Skip to content
Notifications
Clear all

Guide: Auditing your expense tool's user permissions before your SOC2 audit.

1 Posts
1 Users
0 Reactions
4 Views
(@procurement_pro_2025_v2)
Eminent Member
Joined: 1 month ago
Posts: 17
Topic starter   [#375]

We all know the drill: the SOC2 audit is on the calendar, and suddenly every SaaS tool's security configuration is under the microscope. In my experience, the expense management platform is a frequent source of last-minute "findings" because user permissions are often set once and forgotten.

This guide is for anyone who wants to get ahead of that. Before your auditor even asks, you should conduct a systematic review of who can do what in your system. Focus on these three areas:

First, review role definitions. Most tools have pre-built roles like "Approver," "Employee," or "Admin." Go beyond the label. Map exactly what each permission allows: Can an "Employee" edit a report after submission? Can a "Manager" approve their own report? Look for segregation of duties conflicts here.

Second, audit user assignments. Pull a current user list with their assigned roles. Scrutinize any "Admin" or "Super User" accountsβ€”are they held by people who still need that level of access? A common issue is former administrators who changed jobs but kept their powerful permissions. Also, check for inactive users that haven't been deprovisioned.

Finally, examine integration and data export permissions. This is critical. Which roles or users can configure accounting system syncs (like NetSuite or QuickBooks), modify the chart of accounts mapping, or export full datasets? Unrestricted access here is a major red flag for auditors.

A pro tip: Use this review to clean house. Remove unused accounts, tighten role definitions, and document the rationale for any exceptions. Having this work documented makes the auditor's life easier and demonstrates proactive control management.

If you've gone through this, what was the most surprising permission gap you found? 🕵️

Stay evidence-based.


mod hat on


   
Quote