---
title: "\"Access Rights Report in 1C:Accounting for Kazakhstan 3.0 — How to Check Who Can Do What in the Database\""
country: KZ
lang: en
author: Сапа Т.И. (https://buhgpt.kz/authors/sapa-ti)
date: 2026-09-07
canonical: https://buhgpt.kz/suraqtar/otchet-prava-dostupa-v-1s-buhgalteriya-dlya-kazahstana-3--en
source: BuhGPT
---

# "Access Rights Report in 1C:Accounting for Kazakhstan 3.0 — How to Check Who Can Do What in the Database"

> **TL;DR:** Checked on release 3.0.74.2 "Accounting for Kazakhstan" (version 3.0). In the morning, you discovered that the closed period has been altered: someone has reposted a sales document retroactively, and the balances on account 6010 have changed. The question is — who had the righ

---

Checked on release 3.0.74.2 "Accounting for Kazakhstan" (version 3.0).

In the morning, you discovered that the closed period has been altered: someone has reposted a sales document retroactively, and the balances on account 6010 have changed. The question is — who had the right to interfere with this period? Or another situation: a new cashier has been hired, and they call saying they do not see the "Bank and Cash" section. Meanwhile, a part-time accountant accidentally deleted someone else's payment order. To avoid guessing "who has access to what," there is a service report in 1C called "Access Rights." It shows for each user: which access groups they belong to, what profiles and roles are assigned to them, and what restrictions (RLS) apply to them. This is your audit tool for rights — open it, review it, and understand where the gap is.

It is important to note: this is a report, not a document. It does not post anything, does not generate electronic invoices (ESF) or tax return forms (SNT), and does not make movements on accounts. It only shows the picture of rights "as is" at the current moment. Therefore, the sections about debit/credit postings and electronic documents are replaced with what the report actually provides.

1. Purpose

The "Access Rights" report shows what a specific user (or all users) can do in the database: reading, adding, modifying, deleting, posting on objects, as well as restrictions at the record level (by organizations, warehouses, counterparties). It is used for auditing rights, analyzing incidents ("who could have done this"), and preparing for reporting when access to the database needs to be restricted.

2. Where to Find

Path in the interface:

Administration → User and Rights Settings → "Reports" block (or "Access Rights").

If you do not have a direct link to the report in this section, open it through the list of all reports: Main Menu (☰) → All Functions → Reports → Access Rights. The "All Functions" item is enabled in Service → Options → Show "All Functions" command.

The fastest way is through the navigation link. Copy the line, then in 1C: Main Menu (☰) → Service → Go to Navigation Link and paste:

e1cib/list/Report.AccessRights

Only a user with administrator rights or a profile that allows viewing user settings can work with the report. A regular accountant without administrative rights will not have access to the report — this is normal.

2a. How to Know Your Release

Main Menu (☰) → Help → About the Program. In the opened window, you will see two lines: platform version (for example, 8.3.24.xxxx) and configuration version — "Accounting for Kazakhstan, version 3.0 (3.0.74.2)". The instruction is written for release 3.0.74.2; in adjacent releases, the location of menu items and the composition of report columns are the same.

3. How to Fill (Configure the Report)

The report is filled out not like a document — you set the filter and output option, and then click "Generate." Let's break down the key settings.

Setting
Purpose and what happens if set incorrectly

User (key)
You choose whose rights you are viewing. If left empty, the report will display all users, and the table will be large; for analyzing a specific incident, always specify one person, otherwise, you will drown in rows.

Access Group / Profile
Allows you to view not by person, but by group — "who is in the Accountant profile." Convenient when checking if an extra employee has been included in a group with broad rights.

Metadata Object (directory/document)
Filter "who has access to this object." For example, if you select "Document.SalesOfGoodsAndServices" — you will see everyone who can post it. If left empty — it will show rights for all objects, and the report will become lengthy.

Type of Rights (reading/adding/modifying/deleting/posting)
Narrow the output to one action. If you are analyzing document deletion — set "Deletion," and you will immediately see a short list of those who are capable of it.

Show Restrictions (RLS)
A checkbox that adds a column with restrictions at the record level: for which organizations/warehouses access applies. If not included — you will see that access "exists," but you will not understand that it is limited to one organization.

Grouping
Controls the structure: "by users" (under each — their rights) or "by objects" (under each object — who is allowed to it). Choose based on the task: if you are looking for a gap with a person — group by user; if auditing a critical object — by object.

There are no mandatory fields to fill in the usual sense — the report will be generated even without filtering. But without specifying a user or object the result is almost unreadable. Practice: first narrow the filter, then generate.

Order of work: set the filter → click "Generate" (F5) → read the table → if necessary, click "Settings" and add a column/grouping → save the option through "Save Report Option" to avoid reconfiguring.

4. Analyzed Example

Situation. In the database of LLP "Astana-Trade," someone reposted a sale for a closed month. You want to understand who could have done this and also check the new accountant Akhmetova A.

Step 1. Opened the report via the link e1cib/list/Report.AccessRights.

Step 2. In the filter: Object = "Document.SalesOfGoodsAndServices," Type of rights = "Posting," checked the "Show Restrictions" checkbox. Clicked "Generate."

Step 3. Received the table:

User
Profile / Access Group
Posting
Modification
Deletion
Restriction (RLS)

Ivanov I. (chief accountant)
Chief Accountant
Yes
Yes
Yes
No restrictions

Akhmetova A. (accountant)
Accountant
Yes
Yes
No
Organization "Astana-Trade"

Smirnov S. (warehouse worker)
Warehouse Worker
No
No
No
Warehouse "Main"

Petrov P. (director)
View Only
No
No
No
No restrictions

What you read from here. Only two people could repost the sale (the right "Posting") — Ivanov and Akhmetova. The director and warehouse worker are excluded. Akhmetova is limited to one organization "Astana-Trade" and cannot delete documents, while Ivanov can do everything without restrictions. The circle of suspects has narrowed down to two people in a minute; next, check the document versions (who last saved it) or the registration journal.

There are no postings in this example — the report only reads rights. If you were looking for who changed the amounts, the next step would be the registration journal (Administration → Maintenance → Registration Journal) with filtering by document; it is there that you can see the full name and date of the entry.

Note about the country: the report itself does not operate with tax figures, but access to posting sales affects the correctness of VAT. Let’s recall the current values for RK-2026, which you control indirectly: VAT rate 16%, VAT payable accumulates on account 3130, revenue from sales — 6010, cost of goods sold — 7010. If a person with excessive rights reposts a sale retroactively, it is precisely the base on these accounts that "floats."

5. Report Options (What It Can Show)

- Rights by User — a complete snapshot of one employee's rights across all objects.

- Rights by Object — who has access to a specific directory/document (audit of critical objects: "Sales," "Payment Order," "Settlements").

- Composition of Access Groups — who is included in the profile/group ("Chief Accountant," "Accountant," "View Only").

- Restrictions at the Record Level (RLS) — for which organizations, warehouses, divisions each person's access is limited.

- User Roles — technical snapshot: what configuration roles are assigned (useful when analyzing non-standard profiles).

6. What Is Formed When Executed

The report is a service one, therefore:

- Debit/Credit postings — are not formed. The report does not make movements on accounts.

- Electronic documents (ESF in the ESF system, SNT) — are not formed. This is the area of sales/movement documents, not a report on rights.

- Movements in registers — are not created. The report only reads the registers of access rights and role tables.

The result of the work is a tabular document on the screen: a list of users, their profiles, permitted actions, and restrictions. It can be saved, printed, or exported.

7. Printed Forms and Export

There is no separate "printed form" like a document here — the result of the report itself is printed. Available:

- Print (Ctrl+P) of the generated table.

- Save as... — export to Excel (.xlsx / .mxl), PDF, HTML, or tabular document .mxl. Convenient to attach to the act of internal audit or to the order changing rights.

- Email — if an email account is set up in the database.

8. Frequent Errors

"Insufficient rights to perform operations on Report.AccessRights" — you logged in as a user without administrative rights. Correction: ask the administrator to open the report or temporarily enable your profile with the right to view user settings.

The report is empty, although the user definitely exists — too narrow a filter is set (for example, "Deletion" for an object that no one has the right to delete). Remove unnecessary filters and regenerate.

"It is clear that access exists, but the person still cannot open the section" — you did not include the RLS column and did not notice the restriction by organization/warehouse. Enable the "Show Restrictions" checkbox: most likely, access is limited to the wrong organization.

Too many rows, nothing is clear — no filter is set by user or object. Always narrow down: one user OR one object.

You changed the user's rights, but the report shows the old ones — the data has not been refreshed. Click "Generate" (F5) again; the report does not update automatically.

9. FAQ

Q: Does the "Access Rights" report create postings or ESF?
A: No. This is a service report. It does not make movements on accounts, does not generate ESF and SNT, does not change data — it only shows rights.

Q: Where can I find the report itself?
A: Administration → User and Rights Settings → "Reports" block, or via the navigation link e1cib/list/Report.AccessRights, or through ☰ → All Functions → Reports.

Q: Why do I not have this report in the menu?
A: It is only available to users with administrative rights or a profile that allows viewing user settings. A regular accountant will not have it.

Q: How to find out who deleted the document?
A: The report will show who has the right to delete. To find out who exactly deleted it, open Administration → Maintenance → Registration Journal with filtering by the required document — there you can see the full name, date, and time.

Q: What does the "restriction (RLS)" column mean?
A: This is a restriction on access at the record level — for which organizations, warehouses, divisions the right applies. "Organization Astana-Trade" means that the person sees and modifies data only for this organization.

Q: Can rights be configured directly from the report?
A: No, the report only shows. Rights are changed in Administration → User and Rights Settings → Users / Access Groups / Access Group Profiles.

Q: How to restrict the accountant's access to the closed period?
A: You will only check this with the report. The actual blocking is set through Date of Prohibition on Data Modification (Administration → User and Rights Settings → Dates of Prohibition on Modification). After setting up, ensure that the necessary people do not have the right to post in this period.

Q: How to export the result for an order or audit?
A: "Save as..." → choose Excel or PDF. You can also print directly (Ctrl+P).

Q: The report shows roles but does not show what the person actually did. Is this normal?
A: Yes. Rights ≠ actions. The report is about "what can be done," the registration journal is about "what has been done." Both are used for a complete analysis of the incident.

Q: Does this report affect VAT accounting at a rate of 16%?
A: Not directly. But it helps to find excessive rights for posting sales, due to which balances on accounts 6010/7010 and VAT (3130) may be distorted by an unauthorized user.

10. Related Objects

The "Access Rights" report reads d

---
_BuhGPT — ИИ-помощник для бухгалтеров Казахстана: https://buhgpt.kz_