Checked on release 3.0.74.2 "Accounting for Kazakhstan" (edition 3.0).
The accountant opened the list "Individuals" to correct one salary and saw the salaries of everyone, including the director and founders. According to the internal regulations, she should only see her own section. Or conversely: a new assistant was given rights, he opens the employee card and receives "Insufficient access rights." In both cases, you come right here — to the directory "Access Groups for Individuals". This is the lever by which you divide people in the database into "who sees what."
First and foremost: this is a reference directory for the access restriction mechanism (RLS), not a document. It has no entries, no electronic invoices (ESF)/SNT, and no accounting forms. It does not affect amounts, taxes, or VAT — only whose personal data and which individuals the user can open, modify, or see in reports.
1. Purpose
The directory stores groups by which you distribute individuals (employees, founders, accountable persons) to restrict access. The user sees and edits data only for those individuals whose groups are permitted to them. This way, you protect the salaries of management from the ordinary accountant and separate access between branches or sections.
2. Where to find
The path depends on what you need — to create the group itself or assign it to people.
The directory of groups:
- Administration → User and Rights Settings → Access Groups for Individuals (in the access restriction block).
- Quickly open directly in 1C: menu "Service" → "Go to navigation link" and paste:
e1cib/list/Directory.AccessGroupsForIndividuals
Assigning a group to a person — in the individual card: Salary → Individuals (or Directories → Individuals) → open the card → field "Access Group".
Enabling the mechanism itself (without it, the directory does not work): Administration → User and Rights Settings → check the box "Restrict access at the record level". While the checkbox is unchecked, groups can be filled, but they do not affect data visibility.
2a. How to find out your release
"Help" → "About the program" (or the ℹ️ icon in the upper right corner). In the opened window, you will see the platform version (for example, 8.3.24.x) and the configuration release — "Accounting for Kazakhstan, edition 3.0 (3.0.74.2)". All paths and fields below are described for release 3.0.74.2. In neighboring releases, the location of items may differ slightly.
3. How to fill out
The directory is hierarchical: you can create folders (group-groups) and within them — final access groups. There are few fields, but each works.
| Field | Purpose | What happens if filled incorrectly |
|---|---|---|
| Name (mandatory) | The name of the group, by which you will select it in the individual card and in user settings. Write meaningfully: "Management", "Almaty Branch", "Production". | It cannot be saved empty. An unclear name ("Group1") will lead to mistakes when assigning rights, and the person will see the wrong individuals. |
| Code | Assigned automatically, ensures uniqueness. | Usually left untouched. Manual editing to a duplicate will trigger a warning about a non-unique code. |
| Parent / Belongs to group | The folder in which the group is nested. Needed only for convenient navigation in large databases. | If you make a mistake with the folder, the group will simply be in the wrong place. The hierarchy of folders does not affect access. |
| Comment | Free description: for whom the group is, who approved it. | Does not affect anything, but without it, you won't remember the logic of the division in a year. |
Order of actions:
- Open the directory, click "Create" (or "Create group" for a folder).
- Enter Name. Write a comment if needed.
- Save and close.
- Open the card of each individual and in the field "Access Group" specify the required group. For individuals without a group, access is determined by the general user profile setting.
- In user settings (Administration → Users → user card → Access Rights) in their profile/access group, allow viewing the necessary individual access groups.
- Ensure that the checkbox "Restrict access at the record level" is checked.
The exact relationship between "user profile" and "permitted individual groups" depends on the configured access group profiles in your database — this point should be verified with the administrator, as it is version- and setting-dependent.
4. Analyzed example
Task. In LLP "Altyn", there are two accountants. Aigul manages production personnel, Madina — administrative. The salary of the director and founders should not be visible to either; it is managed by the chief accountant.
Step 1. Create three groups:
- "Production"
- "Administration"
- "Management"
Step 2. Distribute individuals among groups (in the card of each — the field "Access Group"):
| Individual | Salary, ₸ | Access Group |
|---|---|---|
| Welder Akhmetov | 250,000 | Production |
| Accountant Kim | 300,000 | Administration |
| Director Ospanov | 1,200,000 | Management |
Step 3. Assign rights to users:
- Aigul → allowed group "Production".
- Madina → allowed group "Administration".
- Chief Accountant → allowed all three groups.
Result. Aigul sees only Akhmetov in the list "Individuals". When attempting to open Ospanov's card, she will receive "Insufficient access rights." In her database, she has 250,000 ₸ in salary reports for her section — no foreign amounts. The chief accountant sees everyone, including the director's salary of 1,200,000 ₸.
This example does not generate entries — salary accrual and taxes (individual income tax 10%, pension contributions 10%, social health insurance 3%, voluntary health insurance 2%, social tax 5%, social tax 6%) are considered separate documents "Salary Accrual". The directory only determines which users will see these amounts. That is why there are no accounts like 3350 or 3120 here — the object is not accounting.
5. Types of operations
The directory does not have separate "types of operations" like a document. What it allows you to do:
- Create a final access group — a working unit of restriction.
- Create a folder (group-group) — for structuring a large list.
- Mark for deletion / unmark — remove an unused group.
- Use as a selection value — the group is inserted into the individual card and in rights settings.
6. What is formed when used
Since this is a directory, and not a document, upon saving:
- No entries. Debit/Credit are not formed.
- No electronic invoices (ESF), SNT, or other electronic documents are created — the object has no relation to the ESF information system.
- No movements in accounting registers.
What actually happens: the group value is recorded in the directory, and when assigned to an individual — it enters the service registers of the access restriction mechanism (sets of access values). The platform then uses these sets in RLS conditions, filtering out "foreign" records in lists, reports, and when opening cards. This leaves no visible accounting trace.
7. Printed forms
The directory does not have its own printed forms — there is no need to print the access group. Only standard service mechanisms of the list are available: "More" → Export list (to export the list of groups to a spreadsheet or Excel) and the standard report on access rights from the administration section, if it is connected.
8. Common errors
"Insufficient access rights" when opening an individual or salary report. The user is not permitted the group to which the person belongs. Check: in the individual card — which group is specified; in user rights — is it permitted? Add the group to permitted or remove it from the individual.
The accountant sees everyone, although groups are set up. The checkbox "Restrict access at the record level" is not checked (Administration → User and Rights Settings). Without it, RLS does not work, and groups are decorative.
"Failed to save ... Field 'Name' is not filled." Enter the name — it is mandatory.
"The item cannot be deleted as it is in use" / "References to the object found." The group is assigned to individuals or specified in rights. First, reassign individuals to another group and remove it from rights settings, then delete it through "All functions" → Deleting marked objects.
A new employee has "disappeared" from the accountant's list. The individual does not have an access group filled, and the user profile is set strictly. Assign the correct group to the person.
Duplicate groups ("Production" and "Production "). Appears with manual input with a space/typo. Maintain a single list, mark extras for deletion, and move individuals to the correct group.
9. FAQ
Is it mandatory to fill out access groups for individuals? No. If access restriction to personal data is not needed and all users can see everyone, the directory does not need to be maintained. It is only needed when access restriction at the record level is enabled.
How does this differ from "User Access Groups"? "Access Groups" (and access group profiles) determine what rights the user has. "Access Groups for Individuals" determine which individuals these rights apply to. The first is about the user, the second is about the object (individual).
How to assign an access group to an individual? In the individual card (Salary → Individuals), there is a field "Access Group" — select the required group and save.
Does the directory have entries or printed forms? No. This is a service object of the access mechanism: it does not provide entries, electronic invoices (ESF)/SNT, or accounting printed forms.
Does the access group affect salary accrual, individual income tax, or social tax? No. Amounts and taxes are considered accrual documents and do not depend on groups. The group only affects who will see this data.
Why does the accountant not see some employees after the setup? These employees are in groups that the user is not permitted, or they do not have a group filled at all. Check the individual cards and permitted groups in user rights.
Can a hierarchy (folders) be built? Yes, the directory is hierarchical — create folders for convenient navigation. But the rights are influenced by the assigned final group to the individual, not the folder structure itself.
How to delete an unnecessary group? First, reassign all individuals from it to another group and remove it from rights settings, then mark it for deletion and perform "Delete marked objects." The program will not allow deletion while there are references.
Who can edit this directory? Users with administration/access rights settings. Ordinary accountants usually do not have access to it — this is part of the database security setup.
Do groups work if the access restriction checkbox is off? No. They can be filled, but actual restriction is only activated by checking the "Restrict access at the record level" checkbox.
10. Related objects
- Individuals — here the group is assigned to a specific person (field "Access Group"). The main "consumer" of the directory.
- Employees — linked to individuals; the visibility of the employee inherits the restriction by the group of their individual.
- Users / Access Groups / Access Group Profiles — here permissions are granted to individual groups. Without this linkage, the directory does not have an effect.
- User and Rights Settings (Administration) — the point of enabling RLS with the checkbox "Restrict access at the record level".
The directory is not introduced "based on" documents and does not itself serve as a basis for documents — it is filled manually when setting up access.
How to find out your release
Open "Help" → "About the program": there you will find the platform version and configuration release. The instructions are relevant for "Accounting for Kazakhstan", edition 3.0, release 3.0.74.2. If you have a different release, check the location of items in the section "Administration → User and Rights Settings".
Prepared for release 3.0.74.2 "Accounting for Kazakhstan" (edition 3.0).
