Security Settings

Finger Manager provides account and back-office access security settings to help institutions establish unified login protection, identity verification, and sensitive-operation controls.

Institutions can apply security restrictions to administrators, staff accounts, and system access behavior according to internal security policies.

Finger Manager 后台(系统设置) 后台管理

Notifications configured in Finger Manager can be delivered precisely inside Finger Trader App according to rules, audience, and schedule.

Purpose of security settings

Security settings protect Manager login, administrator accounts, staff accounts, sensitive operations, API and system access, internal organization permissions, and high-risk operation workflows.

By configuring security policies in one place, institutions can reduce risks caused by account takeover, credential leakage, unauthorized access, and accidental operations.

Login security

Institutions can configure login-related security rules, such as password requirements, failed-login limits, abnormal-login detection, multi-factor authentication, session management, device verification, and login-state expiry.

For back-office accounts with elevated permissions, stricter identity verification is recommended.

Multi-factor authentication

Finger Manager can use additional identity verification mechanisms to improve login security.

After multi-factor authentication is enabled, the user must complete an additional verification step after normal login credentials before entering Finger Manager.

For example: account credentials -> second-factor verification -> verification passes -> enter Finger Manager.

Recommended roles Super administrators, organization administrators, finance staff, risk staff, API administrators, and employees with sensitive-data access.

Session management

The system can manage login sessions to reduce security risks caused by long-lived login states.

Depending on institutional policy, settings can include session validity period, automatic logout after inactivity, login-state expiry, forced re-login, and abnormal-session termination.

For shared devices or high-security environments, shorter session validity is recommended.

Sensitive-operation protection

Some high-risk operations can require additional security verification or stricter permission restrictions.

Examples include changing account permissions, creating or deleting administrators, changing API configuration, changing fund-related settings, changing security policy, changing notification and callback addresses, changing whitelists, and exporting sensitive data.

Institutions can combine roles, permissions, and security settings to further protect these operations.

Abnormal-account handling

When the system detects abnormal access behavior, it can use the configured security mechanisms to respond.

Examples include repeated login failures, abnormal IP login, new-device login, long abnormal sessions, high-frequency sensitive operations, and abnormal permission usage.

Depending on configuration, the system can require re-authentication, restrict login, terminate sessions, or apply other security actions.

Working with the permission system

Security settings can work together with Finger Manager's organization, role, and permission system.

The permission system decides who can do what. Security settings decide under what security conditions the action can be performed.

For example, an employee may have API management permission, but changing API configuration can still require additional identity verification.

Combining the two mechanisms creates a more complete back-office security control model.

Security recommendations

Administrator protection Enable multi-factor authentication for administrator accounts and avoid sharing one back-office account across multiple people.
Least privilege Assign only the minimum permissions required by each role and review administrator and staff accounts regularly.
Account lifecycle Disable access promptly for departed or suspended staff accounts.
Access boundary Use IP whitelists where appropriate to restrict back-office access scope.
Audit review Review login records and operation logs regularly, and protect API keys and other sensitive credentials carefully.

Notes

Finger Manager provides system-level security configuration and access-control capabilities.

The specific configurable items may vary depending on enabled product modules, account permissions, and deployment model.

Institutions should configure security policies according to internal information-security rules, compliance requirements, and IT management policies.

Security Settings define the access-protection baseline for Finger Manager.

Together with organization, role, permission, IP whitelist, login records, and operation logs, they help institutions build a controlled and traceable back-office environment.

  1. The administrator sets password requirements, failed-login limits, anomaly detection, MFA, session expiry, and device verification.

    Finger Manager can apply a consistent login-security baseline to back-office access.
  2. High-risk operations such as permission changes, administrator creation, API updates, callback changes, whitelist changes, and sensitive exports can require extra verification.

    Role permissions decide who can perform an action, while security rules define under which conditions it is allowed.
  3. Administrators can use login records and operation logs to review abnormal IPs, new devices, repeated login failures, and high-frequency sensitive operations.

    Security configuration and audit logs form a traceable access-control workflow.