YonSuite Role Access: Segregation of Duties for High-risk Actions
Translate jobs into least-privilege roles and control create, approve, pay and configure risks.
Learning objective
Build a tested role matrix without unapproved end-to-end self-service.
Roles
Business owners, finance, IT, consultants and audit
Prerequisites
- Conflicts are blocked or compensated.
- Leaver and expired access is removed.
- Users see only authorised data.
Completion checks
- Conflicts are blocked or compensated.
- Leaver and expired access is removed.
- Users see only authorised data.
Common errors
- Copying superuser access.
- Controlling menus only.
- Signature-only reviews.
Thailand project note
For Thailand, confirm multilingual data, THB and foreign currency, Asia/Bangkok time, segregation and retention; VAT, WHT, customs, BOI and statutory accounting require qualified Thai review.
Related modules
Steps
- 01
Inventory users, jobs, organisations, device and service accounts; disable ownerless accounts.
- 02
Design roles around tasks; do not copy predecessors or create one role per user.
- 03
Identify supplier, purchasing, receipt, invoice, payment and access risks.
- 04
Separate creation from approval and entry from payment in a conflict matrix.
- 05
Constrain organisation and data scope separately from menu visibility.
- 06
Log reason, approval, start, end and expiry for temporary access.
- 07
Test positive and negative cases; review quarterly and on job changes.
Implementation notes
- Conflicts are blocked or compensated.
- Leaver and expired access is removed.
References
- U9 cloud 产品介绍 ↗用友 · Accessed: 2026-08-21 · Applicable version: 公开产品能力;实际配置以客户版本与蓝图为准
- U9 cloud 全链路数据分析能力 ↗用友 U9 cloud · Accessed: 2026-08-21 · Applicable version: 公开数据模型、权限和分析能力