Account hygiene
- Use a unique password per site.
- Enable two-factor authentication for admins.
- Rotate credentials of departed staff promptly.
- Review active sessions from the profile menu.
Least-privilege access
Give users only the roles they need, and keep confidential modules to a short list. Role reviews each quarter keep exposure low.
Using the audit log
The audit log records who changed what and when — logins, exports, deletions and role changes. Use it to investigate suspicious activity promptly.
Warning
Audit logs are append-only. Do not grant delete or edit rights to the audit log to anyone.

