible for recovery.
- Navigate to Settings → Data & Backup or Admin → Backup Open in Usystems
- Verify:
- Last backup date and size.
- Backup is stored in a secure location (cloud storage or external drive).
- Test a backup recovery (monthly or quarterly):
- Restore a backup to a test environment.
- Verify data integrity (a few random transactions, user counts, etc.).
Update security settings (as needed)
Periodically review and strengthen security policies.
- Navigate to Settings → Security Open in Usystems
- Check and update:
- Password policy: Minimum length, expiration (e.g., 90 days).
- Session timeout: How long before idle users are logged out (e.g., 30 minutes).
- Two-factor authentication (2FA): Enable for admin accounts if available.
- API tokens: Review active tokens; revoke any that are no longer needed.
- Communicate changes to users.
Tips & common mistakes
- Don't give admin access lightly: Restrict admin privileges to yourself or one backup. Too many admins = too many people who can accidentally delete or corrupt data.
- Document role definitions: Keep a simple spreadsheet of roles, permissions, and which users have each role. Update it as people change roles.
- Deactivate, don't delete: Always deactivate users so their document history remains auditable.
- Test permissions in a sandbox: Before rolling out a new role to many users, have one test user try it to catch mistakes.
- Backup before major changes: Before updating settings or data, back up the system so you can recover if something goes wrong.
هل كان هذا مفيدًا؟