End-to-end workflows
How work moves through Administration from start to finish, who does each step and what the system does in response.
On this page (12)
New employee gets accessLeaver: suspend, then archivePassword lockout and recoveryRole design and separation of dutiesIntegration access with an API keyTemporary access with an exception and a limitAudit protection end to endCompany email setupNumbering change for a new yearNew company set-upConfigure an app for a businessPrice list in action
New employee gets access
Who: Admin A
| # | What the person does | What the system does |
|---|---|---|
| 1 | Create the employee in HR (or use an existing test employee) | Employee exists without a login |
| 2 | System users > New system user > pick the employee; type Internal; Member; role 'Accountant'; Licence Professional; temporary password | User created; must change password |
| 3 | Sign out; sign in as the new user with the temporary password | Asked to set a new password |
| 4 | Set a new password; open Finance | Finance menus match the Accountant role; other apps' menus hidden |
| 5 | As Admin A open the user: Security tab | Sign-in recorded; 'Chose their own password' now ticked on the health score |
Leaver: suspend, then archive
Who: Admin A
| # | What the person does | What the system does |
|---|---|---|
| 1 | User signed in on another browser | Session active |
| 2 | Admin: Suspend user with reason | The other browser is signed out at the next action; sign-in refused |
| 3 | Admin: Activate user | Can sign in again |
| 4 | Admin: Archive user with reason | Archived; cannot sign in; still visible in history and audit |
Password lockout and recovery
Who: User U, Admin A
| # | What the person does | What the system does |
|---|---|---|
| 1 | Sign in as U with a wrong password 5 times | Locked: 'This account is locked after too many attempts. Try again after HH:MM UTC.' |
| 2 | Admin: open U > Security tab | Wrong passwords 5/5; Locked until shown |
| 3 | Admin: Reset password | Automatic lock cleared; U must change password |
| 4 | U signs in with the temporary password | Asked for a new password; then works |
Role design and separation of duties
Who: Admin A, Admin B
| # | What the person does | What the system does |
|---|---|---|
| 1 | Access review: set 'grants_and_approves' (or another rule) to Refuse the grant | Rule shows 'Refuse it' |
| 2 | Give user U the first conflicting role | Granted |
| 3 | Give user U the second conflicting role | Refused with the conflict message |
| 4 | Admin B reviews U: Access is right as it is | Last reviewed = today by Admin B |
| 5 | Admin A tries to review themself | Refused: 'Somebody else has to review your access.' |
Integration access with an API key
Who: Admin A
| # | What the person does | What the system does |
|---|---|---|
| 1 | New system user of type Integration (no employee) | Created; cannot sign in at the login page |
| 2 | API keys > New key for it, limited to partner.view, 90 days | Token shown once |
| 3 | Call the partners API with the token | Works |
| 4 | Rotate the key | New token; old works for 7 days |
| 5 | Revoke the new key | Requests with it refused |
Temporary access with an exception and a limit
Who: Admin A, User U
| # | What the person does | What the system does |
|---|---|---|
| 1 | Exceptions: allow U 'approve' on Journal entries until tomorrow | Listed with Until |
| 2 | Approval limit: Journal limit 1000 for U | Listed |
| 3 | U approves a 500 journal, then a 1500 journal | 500 approved; 1500 refused |
| 4 | After the exception date passes | Shows Expired; U can no longer approve |
Audit protection end to end
Who: Admin A, Admin B, Auditor C
| # | What the person does | What the system does |
|---|---|---|
| 1 | Alert rules: A creates a rule for 'partner.bank' telling C (C holds audit.view) | Rule saved |
| 2 | A changes a customer's bank account | C sees a new alert; A does not |
| 3 | After 60 seconds A clicks Seal new events | A new seal |
| 4 | C clicks Verify the trail | Verified, all intact |
| 5 | A places a legal hold on 'partner.' | Hold listed |
| 6 | A proposes a disposal; A tries to approve it | Refused: 'Somebody other than the person who proposed it approves a disposal.' |
| 7 | B approves | Done; events under the hold were kept ('Kept by holds' count) |
Company email setup
Who: Admin A, User U
| # | What the person does | What the system does |
|---|---|---|
| 1 | A adds a company account (test SMTP) and a personal account for U | Both listed |
| 2 | U opens Email sending | 'Your mail goes out as' shows U's personal account |
| 3 | U sends a quotation by email | Email arrives from U's address |
| 4 | A switches U's account off (In use) | U's mail now goes out from the company account |
Numbering change for a new year
Who: Admin A
| # | What the person does | What the system does |
|---|---|---|
| 1 | Sequences: invoice prefix INV-%(year)s-; next number 1 | Preview shows the year |
| 2 | Create and post an invoice | Number INV-<year>-000001 |
| 3 | Try to set Next number back below the last used | Allowed (warning) - confirm the next invoice does not duplicate a number; log if it does |
New company set-up
Who: Superuser / Admin A
| # | What the person does | What the system does |
|---|---|---|
| 1 | Create company TST01 | Created; standard payment terms; apps installed |
| 2 | Fill company record: TRN, licence, address, defaults | Setup progress 100 % (or note what is missing) |
| 3 | Create branches HQ and DXB | Dimension values and numbering |
| 4 | Add payment methods (standard) | 7 methods |
| 5 | Create a price list for B2B and make it Active | Quotes for business customers use it |
| 6 | Create a test user (Users) and switch to the new company as them | They see only this company |
Configure an app for a business
Who: Admin A (proposer), Admin B (approver)
| # | What the person does | What the system does |
|---|---|---|
| 1 | A: Applications > Purchasing > Features: turn off Reverse auctions / Tenders; Fields: Supplier reference = Required | Draft shows changes |
| 2 | A: Preview changes | What changes listed; nothing blocked |
| 3 | A: enter a reason; Propose for approval | Revision proposed; banner 'waits for approval' |
| 4 | A tries to approve | Not offered: 'Somebody other than its proposer approves it.' |
| 5 | B approves | In force: menus hidden, field required; Activity shows proposed and approved |
| 6 | A restores the previous revision; B approves | Back to defaults |
Price list in action
Who: Sales user
| # | What the person does | What the system does |
|---|---|---|
| 1 | Price list for customer C: product P 90 (standard 100), 10+ at 80 | List Active and assigned |
| 2 | Quote C for 5 P | Price 90 |
| 3 | Quote C for 12 P | Price 80 |
| 4 | Quote another customer for 5 P | Price 100 |
| 5 | Make the list Inactive; quote C again | Price 100 |