
If you use Sage 100, your ERP is undoubtedly central to your daily accounting and finance activity, from transactions and reporting to payroll and vendor records. That is why its security settings deserve attention as part of your regular financial controls. Permissions can cause disruption at both ends, whether by preventing access to a user that should otherwise be authorized, or accidentally granting it to someone who is decidedly not. Access errors often develop as role responsibilities shift, headcount is added, outside support is granted access, or new reports or integrations are introduced.
For a Controller or CFO, the central question is whether each user can access only what the job requires and whether your business can see when that access changes. Sage 100 includes controls for users, roles, passwords, inactivity, security events, and data access. Finance, IT, and your ERP system administrator should review them together on a regular schedule.
Use the questions below to review your Sage 100 access and data practices alongside other finance controls:
1. Are User Accounts Current and Individually Assigned?
Start with user accounts. Each person who uses Sage 100 should have an individual account, not a shared department login. Review the list at least quarterly and whenever someone leaves your business, changes responsibilities, returns from leave, or finishes a temporary assignment. That review should also catch access that may have outlived a person’s responsibilities, including elevated rights left behind after a role change or vendor engagement. Sage 100 can set an expiration date on a user account and start and expiration dates on individual role assignments when access is needed for a defined period.
- Does every active account belong to a current employee, contractor, or support contact?
- Are former employees, inactive vendors, and old test accounts disabled so they cannot be used later?
- Does the Administrator account have documented authorized users, a backup administrator, and a defined emergency-access process?
- Can the finance team provide a current owner for each account with elevated access?
- Are third-party support and vendor accounts set with expiration dates and monitored while active?
2. Do Roles Match Actual Job Responsibilities?
Sage 100 security is role-based. Roles can control access to modules, tasks, selected maintenance functions, and security events. Set them up around the actual jobs, such as AP clerk, AR clerk, payroll processor, warehouse manager, Controller, and system administrator. Treat your ERP’s Default role with care – it grants broad access and should not become the easy fix when someone needs one additional task.
When a user has more than one role, Sage 100 applies the least restrictive permission from any assigned role. Review access across every role assigned to a person, especially when that person can add vendors, change bank or payment details, post journal entries, release batches, or alter payroll-related information. If ODBC security is enabled (it is not available in Sage 100 Premium), review access to selected tables and fields with IT.
- Have overlapping duties created access that defeats segregation of duties?
- Are Create, Modify, Remove, and View permissions appropriate for the task where those options are available?
- Are SData, ODBC, and integration permissions restricted to known business uses and reviewed with IT? If your business uses Visual Integrator, include its scheduled jobs and data export destinations in that review.
3. Are Password and Inactivity Practices Actually Enforced?
Sage 100 can require passwords for all users, with system-defined strong passwords or a specified minimum length. In Sage 100 2026, password-validation settings are enabled by default. If unified logon is in use, confirm that the Windows identity mapped to Sage 100 belongs to the intended employee and follows the company’s broader identity and password policies.
Sage 100 also includes a per-user Automatic Logoff setting measured in minutes. Sage 100 2026 adds a Maximum Hours Session Can Be Inactive field that establishes a system-wide hours limit before inactive users are logged out. Use Sage 100 inactivity settings and Windows screen-lock policies together to protect unattended workstations.
- Are Sage 100 passwords required, strong enough, and never shared?
- Does unified logon map each Sage 100 user to the correct Windows identity?
- Is automatic logoff enabled for users who leave workstations unattended?
4. Is Remote Access Protected Beyond the Application?
Sage 100 permissions protect activity within the ERP. The device, network, remote connection, server, backups, and third-party applications around it need separate controls. Finance needs a clear view of how employees, outside accountants, and support personnel reach Sage 100 when working offsite. That review should cover multi-factor authentication, managed devices, endpoint protection, patching, backup protection, and approval for outside support.
Managed cloud hosting services can strengthen infrastructure controls such as backups, patching, and monitoring, while Sage 100 roles, user access, and finance approval remain internal responsibilities. Businesses evaluating Sage 100 hosting, remote access, and continuity should define who manages Sage 100 permissions, who manages infrastructure controls, and who reviews exceptions.
- Does remote access require MFA and use an approved connection method?
- Do IT and finance agree on who owns application controls versus infrastructure security?
5. Can You See and Review Security Changes?
Sage 100 2026 adds an option to track changes in Role Maintenance and User Maintenance. When enabled, it retains additions, changes, and deletions and provides Role Audit Reports, User Audit Reports, and an Audit Viewer for authorized users. Those reports provide the most direct evidence for a periodic review of access controls.
Assign someone to review the reports and decide how long to retain audit history before using the purge utility. The Activity Log remains useful for significant operating activity, but the dedicated audit reports should be the starting point when reviewing changes to users and roles.
- Who reviews the Role Audit Report and User Audit Report, and how often?
- Is there evidence of the review for auditors, management, or internal control purposes?
- Is audit-history retention long enough for the business’s audit and control needs?
6. How Are You Managing Sensitive Data, PII, and Exports?
Your Sage 100 data protection needs to cover more than Payroll module files. Sensitive information, including personally identifiable information (PII), can turn up in employee records, vendor banking details, customer contacts, custom fields, reports, exports, emailed documents, backups, and integrated applications. Identify the data kept in Sage 100 and connected systems, then decide who needs to see it, change it, export it, or receive it.
Include customizations and user-defined fields in that review. A field added years ago for convenience may hold a Social Security number, bank account information, date of birth, or other data that does not belong in routine screens and reports. Sage 100 2026 makes this review easier by identifying tables that contain user-defined fields in User-Defined Field and Table Maintenance. Paperless Office document locations and other folders that hold exports or PDFs also need appropriate access controls. Where sensitive data must remain, limit access and exports, and check the safeguards wherever data is copied or transmitted. Privacy obligations vary by state, industry, customer contract, and data type, so involve legal or compliance advisers when needed.
- Have you mapped sensitive employee, customer, and vendor information in Sage 100, reports, integrations, and backups?
- Do custom fields, report folders, and exports expose information that routine users do not need?
- Are folders used to store Paperless Office documents and other PDFs limited to the people who need access?
- Do payment and payroll changes pair system permissions with an independent business review?
Review Sage 100 Security with SWK Technologies
A practical first step is a focused internal working session with your Controller, IT lead, and Sage 100 administrator. Export the user and role lists, run the Role Audit Report and User Audit Report if you are using Sage 100 2026 and audit tracking is enabled, identify the finance tasks with the greatest risk, and review remote access and integrations. If a 64-bit upgrade is ahead, use that work to review third-party integrations and their SData or ODBC access. End the session with a short action plan that identifies priority gaps, owners, and due dates.
If your team would benefit from help evaluating the results, SWK Technologies can assist with Sage 100 security settings, user access, connected applications, and the IT environment that supports the ERP. Contact SWK Technologies to discuss your Sage 100 security and access-control requirements.
