RUKKENZH
Задать вопрос AI
SectionsОбъекты конфигурации 1С
Access Group Profiles in "Accounting for Kazakhstan" 3.0: Comprehensive Guide for Accountants
Язык статьи:🇷🇺 RU🇰🇿 KK🇬🇧 EN🇨🇳 ZH
Версия статьи:📘 Для бухгалтера⚙️ Для тех-специалиста

Access Group Profiles in "Accounting for Kazakhstan" 3.0: Comprehensive Guide for Accountants

Applies to: 1С:Бухгалтерия для Казахстана, release 3.0.74.2 · by 1C-Sapa Group, 1C partner
СТ
Сапа Т.И. — Эксперт по 1С и бухгалтерскому учёту, преподаватель-практик

Checked on release 3.0.74.2 "Accounting for Kazakhstan" (version 3.0).

You have taken an assistant. They need to create invoices and electronic invoices (ESF), but they should not see employee salaries, nor should they delete documents, and they can only work with one of the three organizations listed in your database. You open the user list, click "Access Rights" — and you come across the unfamiliar word "Profile". It is here, in the directory "Access Group Profiles", that it is determined who sees what in the program. If you make a mistake with just one checkbox — the newcomer will either not be able to process any documents, or, on the contrary, will open a report on all LLPs and see the salaries of directors.

Let's break down the directory in a human way: what each field is responsible for and what will break if you check the wrong box.

1. Purpose

An access group profile is a ready-made set of roles and restrictions that you assemble once and then assign to user groups. Roles determine what a person can do (create documents, view reports, administer). Restrictions (RLS) determine which data — only their own organization, only their own warehouse, only their own counterparties. The profile itself does not grant any rights to anyone: it "comes to life" through the Access Group, to which you include users.

2. Where to find

Administration → User and Rights Settings → Access Groups → Access Group Profiles.

This item is only visible to users with administrator rights. If it is not there — then you do not have the right to manage access, please contact the person who configured the database.

A quick way to open the list directly in 1C: Service (or Main Menu) → "Go to navigation link" and paste:

e1cib/list/Directory.AccessGroupProfiles

For the tab "Access Restrictions" to appear in the profile, the checkbox "Restrict access at the record level" must be checked in the Administration → User and Rights Settings section. Without it, you will only see roles, and you will not be able to set "access to one organization".

2a. How to find out your release

Main Menu → Help → About the program. In the opened window: at the top — the version of the platform "1C:Enterprise" (for example, 8.3.24.xxx), below — the line "Accounting for Kazakhstan, version 3.0 (3.0.74.2)". The first number (3.0) is the version, the second (74.2) is the release. All steps below have been checked on release 3.0.74.2; in neighboring releases, the names of the fields are the same.

3. How to fill out

Creating a profile from scratch is almost never necessary — it is more correct to copy the supplied one (the "Create by copying" button on the highlighted profile "Accountant") and trim the excess. Below are all the fields of the card.

Field What it is for and what will happen in case of an error
Name (mandatory) How the profile is named in the list. Give it a descriptive name — "Accountant for LLP Romashka", not "Profile1". It cannot be saved empty.
Profile Group (folder) Optional. Organizes profiles into folders so that the list does not grow too large. Does not affect rights.
Roles (tab, must be ≥ 1) A list of checkboxes — what a person can do. If you remove a necessary role — the user will not see the section or will receive "Insufficient rights". If you add an unnecessary one (for example, "Administration") — you will open access to everything.
Access Restrictions (tab) Types of restrictions: by organizations, individuals, warehouses, counterparties, etc. For each — "All allowed" or "All prohibited, exceptions...". If you forget to restrict — the person will see data from all organizations.
Description Free text: what the profile is for, who to assign it to. Does not affect access, but helps when transferring the database.
Profile assigned manually / service The checkbox "Service" is checked for profiles that service mechanisms (exchange, external processing). They are usually not assigned to access groups.

Procedure

  1. Select the supplied profile "Accountant"Create by copying.
  2. Set the Name.
  3. On the Roles tab, remove the unnecessary ones (for example, roles related to payroll and personnel, if the assistant should not manage them) and keep the roles for the bank, cash, purchases/sales, ESF.
  4. On the Access Restrictions tab, for the type "Organizations", select "All prohibited" and add an exception — your organization. The default value "All allowed" means "sees all LLPs".
  5. Save and close.
  6. Go to Access Groups, create a group based on this profile and add the user (or group of users) to it. Only after this will the rights take effect — the profile itself does not work without a group.

4. Analyzed example

Task: the assistant Akmetova A. should handle primary documents only for LLP "Romashka", see VAT documents (rate 16% in 2026), but not see salaries and not delete documents. There are three organizations in the database.

Steps:

  1. Copy the profile "Accountant" → name it "Accountant for LLP Romashka".
  2. On the Roles tab, remove roles related to payroll and personnel; remove the role "Delete marked objects"; "Interactive deletion" is not present in the basic roles of the accountant anyway.
  3. On the Access Restrictions tab, type "Organizations""All prohibited", exception → LLP "Romashka".
  4. Save the profile.
  5. Access Groups → create a group "Accountants of Romashka", profile — ours, member — Akmetova A.

What Akmetova will get: she enters "Sales", sees documents and balances only for LLP "Romashka"; processes an electronic invoice (ESF) for 116,000 ₸ (100,000 ₸ goods + 16,000 ₸ VAT 16%), generates ESF; opens the account statement — but only for her organization; in the "Payroll" section, she receives an empty list or a message about insufficient rights; the delete mark button is unavailable.

⚠️ Important and honest: the directory "Access Group Profiles" does not generate accounting entries. This is an object of the rights subsystem, not an accounting document. Entries (for example, Dr 1210 Cr 6010 — income from sales, Dr 1210 Cr 3130 — VAT 16%, Dr 7010 Cr 1330 — cost) will appear when the user starts processing sales documents within the rights granted to them. The profile only determines whether they can open this document at all and for which organization.

5. Types of operations (what the directory provides)

There are no separate "types of operations" in the directory — this is not a document. But in practice, you work in three modes:

  • Using the supplied profile — you take the ready-made "Chief Accountant", "Accountant", "HR-Calculator", "Administrator" as is.
  • Copy of the supplied one — the most common and safe way: you copy and trim it for a specific position.
  • Profile from scratch — a completely custom set of roles; rarely used, easy to forget a service role and get a non-working interface.

6. What is generated upon saving

No entries, ESF, or tax returns are created by the directory — these documents are unrelated to it. When saving the profile and assigning it to an access group, the system part of the database changes:

  • user roles of the information database that are part of the related access groups are updated (in BSO this is reflected automatically);
  • movements are written to the service registers of the "Access Management" subsystem: "Access Group Roles" and "Access Restriction Values of Access Groups" (sets of RLS values — specific organizations, warehouses, etc.);
  • access rights cache and session access parameters are rebuilt — sometimes changes are only visible after the user re-enters the program.

7. Print forms

The profile card does not have its own print forms — there is nothing to print. For analyzing rights, use not printing, but service reports of the subsystem: Administration → User and Rights Settings → "Access Rights Reports" (who is in which groups, what roles and restrictions are active). This is the replacement for the "print form" for profiles.

8. Common mistakes

"Insufficient rights to perform an operation on the data". The user receives this when the necessary role is removed from the profile or the restriction by organization has been triggered. Check the "Roles" tab and RLS exceptions — often they forget to add their organization to the exceptions list.

No "Access Restrictions" tab. The checkbox "Restrict access at the record level" is not checked in user and rights settings. Check it — the tab will appear.

"The profile is supplied and cannot be changed" / changes are overwritten after an update. You are editing the supplied profile directly. Do not edit "Accountant"/"Administrator" — make a copy. Supplied profiles revert to the standard upon configuration updates.

The user still sees all organizations. The restriction by organizations still has the default value "All allowed". Change it to "All prohibited" and list the allowed ones.

The rights did not change immediately. The user was working at the time of the profile editing. Ask them to log out and log back in — rights are applied at the start of the session.

Accidentally granted "Full rights/Administrator" role. The person gains access to everything, including deletion and settings. Remove the role, check who else is in this access group.

9. FAQ

Q: How does an access group profile differ from an access group? A: A profile is a template (roles + restrictions). An access group is a specific list of users assigned the profile. One profile can be used in several access groups.

Q: How to give an accountant access only to one organization? A: Check "Restrict access at the record level", in the profile on the "Access Restrictions" tab for the type "Organizations" set "All prohibited" and add the necessary organization as an exception.

Q: Why don't I have an "Access Restrictions" tab? A: The restriction at the record level is disabled. Administration → User and Rights Settings → check the "Restrict access at the record level" checkbox.

Q: Can I edit the supplied profile "Accountant"? A: Technically, you can remove the protection, but you shouldn't: upon updating, it will revert to the standard, and your edits will be lost. Always make a copy.

Q: The user does not see the "Payroll" section, is this normal? A: Yes, if the roles related to payroll and personnel are removed from the profile. This is how access to salaries is restricted. Restore the roles if access is needed.

Q: How to prohibit document deletion? A: Remove from the profile roles that grant interactive and marked deletion (for example, "Delete marked objects"). Then the delete button will become unavailable.

Q: What does the "Service" checkbox mean? A: The profile services technical mechanisms (data exchange, external processing). It is not assigned to regular users.

Q: I changed the profile, but nothing changed for the user. Why? A: Rights are applied upon entry. Have the user end the session and log in again.

Q: How to assign a profile to several people at once? A: In the access group based on the profile, add not individual users, but a user group to the participants — all its members will receive the rights.

Q: Who should be given the "Administrator" profile? A: Only those responsible for configuring the database. It grants full rights, including data deletion and user management.

Q: Does the profile affect amounts and VAT in documents? A: No. The profile determines access, not calculations. The VAT rate of 16%, individual income tax deductions, and other amounts are calculated by the document itself regardless of rights.

10. Related objects

  • Access Groups (Directory.AccessGroups) — this is how the profile is assigned to people. Created based on the profile.
  • Users and User Groups — those included in access groups.
  • Roles (metadata configuration objects) — the "bricks" from which the profile is built.
  • Access Rights Reports — checking who sees what in the end.

How to find out your release

Main Menu → Help → About the program — there you will find the version of the platform and the release of the configuration "Accounting for Kazakhstan, version 3.0 (3.0.74.2)". Check: the names of the fields and supplied profiles may differ between releases.

This guide is prepared for "Accounting for Kazakhstan", version 3.0, release 3.0.74.2.

Частые вопросы

What is the difference between an access group profile and an access group?
A profile is a template (roles + restrictions). An access group is a specific list of users assigned to a profile. One profile can be used in multiple access groups.
How can I give an accountant access to only one organization?
Enable "Restrict access at the record level," in the profile on the "Access Restrictions" tab for the type "Organizations," set "All denied" and add the required organization as an exception.
Why don't I have the "Access Restrictions" tab?
The restriction at the record level is disabled. Administration → User and Rights Settings → check the box "Restrict access at the record level."
Can I edit the supplied profile "Accountant"?
Technically, you can remove the protection, but you shouldn't: upon updating, it will revert to the standard, and your changes will be lost. Always make a copy.
The user does not see the "Payroll" section; is this normal?
Yes, if the payroll and personnel roles are removed from the profile. This is how access to salaries is restricted. Restore the roles if access is needed.
How to prohibit the deletion of documents?
Remove from the profile the roles that allow interactive and marked deletion (for example, "Delete marked objects"). Then the delete button will become unavailable.
What does the "Service" checkbox mean?
The profile serves technical mechanisms (data exchange, external processing). It is not assigned to regular users.
I changed the profile, but the user did not see any changes. Why?
Permissions are applied upon login. Have the user end the session and log in again.

Read also

Источники

Была ли статья полезна?
💼 Нужна помощь с 1С или учётом? Слава КВЦ — многолетняя практика в 1С в Казахстане. Изучите разложенный НК РК 2026 или спросите в чате BuhGPT — ответит за секунды.