Back to blog
Security & Access9 min read

Strengthen Internal Control With Access Granted by Role

Stop insider data leaks in your core business system. Learn how role-based access, passkey login, and IP limits protect Japanese firms today.

by Kikan System TeamPublished EN/JA

It is 7:40 on a Monday morning in Nagoya. The accounting lead opens the new ERP to post month-end journal entries and notices something odd. A sales rep, three weeks from his last day, exported the full customer master on Friday at 9:12 p.m. Nobody approved it. Nobody was even copied. The data is already sitting in a personal cloud drive.

That is not a hacking story. It is the most common breach shape in Japan today, and it almost never starts with a stranger. It starts with an employee who had more access than the job required.

A core business system that grants access by role exists to make that Friday-night export impossible in the first place. This article walks through what role-based permissions actually do, why the Japan market treats them as non-negotiable in 2026, and how a mid-sized manufacturer can put the controls in place without slowing the work.

The Scene Nobody Wants to Repeat

Picture a precision parts maker in Higashi-Osaka, about seventy staff, revenue near 1.8 billion yen a year. The company runs its books, sales orders, purchase orders, inventory, and timesheets in one shared system. For years, access was simple. Everyone got a full account. The thinking was practical. Small team, trusted people, no time to manage permissions.

Then a senior salesperson resigned to join a competitor. Two weeks after he left, the company learned he had pulled the complete quotation history, pricing margins, and the supplier list for the company's highest-margin product line. There was no log of intent. There was no approval step. There was only a generic login that could see and export everything.

The cost was not just the lost deals. The company spent eleven million yen on lawyers, forensic review, and customer notification. Three key customers asked for written assurances. One moved a portion of its orders elsewhere. The real damage was trust, and trust is the slowest thing to rebuild.

This is the gap that access granted by role closes. It replaces the idea of trusted people with the practice of least privilege. Each person gets exactly the access their job needs, and nothing more.

What Role-Based Permissions Actually Do

A modern core business system models access as a grid. Down one side are the things a person can touch: customers, products, inventory lots, journal entries, budgets, sales orders, purchase orders, manufacturing orders, expense claims, approval requests. Down the other side are the actions: view, create, edit, delete, export.

A role is a saved answer to that grid. An accounts payable clerk role might allow view and create on bills, view on the chart of accounts, and nothing at all on sales quotations. A warehouse lead might get full control on inventory movements and shipments but no visibility into journal entries or budgets. A sales rep can edit their own quotations and export nothing without an approved reason.

The mechanism in Kikan System reads from a real permission map stored on each role. Every screen and every operation carries a requirement, and the system checks the requirement against the role before the action runs. If the role does not grant that specific action on that specific resource, the request is refused. There is no partial credit and no override by default.

Three properties make this work in practice.

First, the check is fine-grained. It is not all-or-nothing per module. The accounting reports layer, for example, treats each report as its own resource. A manager can read the trial balance but be blocked from the detailed general ledger, or allowed to export the income statement but blocked from exporting the balance sheet. That precision matters when you are preparing for a J-SOX review or a customer security questionnaire.

Second, the check is enforced at the operation, not the menu. Hiding a button is decoration. The real control is that the underlying action refuses to run for a user whose role does not permit it. A determined employee cannot reach a restricted record through a saved link or an export job.

Third, the matrix is yours to shape. Kikan System ships with seeded system roles you cannot rename or delete by accident. Around them you build the roles your organization actually uses. You set who can view, create, edit, delete, and export across more than ninety resource areas, from CRM leads and manufacturing orders to tax settings and approval workflows.

A Realistic Day at the Higashi-Osaka Maker

Walk through how the same seventy-person company runs once the controls are in place.

The new sales hire logs in on her first morning. Her role grants view and create on quotations, view on customers, and nothing on the chart of accounts or budget screens. She can draft a quote for a prospect. She cannot see what the company paid for the parts, and she cannot export the customer list to her laptop.

The warehouse lead opens a transfer order between the main plant and the satellite warehouse in Gifu. His role allows create and edit on inventory movements and shipments. When a lot is recalled for a quality issue, his lot traceability view shows exactly which customers received the affected batch. He cannot, however, post the scrap write-off to the ledger. That requires an accounting role, and the system blocks the attempt at the source.

The accounting manager reviews month-end. She has full access to journal entries, closing runs, and the report layer, including the trial balance, income statement, and balance sheet. She approves the expense reimbursement that a field engineer filed on the road. Because the approval routes through the built-in approval workflow, the request, the approver, and the timestamp are all recorded together.

At 6:30 in the evening the departing salesperson tries one last export of the pricing sheet. His role never had export rights on quotations. The system returns a clean refusal. No alert fires, no drama, no forensic bill. The control simply did its job.

The Safeguards Around the Roles

Strong roles are only half the picture. The other half is the scaffolding that keeps the roles honest. Kikan System builds several of these in, and each one answers a question an auditor will eventually ask.

Who changed a role, and when? Every role record carries the creator and the last editor, with timestamps. If someone widens a sales rep's export rights the night before they leave, that change is visible and attributable. You are not relying on memory.

Can a single mistake lock out the whole company? No. The system protects the last administrator role. You cannot delete the final admin role, and you cannot strip admin privileges from the last remaining one. A tired click cannot lock out the whole company.

Are seeded roles safe from drift? Yes. System roles are flagged and shielded. They reject rename and delete attempts. Your baseline controls stay intact even as people come and go.

Does a concurrent edit corrupt a role? No. Each role carries a version counter. If two people edit the same role at once, the second save is rejected with a clear conflict rather than silently overwriting the first. Permissions are too important to lose to a race condition.

Is each company's data actually separate? Yes. Each company keeps its data fully isolated. A role in one company has no path into another company's records. This is what makes the model safe for group companies and for service providers running multiple clients.

Why Japan Treats This as Non-Negotiable in 2026

Two forces are pushing role-based access from nice-to-have to baseline requirement for Japanese firms.

The first is the supply chain pressure. Large manufacturers and trading houses now send security questionnaires down to their SME suppliers, and access management is always on the list. If you cannot show that a resigned employee's access was scoped and revoked, you can lose the contract. Roughly 70 percent of Japanese SMEs report that they do not manage information security in an organized way, according to the IPA 2024 survey of 4,191 small and mid-sized enterprises. That gap is exactly what customers are starting to audit.

The second force is the steady drum of insider incidents. In its 10 Major Security Threats 2024 report, IPA ranked internal fraud and improper access causing information leakage among the top threats for the ninth year in a row. Tokyo Shoko Research counted 189 personal information leakage incidents at listed companies in 2024, a record high, affecting about 15.86 million individuals, with unauthorized access and virus infection behind roughly 60 percent of cases. The pattern is clear. Once an attacker or a disgruntled insider is inside, the damage scales with how much they can reach.

Layer on the practical realities. The 2025 legacy cliff is pushing firms off unsupported accounting and sales tools onto a single core business system. The qualified invoice system and multi-rate consumption tax rules mean more financial data flowing through one place. Succession planning means founders handing the keys to a next generation that needs structured, not tribal, controls. The labor shortage means more contractors and part-time staff touching the system, each with a different need-to-know.

Access granted by role is the answer to all of these at once. It is the difference between handing someone the master key and handing them the key to one room.

What Is Manual Today, and What Is on the Roadmap

Honesty matters here, because overselling controls is how firms get burned. Kikan System handles a great deal automatically, and there are places where the human step still does the work.

What the system enforces for you. Role creation and editing with a validated permission grid. Refusal of actions the role does not grant, enforced at the operation. System role protection, last-admin protection, optimistic locking, and full attribution of who changed what. Passkey and passwordless login so staff are not reusing weak passwords. IP restrictions that limit where the system can be reached from. Token revocation and inactive account blocking, so a departed employee's session dies the moment their account is turned off. Approval workflows that pair a request with its approver and timestamp.

What is still a manual discipline. There is no single immutable audit-log table that captures every read of every record. For a full forensic trail, you combine the role change history, the approval workflow records, and the login records, and you keep your offboarding checklist tight. Multi-currency and exchange-rate handling is not built, so firms operating across currencies still reconcile that outside the ledger. Certified storage under the electronic bookkeeping preservation law is not in scope, so regulated record retention still relies on your existing archival process.

The point is not that the system is incomplete. The point is that the controls that matter most for stopping the Friday-night export, scoped roles, enforced refusals, passkey login, IP limits, and clean approval trails, are real and working today. The rest is roadmap, and we will say so plainly when you ask.

Frequently Asked Questions

Will locking down access slow the team down?

Almost never, because least privilege is about removing what you do not need, not adding friction to what you do. A sales rep who only ever drafts quotations loses nothing when quotations are the only thing she can touch. The visible friction is one moment of refusal when someone tries something outside their role, and that refusal is usually the control earning its keep.

Is role-based access only for companies facing formal internal control reviews?

No. Larger listed firms need formal internal control documentation, and role-based access gives them the structure to document. But the Friday-night export hurts a seventy-person maker just as much as it hurts a listed group. The controls scale down. A smaller firm simply defines fewer roles, and Kikan System ships seeded roles so you start from a safe baseline rather than a blank slate.

How hard is it to migrate from a current free-for-all setup?

The honest path is in phases. Start with the seeded roles, then map your real job functions to a short list of five to eight roles. Assign people, then tighten the export permissions last, because export is where most of the risk and most of the resistance live. Expect two to four weeks of tuning for a mid-sized company, and you can model it on the free plan for up to 2 users, no credit card required.

What happens when someone leaves?

Turn off the account. Token revocation kills active sessions, the inactive flag blocks new logins, and the scoped role means there was never broad data sitting on a personal device to begin with. Offboarding becomes a one-step action instead of a damage hunt, because the person only ever had the keys to one room.

Can a single admin mistake lock out the whole company?

No. The system protects the last administrator role, so you cannot delete the final admin role or strip admin privileges from the last remaining one. A tired click cannot lock out the whole company, and seeded system roles are shielded from accidental rename or delete.

Key Takeaway: Access granted by role turns security from a question of trusting people into a question of designing the system. The right design makes the breach impossible, not the employee trustworthy.

Take the Next Step Toward Clean Controls

If the Friday-night export scenario made you wince, that is the signal. Your core business system should never hand a sales rep the keys to the general ledger, and your offboarding should never end in an eleven-million-yen forensic bill.

Kikan System gives you role-based permissions enforced at the operation, passkey login, IP restrictions, approval workflows, and full attribution of who changed what, all with each company's data kept fully isolated. You can stand up your first set of roles in an afternoon and tighten them over the following weeks as you learn where the real boundaries are.

Start on the free plan, up to 2 users, no credit card required. See /#get-started to begin, or review the tiers at /#pricing.

When your largest customer sends the security questionnaire next quarter, you will have an answer that is true, documented, and already in production.

-> Related: J-SOX Internal Controls and Approval Workflows

-> Related: Choosing a Core Business System in 2026

Related articles

Ready to Get Started?

Start free with up to two users and no credit card. Bring your biggest month-end headache, and we'll show you what the first 30 days look like on Kikan System.

Start free