Chapter 2 Getting Started : Basic Administration : Administrators : Security Precautions : Segregated administrative roles
  
Segregated administrative roles
To minimize the effect of an administrator causing errors to the FortiGate configuration and possibly jeopardizing the network, create individual administrative roles where none of the administrators have super-admin permissions. For example, one admin account is used solely to create security policies, another for users and groups, another for VPN, and so on.
See Also
Security Precautions
Passwords
Disable admin services
Disable the console interface
Disable interfaces
SSH login time out
See Also
Idle time-out
HTTPS redirect
Change the admin username
Segregated administrative roles