---
title: "The \"Access Rights Analysis\" report in \"Accounting for Kazakhstan\" 3.0: how to understand what a user sees and can do"
country: KZ
lang: en
author: Сапа Т.И. (https://buhgpt.kz/authors/sapa-ti)
date: 2026-09-08
canonical: https://buhgpt.kz/suraqtar/otchet-analiz-prav-dostupa-v-buhgalterii-dlya-kazahstana--en
source: BuhGPT
---

# The "Access Rights Analysis" report in "Accounting for Kazakhstan" 3.0: how to understand what a user sees and can do

> **TL;DR:** Verified on release 3.0.74.2 "Accounting for Kazakhstan" (edition 3.0). Situation: your new accountant, Akhmetova, calls and says she can't see the documents for one of your LLPs — the "Sales of Goods and Services" list is empty, even though there definitely are sales there. O

---

Verified on release 3.0.74.2 "Accounting for Kazakhstan" (edition 3.0).

Situation: your new accountant, Akhmetova, calls and says she can't see the documents for one of your LLPs — the "Sales of Goods and Services" list is empty, even though there definitely are sales there. Or the other way around: an auditor asks you to show who in the database has the right to delete posted documents and change other people's settings. Guessing from the checkboxes in the user card is slow and unreliable. You open the "Access Rights Analysis" report — and within a minute you see the whole picture: what roles, profiles, and access groups a person has, which organizations they're allowed into, and exactly what they're permitted to do with each object.

1. Purpose

The report shows the actual rights of the selected user (or access group): their roles, profiles, access groups, permitted actions on objects (read, add, change, delete), and record-level restrictions — for example, the list of organizations visible to them. It is an administrator's diagnostic tool: it changes nothing on its own and only explains why a person sees or doesn't see something.

2. Where to find it

Menu path:

Administration → User and Rights Settings → "Access Rights" block → Access Rights Analysis.

The report can also be opened directly from the user card (the "Access Rights" / "Rights Report" button) and from the access group form.

To open it right away in 1C, copy the navigation link and paste it via "Tools (Main Menu) → File → Open" → "Follow navigation link" (Ctrl+F11):

e1cib/list/Отчет.АнализПравДоступа

The report is available only to a user with the "Administrator" profile (or full rights). An ordinary accountant won't open it — and that's correct, since it reveals the entire access picture of the database.

2a. How to find out your release

Main menu (the ▼ icon at the top left) → Help → About. In the window that opens you'll see two lines: "Platform 1C:Enterprise 8.3.xx.xxxx" and "Configuration: Accounting for Kazakhstan, edition 3.0 (3.0.74.2)". The second number is the configuration release; this instruction is tied to exactly that. If your release is older or newer, the set of checkboxes and the names of the access groups may differ slightly.

3. How to fill it in (set up the report)

The report is not posted and records nothing — you simply set the parameters and click "Generate". Key fields:

Field / parameter
Why it's needed
What happens if set incorrectly

User (REQUIRED)
The person whose access we're analyzing. Selected from the "Users" catalog.
Empty — the report won't build or will show an empty result. Pick the wrong one — you'll draw conclusions about someone else's rights.

Report type / variant
Switches the view: user rights, rights by object, access restrictions.
Wrong variant — you won't see the needed cross-section (e.g., you're looking for the reason "doesn't see the organization" but are viewing the list of roles).

Object / metadata section
Narrows the analysis to a specific document or catalog (for example, "Sales of Goods and Services").
Leaving it empty on a large database makes the report very long, and you'll have to hunt for the needed line.

Show roles
Expands the list of roles included in the profiles.
Turn it off — and you won't understand which particular role grants the excess right.

Show access groups and values
Shows which organizations / warehouses the user is allowed into (record-level restriction, RLS).
Turn it off — and you won't find the cause of an "empty document list by organization".

Assigned rights only
Hides empty lines, keeping only what is actually permitted.
Turn it on for a short, readable report; turn it off when you need to prove that a right is ABSENT.

Sequence of actions: selected the user → selected the variant ("User rights" for the overall picture) → specified the object if needed → "Generate". The result can be collapsed/expanded by groupings, saved to a file, or printed.

4. Worked example

Task. Accountant G. S. Akhmetova can't see the sales documents for LLP "Astana-Stroy", although everything is visible for LLP "Aktobe-Trade". We need to figure out the cause and fix it.

Step 1. Generate the report. User — "G. S. Akhmetova", variant — "User rights", "Show access groups and values" enabled.

Step 2. Read the result.

Level
What the report showed

Access groups
"Accountants (by organizations)"

Profile
"Accountant"

Roles (examples)
Adding/changing documents, Reading master data, Reflecting transactions

Rights on "Sales of Goods and Services"
Read — yes, Add — yes, Change — yes, Delete — no

Access values: Organizations
LLP "Aktobe-Trade" (only this one)

The main thing is clear: she has rights to the document itself, but in the access group only LLP "Aktobe-Trade" is listed as a permitted organization. The record-level restriction mechanism (RLS) cuts off all documents of other organizations — which is why "Astana-Stroy" is not visible.

Step 3. Fix it. Open the access group "Accountants (by organizations)" → on the access values tab add the line LLP "Astana-Stroy" → save. Generate the report again: the "Organizations" line now has both companies.

Step 4. Check. Akhmetova logs back into the database (or refreshes the list with F5) — the sales documents for both organizations are visible.

Note: this report produces no accounting entries at all. The figures of amount-based transactions (income 6010, cost 7010, VAT 3130 at the rate of 16%) appear in other documents — while "Access Rights Analysis" merely explains which employees have the right to create, post, and see those documents.

5. Operation types (report variants)

The report gives several cross-sections of one and the same picture:

- User rights — everything for one person: access groups, profiles, roles, permitted actions, restrictions. The most common variant.

- Rights by object — take a specific object (for example, "Payment order") and see who can do what with it.

- Access restrictions (RLS) — a cross-section by values: which organizations, warehouses, divisions are open to the user. This is exactly where you look for the cause of "empty lists".

- Access group / profile rights — analysis not of a person but of the group itself: convenient before adding employees to it.

6. What is generated on posting

Nothing. This is a report, not a document. It is not posted, makes no entries in accounting and accumulation registers, does not generate an ESF or SNT, creates no Dr/Cr entries. The only result is a spreadsheet document on the screen, which can be saved or printed. All rights changes are made not here but in the "Users", "Access groups", and "Access group profiles" objects.

7. Printed forms

The report has no separate regulated printed forms — the generated spreadsheet document itself is printed. Available actions on the result:

- Print (Ctrl+P) — output the spreadsheet document to the printer.

- Save as… — export to a file: .mxl, Excel (.xlsx), PDF, HTML.

- Send by email — as an attachment from the report form.

This is convenient when an auditor or security service asks for written confirmation of who has which rights.

8. Common mistakes

"Insufficient rights to open" (or the menu item is not visible at all). The report opens only under the administrator. Solution: ask to open the database as a user with the "Administrator" profile, or temporarily grant the needed rights.

The report is empty even though a user is selected. Usually the "Assigned rights only" flag is unchecked together with a filter by an object the user doesn't have — or, conversely, too narrow a selection is enabled. Remove the object filter and generate again.

"Rights changes are not applied". You corrected the access group, but the user still doesn't see the documents. The reason is that the session hasn't refreshed: the user must log back into the database, and the list must be refreshed (F5). Scheduled jobs recalculating rights (RLS) are sometimes executed with a delay.

Rights are visible that "shouldn't be there". Most often the extra comes from a second access group or from a profile with a broad role. In the report, expand the "Roles" branch — there you can see which particular role grants the right; you need to remove it, not the action as a whole.

Confusing "no right to the object" with "no access value". If Read of the object = "yes" but the list is still empty — the issue is not the object rights but the restriction by organization/warehouse (the "Access values" section). Do not remove the role — add the needed value to the access group.

9. FAQ

Does this report change the user's rights?
No. It only shows the current picture. Rights are changed in "Users", "Access groups", and "Access group profiles".

Why can't an accountant see documents for one of the organizations?
Almost always this is a record-level restriction: that organization is not listed in the access values of their access group. In the report this is visible in the "Access values: Organizations" section. Add the organization to the group.

What's the difference between "no rights to the object" and "no access value"?
Rights to the object are the permission for an action (read, change, delete) on the document type in principle. An access value is the specific organizations/warehouses to which this action applies. An empty list while rights are present almost always means an absent value.

How can I see who in the database can delete posted documents?
Build the report in the "Rights by object" variant, select the needed document, and look at the "Delete" / "Deletion mark" right for users and groups.

Can the report be printed for an auditor?
Yes. Generate it and export to PDF or Excel via "Save as…", or print directly (Ctrl+P).

Why did nothing change after editing the rights?
The user needs to log back into the database, and the list needs to be refreshed. Access restrictions are recalculated by a background job, sometimes with a slight delay.

Where do a user's excess rights come from?
Usually from a second access group or from a profile with a broad role. Expand the roles branch in the report — you'll see the source of the specific right.

Does the report affect month-end closing, VAT, or the ESF?
No. It makes no entries, does not calculate VAT (the 16% rate in 2026 is applied in sales documents and in the ESF, not here), and does not generate electronic documents. It is an administration tool, not an accounting one.

Can the report tell whether a user belongs to the "Administrators" group?
Yes. In the "User rights" cross-section all access groups and profiles are visible, including "Administrator". Having full rights is reflected there as well.

Who should use this report at all?
The database administrator or the person responsible for information security. It is unavailable and unnecessary to an ordinary accountant.

10. Related documents and objects

The report is not entered "based on" and does not itself serve as the basis for other documents. It works together with the objects of the access management subsystem:

- Users (Administration → User and Rights Settings) — the employee card; the report is opened from here via the "Access Rights" button.

- Access groups — here the members and access values (organizations, warehouses) are set. The main place to fix the causes of "empty lists".

- Access group profiles — sets of roles; they determine which actions are permitted in principle.

- Rights settings by section / User settings — general restrictions on functionality.

- Event log — a related tool: if the report showed that a right exists, the log will show who used it and when.

How to find out your release

Main menu → Help → About. The line "Configuration: Accounting for Kazakhstan, edition 3.0 (…)" contains the release number; the platform is indicated in the line above. Check the instruction against exactly this number.

This guide was prepared for "Accounting for Kazakhstan", edition 3.0, release 3.0.74.2.

---
_BuhGPT — ИИ-помощник для бухгалтеров Казахстана: https://buhgpt.kz_