Auditors ask who can change orders and who can release non-conforming goods. IT opens an "auditor" account overnight and the demo path runs smoothly. Ask for daily accounts and three months of logs—they cannot produce them. Customer audits of system permissions look for controls that exist every day, not only on audit day. Temporary access cannot fill daily gaps; gaps get recorded as system defects.
The permission model must exist before the audit: roles, least privilege, offboarding closure, extractable logs.
Daily Accounts Are the Evidence
Positions map to roles; sensitive actions use dual control; release and order changes leave traces. Auditors use read-only roles on real menus—not demo menus built for them. Spot-check modification history on a shipment document—it must open. If it does not, control does not exist.
- Shared accounts are forbidden—audits fail here most often.
- If temporary accounts are required, set start/end times and audit flags—they cannot become daily use.
- Maintain the permission matrix with org structure; change roles the day someone transfers.

Treat Audits as Spot Checks, Not Performances
The XYN digital intelligence system trims foreign-trade and quality actions by role; logs replay by document. Before the audit, spot-check yourself: pick a departed employee and a changed order. If you fail your own check, you fail the customer. Pass it, and temporary accounts are no longer needed.
Post the permission matrix on the wall before it lives in the system. What the system lacks, the wall cannot cover.
