

THE DIGITAL GOVERNANCE CASE FILES
True stories… or almost.
Situations inspired by real-life cases that shed light on the often-overlooked risks associated with digital assets, access, licenses, and responsibilities within organizations.

CASE FILE 001
The manager code that everyone knows
When everyone uses the same manager code, who actually authorized the discount, cancellation, or refund?
In some restaurants, the same manager code is known and used by several employees to simplify daily operations. However, this code can grant access to sensitive functions of the point-of-sale system: applying discounts, canceling transactions, issuing refunds, modifying orders, or other operations normally reserved for a manager.
The practice may seem operationally efficient. However, as soon as several people use the same credentials or authorization code, it becomes difficult to determine who performed an operation, when, and with what authorization.
In an environment where transactions are recorded and where certain data can be used for accounting or tax control purposes, this lack of traceability constitutes a real governance challenge.
ASSET CONCERNED
Point of Sale (POS) system, user accounts and management access
GOVERNANCE ISSUE
Access management, traceability of operations, and privilege control
GOVERNANCE FINDINGS
Le problème n’est pas le code gérant lui-même. Le problème est l’absence d’identité individuelle derrière son utilisation.
Lorsqu’un code privilégié est partagé par plusieurs personnes, le système peut enregistrer qu’une opération a été autorisée avec des privilèges de gestion, sans nécessairement permettre d’identifier avec certitude la personne qui l’a réellement effectuée.
L’entreprise perd alors une partie importante de sa capacité d’audit et de contrôle interne.
Accès partagé = responsabilité partagée = traçabilité affaiblie.
IDENTIFIED RISKS
Insufficient traceability
It is impossible or difficult to attribute certain operations to a specific person.
Unauthorized discounts
An employee with the code can potentially apply discounts without actual manager approval.
Unjustified cancellations
Transactions can be cancelled without it being easy to establish who made the decision.
Refunds or unauthorized changes
The privileges associated with the code can allow operations with a financial impact.
Weakened internal control
The company can no longer clearly demonstrate the separation between ordinary users and those authorized to perform certain operations.
Anomalies that are difficult to investigate
When a discrepancy is discovered, the absence of individual identifiers greatly complicates the analysis of activity logs.
Compliance risk
Unusual, repetitive or insufficiently documented transactions may require further verification, particularly in the context of the obligations applicable to billing systems and the MEV in Quebec.
RECOMMENDED MEASURES
Assign individual access
Each manager should have their own credentials or authorization mechanism where the system allows it.
Limit privileges according to functions
An employee should only have access to the features necessary for their role.
Eliminate shared codes
Generic codes or codes known to the whole team should be replaced with named access codes.
Documenting the authorizations
Clearly define who can approve a discount, cancellation, refund, or significant change.
Enable and retain activity logs
Sensitive operations should be able to be associated with a user, a date, and a time.
Review access periodically
Rights should be checked during job changes, employee departures, and modifications to responsibilities.
WHAT TO CHECK IN YOUR ORGANIZATION
☐ Does each manager have individual access?
☐ Do any employees know or use a manager's code?
☐ Can discounts be associated with the user who authorized them?
☐ Are cancellations individually traceable?
☐ Do refunds require proper authorization?
☐ Do the permissions truly correspond to the responsibilities of each position?
☐ Are the access rights of former employees deactivated quickly?
☐ Do activity logs allow for the reconstruction of a sensitive operation?
☐ Are anomalies related to discounts, cancellations and refunds subject to periodic review?