Ask AwraIQ about features, pricing, onboarding, login, integrations, security, demos, mobile apps, automation, reports, or support.
Blog Category
Security & Compliance
Audit readiness, access control, and data protection.
15 articles in security.
The Auditor Who Has to Be an Administrator
An external auditor asks for read access to the audit log. The smallest permission that opens it also opens settings administration — so granting the narrow thing they asked for means granting a great deal they did not, and two permissions built for exactly this govern nothing.
An Audit Trail Nobody Can Delete
Audit entries here are permanent: no administrator can remove the record of what they just did, because we took that button out. The cryptography we shipped alongside it is the interesting half; the permanence is the important one.
The Approval That Needs No Pad
The most common request we turn down about signatures is a pad on the approval screen. An authenticated, permission-gated approval written to the audit trail is already the stronger record — and adding a drawing on top of it disguises a real control as a ceremonial one.
Controller or Processor? Who Owes What Under Kenya's Data Protection Act
Four of the Act's seven operational duties are wholly yours, three are shared, and none can be discharged by a purchase. The controller and processor boundary, what belongs in a processing agreement, and the breach-notification gap stated plainly.
Kenya's Data Protection Act, Retention & Deletion: A Practical Reading
You do not need to be a data business to be a data controller — an employer with payroll already is. Where personal data actually hides, what retention means in software, and the honest limit of any product. Not legal advice.
Roles & Permissions: Deciding Who Can See What
Most access problems are ordinary people holding permissions nobody meant to give them. Designing roles around jobs, why approval must be a separate permission from action, and the quarterly review that keeps it honest.
The Audit Trail: Who Changed What, and When
An audit trail only earns its keep when somebody reads it. What a usable entry records, why exports matter as much as edits, the edit-after-approval query worth running monthly, and what a trail cannot do.
Logins, MFA & the Leaver Problem: Access That Ends When Employment Does
Two things account for most account risk in a small business: passwords one breach away from public, and accounts belonging to people who left. Why an employee record and a user account are not the same object.
Who Can Do What: Access Control When Everyone Has Been an Admin
Kenyan businesses make everyone an administrator in the first two weeks because it stops the complaints — and deletes the meaning of every other control. Getting back to least privilege without blocking work.
The Audit Trail: What Reconstructing One Transaction Actually Takes
An auditor picks one line and asks you to rebuild it. The documents, the approvals and the change history together — plus the retention trap that makes evidence expire before the obligation does.
Five Ways Money Leaves a Kenyan Business (And the Controls That Close Them)
Ghost suppliers, inflated prices, adjustments that cover a count, ghost employees, and the till. Each needs two capabilities in one pair of hands — and each has an aggregate view that exposes it in ten minutes.
The Shared Login: Why One Password for the Whole Shop Breaks Everything Else
One login per location is the most common security arrangement in Kenyan SMEs, and it turns your system from a record of what people did into a record of what a place did. Fixing identity first.
Getting Your Data Out: Exit Terms, Export and Who Stays Liable
Every term you want at the end of a vendor relationship is available before signature and none of it afterwards. No-cost export, post-termination destruction, the grace period on deletion — and where the disposal boundary actually falls.
Segregation of Duties: The Control Behind Every Clean Audit
The oldest control in the book and the one small teams quietly abandon — the four functions it splits, the dangerous combinations, and how to keep it without more headcount.
Security & Compliance: Audit Readiness for Operational Teams
Security, governance, audit readiness, role access, mobile evidence, and compliance practices for operational teams.
No articles match your search yet — try another keyword.
More topics
Browse by market instead
Each hub opens with the currency, tax and filing context for that region.
Help Center
Need a quick answer while you read?
Run inventory, procurement, assets, sales, and field work with approved AWRA guidance for setup, migration, integrations, security, pricing, and support.