More flexible "online payments" privilege
T
Theresa Hamacher
Allow full administrators to control what other admins with the "online payments" privilege can view/update with this feature.
ORIGINAL POST:
The "online payments" permission allows the user to access all features on the payment page, including updating bank account information. I would recommend making this a separate permission.
We would like to give our bookkeeper access to payment information, especially payments received. However, we would prefer that they not have the ability to change bank account info. A dishonest person could use this permission to redirect funds to a personal. Alternatively, generate an email to admins and other users with payment permissions whenever bank account information is changed.
Log In
Meredith Owens
Merged in a post:
Control concern: Specific privilege to create new payment options
T
Theresa Hamacher
I've submitted this before, and it has somehow gotten dropped, but it is a big deal from a control standpoint.
The privilege to manage payments should be split into 2 privileges:
- Create new payment options
- View payment history
By combining the 2, you make it easier for people to steal from the organization.
For instance, in our case, we have a bookkeeping firm that processes payments. Theoretically, they could create a new payment option that directs payments to their personal bank account, and then cover their tracks by creating false revenue entries is QuickBooks (since the payment system doesn't connect to the accounting system).
I urge you to think about this issue and consider how you can improve the controls. Note that this issue will become worse if specific payment types can be enabled for different individuals (making it easier to bypass the Treasurer, for instance.)
Yes, eventually they would get caught, but for a small organization, this would be devastating.
Mitch Moseley
We would love to see more than one account as we direct payments to different accounts based on what the funds are for. Being able to assign a drop down in the payment page would help also, when the user makes a payment, they can select the dropdown and pick what type of payment and it would direct the payment to the proper account.
Meredith Owens
Mitch Moseley: We are open to considering adding the ability to store multiple bank accounts and then associate a bank account with each payment option. Would you please create a new post for this request so we can collect feedback from there?