Chapter 10 Install and System Administration for FortiOS 5.0 : Basic Administration : Administrators : Security Precautions : Segregated administrative roles
  
Segregated administrative roles
To minimize the effect of an administrator causing errors to the FortiGate configuration and possibly jeopardizing the network, create individual administrative roles where none of the administrators have super-admin permissions. For example, one admin account is used solely to create security policies, another for users and groups, another for VPN, and so on.
See Also
Security Precautions
Passwords
Disable admin services
Disable the console interface
Disable interfaces
SSH login time out
Administrator lockout
Idle time-out
Administrative ports
Change the admin username and password
Segregated administrative roles