---
title: "Directory \"User Groups\" in 1C:Accounting for Kazakhstan 3.0 — Configuration, Composition, Access"
country: KZ
lang: en
author: Сапа Т.И. (https://buhgpt.kz/authors/sapa-ti)
date: 2026-09-07
canonical: https://buhgpt.kz/suraqtar/spravochnik-gruppy-polzovateley-v-1s-buhgalteriya-dlya-ka-en
source: BuhGPT
---

# Directory "User Groups" in 1C:Accounting for Kazakhstan 3.0 — Configuration, Composition, Access

> **TL;DR:** Checked on release 3.0.74.2 "Accounting for Kazakhstan" (version 3.0). You have hired a second accountant — for payroll calculations. You grant him access, and he immediately sees the entire cash register, bank, and contracts with suppliers. This is not allowed. Or conversely:

---

Checked on release 3.0.74.2 "Accounting for Kazakhstan" (version 3.0).

You have hired a second accountant — for payroll calculations. You grant him access, and he immediately sees the entire cash register, bank, and contracts with suppliers. This is not allowed. Or conversely: you have three accountants, and every time the access profile changes, you adjust the rights for each individual. You are tired of it. In both cases, you go to the directory "User Groups" — it gathers people into sets to distribute rights and limit data visibility not one by one, but in bulk.

To be honest, this is an administrative object, not an accounting document. It is not posted, does not create debit/credit entries, does not relate to VAT, accounts like 1210 or 3130, and does not generate electronic invoices (ESF) or tax return forms (FNO). All it can do is group users and participate in record-level access restriction (RLS). Therefore, there will be no "amounts by act" here — there will be people, checkboxes, and rights.

1. Purpose

A user group is a named list of employees in the information base. Groups are needed to (1) distribute access rights not to each person individually, but to the entire group, and (2) limit data visibility at the record level — for example, to show the "Almaty Managers" group only their organization or their counterparties.

2. Where to find

Menu: Administration → User and Rights Settings → Users → in the user list form, the "User Groups" command (on the left, if group hierarchy is enabled).

1C navigation link (Service → "Go to navigation link" or Ctrl+click on the address bar):

e1cib/list/Directory.UserGroups

If the "User Groups" section is not visible — enable the functional option: Administration → User and Rights Settings → Users → "User Groups" (checkbox). Without it, the directory exists, but is hidden in the interface.

2a. How to find out your release

Main menu (≡ icon or "Help") → "About the program". In the opened window: platform version (for example, 8.3.24.x) and configuration release — the line "Accounting for Kazakhstan, version 3.0 (3.0.74.2)". Everything described below relates to release 3.0.74.2; in other releases, the location of commands may differ by a couple of clicks.

3. How to fill out

Open the list of groups → "Create".

Field
Mandatory
Purpose and what happens in case of error

Name
Yes
The name of the group, by which you will select it in access settings. Name it meaningfully: "Payroll Calculators", "Almaty Managers". It cannot be saved empty. A vague name like "Group1" will not help you understand who you opened access for later.

Group (parent)
No
The parent folder if you are building a hierarchy (the directory is hierarchical). Useful when there are many groups. It does not affect rights — it is only for navigation convenience.

Comment
No
A note "for yourself": why the group exists, who manages it. It does not affect anything but saves time for the successor.

Automatically include new users
No
If checked — every newly created user in the information base will automatically join this group. Use it consciously: a newcomer may unexpectedly gain (or conversely lose through RLS) access to data. For a narrow group like "Calculators", keep this checkbox unchecked.

Group composition (table part / list of participants)
Practically yes
Here you use the "Select" button to add specific users. A group without participants is useless — there is no one to distribute rights to. Only registered users in the information base can be selected; an employee from the "Individuals" directory, who does not have access to the database, will not be included here.

After filling out — "Save and close". Rights are recalculated automatically, but the changes will be visible to users already in the database only after they log in again.

The predefined group "All Users" already exists and contains everyone automatically. It cannot be deleted or manually changed — it serves as a "base" for access rules.

4. Analyzed example

Situation: the company has three users — Ivanova (chief accountant), Petrova (payroll calculation), Sidorov (primary documents for goods). Task: Petrova and Sidorov should not see payroll documents, except for their tasks.

Steps:

- Enable the "User Groups" option.

- Create the group "Payroll Calculators".
- Name: Payroll Calculators

- Comment: Access to the Payroll and Personnel section

- The checkbox "Automatically include new users" — unchecked.

- "Select" → add Petrova (and, if necessary, Ivanova).

- Save.

- Go to Access Groups (Administration → Users and Rights → Access Groups) → create/open an access group with the "Payroll Calculation" profile → add the "Payroll Calculators" user group entirely to the composition.

- Check: log in as Sidorov — the "Payroll" section with accrual documents is unavailable; log in as Petrova — it is available.

What "formed" from this data: a record in the "User Groups" directory + entries in the service information register about the group composition (Petrova ↔ Payroll Calculators). No accounting entries, amounts, VAT, or ESF are present here — it is an administrative object. The group "works" within the rights mechanism: when Petrova opens a document, the platform checks her membership in the group and decides whether to show the record or not.

If you had also created a group "Almaty Managers" and set up RLS by organization, the same approach (group → access group → profile with restriction) would make the managers see only documents of their organization. The mechanics are the same.

5. Types of use (what the object provides)

The directory does not have "operation types" like a document, but it actually works in four modes:

- Folder (hierarchy) — parent group for a neat directory structure.

- Manual composition — you select participants yourself. The most common and predictable option.

- Auto-fill — with the checkbox "Automatically include new users", newcomers join the group without your involvement.

- Basis for RLS — the group is substituted in record-level access restriction rules and in the composition of access groups.

6. What is formed upon recording

When recording a group (not "posting" — the object is not posted):

- Record/change of the directory item "User Groups".

- Movements in service information registers about the composition of user groups — the link "user ↔ group". These records are then read by the rights mechanism.

- Recalculation of access rights — if the group is already participating in access groups, the rights of participants are updated.

What is not formed: accounting entries, VAT accounting registers, ESF, FNO, movements in accounts. This is not an accounting document.

7. Printed forms

The "User Groups" directory does not have its own printed forms. For auditing rights, use separate reports from the subsystem: Administration → User and Rights Settings → Rights Reports (for example, "Access Rights", "Users") — there you can output and print the composition of groups and rights.

8. Common errors

"Insufficient rights to perform the operation on the information base" — you are logged in as a non-administrator. Only those with user administration rights can modify user groups. Log in with an account that has full rights.

The "User Groups" section is not in the interface — the functional option is not enabled. Administration → User and Rights Settings → Users → check the "User Groups" checkbox.

The needed employee is not visible in "Select" — they do not have an account to log into the database. First, create the user (Administration → Users → Create, with the checkbox "Access to the program allowed"), then add them to the group.

"The predefined item cannot be deleted" — you are trying to delete or rename "All Users". This group cannot be modified; it is system-defined.

The user still sees "extra" data — membership in the group does not grant rights by itself. The group needs to be included in the Access Group with the appropriate profile. Check the chain: user → user group → access group → profile.

Changes did not take effect immediately — the participant was already in the database. Rights are applied upon the next login; ask them to log in again.

9. FAQ

How does a user group differ from an access group?
A user group is simply a list of people. An access group is a combination of "rights profile + who to grant it to". Rights are granted by the access group; you substitute the user group there to avoid listing individuals one by one.

Is it mandatory to use user groups?
No. If there are few users, access can be granted to each directly. Groups save time when there are many people or the composition changes.

Can one user be in multiple groups?
Yes. Rights accumulate: a person receives everything that each of their groups grants.

What does the checkbox "Automatically include new users" do?
Every newly created user in the information base will automatically join this group. Convenient for "All Employees", risky for narrow groups with extended rights.

Can access to a specific organization be restricted through a group?
Yes — through record-level access restriction (RLS). The group is substituted in access rules, and participants see only permitted organizations/data.

Why does a person still not see anything new after being added to a group?
Because the group is not included in any access group with a profile. Membership alone does not grant rights — a link to a profile is needed.

Does this setting affect accounting — VAT, accounts, reporting?
No. The directory is administrative: it does not create entries, does not calculate VAT at 16%, does not generate ESF. It only manages visibility and rights.

How to delete a group?
Mark for deletion (right-click → "Mark for deletion") and perform "Delete marked objects". The predefined "All Users" cannot be deleted. Before deletion, remove the group from all access groups; otherwise, "dangling" links will remain.

Who can create and edit groups?
Only a user with user administration rights (full rights). A regular accountant cannot create a group.

Are changes applied immediately?
For new logins — yes. A user already working in the database needs to log in again.

10. Related objects

- Directory "Users" — the source of participants; a group without registered users cannot be filled.

- Access Groups and Access Group Profiles — this is where you substitute the user group for the rights to take effect.

- User and Rights Settings — the section where the "User Groups" option is enabled and RLS is configured.

- Access Rights Reports — for checking who is in which group and what they see.

How to find out your release

Main menu → "Help" → "About the program": there you will find the platform version and configuration release. Compare it — commands and options in the rights subsystem may shift from release to release.

The manual was prepared for "Accounting for Kazakhstan", version 3.0, release 3.0.74.2.

---
_BuhGPT — ИИ-помощник для бухгалтеров Казахстана: https://buhgpt.kz_