YonSuitePlatform & AnalyticsIntermediateContent quality · 94/100

YonSuite Role Access: Segregation of Duties for High-risk Actions

Translate jobs into least-privilege roles and control create, approve, pay and configure risks.

角色权限与职责分离 / RBAC and SoD17 minUpdated 2026-08-21
01

Learning objective

Build a tested role matrix without unapproved end-to-end self-service.

Roles

Business owners, finance, IT, consultants and audit

Prerequisites

  • Conflicts are blocked or compensated.
  • Leaver and expired access is removed.
  • Users see only authorised data.

Completion checks

  • Conflicts are blocked or compensated.
  • Leaver and expired access is removed.
  • Users see only authorised data.

Common errors

  • Copying superuser access.
  • Controlling menus only.
  • Signature-only reviews.

Thailand project note

For Thailand, confirm multilingual data, THB and foreign currency, Asia/Bangkok time, segregation and retention; VAT, WHT, customs, BOI and statutory accounting require qualified Thai review.

Related modules

u9cloud-multi-organization-model-setupu9cloud-master-data-governance-baselineerp-audit-log-and-access-review

03

Steps

01Inventory users, jobs, organisations, device and service accounts; disable ownerless accounts.
02Design roles around tasks; do not copy predecessors or create one role per user.
03Identify supplier, purchasing, receipt, invoice, payment and access risks.
04Separate creation from approval and entry from payment in a conflict matrix.
05Constrain organisation and data scope separately from menu visibility.
06Log reason, approval, start, end and expiry for temporary access.
07Test positive and negative cases; review quarterly and on job changes.
  1. 01

    Inventory users, jobs, organisations, device and service accounts; disable ownerless accounts.

  2. 02

    Design roles around tasks; do not copy predecessors or create one role per user.

  3. 03

    Identify supplier, purchasing, receipt, invoice, payment and access risks.

  4. 04

    Separate creation from approval and entry from payment in a conflict matrix.

  5. 05

    Constrain organisation and data scope separately from menu visibility.

  6. 06

    Log reason, approval, start, end and expiry for temporary access.

  7. 07

    Test positive and negative cases; review quarterly and on job changes.

04

Implementation notes

  • Conflicts are blocked or compensated.
  • Leaver and expired access is removed.
05

References