Services

Access, change, and exception controls

We review user roles, change tickets, and override behaviour so that a published dashboard figure can be tied to an accountable person.

Two colleagues discussing papers across a table

A dashboard application is only as trustworthy as the people who can change it. We look at who may upload files, edit security masters, change return settings, and push a view to the committee pack. Shared logins and undocumented “break-glass” users are recorded as findings.

Overrides deserve special attention. Many applications allow a user to pin a price or suppress a transaction so that a tile “looks right” for a meeting. That may be legitimate. It is not legitimate if the override leaves no trail, no expiry, and no second reviewer.

We also sample change records for mapping tables and calculation settings. A mapping that was edited the night before a quarter-end is not automatically wrong, but it should be explainable.

Request this work