Skip to content
HNROS Help Center
English
Start free
Contents1. What do the three layers do?2. The whole story of one document: the Document File3. Security gates — six stoppers3.5 The administrator decision now comes from the server3.6 What a permission refusal tells you4. How to open a gate5. Anomalies — not an accusation, a place to look6. A ten-minute weekly routine7. Four new gates (2026-09): single signature, automatic period lock, CoC lot requirement, automatic lot pattern8. Role templates and permissions taking effect on open sessions immediately9. Login errors come in three classes: identity, throttle, load10. Staff portal: login throttle and unlockingSecurity classification and need-to-know

Help › Audit, Gates & Anomalies

Audit Trail, Security Gates and Anomalies

This guide covers three separate layers of defence. In short: the first one records, the second stops, the third shows. Each is useful on its own, but their real strength appears when they are used together.

⏱ How long does it take?

Sections 1–2 are what every manager should read: ten minutes. If you are going to switch gates on, read sections 3–4 too.

1. What do the three layers do?

What separates an accident from an abuse is intent, and no software can see intent. That is why the system answers three separate questions separately:

Layer The question it answers Where
1 · Audit trail Who did this, when, and from which machine? Management → Audit → Search
2 · Security gates Should this have been possible at all? Management → Audit → Security gates
3 · Anomalies What looks normal on its own but is not? Management → Audit → Anomalies

2. The whole story of one document: the Document File

On invoice, order, quote, delivery note, voucher and cheque-bordereau screens — if you are signed in as a manager — you will see a Document File button. One click opens that document's entire story:

⚠ Numbers get reused

HNR can hand out a deleted document's number again. That is why the Document File matches the trail not by number alone but by the document's own timestamp. Distant matches are shown in a separate number history block — do not confuse the two.

3. Security gates — six stoppers

Every gate is off by default. Nothing stops by itself for a company upgrading to a new version; switching a gate on is a deliberate decision. Every gate has an escape, and it is always printed on screen — a gate whose escape is invisible gets switched off wholesale at the first complaint.

Gate What it does / why it exists Escape
Period lock Prevents adding documents to a month whose tax return has already been filed. A manager can pass (this too can be switched off).
Delete threshold Let small mistakes be fixed; make large documents pass a second pair of eyes. A manager can delete any amount.
Voucher ceiling Large cash movements should not happen on a single signature. A manager writes without limit.
Scrap tolerance Scrap is the easiest place to hide missing goods. An explicit approval is added to the confirmation; the approver is recorded.
Cost lock Typing a cost by hand is the shortest route to making the profit report say what you want. It can be set to manager-only; in the closed mode only the calculated cost counts.
New account approval An invoice to a made-up customer is a receivable that will never be collected. Editing existing accounts is always free.
💡 Advice for a small business

In a one-person business, switch nothing on; "no gate is open" on the screen is not a shortcoming. When a second employee joins, open the period lock first, then the delete threshold. The others go on only if that line of work truly needs them.

3.5 The administrator decision now comes from the server

The question of whether a user is a system administrator used to have two possible answers: the server's answer and the screen's own interpretation. Because both sides read the same permission bits separately, they could — rarely — diverge: the button showed, the action was refused. Now there is a single answer: as you sign in, the server settles "is this user an administrator" itself and states the verdict to the program explicitly. The screen reads that verdict and does not interpret anything on its own.

🔑 What changed in practice?
  • Consistency: What you see and what you can do no longer diverge. If you can see a button, the server also counts you as entitled to that job.
  • Immediate effect: When your administrator changes your rights, signing out and in once is enough; the program refreshes the verdict from the server at startup.
  • What has not changed: Visibility is still only decoration. The real gate is on the server — hiding a button is not a permission; removing a permission is.

3.6 What a permission refusal tells you

When an action is refused the program no longer just says "you are not authorised"; it names the permission that is required. That lets you go to your administrator with "could you turn this permission on" instead of "something is not working" — and the fix takes minutes. The message always follows the same shape:

The message you see What actually happened What to do
"This action requires the '…' permission or system administrator rights." Your session is valid but the permission bit for that job is off Tell your administrator the name inside the quotes — it is enabled from Settings › Users
"This action requires system administrator rights." This job is not gated by a bit but reserved for administrators (user management, HR, quality, warehouse definitions…) Hand the job to an administrator; no partial permission opens it
"A session is required: … you must be signed in to WebOS." Not a permission problem: your session has expired or was never opened Sign in again; nothing is lost, retry the action
💬 If you say "I can see the button but it does not work"

Instead of refreshing the screen, read the message and pass it on verbatim. The permission name inside it is the one clue your administrator can find without searching. If you are on an old session (the program has been open for days) signing out and in once may also be needed — on sign-in the program takes the administrator verdict from the server again.

4. How to open a gate

  1. Open the Management window → Audit tab → Security gates.
  2. Read the gate's description and its Escape line. If you cannot explain the escape to your team, do not open that gate.
  3. Enter the value (a date, a number or a choice) and press Apply. An open gate turns amber and the header says "1 gate open".
  4. If you change your mind, Close returns the setting to its default; no record changes, only the gate closes.
⚠ A typo will not stay silent

The system only accepts setting names it knows. A misspelled setting would silently do nothing while the company believes the gate is on — so an unknown name is rejected and the valid names are listed.

5. Anomalies — not an accusation, a place to look

Deleting an invoice is normal. Issuing a new invoice for the same account on the same day for a similar amount is normal too. The two happening back to back is not. This screen shows exactly that class of event — four views:

⚠ A count is not a finding

The numbers on this screen count rows to look at. A non-zero count does not mean there is a problem, and a zero does not prove everything is fine. Every row may have a perfectly good explanation — a wrong invoice was corrected, two branches bought the same item, a subscription costs the same every month.

6. A ten-minute weekly routine

  1. Open the Anomalies tab and look at the four badge counts. Any jump compared with last week?
  2. In same-day delete-and-rewrite, open the rows where "same person = yes" and the difference is negative. Read the story with the Document File button.
  3. In duplicate purchases, look only at rows where "document no is the same"; the rest is usually regular buying.
  4. If you find something, ask the person involved — the system does not judge, you do.
  5. If you must send the list to your accountant, use the CSV button; the "this is not an accusation" note travels with the file.

7. Four new gates (2026-09): single signature, automatic period lock, CoC lot requirement, automatic lot pattern

You will see four new rows on the same screen (Management › Audit › Security gates). The rule is unchanged: all off by default, each with an escape and a trace, changed only by the system administrator.

Gate What it does / why it exists Value, escape and trace
Single signature (depo.dort_goz_tek_imza) Whoever opens a transfer instruction cannot approve it (four eyes). With a single manager in the company this rule deadlocks work. With the gate on, that lone manager may approve his own instruction. kapali | acik. If another manager exists the setting is NOT applied (they are the second signature). When applied, a "TEK_IMZA" trace in the notes plus a separate Audit-trail row.
Automatic period lock (mali.donem_kilidi_otomatik) On day N of every month the previous month locks by itself; no more "we forgot to set the lock" after the tax return. 0 = off, 1–28 = day of month. The lock date written is the 1st of the month (that day open, earlier closed). A lock moved forward by hand is never pulled back. Every run posts an announcement to managers + an audit record; manual rollback: mali.donem_kilidi.
CoC lot requirement (kalite.coc_lot_zorunlu) On a card where a certificate is mandatory, a CoC check without a lot number gives a "general" answer. With the gate on, a lotless query is refused. kapali | acik. Off: the response carries a "general check — not lot-based" warning; on: LOT_GEREKLI. Details: Quality guide.
Automatic lot pattern (depo.otomatik_lot_kalibi) When a lot-tracked card is received on a purchase invoice without a lot number, the program opens a lot with this pattern. Text, at most 60 characters; placeholders {belgeNo} {sira} {kod} {tarih} {depo}; {belgeNo} is mandatory. Default "{belgeNo}-{sira}". Details: Warehouse guide.

8. Role templates and permissions taking effect on open sessions immediately

When creating a user you now pick a role template (sales, purchasing, warehouse, production, quality, finance, accounting, HR, planning, management) — the era of "clone the warehouse clerk, then flip bits one by one" is over. How to use it is in the Settings guide. Two rules matter for security:

  1. No template contains the system-administrator bit. Administrator rights are always granted by hand and deliberately; even the "management" template does not open the Management cockpit.
  2. A permission change takes effect on open sessions immediately. Users used to have to log out and back in; now, the moment the administrator saves, that user's open sessions are refreshed transparently — the session does not drop, a page refresh is enough. If a user's password is changed their open sessions drop (they log in with the new password) — expected and safe.

Permission by invoice kind: return invoices are issued with the bit of their own commercial area — sales return faturacikis, purchase return faturagiris. A permission refusal now always arrives as 403 and names the required right (some paths used to show a "server error" 502). Details: Purchasing guide.

9. Login errors come in three classes: identity, throttle, load

Not every refused login is "wrong password". Read the message:

Code Message What to do
401 User name or password is wrong Your mistake; after the third attempt each wrong login adds a growing delay (up to 2 s).
429 Too many attempts — wait The login throttle. Only wrong logins count; colleagues logging in correctly from the same network do not trigger it. Wait a minute.
503 Server busy: concurrent session ceiling reached / cannot connect to the HNR server Not your fault, and it does not count towards the throttle. When the session ceiling is full, idle sessions are swept first; if there is still no room, retry shortly. If it persists, tell the administrator.

Attachment upload: when many files are being scanned at once you may see "File scan queue full — try again shortly" (503); your file was not rejected, it just was not queued. Upload again a few seconds later.

10. Staff portal: login throttle and unlocking

The portal has two separate protections. (1) IP throttle: too many wrong PINs from the same address in a short time gives "Too many attempts — wait 1 minute" (429). Correct logins do not count; fifty people logging in from the same factory network at shift change do not trigger it. (2) Account lock: 5 wrong PINs for the same personnel number → 15-minute lock. The only way to unlock used to be changing the PIN; now an HR manager unlocks without waiting via "Unlock" (for now via the API, a screen button comes in a later round: POST /api/ik/portal/kullanicilar/<seq>/kilit-ac); the action is logged. Details: HR guide.

🔗 Related guides

The Print button at the top right produces an A4-friendly version. Related guides: Cockpit, Settings and Log, Archived Records.

HNR Help Center · Audit, Gates and Anomalies · This page is updated together with the program. Report anything missing or wrong to your system administrator.

Security classification and need-to-know

For companies working in defence, file attachments and projects are filtered by security classification: public < internal < restricted < secret. A user without the clearance does not even see the record IN THE LIST, because the existence of a document is itself information. This gate has no visible escape and every refused access is written to the access trail. Detail: Defence Traceability → Need to know.