---
title: "External User Groups in \"Accounting for Kazakhstan 3.0\": How to Grant Access to Clients and Counterparties"
country: KZ
lang: en
author: Сапа Т.И. (https://buhgpt.kz/authors/sapa-ti)
date: 2026-09-23
canonical: https://buhgpt.kz/suraqtar/gruppy-vneshnih-polzovateley-v-buhgalterii-dlya-kazahstan-en
source: BuhGPT
---

# External User Groups in "Accounting for Kazakhstan 3.0": How to Grant Access to Clients and Counterparties

> **TL;DR:** Verified on release 3.0.74.2 "Accounting for Kazakhstan" (edition 3.0). You have set up several external users in the database — for example, a representative of a client whose accounting you handle, and an auditor who logs in once a quarter to review the reports. Each needs r

---

Verified on release 3.0.74.2 "Accounting for Kazakhstan" (edition 3.0).

You have set up several external users in the database — for example, a representative of a client whose accounting you handle, and an auditor who logs in once a quarter to review the reports. Each needs rights assigned: the client — only their own documents, the auditor — view everything. Configuring access for each one separately takes a long time and is easy to get wrong. This is where you open "Groups of external users": you gather people into a group and assign rights once — to the entire group at once.

An important clarification right away, so you don't look for the wrong thing. This is not an accounting document, although in the service name you may encounter the prefix "Document". Technically it is a catalog from the Standard Subsystems Library (SSL). Therefore it has no postings, no VAT, no ESF/SNT, and no printable forms in the accounting sense. It manages only access. Below I will honestly analyze what it actually does, and I will not insert tax figures here — there is nowhere for them to come from.

1. Purpose

A group of external users is a way to combine several external users (clients, counterparties, auditors, contractors) and assign them access rights collectively rather than individually. Rights are granted to the group, and the members inherit them automatically.

2. Where to find it

First, the external users mechanism must be enabled (by default it is often disabled):

Administration → User and rights settings → "External users" checkbox.

After enabling it, access to the lists appears:

Administration → User and rights settings → External users → Groups of external users.

The "Create" button — a new group. "Create" inside a member's card — add to the composition.

1C navigation link. You can open the list directly via "Tools → Go to navigation link":

- Working link for the catalog: e1cib/list/Справочник.ГруппыВнешнихПользователей

- If you were given the link e1cib/list/Документ.ГруппыВнешнихПользователей — it will not open: the object is a catalog, not a document. Use the variant with Справочник..

2a. How to find out your release

"Help" → "About the program" (or the "i" icon in the upper right corner). There are two lines there: the platform version (for example, 8.3.24.xxxx) and the configuration release — "Accounting for Kazakhstan", edition 3.0, version 3.0.74.2. This instruction was verified on 3.0.74.2. On neighboring releases the names of commands and sections coincide.

3. How to fill it in

The group card is simple. Let's go through it field by field.

Field
Why it is needed
What happens if filled in incorrectly

Name (REQUIRED)
The name of the group by which you recognize it in the rights lists. For example, "Clients — only their own data"
You cannot save an empty name. An unclear name ("Group 1") will confuse you later: you won't understand who was given which rights

Parent group
If the catalog is hierarchical — you can nest the group into a folder for order
The error is not critical, but the members still inherit the rights of their group, not of the folder

Composition / Members
The list of external users included in the group. It is they who will receive the group's rights
You forgot to add a user — he will be left without the necessary rights. You added an extra one — he will see someone else's data

Access group profiles / Access rights
Here you assign WHAT the group can do: which profile (set of roles) is granted to it. This is the core of the setup
You did not assign a profile — the members will log in but see nothing. You assigned an extra one — you granted broader access than needed

Comment
A free note: why the group was created, who is responsible
It affects nothing, but helps when handing over affairs

Procedure:

- Make sure the external user is already set up (the "External users" catalog). The group only combines already existing ones.

- Create the group, set a clear Name.

- On the Members tab, add the required external users.

- On the Access rights tab (access group profiles), select the profile that determines the permitted actions.

- Click "Save and close". The rights will be recalculated automatically.

There is also a separate predefined group "All external users". Every external user is automatically included in it. Through it, it is convenient to grant basic rights to everyone at once.

4. A worked example

Situation. You handle the accounting for two outsourced clients. Their accountants must log into the database and see only the documents of their own organization, without access to other people's data or to the settings.

Steps:

- Set up external users: Client A — Akhmetova and Client B — Ivanov (each linked to their own counterparty/individual).

- Created the group "Clients — view of own data".

- In Members added both.

- In Access rights assigned the profile "View only" (or a specially created profile with a restriction by organization via RLS).

- Saved.

Result: both clients log in through the web client, see the same restricted interface, and the distinction by organization is ensured by the RLS mechanism based on the user's link to the counterparty.

There are no postings. Once again: this is an administrative object. Saving the group does not create a single accounting posting, does not move accounts 1210/1030/3310/3130, etc. — there is simply nothing to post here. If you need examples with amounts, 16% VAT, and postings — that pertains to accounting documents (sale, receipt, advance report), not to user groups.

5. Types of operation

The catalog has no "types of operation" like a document. But in essence groups come in two types:

- An ordinary group — you create it yourself, manually managing its composition and rights. The example from section 4.

- The predefined "All external users" — created by the system, its composition is replenished automatically when any external user is added. Deleting and renaming it are not available.

6. What happens on saving

Since there is no posting, the event is saving the group. What changes:

- Recalculation of access rights (RLS). After saving, 1C updates the members' rights: they get access according to the assigned profiles.

- Movements in the service access registers. The service information registers of the rights subsystem are updated — the "user ↔ group" links and the sets of access values by which record-level restriction works.

- No ESF, SNT, or uploads to the IS ESF — the object has no relation to electronic invoices.

The exact names of the service access rights registers depend on the SSL version within the release — this is the only point worth clarifying in your specific release if you need to administer them directly. For ordinary work there is no need to dig into these registers.

7. Printable forms

A group of external users has no printable forms of its own — there is nothing to print here. To check who can do what, use the service reports on rights:

- "Access rights" / the report on a user's rights (available from the "Administration → User and rights settings" section).

- The list of members is visible right in the group card.

8. Common mistakes

"Insufficient rights to perform the operation on data". You (as an administrator) are trying to configure a group without full rights. Fix: perform the setup under a user with the "Administrator" / "System administrator" role.

The "Groups of external users" list is not visible in the menu. The mechanism is not enabled. Fix: "Administration → User and rights settings → External users checkbox".

"The 'Name' field is not filled in". You are trying to save a group without a name. Fix: set a name.

An external user has logged in but sees nothing. The group has not been assigned an access group profile, or the user himself does not have the "Access to the program is allowed" checkbox set. Fix: assign a profile on the "Access rights" tab and check the user card.

"The user is already included in another group with incompatible rights" / access is broader than expected. The user is a member of several groups at once, and the rights are summed up. Fix: check all of the member's groups — the resulting rights are the union.

The navigation link does not open. A link with the Документ. prefix was used. Fix: replace it with e1cib/list/Справочник.ГруппыВнешнихПользователей.

9. FAQ

Is this a document or a catalog?
A catalog from the Standard Subsystems Library. It has no postings, VAT, or ESF, so do not look for them — it manages only access.

How does an external user differ from an ordinary one?
An ordinary user is an employee working in the full configuration. An external one is a client, counterparty, auditor; he is linked to a catalog item (counterparty/individual) and works through restricted access, usually the web client.

How to grant rights to all external users at once?
Through the predefined group "All external users" — assign it a profile, and everyone will receive the basic rights.

Why did the rights not change after saving the group?
Check that the user is actually in the group's composition, that a profile is assigned to the group, and that the user is allowed to log in. Sometimes having the user log in again helps.

Can one external user be in several groups?
Yes. The rights are then combined — the user will get everything that all of his groups grant.

Are any postings or account movements on accounts 1210, 6010, 3130 generated when saving?
No. This is an administrative object; it does not create accounting movements.

How to restrict a client to only their own organization?
Through a profile with a record-level restriction (RLS) and linking the external user to a specific counterparty/organization. The group merely combines such users under a common profile.

Is there a printable form of the member list?
There is no separate printable form. The composition is visible in the group card, and a summary of the rights is provided by the service report "Access rights".

How to delete a group?
Mark it for deletion and run "Administration → Deletion of marked objects". The predefined "All external users" cannot be deleted.

Does this object need the internet and a connection to the IS ESF?
No. Electronic documents (ESF, SNT) have no relation to user groups.

10. Related objects

- External users (catalog) — the group's composition is formed based on its items; a group without users makes no sense.

- Counterparties / Individuals — external users are linked to them, which is exactly what allows access to be distinguished.

- Access group profiles — they define the set of roles; it is the profile that is assigned to the group.

- Access groups — the service mechanism through which the rights from the profiles reach the group members.

- Users (ordinary) and User groups — the "internal" analog of the same mechanism for employees.

How to find out your release

"Help" → "About the program": the line with the platform version (8.3.x) and the configuration release "Accounting for Kazakhstan", edition 3.0. Compare it with the version from the signature below — if you have a different release, the command names most likely coincide, but the placement of the checkboxes may differ slightly.

The instruction was prepared and verified on release 3.0.74.2 "Accounting for Kazakhstan" (edition 3.0).

---
_BuhGPT — ИИ-помощник для бухгалтеров Казахстана: https://buhgpt.kz_