Reviewing employee access to member balances: List every role with balance access and confirm each is still needed.; Use individually attributable accounts and multi-factor authentication for sensitive access.; Sample manual adjustments and match each to a case, operator, time and outcome.
Image: Loyalty Marketing Guide

Loyalty Fraud

Part of Loyalty fraud and abuse

Reviewing employee access to member balances

Audit who can view or change loyalty balances, review sensitive actions and remove permissions that staff no longer need.

List every role that can view a member balance, change it or issue a reward. Check whether each permission is still needed. Balance changes need tighter control than viewing. Every sensitive action should be attributable and explainable.

Map permissions to tasks

A store associate may need to check reward availability. A support agent may need transaction history to resolve a complaint. A programme administrator may need to correct a balance after an approved case. These tasks do not automatically require the same access.

ActionReview question
View balance or historyIs the view needed for this role and limited to relevant records?
Add or remove pointsIs a case reason required, and can the operator approve their own adjustment?
Issue, cancel or restore a rewardCan a reviewer trace the resulting member and ledger record?
Export member dataWho can request, create and receive the file?

Include temporary and agency staff, service accounts, vendor access and shared till logins. A shared login that cannot identify the operator weakens the audit trail. Check which permissions the actual platform and identity provider can separate; systems vary.

Revalidate access

Compare user accounts with current staff duties. Remove access left after a transfer or departure. Recheck elevated access regularly and after role changes.

Use individually attributable accounts and multi-factor authentication for sensitive staff access where the platform or identity provider supports it. Where the platform allows it, keep privileged access separate from ordinary user accounts and tie it to authorised duties.

For rare corrections, use a defined approval route and a separate privileged account where applicable. Keep an emergency process with a later independent review. Avoid giving an ordinary user account broad privileges simply for convenience.

Review what staff did

Sample manual credits and debits, reward issues, exports and unusual member-record views. Match each action to a case, operator, time and outcome. Repeated adjustments or a cluster of actions under one account warrant a check, but can also reflect legitimate incident work.

Preserve original ledger entries and post a separate correction when needed. If a review suggests unauthorised access to personal information, involve the privacy or security response owner. Entities with obligations under the Privacy Act must comply with the Notifiable Data Breaches scheme; the OAIC provides guidance to help assess whether a data breach needs to be notified.

End the review with owners for permission changes, known platform limits and follow-up dates.

Key compliance and security metrics

Audit frequency
Quarterly
Mandatory breach notification threshold
If likely to result in serious harm
Multi-factor authentication requirement
For all privileged access
Shared login risk
High – weakens audit trail

More from Loyalty Fraud

Loyalty Fraud

Loyalty fraud and abuse

Map loyalty abuse risks across signup, earning, redemption and staff access, then investigate unusual activity without treating alerts as proof.