PracticeTrove user guide · Chapter 15

15. Security, the audit trail and your firms

Steps in this chapter (4)

4 steps, each with a screenshot · Chapter 15 of 16

The tamper-evident audit trail, signed-in devices, belonging to several firms, and read-only access for a viewer.

PracticeTrove keeps every change in an audit trail that cannot be edited or deleted, signs everyone in with two-factor, and asks partners for a fresh code before decisions that bind the firm. A login can belong to several firms, each with its own clients and roles.

15.1 The audit trail

PracticeTrove screenshot: Audit trail. Numbered orange markers point to the items described in the steps.
Figure 15.1 — Audit trail

Why

Every change: who, what and when, with the record and a description; details › shows the fields that changed (3). Filter by date, person, action or record type (2). The trail is sealed in hash-chained blocks: Verify integrity (1) checks that nothing has been altered.

Who

Owner, practice administrator, partner or viewer.

What to do

  1. Choose Audit trail in the menu.
  2. Filter, then choose details › on a line to see what changed.
  3. Choose Verify integrity (1) to check the chain.

Back to top ↑

15.2 Signed-in devices

PracticeTrove screenshot: Settings → Signed-in devices. Numbered orange markers point to the items described in the steps.
Figure 15.2 — Settings → Signed-in devices

Why

Where your login is signed in now: when, from which IP address and browser, and in which firm. Sign out anything you do not recognise (1), then change your password. This device (2) stays signed in.

Who

Everyone.

What to do

  1. Choose Settings, then Signed-in devices.
  2. Choose Sign out on a session, or Sign out all other devices (1).

Back to top ↑

15.3 Your firms

PracticeTrove screenshot: Settings → Firms. Numbered orange markers point to the items described in the steps.
Figure 15.3 — Settings → Firms

Why

A login can belong to several firms — a consultant who helps two practices, for example. Firms lists them with your role and your open work; the one open now is marked (1). Invitations to join another firm appear here too: accept only if you expected one.

Who

Everyone.

What to do

  1. Choose Settings, then Firms.
  2. Choose Open beside another firm to switch to it.

Back to top ↑

15.4 Read-only access for a viewer

PracticeTrove screenshot: Clients, as Kunle Adebayo (viewer). Numbered orange markers point to the items described in the steps.
Figure 15.4 — Clients, as Kunle Adebayo (viewer)

Why

Kunle Adebayo, the firm's director of quality assurance, has the Viewer role: he sees clients (1), engagements, work and reports, and the audit trail, but cannot change anything, and his menu has no Users & roles. The role suits an inspector or a reviewer from outside the firm.

Who

Viewer.

What to do

  1. An owner or practice administrator adds the person with the Viewer (read-only) role (chapter 3).

Back to top ↑