Role Guides

System Administrator: daily workflow

Step-by-step tasks for user management, permissions, and system monitoring.

Jul 11, 2026

Each morning: Check system health

Start your day by verifying the system is running and all critical services are online.

  1. Navigate to Settings → System Status or Admin → Dashboard Open in Usystems
  2. Verify:
    • Database: Connected and responding.
    • Backup: Last backup completed without error.
    • Integrations: Payment gateways, bank feeds, or external APIs are synced.
  3. If any service is down, log the issue and notify your team; escalate to IT if needed.

Onboard a new user

When someone joins the organization, create their account and assign permissions.

  1. Navigate to Settings → Users & Accounts or Admin → Users Open in Usystems
  2. Click Add User or Create User.
  3. Enter:
    • Name: Full name.
    • Email: Work email address.
    • Role: Select from existing roles (Accountant, Sales Manager, HR Officer, Admin, etc.).
    • Start date: When they begin.
  4. Click Send Invite. The system emails them a temporary password and login link.
  5. Ask them to log in, change their password, and confirm they can access the menus for their role.

Assign or modify permissions for a user

If a user needs different access (e.g., a junior accountant should now be able to approve invoices), update their role or permissions.

  1. Navigate to Settings → Roles or Admin → Permissions Open in Usystems
  2. Select the user or role you want to modify.
  3. Review the permissions list:
    • ✓ Permissions the role can do.
    • ✗ Permissions the role cannot do.
  4. Check or uncheck permissions as needed. Examples:
    • Create invoices, Sales receipts, Bills — financial data entry.
    • Approve invoices, Bills — authorization.
    • View reports, Ledger — read-only reporting.
    • Manage users, Export data — admin-only.
  5. Click Save.
  6. Ask the user to log out and log back in for permissions to take effect.

Deactivate a user (when someone leaves)

When an employee departs, disable their login to protect security.

  1. Navigate to Settings → Users & Accounts Open in Usystems
  2. Find the user.
  3. Click Deactivate or toggle Active off.
  4. Optionally, mark their data records (documents they created) as read-only or reassign them to another user.
  5. The user cannot log in; their old data remains for audit purposes.

Tip: Never delete a user entirely — deactivation preserves the audit trail of documents they created.

Weekly: Audit user access

Review who has access and whether permissions still align with their role.

  1. Navigate to Settings → Audit Trail or Admin → Activity Log Open in Usystems
  2. Filter by recent activity (last 7 days) and scan for:
    • Unusual login times or locations.
    • Bulk exports or data access outside normal scope.
    • Deleted or modified documents (verify if intentional).
  3. If something looks wrong, investigate and document your findings.

Monthly: Review and export backups

Ensure your data is being backed up and accessible for recovery.

  1. Navigate to Settings → Data & Backup or Admin → Backup Open in Usystems
  2. Verify:
    • Last backup date and size.
    • Backup is stored in a secure location (cloud storage or external drive).
  3. Test a backup recovery (monthly or quarterly):
    • Restore a backup to a test environment.
    • Verify data integrity (a few random transactions, user counts, etc.).

Update security settings (as needed)

Periodically review and strengthen security policies.

  1. Navigate to Settings → Security Open in Usystems
  2. Check and update:
    • Password policy: Minimum length, expiration (e.g., 90 days).
    • Session timeout: How long before idle users are logged out (e.g., 30 minutes).
    • Two-factor authentication (2FA): Enable for admin accounts if available.
    • API tokens: Review active tokens; revoke any that are no longer needed.
  3. Communicate changes to users.

Tips & common mistakes

  • Don't give admin access lightly: Restrict admin privileges to yourself or one backup. Too many admins = too many people who can accidentally delete or corrupt data.
  • Document role definitions: Keep a simple spreadsheet of roles, permissions, and which users have each role. Update it as people change roles.
  • Deactivate, don't delete: Always deactivate users so their document history remains auditable.
  • Test permissions in a sandbox: Before rolling out a new role to many users, have one test user try it to catch mistakes.
  • Backup before major changes: Before updating settings or data, back up the system so you can recover if something goes wrong.

Was this helpful?

More like this