Checked on release 3.0.74.2 "Accounting for Kazakhstan" (version 3.0).
The counterparty calls and asks: "Let me access your database and view my reconciliation acts and invoices, so I don't have to bother your accountant every time." Or an auditor remotely wants to read documents but without the right to change anything. Or you are keeping records on an outsourcing basis, and the client wants to see their entries themselves. In all these cases, you do not create a regular employee — you open the directory "External Users" and create a guest with limited rights and their own login.
First, an important and honest warning: this is an administrative (service) directory, not an accounting document. It does not make entries, does not issue electronic invoices (ESF) and tax invoices (SNT), does not calculate VAT and individual income tax (IIT), and does not have printed invoices. It manages who and with what rights accesses the database from outside. Therefore, the sections on entries and taxes below are adapted to the real nature of the object — inventing non-existent movements in accounts would be deceitful.
1. Purpose
The directory stores external (third-party) users of the information database: counterparties, individuals, auditors, clients on outsourcing. Each such user is linked to an "authorization object" (usually to an element of the directory "Counterparties" or "Individuals") and gains access to the program with limited rights. They are separated from regular employees by a separate list and separate profiles of rights.
2. Where to find
Path in the interface:
Administration → User and Rights Settings → section "External Users".
First, you need to check the box "External Users" — without it, the list is hidden, and you cannot create a guest. After enabling, a link "External Users" appears, opening the list itself.
To open the list directly in 1C: copy the navigation link and paste it through "Service → Go to Navigation Link" (or Main Menu → "All Functions"):
e1cib/list/Directory.ExternalUsers
2a. How to know your release
Main menu (icon ≡ or "Help") → "About the Program". In the opened window, you will see the platform version (for example, 8.3.24.x) and the configuration release — a line like "Accounting for Kazakhstan, version 3.0 (3.0.74.2)". This instruction refers specifically to release 3.0.74.2. If you have a different release, the location of checkboxes and the composition of the functionality may differ slightly.
3. How to fill
Creation takes place in the form of a directory item. Let's break down each field.
| Field | Required | Purpose / what happens in case of error |
|---|---|---|
| Authorization Object | Yes | Who exactly you are letting in: a counterparty or an individual. This is the "identity" of the external user. If not filled in — the record will not be saved. If you make a mistake with the object — the guest will gain access to someone else's data. |
| Name | Auto | Filled in from the authorization object, usually not edited separately. Serves for searching in the list. |
| Access to the program allowed | — | The main "switch". If unchecked — the person will not enter the database, even if they have a login and password. When checked, authentication fields open. |
| 1C:Enterprise Authentication | — | Login and password access. The main method for externals. If unchecked — password access will not work. |
| Name (login) | Yes, if access is allowed | What the person enters upon login. Must be unique across the entire database (including among employees). A duplicate will not be saved by the database. |
| Password / Confirmation | Yes | Initial password. If complexity checking is enabled in the settings, a weak password will not be accepted. |
| Require password change upon login | — | The guest will change the password themselves upon first login. Recommended: you do not store "someone else's" password. |
| User is prohibited from changing password | — | On the contrary — firmly fixes the password. Set consciously. |
| Show in selection list | — | The login will be visible in the login window. For externals, it is usually unchecked — do not expose the list of guests. |
| OpenID / certificate authentication | — | For integrations and SSO. Rarely used in standard accounting. |
| Expiration date (limit to...) | — | Automatic disconnection of access by date. Convenient for an auditor "for two weeks". |
| Invalid | — | Soft disconnection: the user remains in the database for history but cannot log in. The main way to "fire" a guest without deletion. |
| Access Groups (tab "Access Rights") | Yes | Set of rights. Without at least one access group, the person will enter "into emptiness" — will not see any objects. Profiles are taken from those marked as profiles for external users. |
| Comment | — | For yourself: who, why, until what date. |
The mandatory minimum for a working guest: authorization object → checkbox "Access allowed" → login and password → at least one access group with an appropriate profile.
4. Analyzed Example
Task: the counterparty LLP "Astra" requests access for their accountant to view reconciliation acts and invoices. They should not change anything — just read.
Steps:
- Administration → User and Rights Settings → check the box "External Users" (if it was not checked yet).
- Open the list "External Users" → "Create".
- Authorization Object → type "Counterparty" → select LLP "Astra". The name will be filled in automatically.
- Check "Access to the program allowed".
- Login:
astra_buh. Set a temporary password, check "Require password change upon login", uncheck "Show in selection list". - Tab "Access Rights" → add an access group with a profile, for example "External User (read-only)" (the profile must be created in advance and marked as a profile for externals).
- Save and close.
- Provide the counterparty with the login
astra_buhand the temporary password through a secure channel.
What happened in terms of numbers and accounts: nothing. There are no entries — this is a directory, not a document. No 1210, 3310, 6010, 3130 are affected, VAT 16% is not calculated, ESF/SNT are not generated. The only "result of the operation" is that a new guest appeared in the database, who upon login will see only what the profile allows (in our case — reconciliation acts and invoices in read mode). If you mistakenly gave a profile with the right to change sales documents — the guest could change amounts and VAT rates in your documents. Hence the rule: for counterparties, provide profiles only for reading.
5. Types of "Operations" (Application Variants)
The directory does not have "types of operations" in the sense of documents. In practice, the following are distinguished:
- By authorization object: external user-counterparty (legal entity/sole proprietor) and external user-individual.
- By access method: 1C:Enterprise authentication (login/password), OpenID/authentication server, certificate access.
- By level of rights: read-only (view their documents), read + limited input, access to specific reports.
- By duration: indefinite access or limited until a date (audit, one-time check).
6. What is formed upon recording
When recording an item with allowed access, the following is created/changed:
- Directory item "ExternalUsers" — the guest's card itself.
- User of the information database — an account for login (login, password, authentication settings). Visible in the list of users of the platform's information base.
- Membership in access groups — records linking the user with rights profiles (information register of access groups).
- User settings (interface, regional settings, etc.) upon first login.
What the document does not do (important to understand): there are no entries in accounts; no movements in accounting registers and tax registers; ESF in the ESF and SNT information systems are not issued; calculations of VAT, IIT, OPP, SO, etc. are not made. This is purely an administrative record.
7. Printed Forms
The directory does not have its own printed forms (invoice, waybill, act) — there is nothing to print here. For access control, use service reports from the "User and Rights Settings" section:
- "Access Rights" (for a specific user) — what the guest actually sees;
- "Report on Access Groups" — who and which groups they belong to;
- journal "Change Registration" / change history — who and when edited the card.
8. Common Errors
"External users are prohibited in the program" (or the list is unavailable) — the checkbox "External Users" is not checked. Solution: Administration → User and Rights Settings → enable the checkbox.
"User with the name '...' already exists" — the login is taken (including by an employee). Solution: set a unique login, for example with the prefix ext_.
"The field 'Authorization Object' is not filled" — you did not select a counterparty/individual. Solution: fill in the authorization object.
"Password does not meet policy requirements" — complexity checking is enabled. Solution: password of the required length with numbers/cases or relax the policy in the settings.
"User has not been assigned any access groups" — the guest will log in and see nothing. Solution: on the "Access Rights" tab, add a group with a profile for external users.
"Login to the program is impossible, user marked as invalid" — the checkbox "Invalid" is checked. Solution: uncheck it if access is needed again.
"There are no profiles for external users" — when adding an access group, it is empty. Solution: create an access group profile and mark it as for external users.
9. FAQ
What is the difference between an external user and a regular one? Regular users (directory "Users") are your employees. External users are third parties (counterparties, individuals, auditors) with a separate list, separate rights profiles, and, as a rule, access only to "their" data.
How to enable external users? Administration → User and Rights Settings → checkbox "External Users". While it is unchecked, the directory is unavailable.
Can an external user change my documents? Only if you gave them a profile with modification rights. For counterparties and auditors, provide "read-only" profiles.
How to temporarily disable a guest without deleting? Check the "Invalid" checkbox or uncheck "Access to the program allowed". History and links will be preserved.
Can an external user be deleted? Yes, through marking for deletion and processing "Delete marked objects". But it is often safer to make them "Invalid" — to avoid losing action history.
Will the guest see documents of all counterparties or only their own? This is determined by the profile and access restriction settings at the record level (RLS). A properly configured profile shows only data related to their authorization object.
Does this record make entries or ESF? No. This is an access directory. Entries, ESF, SNT, VAT calculations of 16%, and taxes are made by accounting documents, not by the user card.
How to set access "until date" for an auditor? Enable the expiration date restriction and specify the date. After that, access will automatically close.
What to do if the guest forgot their password? Open their card, set a new temporary password, and enable "Require password change upon login". Provide the password through a secure channel.
Is the guest's login visible to everyone in the login window? Only if "Show in selection list" is checked. For externals, this checkbox is usually unchecked for security reasons.
10. Related Objects
- Based on what it is created: directory item "Counterparties" or "Individuals" — this is the authorization object of the external user.
- Closely related: "Access Group Profiles" (marked "for external users") and "Access Groups" — they define rights; "Users" — a similar directory for employees.
- What is viewed nearby: reports "Access Rights" and "Access Group Report".
