Hey folks,
I'm wondering if anyone has experience locking down EFT (orchidsystem)?
We have things restricted so that the normal accounting operator can generate the NACHA files but cannot add nor edit bank accounts. The file is dropped into a server directory by the EFT module and then a separate user (executive) uploads the file to our bank and a second exec approves them[note that these guys aren't going to read through a NACHA file to confirm destination account numbers as the volume is to high]. The issue I'm facing is that the user who runs the EFT module and creates the NACHA files also must have the ability to write files into the EFT output directory... thus they could in theory hand build a file with their own account information in it.
Have you worked around this issue? Orchid has not been great at supporting me ("Our website is for Accpac dealers only") - I don't have access to their KB so I thought I'd give it a shot here.
thanks!
I'm wondering if anyone has experience locking down EFT (orchidsystem)?
We have things restricted so that the normal accounting operator can generate the NACHA files but cannot add nor edit bank accounts. The file is dropped into a server directory by the EFT module and then a separate user (executive) uploads the file to our bank and a second exec approves them[note that these guys aren't going to read through a NACHA file to confirm destination account numbers as the volume is to high]. The issue I'm facing is that the user who runs the EFT module and creates the NACHA files also must have the ability to write files into the EFT output directory... thus they could in theory hand build a file with their own account information in it.
Have you worked around this issue? Orchid has not been great at supporting me ("Our website is for Accpac dealers only") - I don't have access to their KB so I thought I'd give it a shot here.
thanks!