RUKKENZH
Задать вопрос AI
SectionsОбъекты конфигурации 1С
Report "Role Permissions" in 1C:Accounting for Kazakhstan 3.0 — How to Check Role Permissions
Язык статьи:🇷🇺 RU🇰🇿 KK🇬🇧 EN🇨🇳 ZH
Версия статьи:📘 Для бухгалтера⚙️ Для тех-специалиста

Report "Role Permissions" in 1C:Accounting for Kazakhstan 3.0 — How to Check Role Permissions

Applies to: 1С:Бухгалтерия для Казахстана, release 3.0.74.2 · by 1C-Sapa Group, 1C partner
СТ
Сапа Т.И. — Эксперт по 1С и бухгалтерскому учёту, преподаватель-практик

1. Purpose

The report "Role Rights" shows what actions each configuration role is allowed to perform: read, add, modify, delete, post documents, open reports and processes. This is a tool for the administrator and chief accountant: with its help, you can see in a minute who can technically do what in the database. It does not generate entries, movements, or printed acts — it only displays the rights settings from the configuration metadata.


2. Where to find

The report is internal, so it is not found in the usual sections ("Sales", "Purchases", "Bank and Cash"). There are two working paths:

  • Main menu → "All Functions" → "Reports" → "Role Rights". If the "All Functions" item is not visible: "Service and Settings" (icon ☰) → Settings → Options → check the box "Display the 'All Functions' command".
  • Through the navigation link. Copy the line below, then "Service and Settings" → File → Open by Navigation Link (or "Go to Navigation Link") and paste:
e1cib/list/Report.RoleRights

If the link does not open, try the option e1cib/app/Report.RoleRights — in some releases, the report is called as an application form.

Only a user with administrator rights (role "Full Rights" / "System Administrator") can open the report. A regular accountant will not have access to this item — and this is correct: security settings should not be visible to everyone.


2a. How to find out your release

"Help" → "About the Program" (or icon ☰ → "About the Program"). In the opened window, you will see two key lines:

  • Platform version (for example, 8.3.24.xxxx) — this is the "engine" of 1C.
  • Configuration: Accounting for Kazakhstan, edition 3.0 (3.0.74.2) — this is the release to which the instruction refers.

If your release differs, the names of menu items may change slightly, but the logic of the report remains the same.


3. How to fill out (configure the report)

The report does not have a "document header" — there are selection parameters. You fill them out before the "Generate" button.

Parameter Purpose What happens if set incorrectly
Role / list of roles (mandatory by meaning) Select which roles' rights to view: "Accountant", "Seller", "Full Rights", etc. If all roles are left selected — the report will expand to hundreds of lines, and you will take a long time to find the needed role. Choose 1–3 roles.
Metadata objects (filter) Limits the list of objects: only directories, only documents, or a specific object (for example, Document.InvoiceIssued). Without filtering, all configuration objects will be exported — thousands of lines. Set the filter for the required document.
Types of rights Which rights to display: Read, Add, Modify, Delete, Post, etc. If you remove the necessary right from display — you will not see the exact reason you are looking for the report.
Only established rights Hides empty lines, leaving only what is actually allowed for the roles. Without the checkbox, the table is filled with "minuses", making it harder to read.
Only differences in roles Shows objects where the rights of roles differ. Ideal for comparing "why one works, and the other does not". Especially useful when addressing user complaints.
Grouping By object type (documents/directories/registers) or by subsystems. Affects only reading convenience, not the data.

After configuring, click "Generate" — the report builds a matrix: objects in rows, rights (or roles) in columns, marks "+"/"–".


4. Analyzed example

Situation. Seller Asel complains: she creates an "Invoice (issued)", but the "Post" button does not work — the document remains unposted. The chief accountant posts the same documents without problems. It is necessary to understand what the difference is.

What to do:

  1. Open "Role Rights".
  2. In the role selection, choose two: "Seller" and "Accountant".
  3. In the object selection, specify Document.InvoiceIssued.
  4. Check the box "Only differences in roles" and click "Generate".

Result — rights matrix:

Right to Document.InvoiceIssued Role "Accountant" Role "Seller"
Read + +
Add + +
Modify + +
Post +
Cancel posting +
Delete +
Interactive deletion

It is obvious: the role "Seller" does not have the "Post" right for this document. Asel can create and save the invoice, but cannot post it. Therefore, the document remains unposted.

What this changes in accounting (in numbers). While the document is unposted, the sale is not reflected: income 6010, customer debt 1210, and VAT payable 3130 do not arise. For example, an invoice for goods worth 1,000,000 ₸ without VAT at a rate of 16% after posting will result in:

Dr Cr Amount, ₸ Description
1210 6010 1,000,000 Revenue from sales
1210 3130 160,000 VAT 16%
7010 1330 (cost) Write-off of goods

But these entries are made by the invoice/sale upon posting, not by the report "Role Rights". The report only explained why the posting did not occur. Further, the administrator either adds the "Post" right to the seller's access group profile or leaves posting to the accountant — this is a management decision.


5. Types of operations (report modes)

Strictly speaking, there are no "types of operations" like in a document here. There are generation modes:

  • Rights for one role — a complete list of rights for the selected role on all objects.
  • Role comparison — several roles side by side in columns, convenient for finding differences.
  • Rights for a specific object — all roles that have access to the selected document/directory.
  • Top-level rights (administrative) — not by objects, but by role as a whole: "Administration", "Exclusive Mode", "Active Users", "Registration Journal", "Interactive Opening of External Reports and Processes", "Thin/Web Client", "External Connection".

6. What is generated upon execution

Here it is honest and brief, to avoid misleading:

  • No entries. The report is not reflected in accounting and tax records.
  • No electronic documents (ESF, SNT). The report does not interact with the ESF information system.
  • No movements in registers. It does not write anything to the database; it only reads the rights description from the configuration metadata.
  • Result — a screen tabular form (rights matrix), which can be saved or printed.

That is why "Role Rights" can be safely opened in the working database: it does not change anything.


7. Printed forms

The report does not have separate standardized forms (like for a waybill or invoice). However, the generated table can be:

  • Printed — the "Print" button on the report form (Ctrl+P).
  • Saved to a file — the "Save" button → formats PDF, Excel (.xlsx), Word (.docx), MXL, HTML.
  • Copied the selected fragment of the table to the clipboard (Ctrl+C) and pasted into an email to the auditor or access policy.

Practical advice: before checking the IB, export the rights matrix to PDF — this is a ready application to the access policy.


8. Common mistakes

"Insufficient rights to open the report 'Role Rights'"/the report is not in the list. You logged in under a role without administration. Log in under a user with the "Full Rights" role or ask the administrator to open the report and export the needed part.

"Role Rights ≠ user rights". The most common logical error. The report shows the rights of roles, not a specific person. The user's total rights are the combination of all roles from the access groups assigned to them. If the report shows that the "Seller" role does not have posting rights, but the user still posts — it means they have been assigned another role (for example, through a second access group). Check "Administration → User and Rights Settings → Users".

"The report shows the right, but the button in the document is still unavailable". RLS (record-level security) is in effect: the right to the object exists, but the specific record is not visible to the user due to filtering by organization/department. "Role Rights" shows rights to the object as a whole and does not reveal RLS conditions — they are viewed in the access group profile.

"I changed the profile — but the report still shows old rights". The report reads the configuration metadata, while access group profiles are built from roles. Update the report by clicking the "Generate" button again; if you changed the role in the configurator — a database configuration update is needed.

"Too many lines, can't find anything". You did not set a filter. Limit the roles (1–3) and objects (specific document), and enable "Only established rights".


9. FAQ

Does the report create any entries or movements? No. This is an internal report on security settings. It does not create entries, does not affect registers, and does not influence month-end closing or VAT.

How do "Role Rights" differ from "User and Rights Settings"? "Role Rights" show what is embedded in the role at the configuration level. "User and Rights Settings" (Administration) show which people have been assigned which access groups and roles. The first is "what a role can do", the second is "who has been given this role".

How to find out the total rights of a specific employee? A person's rights are the sum of all their roles. Open the user card → their access groups → incoming profiles and roles. Then check the contents of each role in "Role Rights".

Why does a role not have the "Post" right, but the user posts documents? This means they have a second role (from another access group) with this right. Role rights are combined, not intersected: one role with permission is enough.

Can rights be changed from the report? No, the report only reads. Rights are changed through access group profiles (Administration) or in the configurator (for standard roles, changing the composition directly is not recommended — use profiles and additional roles).

What do "administrative" rights in the report (Administration, Exclusive Mode, etc.) mean? These are rights at the level of the entire information base, not tied to a specific document: launching in exclusive mode, viewing the registration journal, working with the thin/web client, opening external reports and processes. The right "Interactive opening of external reports and processes" is the most sensitive from a security standpoint and should be checked separately.

Does the report show rights by organizations (RK: several legal entities in one database)? Not directly. Division by organizations is implemented through RLS and settings in access groups. "Role Rights" shows the right to the object as a whole; the organization filter is set in the profile.

Does this report affect ESF, SNT, or reporting to the tax authorities? No. The report is not connected to the ESF information system and tax reporting. However, it is indirectly useful: if a role does not have rights to the document "Invoice (issued)" or to the ESF export process, the employee will not be able to issue an electronic invoice — and the report will show this.

Can the rights matrix be saved for the auditor? Yes: the "Save" button → PDF or Excel. This is a convenient application to the internal access policy.

Are administrator rights needed for the report? Yes. Security settings are only visible to users with full rights.


10. Related objects

  • Users (Administration → User and Rights Settings → Users) — who has been assigned roles; this is where the real rights of a person "grow" from.
  • Access Groups and Access Group Profiles — the mechanism through which roles are assigned to users; this is where rights are changed.
  • Record-Level Security (RLS) — explains cases of "the right exists, but the record is not visible".

Частые вопросы

Does the report make any transactions or movements?
No. This is a service report on security settings. It does not create transactions, does not touch registers, and does not affect month-end closing or VAT.
How do "Role Rights" differ from "User and Rights Settings"?
"Role Rights" show what is embedded in the role at the configuration level. "User and Rights Settings" show which people are assigned to which access groups and roles. The first is "what the role can do," the second is "who has been given this role."
How to find out the total rights of a specific employee?
A person's rights are the sum of all their roles. Open the user card → their access groups → incoming profiles and roles, and then check the contents of each role under "Role Rights."
Why does the role not have the "Posting" right, but the user posts documents?
This means they have a second role from another access group with this right. Role rights are combined, not intersected: one role with permission is sufficient.
Can rights be changed from the report?
No, the report only reads. Rights are changed through access group profiles (Administration) or in the configurator — for standard roles, it is not recommended to change the composition directly; use profiles and additional roles.
What do "administrative" rights in the report (Administration, Monopoly Mode, etc.) mean?
These are rights at the level of the entire database, not tied to a document: monopoly mode, registration journal, thin/web client, opening external reports and processes. The last one is the most sensitive for security, and it is checked separately.
Does the report show rights by organizations (multiple legal entities in one database)?
Directly — no. The separation by organizations is implemented through RLS and access group settings. "Role Rights" shows the right to the object as a whole; the filter by organization is set in the profile.
Does this report affect ESF, SST, or reporting to the tax authority?
No, the report is not related to the ESF information system and tax reporting. However, it is indirectly useful: if a role does not have the right to "Invoice (issued)" or to export ESF, the employee will not be able to issue an electronic invoice — and the report will show this.

Read also

Источники

Была ли статья полезна?
💼 Нужна помощь с 1С или учётом? Слава КВЦ — многолетняя практика в 1С в Казахстане. Изучите разложенный НК РК 2026 или спросите в чате BuhGPT — ответит за секунды.