Access and permissions

Which permission each Finance and Accounting screen needs, who may see and change what, and the rules that keep people from approving their own work.

On this page (42)

Permissions by screen

ScreenMenuPermission needed
Accounting dashboardFinance > Dashboarddashboard.accounting (blocks for collections, treasury, budgets only shown to holders of those rights)
Journal entries (list)Finance > Accounting > Journal entriesjournal.view (list); creating needs journal.post on the server
Journal entry pageJournal entries > New / open an entryjournal.view; journal.post (create/edit/post), journal.prepare (submit, withdraw, cancel), journal.approve (approve/reject), journal.reverse (reverse/reset)
Journal itemsFinance > Accounting > Journal itemsjournal.view
Chart of accountsFinance > Configuration > Chart of accountscompany.view (read); reference.manage on the server, company admin in the screen, to change
Posting accountsFinance > Configuration > Posting accountscompany.view (read); reference.manage (change)
Journals (journal types)Finance > Configuration > Journalsjournal.view (read); reference.manage (change)
Accounting periodsFinance > Configuration > Accounting periodsjournal.view (read); period.lock (generate, status, sign off, send back, template); period.adjust (request reopen); period.reopen (reopen, approve requests, policy)
Period controls (lock date)Finance > Configuration > Period lock dateScreen: company admin; server: journal.post on POST /finance/lock
Opening balancesFinance > Accounting > Opening balancesjournal.view; journal.prepare (create, upload, validate, back to draft); journal.approve; journal.post; journal.reverse (roll back)
Trial balance (classic)Finance > Reporting > Trial balance (classic)report.view (route policy)
CurrenciesFinance > Configuration > CurrenciesRead: any signed-in user; change: deployment superuser only
Exchange ratesFinance > Configuration > Exchange ratesfx.view; fx.manage (enter); fx.approve (approve)
Exchange revaluationFinance > Accounting > Exchange revaluationfx.view (read); journal.post (post, reverse due); fx.approve (policy)
Currency translationFinance > Accounting > Currency translationfx.view
Recurring entriesFinance > Accounting > Recurring entriesjournal.view; journal.prepare (create/edit/discard); journal.approve (approve/pause/resume/end); journal.post (run)
AccrualsFinance > Accounting > Accrualsjournal.view; journal.post (post)
DeferralsFinance > Accounting > Deferralsjournal.view; journal.prepare (create, cancel); journal.approve (approve); journal.post (release)
Year-end closeFinance > Accounting > Year-end closejournal.view; period.lock (prepare, execute, cancel); period.reopen (reverse)
Posting profilesFinance > Configuration > Posting profilesjournal.view; account.manage (create/edit/new version/discard); journal.approve (approve/retire)
Payments and receiptsFinance > Accounting > Payments and receipts (also Receivables > Receipts, Payables > Payments)payment.record (record, allocate, settle); payment.reverse (reverse); journal.view to read
Register payment / Register receipt dialogAny posted invoice or bill > Register payment (dialog)payment.record
Payment recordPayments and receipts > open a paymentpayment.record; payment.reverse
Open itemsFinance > Accounting > Open items (also Receivables > Customer open items, Payables > Vendor open items)journal.view (read); payment.record (allocate, undo)
Bank reconciliation (statements)Finance > Accounting > Bank reconciliation (also Banking > Bank reconciliation)journal.view (read); journal.prepare (import, match, close); bankrec.prepare / bankrec.approve (review steps)
Bank reconciliation workspaceBank reconciliation > open a statement (AI assist workspace)bankrec.view; bankrec.prepare; bankrec.approve; bankrec.configure (policy)
Reconciliation rules and import profilesFinance > Configuration > Reconciliation rules and Bank import profilesbankrec.view (read); bankrec.configure (change)
Customer statementsFinance > Receivables > Customer statementsreport.view
Receivables agingFinance > Receivables > Receivables agingreport.view
Write-offs (customer and supplier)Finance > Receivables > Write-offs / Payables > Write-offsjournal.view (read); payment.record (request, cancel own, recover); journal.approve (approve, refuse); journal.reverse (reverse); account.manage (tolerances)
DisputesFinance > Receivables > Disputes (and Payables)journal.view (read); payment.record (open, edit, resolve, cancel)
Collections worklistFinance > Receivables > Collectionscollections.view (read); collections.manage (log contacts)
Promises to payFinance > Receivables > Promises to paycollections.view; collections.manage
Dunning runsFinance > Receivables > Dunningcollections.view; collections.manage
Collection policy and dunning levelsFinance > Configuration > Collection policy and dunning levelscollections.view (read); collections.configure (change)
Payment proposals (list)Finance > Payables > Payment proposalsjournal.view (read); payment.prepare (create); account.manage (policy)
Payment proposal recordPayment proposals > open a proposalpayment.prepare (prepare, submit, hold, cancel); payment.approve (approve, send back, download file); payment.release (release, record answer, download file)
Supplier statementsFinance > Payables > Supplier statementsreport.view
Payables agingFinance > Payables > Payables agingreport.view
Payment dueFinance > Payables > Payment duereport.view
Goods received not invoiced (GRNI)Finance > Payables > Goods received not invoicedreport.view
Payment holdsFinance > Payables > Payment holdsjournal.view (read); payment.prepare (place); payment.approve (release)
Credit positionFinance > Credit control > Credit positionpartner.view (read); credit.release (apply overdue rule)
Credit overridesFinance > Credit control > Overridespartner.view (read); document.confirm (request); credit.release (approve, refuse)
Credit reservationsFinance > Credit control > Reservationspartner.view (read); credit.release (release)
Credit groupsFinance > Credit control > Credit groupscredit.limit.reveal (read); credit.release (create, edit)
Expected credit loss runsFinance > Credit control > Expected credit lossreport.view (read); ecl.manage (prepare, cancel); ecl.approve (post, reverse)
Provision matricesFinance > Configuration > Provision matricesreport.view (read); ecl.manage (build); ecl.approve (approve)
Budgets (list)Finance > Planning > Budgetsreport.view (read, menu); budget.manage (create, edit, lines, new version, discard); budget.approve (approve)
Budget pageBudgets > open a budgetbudget.manage / budget.approve
Budget against actualFinance > Planning > Budget against actualreport.view
Budget control policiesFinance > Planning > Budget control > Control policiesreport.view (read); budget.manage (change)
Budget commitmentsBudget control > Commitmentsreport.view (read); budget.manage
Budget overridesBudget control > Overridesreport.view (read); budget.manage (request, cancel own); budget.approve (approve, refuse, cancel any)
Treasury registerFinance > Treasury > Registertreasury.view (read); treasury.manage (register, edit, status, drawing); treasury.release (release); collateral shown only to manage or release holders
Instrument pageTreasury > open an instrumenttreasury.manage / treasury.release
Treasury maturitiesFinance > Treasury > Maturitiestreasury.view
Treasury instrument typesFinance > Configuration > Treasury instrument typestreasury.view (read); treasury.manage (change)
Bank accountsFinance > Banking > Bank accountscompany.view (read, no mask lifted); reference.manage (create, change); screen button for company admins only
Bank statementsBanking > Bank reconciliation > Statementsjournal.view (read); journal.prepare (import, create)
Import statement wizardStatements > Import statementjournal.prepare (preview and import)
Bank reconciliation workspaceBank reconciliation > Reconciliationjournal.view / bankrec.view (read); journal.prepare and bankrec.prepare (match, validate, submit); bankrec.approve (approve, return)
Bank exceptionsBank reconciliation > Exceptionsbankrec.view (read); bankrec.prepare (change)
Reconciliation policy and rules (tab)Bank reconciliation > Rules (tab)bankrec.view / bankrec.configure
Mapping studioBank reconciliation > Mapping studio (tab)n/a
Bank import profilesFinance > Configuration > Bank import profilesbankrec.view (read); bankrec.configure (change). Menu entry needs bankrec.view
Reconciliation rulesFinance > Configuration > Reconciliation rulesbankrec.view (read); bankrec.configure (change)
Cash positionFinance > Banking > Cash positionreport.view
Cash forecastFinance > Banking > Cash forecastreport.view (calculate, read); journal.prepare (save a version)
Report runnerFinance > Reporting > (each report) and Accounting reportsreport.view (run, definitions, drill-down, saved views); report.export (export); doc.print (PDF); audit.view (Journal Audit)
Trial balance (report)Reporting > Trial Balance (report engine)report.view
Financial statementsReporting > Profit & Loss, Balance Sheet, Cash Flowreport.view
Ledgers and booksReporting > General Ledger, Journal Register, Day Book, Bank Book, Cash Book, Customer / Vendor ledgers and balances, Reversed entriesreport.view
Tax reportsReporting > Tax Return Summary, Tax Detail, Reverse Chargereport.view
Management P&L by dimensionReporting > Cost Centre / Profit Centre / Department / Project / Branch P&Lreport.view
Exchange and audit reportsReporting > Realized / Unrealized Exchange Differences, Journal Auditreport.view; audit.view for Journal Audit
Accounting settingsFinance > Configuration > Settingsperiod.lock (change fiscal start month and lock); reading shown to any member
Taxes (tax codes)Finance > Configuration > Taxescompany.view (read); reference.manage (create, change, rates, install pack)
Tax code recordTaxes > open a taxreference.manage
Install a tax packTaxes > Install a country's taxesreference.manage
Fiscal positions (list)Finance > Configuration > Fiscal positionscompany.view (read); reference.manage (change)
Fiscal position recordFiscal positions > open a positionreference.manage
Dimension valuesFinance > Configuration > Dimensions (Branch, Cost centre, Department, Project, Profit centre)company.view (read); reference.manage (change)
Account structure rulesFinance > Configuration > Account structure rulescompany.view (read); reference.manage (change)
Valid dimension combinationsFinance > Configuration > Valid combinationscompany.view (read, try); reference.manage (change)
Distribution modelsFinance > Configuration > Distribution modelscompany.view (read, suggest); reference.manage (change)
Finance Features (switches)Administration > Applications > Finance > Featuresapps.configure (propose); apps.config.approve (decide)
Finance Fields (switches)Administration > Applications > Finance > Fieldsapps.configure / apps.config.approve

Journal entries

RuleWhat the system does
Viewing needs journal.viewMenu hidden; API refused 'You do not have permission for this action.'

Journal entry page

RuleWhat the system does
Preparer cannot approve own entryRefused: 'Whoever prepares a journal does not approve it. Another person with the approval permission has to agree.'
Each step needs its own rightApprove needs journal.approve, post needs journal.post, reverse/reset need journal.reverse; each refused otherwise
Company isolation'Record not found.'; another company's account or partner on a line -> 'Line 1: the account is not in this company.'

Accounting periods

RuleWhat the system does
Locked period never reopensRefused: '<Period> is locked. A locked period is not reopened through the application.'
Reopen needs period.reopenRefused: 'Reopening <Period> needs the right to reopen a period.'
Reopen request approved by someone elseRefused: 'Somebody other than the person who asked has to approve a reopen.'

Opening balances

RuleWhat the system does
Preparer cannot approve the batchRefused: 'Somebody other than the person who prepared, uploaded or validated this batch has to approve it.'

Access review

RuleWhat the system does
Duty conflicts flaggedAccess review lists 'Prepares journals and posts them' (high) / 'Posts journals and closes the period' (medium)

Exchange rates

RuleWhat the system does
Entering and approving need different rightsBoth refused 'You do not have permission for this action.'

Revaluation policy

RuleWhat the system does
Policy change needs fx.approveRefused

Recurring / deferrals / posting profiles / year-end

RuleWhat the system does
Four-eyes everywhere the code has itEach refused with its 'Somebody other than ...' message

Year-end close

RuleWhat the system does
Reverse needs period.reopenRefused

Currencies

RuleWhat the system does
Only a superuser changes decimalsRefused: 'Only an administrator of the deployment may change a currency's decimal places...'

Exchange revaluation

RuleWhat the system does
Company isolationNothing of the other company; 'Record not found.'

Payments and receipts

RuleWhat the system does
Record permissionRefused; nothing posted; payment.record is the code the server checks
Reverse is a separate permissionFirst refused; second succeeds and posts the reversing entry
Optimistic locking on editsSecond gets 'Somebody changed this write-off. Reload it and look again.' (same for dispute, hold, group, promise levels)

Register payment dialog

RuleWhat the system does
Idempotent keySecond is refused as a 409: 'This payment key was already used for different details.'
Company isolation'Record not found.' or 'Choose the customer or supplier whose money this is.'; no cross-company data returned

Open items

RuleWhat the system does
Allocate is a money permissionRefused (payment.record needed); viewing open items works

Payment holds

RuleWhat the system does
Place versus lift (segregation)Placer cannot lift unless he also holds payment.approve; lifting needs a reason

Payment proposal record

RuleWhat the system does
Preparer cannot approve'Somebody other than the person who prepared this proposal has to approve it.'
Releaser independence'The person who releases a payment is neither the person who prepared it nor the one who approved it.' The preparer is always refused
Authorised signers'You are not an authorised signer of <bank account>.'
Bank file tamper checkRelease pays nothing, withdraws the approval and holds the line; a fresh independent approval is needed
Bank file and bank details visibilityDownload refused ('Only somebody who approves or releases payments can download the bank file.'); bank detail shown masked

Write-offs (customer and supplier)

RuleWhat the system does
Approver is not the requester'Somebody other than the person who asked has to approve a write-off.'
Approve, reverse and tolerance permissionsApprove needs journal.approve; reverse needs journal.reverse; tolerances need account.manage
Cancel scope'Only the person who asked, or an approver, can cancel this.'

Bank reconciliation workspace

RuleWhat the system does
Maker-checker on reconciliationOn: refused 'You submitted this reconciliation, so someone else has to approve it (maker-checker).' Off: same person may approve (policy change needs bankrec.configure)
Second approver on bank reconciliationRefused while the policy (or rule) has the second approver on; allowed only when the policy sets it off.
View, prepare, configure and approve are separateView reads only; prepare matches, validates, submits; approve approves or returns; configure edits policy, rules, import profiles. Missing right -> 403.

Credit overrides

RuleWhat the system does
Override approver is not the requester'Somebody other than the person who asked has to approve a credit override.'
Blocked customers'A blocked or blacklisted customer cannot be given a credit override.'

Credit groups

RuleWhat the system does
Credit limits are confidentialThe list is refused; limits are not shown

Expected credit loss runs

RuleWhat the system does
Matrix maker-checker'Somebody other than the person who built this matrix has to approve it.'
Provision poster is not the preparer'Somebody other than the person who prepared the provision has to post it.'

Collection policy and dunning levels

RuleWhat the system does
Collections permissionsContacts and runs need collections.manage; the policy and levels need collections.configure
Fees need a legal confirmation on recordSwitching on is audited with the reviewer's note; switching off is audited; both need collections.configure

Customer statements

RuleWhat the system does
Reports are read-only and permission-gatedRefused; with the right they read only their company's data

Budgets (list)

RuleWhat the system does
Viewing needs report.view; changing needs budget.manageThe list opens; New budget is hidden and the API answers 403 for create, lines, version, discard.
Company isolation'Record not found.'

Budget page

RuleWhat the system does
Budget approval needs budget.approve and a second personBuilder: 'Somebody other than the person who built this budget has to approve it.' Without the right: 403.

Budget overrides

RuleWhat the system does
Override approval is maker-checker'Somebody other than the person who asked has to approve a budget override.'
Override scope is boundedAn override works only for its own account, before it ends, and until Used reaches May exceed by.

Budget control policies

RuleWhat the system does
Block policy cannot be bypassed from other screensEvery posting goes through the same check (ledger.post_journal); only reversal, year-end, opening, FX and ECL journals skip it.

Budget commitments

RuleWhat the system does
Releasing needs budget.manage and a reason403; 'Say why it is released or cancelled.'

Treasury register

RuleWhat the system does
View, manage and release are separate rightsView: read lists and instrument pages. Manage: register, edit, change status, drawings. Release: the Release action only. Missing right -> 403.
Company isolation'Record not found.'
Fields switch finance.treasury.notesRefused; with Required, an instrument without notes is refused.

Instrument page

RuleWhat the system does
Release is maker-checker where the type says so'Somebody other than the person who registered this instrument has to release it.' Untick the type's second-person rule and A can release.
Releasing through the status route needs the release right403 'Releasing an instrument needs the treasury release right.'
Collateral is masked for view-only usersCollateral details are hidden and replaced by 'held (details are restricted)'; the JSON has masked true and empty fields.

Bank accounts

RuleWhat the system does
Bank details are sealed and maskedOnly the masked IBAN, last 4 of the account number and has_iban / has_swift flags are returned; the full values are never sent.
Changing a beneficiary leaves a trailBeneficiary version rises, History shows who and when, audit 'bank_account.beneficiary_changed'. Only reference.manage can change (403 otherwise).

Import statement

RuleWhat the system does
Importing needs journal.prepare403.

Bank statements

RuleWhat the system does
Company isolation'Record not found.'

Cash forecast

RuleWhat the system does
Saving a version needs journal.prepare, reading report.viewCalculate works; saving is refused 403.

Report runner

RuleWhat the system does
Running needs report.view, export needs report.export, PDF needs doc.printRun works; export 403; PDF 403 without doc.print.
Company isolation of filters and results'An account in the filter is not in this company.' and no foreign rows.

Exchange and audit reports

RuleWhat the system does
Journal Audit needs audit.view403; the other reports remain available.

Taxes

RuleWhat the system does
Tax codes: read for members, change needs reference.manage403 for each; list readable.

Fiscal positions

RuleWhat the system does
Fiscal positions need reference.manage to change403; position list readable.

Accounting settings

RuleWhat the system does
Fiscal start month and lock need period.lock403.

Valid combinations

RuleWhat the system does
Dimension rules change who can postPostings that passed yesterday are refused with the rule name; only reference.manage can add or remove it.

Finance Features

RuleWhat the system does
Configuration changes are two-personSelf review refused; missing right gives 403; every proposal and decision is audited.
Protected controls cannot be turned off'A protected control cannot be turned off.'