Start with named identities
Shared accounts remove accountability from registration logs. Give every user and administrator an individual identity and every integration a separate service account with limited permissions.
The 8.5.4 platform expands authentication controls, including access periods, temporary blocking, configurable second-factor codes and more detailed rights-change records.
Align roles with process
Grant permissions for job operations rather than copying a colleague’s role. Separate high-risk functions and connect hiring, transfer, contractor expiry and termination to access review.
Protect the full environment
The security boundary includes application and database servers, web publication, backups, exchange folders, clients and administration tools. Use TLS, network restrictions, protected identities and failed-login monitoring. Certified protected editions may support regulated systems, but certification does not replace system design and operating controls.
Make audit actionable
Select events that will actually be reviewed: administrator access, role changes, bulk export, logging changes and suspicious master-data edits. Assign an owner and response time to every alert.

