Add user security levels to payment batches so that payment batches can't be edited by all users.
Currently, WIPP and Direct Withdrawal payment batches can be edited by anyone once the batch has been created/downloaded into Edmunds.
Someone could then employ a technique called kiting to replace cash collections with a WIPP or Direct Withdrawal transaction.
This is a weakness with any payment batch that can be edited once it has been created.
User Security that would associate a batch with a user and prohibit editing by anyone other than the initial user and, allowing only a management level security to edit WIPP, Direct Withdrawal and Check Aggregation Batches would strengthen this internal control weakness
