Skyline Nexus ERP Skyline Nexus ERP
Skyline Nexus ERP

Roles, permissions and segregation of duties

Design ERP roles that separate authorising, recording, custody and review, with approval limits and branch access, worked through in Skyline Nexus ERP.

Last reviewed 10 min

What segregation of duties means

Segregation of duties is the control principle that no single person should be able to authorise a transaction, record it, hold the asset it involves and check the result. It matters because most internal fraud and many undetected errors need one person to control two of those steps, and splitting them means a mistake or a theft has to get past a second person.

In an ERP, segregation of duties is implemented through roles and permissions: each role grants the screens and actions that one job needs, and nothing more. The principle is simple; the difficulty is applying it with a small team, where there are not enough people to separate everything, and with administrator accounts that can do everything. This guide explains the principle, then shows how roles, permissions, location access and approvals work in Skyline Nexus ERP, and how to compensate where a team is too small to separate duties fully.

The four functions to keep apart

The COSO Internal Control Integrated Framework treats segregation of duties as a control activity, and auditors assessing internal control under ISA 315 (Revised 2019) look for it in the processes that matter most: purchasing and payments, sales and receipts, payroll and journal entries. The usual model separates four functions. Any person who holds two of them for the same transaction can create a problem and hide it.

  • Authorisation: approving a purchase, a price change, a credit limit or a journal
  • Recording: entering invoices, receipts, payments and journals in the system
  • Custody: handling cash, cheques, stock or bank payment credentials
  • Reconciliation and review: bank reconciliations, stock counts, ledger review
  • Example conflict: the person who adds suppliers should not also release payments
  • Example conflict: the cashier should not reconcile the cash register they operate
  • Example conflict: the person who posts journals should not approve their own

How roles work in Skyline Nexus ERP

Roles in Skyline Nexus ERP are created under User Management, Roles, Add Role, with a Role Name and a list of Permissions grouped by area: User, Roles, Supplier, Customer, Product, Purchase and Stock Adjustment, POS, Sales, Expenses, Reports, Settings and others. Several permissions come in view own and view all variants, so a salesperson can be limited to their own sales. Others control sensitive data and actions directly, such as View Purchase Price and the rights to edit prices or give discounts at the POS.

Each module adds its own permissions. The Accounting module adds, among others: access accounting module; view chart of accounts; create, edit and delete accounts; view, create, edit and delete journal entries; post journal entries; reverse journal entries; view, create, edit and delete vouchers; approve vouchers; map transactions; reconcile accounts; view and manage cost centres and budgets; view accounting reports; manage fiscal years; close fiscal period; manage settings; and manage consolidation. That granularity lets you separate posting from reversing, and period closing from day-to-day entry.

The Admin role: keep it small

Every business in Skyline Nexus ERP has an Admin role that passes every permission check. That is necessary for set-up and emergencies, but it defeats segregation of duties for anyone who holds it: an Admin user can create a supplier, enter a bill, pay it and reverse the evidence. Limit the Admin role to the owner and, where needed, one finance lead, and give everyone else a named role built for their job.

Admin users also carry the approval of submitted journals. Journal approval checks permissions that are held in practice by the Admin role, and the approval step records who approved but does not by itself prevent the creator of an entry from approving it. Treat that as a design point to control: have journals created by non-Admin users and approved by an Admin, and review the Audit Trail each month for any entry approved by the person who created it.

The permissions that deserve the most care

Some permissions look administrative but change the numbers as surely as a journal does. The right to manage accounting settings is the clearest example. Whoever can change the Auto-Post Settings or the account mapping can redirect every future sale, purchase or expense to a different account, or stop posting altogether, without entering a single journal. That makes manage settings a higher-risk permission than create journal entries, and it belongs with the finance lead alone.

The same reasoning applies to the permissions that close or reopen the books and to those that change history. Close fiscal period controls whether a reported month can move. Reverse journal entries can undo a posted entry, which is legitimate for corrections but also the tool of choice for hiding one. Delete accounts, create and edit accounts, and map transactions reshape the chart of accounts that every report depends on. On the operational side, View Purchase Price exposes margins, and the POS price and discount rights let a cashier change what the customer pays. Grant each of these deliberately, to named roles, and look at who holds them in every access review.

  • Manage settings: auto-post toggles and account mapping, finance lead only
  • Close fiscal period and manage fiscal years: finance manager, reviewed by the owner
  • Reverse journal entries: separate from create journal entries where the team allows
  • Create, edit and delete accounts; map transactions: finance manager only
  • View Purchase Price and POS price or discount edits: named supervisors only

Approval thresholds for journals

Approval workflows turn authorisation into a system step. In Skyline Nexus ERP, Fiscal Authority, Settings, Approval Settings holds Require Approval for Journals and the Approval Threshold; the install defaults are approval on and a threshold of 10,000 in the base currency. Save and Submit sends an entry at or above the threshold for approval, while an entry below it is approved automatically. An approved entry is posted by a user with the post journal entries permission, or automatically if Auto-post on Approval is on. Amounts at or above twice the threshold need a second level of approval.

Choose the threshold from your materiality, not from convenience. A threshold set just above the typical month-end accrual means nothing is ever reviewed; one set so low that everything queues teaches approvers to click through. Review the Audit Trail for clusters of manual journals just below the threshold, a classic sign of splitting.

  • Manual journal of 4,500: below 10,000, approved automatically
  • Manual journal of 12,000: at or above 10,000, waits for approval
  • Manual journal of 25,000: at or above 20,000, needs level-2 approval
  • Pending items: Journal Entries, pending approvals, approve or reject with notes

Other approval steps across the system

Journals are not the only approval point. Skyline Nexus ERP also has approval steps for budgets, which are submitted and then approved or rejected; Zakat returns, which move from draft to ready, submitted and filed; FDI surveys; asset acquisitions through Pending Approvals; Treasury approvals; and HCM approvals for payroll and leave. Expense Vouchers have their own approve vouchers permission.

Map each approval step to a named person and a deputy, and make sure the approver is never the person who prepared the item. For payroll in particular, the approver should compare the run with the previous month and with headcount changes, because payroll is where ghost employees and unauthorised pay rises hide.

Branch access as a second dimension

Roles decide what a user can do; location access decides where. Under User Management, Users, each user's Access locations is either All Locations or a list of specific locations, and a user without All Locations sees and transacts only for the locations granted in the sales, purchase and stock screens. A branch manager can therefore approve and record within their branch while having no visibility of another branch's customers, prices or stock.

Combining the two dimensions gives a clean design for multi-branch businesses: a small number of roles by job, applied per branch through location access. Our guide on multi-branch accounting in Skyline Nexus ERP covers the branch set-up that sits underneath.

Worked example: roles for a small wholesaler

A Canadian wholesaler with two warehouses has an owner, a finance manager, an accounts payable clerk, an accounts receivable clerk, a warehouse supervisor at each site and a part-time payroll administrator. The design below gives each person one role, keeps the Admin role to the owner and the finance manager, and splits every conflicting pair between two people outside the Admin role.

Two gaps remain, as they do in most small teams: the finance manager can both post and approve journals, and the AR clerk handles receipts and customer statements. The compensating controls are the owner's monthly review of the Audit Trail for journals approved by their creator, and the owner receiving the bank statements directly and reviewing the bank reconciliation.

  • Owner: Admin; approves journals above the threshold, reviews bank reconciliation and Audit Trail
  • Finance manager: Admin; month-end journals, close fiscal period, reconciliations
  • AP clerk: purchases, supplier records, vouchers; no approve vouchers, no bank payment release
  • AR clerk: sales, receipts, customer statements; no rights to edit prices or give POS discounts
  • Warehouse supervisors: stock transfers and adjustments; access to their own location only
  • Payroll administrator: payroll preparation; approval by the owner
  • Outside the two Admin users, nobody can both add a supplier and release a payment

Quarterly access review

Permissions drift. People change jobs, cover for colleagues and keep the access, and temporary Admin rights become permanent. A quarterly access review catches the drift. List the users with their roles and locations, have each manager confirm their team's access in writing, and remove anything unexplained the same day. Use the Activity Log, which records logins and logouts, to find accounts that have not been used and should be disabled.

Our guide on financial controls a small business actually needs explains which controls to prioritise when a team is too small to separate everything, and our guide on the audit trail and activity log in Skyline Nexus ERP shows how to review what users actually did with the access they have.

  • List every user in the Admin role and justify each one
  • Check each role's accounting permissions: post, reverse, close fiscal period, manage settings
  • Confirm Access locations for branch staff
  • Disable users with no logins in the Activity Log for 90 days
  • Record the review date, reviewer and changes made

Common questions

What is segregation of duties in accounting?

Segregation of duties in accounting is the control that splits authorisation, recording, custody of assets and reconciliation between different people, so no one person can both create and conceal an error or fraud. Segregation of duties is applied through job design and through ERP roles that grant each user only the permissions their job needs.

How do you segregate duties in a small business?

To segregate duties in a small business with few staff, split the most dangerous pairs first, such as adding suppliers and releasing payments, and use compensating controls where splitting is impossible. Typical compensating controls are the owner receiving bank statements directly, reviewing the bank reconciliation and reviewing the journal audit trail every month.

What is a maker-checker control?

A maker-checker control requires one person to prepare a transaction and a different person to approve it before it takes effect. In Skyline Nexus ERP, journals at or above the Approval Threshold wait for approval, and the separation between maker and checker is set through role assignment rather than an automatic block, so keep approval separate from the people who prepare journals and confirm it with a monthly Audit Trail review.

Who can approve journal entries in Skyline Nexus ERP?

In Skyline Nexus ERP, submitted journal entries are approved in practice by users in the business's Admin role, which passes every permission check. Journals below the Approval Threshold are approved automatically, and amounts at or above twice the threshold need level-2 approval. Keep the Admin role small so that approval stays a separate step.

Can users be restricted to one branch in Skyline Nexus ERP?

Yes. In Skyline Nexus ERP, each user's Access locations can be set to All Locations or to specific locations under User Management, Users. A user restricted to one location sees and transacts only for that branch in the sales, purchase and stock screens, which lets one role be reused safely across branches.

How often should user access be reviewed?

User access should be reviewed at least quarterly, and immediately when someone changes job or leaves. A user access review lists every user, role and location, asks managers to confirm each one in writing, removes unexplained access and disables unused accounts. Admin-level access deserves the closest scrutiny in every user access review.

This guide is general information, not tax, accounting or legal advice. Rules differ from country to country and change over time; confirm the current position with your tax authority or a qualified adviser before acting on anything here.

Ready to run your operation on a single workspace?

Talk to us about your business

Tell us what you run and we will come back with a straight answer about fit, timeline and price.

No card, no obligation. We reply within one business day.