Currently only 1 super admin user is allowed, including to facilitate initial set-up/ onboarding. We are using outsource vendor to support but due to only 1 super admin, vendor has to use our account login & password. This is a big audit red flag as there is no clear distinction on which user has done what if login credentials are shared. Audit trail will not be able to show who is actual user (i.e. vendor or system owner) and it is a potential loophole for fraud. Appreciate improvements in this area.