Access and permissions
Which permission each Finance and Accounting screen needs, who may see and change what, and the rules that keep people from approving their own work.
On this page (42)
Permissions by screenJournal entriesJournal entry pageAccounting periodsOpening balancesAccess reviewExchange ratesRevaluation policyRecurring / deferrals / posting profiles / year-endYear-end closeCurrenciesExchange revaluationPayments and receiptsRegister payment dialogOpen itemsPayment holdsPayment proposal recordWrite-offs (customer and supplier)Bank reconciliation workspaceCredit overridesCredit groupsExpected credit loss runsCollection policy and dunning levelsCustomer statementsBudgets (list)Budget pageBudget overridesBudget control policiesBudget commitmentsTreasury registerInstrument pageBank accountsImport statementBank statementsCash forecastReport runnerExchange and audit reportsTaxesFiscal positionsAccounting settingsValid combinationsFinance Features
Permissions by screen
| Screen | Menu | Permission needed |
|---|---|---|
| Accounting dashboard | Finance > Dashboard | dashboard.accounting (blocks for collections, treasury, budgets only shown to holders of those rights) |
| Journal entries (list) | Finance > Accounting > Journal entries | journal.view (list); creating needs journal.post on the server |
| Journal entry page | Journal entries > New / open an entry | journal.view; journal.post (create/edit/post), journal.prepare (submit, withdraw, cancel), journal.approve (approve/reject), journal.reverse (reverse/reset) |
| Journal items | Finance > Accounting > Journal items | journal.view |
| Chart of accounts | Finance > Configuration > Chart of accounts | company.view (read); reference.manage on the server, company admin in the screen, to change |
| Posting accounts | Finance > Configuration > Posting accounts | company.view (read); reference.manage (change) |
| Journals (journal types) | Finance > Configuration > Journals | journal.view (read); reference.manage (change) |
| Accounting periods | Finance > Configuration > Accounting periods | journal.view (read); period.lock (generate, status, sign off, send back, template); period.adjust (request reopen); period.reopen (reopen, approve requests, policy) |
| Period controls (lock date) | Finance > Configuration > Period lock date | Screen: company admin; server: journal.post on POST /finance/lock |
| Opening balances | Finance > Accounting > Opening balances | journal.view; journal.prepare (create, upload, validate, back to draft); journal.approve; journal.post; journal.reverse (roll back) |
| Trial balance (classic) | Finance > Reporting > Trial balance (classic) | report.view (route policy) |
| Currencies | Finance > Configuration > Currencies | Read: any signed-in user; change: deployment superuser only |
| Exchange rates | Finance > Configuration > Exchange rates | fx.view; fx.manage (enter); fx.approve (approve) |
| Exchange revaluation | Finance > Accounting > Exchange revaluation | fx.view (read); journal.post (post, reverse due); fx.approve (policy) |
| Currency translation | Finance > Accounting > Currency translation | fx.view |
| Recurring entries | Finance > Accounting > Recurring entries | journal.view; journal.prepare (create/edit/discard); journal.approve (approve/pause/resume/end); journal.post (run) |
| Accruals | Finance > Accounting > Accruals | journal.view; journal.post (post) |
| Deferrals | Finance > Accounting > Deferrals | journal.view; journal.prepare (create, cancel); journal.approve (approve); journal.post (release) |
| Year-end close | Finance > Accounting > Year-end close | journal.view; period.lock (prepare, execute, cancel); period.reopen (reverse) |
| Posting profiles | Finance > Configuration > Posting profiles | journal.view; account.manage (create/edit/new version/discard); journal.approve (approve/retire) |
| Payments and receipts | Finance > Accounting > Payments and receipts (also Receivables > Receipts, Payables > Payments) | payment.record (record, allocate, settle); payment.reverse (reverse); journal.view to read |
| Register payment / Register receipt dialog | Any posted invoice or bill > Register payment (dialog) | payment.record |
| Payment record | Payments and receipts > open a payment | payment.record; payment.reverse |
| Open items | Finance > Accounting > Open items (also Receivables > Customer open items, Payables > Vendor open items) | journal.view (read); payment.record (allocate, undo) |
| Bank reconciliation (statements) | Finance > Accounting > Bank reconciliation (also Banking > Bank reconciliation) | journal.view (read); journal.prepare (import, match, close); bankrec.prepare / bankrec.approve (review steps) |
| Bank reconciliation workspace | Bank reconciliation > open a statement (AI assist workspace) | bankrec.view; bankrec.prepare; bankrec.approve; bankrec.configure (policy) |
| Reconciliation rules and import profiles | Finance > Configuration > Reconciliation rules and Bank import profiles | bankrec.view (read); bankrec.configure (change) |
| Customer statements | Finance > Receivables > Customer statements | report.view |
| Receivables aging | Finance > Receivables > Receivables aging | report.view |
| Write-offs (customer and supplier) | Finance > Receivables > Write-offs / Payables > Write-offs | journal.view (read); payment.record (request, cancel own, recover); journal.approve (approve, refuse); journal.reverse (reverse); account.manage (tolerances) |
| Disputes | Finance > Receivables > Disputes (and Payables) | journal.view (read); payment.record (open, edit, resolve, cancel) |
| Collections worklist | Finance > Receivables > Collections | collections.view (read); collections.manage (log contacts) |
| Promises to pay | Finance > Receivables > Promises to pay | collections.view; collections.manage |
| Dunning runs | Finance > Receivables > Dunning | collections.view; collections.manage |
| Collection policy and dunning levels | Finance > Configuration > Collection policy and dunning levels | collections.view (read); collections.configure (change) |
| Payment proposals (list) | Finance > Payables > Payment proposals | journal.view (read); payment.prepare (create); account.manage (policy) |
| Payment proposal record | Payment proposals > open a proposal | payment.prepare (prepare, submit, hold, cancel); payment.approve (approve, send back, download file); payment.release (release, record answer, download file) |
| Supplier statements | Finance > Payables > Supplier statements | report.view |
| Payables aging | Finance > Payables > Payables aging | report.view |
| Payment due | Finance > Payables > Payment due | report.view |
| Goods received not invoiced (GRNI) | Finance > Payables > Goods received not invoiced | report.view |
| Payment holds | Finance > Payables > Payment holds | journal.view (read); payment.prepare (place); payment.approve (release) |
| Credit position | Finance > Credit control > Credit position | partner.view (read); credit.release (apply overdue rule) |
| Credit overrides | Finance > Credit control > Overrides | partner.view (read); document.confirm (request); credit.release (approve, refuse) |
| Credit reservations | Finance > Credit control > Reservations | partner.view (read); credit.release (release) |
| Credit groups | Finance > Credit control > Credit groups | credit.limit.reveal (read); credit.release (create, edit) |
| Expected credit loss runs | Finance > Credit control > Expected credit loss | report.view (read); ecl.manage (prepare, cancel); ecl.approve (post, reverse) |
| Provision matrices | Finance > Configuration > Provision matrices | report.view (read); ecl.manage (build); ecl.approve (approve) |
| Budgets (list) | Finance > Planning > Budgets | report.view (read, menu); budget.manage (create, edit, lines, new version, discard); budget.approve (approve) |
| Budget page | Budgets > open a budget | budget.manage / budget.approve |
| Budget against actual | Finance > Planning > Budget against actual | report.view |
| Budget control policies | Finance > Planning > Budget control > Control policies | report.view (read); budget.manage (change) |
| Budget commitments | Budget control > Commitments | report.view (read); budget.manage |
| Budget overrides | Budget control > Overrides | report.view (read); budget.manage (request, cancel own); budget.approve (approve, refuse, cancel any) |
| Treasury register | Finance > Treasury > Register | treasury.view (read); treasury.manage (register, edit, status, drawing); treasury.release (release); collateral shown only to manage or release holders |
| Instrument page | Treasury > open an instrument | treasury.manage / treasury.release |
| Treasury maturities | Finance > Treasury > Maturities | treasury.view |
| Treasury instrument types | Finance > Configuration > Treasury instrument types | treasury.view (read); treasury.manage (change) |
| Bank accounts | Finance > Banking > Bank accounts | company.view (read, no mask lifted); reference.manage (create, change); screen button for company admins only |
| Bank statements | Banking > Bank reconciliation > Statements | journal.view (read); journal.prepare (import, create) |
| Import statement wizard | Statements > Import statement | journal.prepare (preview and import) |
| Bank reconciliation workspace | Bank reconciliation > Reconciliation | journal.view / bankrec.view (read); journal.prepare and bankrec.prepare (match, validate, submit); bankrec.approve (approve, return) |
| Bank exceptions | Bank reconciliation > Exceptions | bankrec.view (read); bankrec.prepare (change) |
| Reconciliation policy and rules (tab) | Bank reconciliation > Rules (tab) | bankrec.view / bankrec.configure |
| Mapping studio | Bank reconciliation > Mapping studio (tab) | n/a |
| Bank import profiles | Finance > Configuration > Bank import profiles | bankrec.view (read); bankrec.configure (change). Menu entry needs bankrec.view |
| Reconciliation rules | Finance > Configuration > Reconciliation rules | bankrec.view (read); bankrec.configure (change) |
| Cash position | Finance > Banking > Cash position | report.view |
| Cash forecast | Finance > Banking > Cash forecast | report.view (calculate, read); journal.prepare (save a version) |
| Report runner | Finance > Reporting > (each report) and Accounting reports | report.view (run, definitions, drill-down, saved views); report.export (export); doc.print (PDF); audit.view (Journal Audit) |
| Trial balance (report) | Reporting > Trial Balance (report engine) | report.view |
| Financial statements | Reporting > Profit & Loss, Balance Sheet, Cash Flow | report.view |
| Ledgers and books | Reporting > General Ledger, Journal Register, Day Book, Bank Book, Cash Book, Customer / Vendor ledgers and balances, Reversed entries | report.view |
| Tax reports | Reporting > Tax Return Summary, Tax Detail, Reverse Charge | report.view |
| Management P&L by dimension | Reporting > Cost Centre / Profit Centre / Department / Project / Branch P&L | report.view |
| Exchange and audit reports | Reporting > Realized / Unrealized Exchange Differences, Journal Audit | report.view; audit.view for Journal Audit |
| Accounting settings | Finance > Configuration > Settings | period.lock (change fiscal start month and lock); reading shown to any member |
| Taxes (tax codes) | Finance > Configuration > Taxes | company.view (read); reference.manage (create, change, rates, install pack) |
| Tax code record | Taxes > open a tax | reference.manage |
| Install a tax pack | Taxes > Install a country's taxes | reference.manage |
| Fiscal positions (list) | Finance > Configuration > Fiscal positions | company.view (read); reference.manage (change) |
| Fiscal position record | Fiscal positions > open a position | reference.manage |
| Dimension values | Finance > Configuration > Dimensions (Branch, Cost centre, Department, Project, Profit centre) | company.view (read); reference.manage (change) |
| Account structure rules | Finance > Configuration > Account structure rules | company.view (read); reference.manage (change) |
| Valid dimension combinations | Finance > Configuration > Valid combinations | company.view (read, try); reference.manage (change) |
| Distribution models | Finance > Configuration > Distribution models | company.view (read, suggest); reference.manage (change) |
| Finance Features (switches) | Administration > Applications > Finance > Features | apps.configure (propose); apps.config.approve (decide) |
| Finance Fields (switches) | Administration > Applications > Finance > Fields | apps.configure / apps.config.approve |
Journal entries
| Rule | What the system does |
|---|---|
| Viewing needs journal.view | Menu hidden; API refused 'You do not have permission for this action.' |
Journal entry page
| Rule | What the system does |
|---|---|
| Preparer cannot approve own entry | Refused: 'Whoever prepares a journal does not approve it. Another person with the approval permission has to agree.' |
| Each step needs its own right | Approve needs journal.approve, post needs journal.post, reverse/reset need journal.reverse; each refused otherwise |
| Company isolation | 'Record not found.'; another company's account or partner on a line -> 'Line 1: the account is not in this company.' |
Accounting periods
| Rule | What the system does |
|---|---|
| Locked period never reopens | Refused: '<Period> is locked. A locked period is not reopened through the application.' |
| Reopen needs period.reopen | Refused: 'Reopening <Period> needs the right to reopen a period.' |
| Reopen request approved by someone else | Refused: 'Somebody other than the person who asked has to approve a reopen.' |
Opening balances
| Rule | What the system does |
|---|---|
| Preparer cannot approve the batch | Refused: 'Somebody other than the person who prepared, uploaded or validated this batch has to approve it.' |
Access review
| Rule | What the system does |
|---|---|
| Duty conflicts flagged | Access review lists 'Prepares journals and posts them' (high) / 'Posts journals and closes the period' (medium) |
Exchange rates
| Rule | What the system does |
|---|---|
| Entering and approving need different rights | Both refused 'You do not have permission for this action.' |
Revaluation policy
| Rule | What the system does |
|---|---|
| Policy change needs fx.approve | Refused |
Recurring / deferrals / posting profiles / year-end
| Rule | What the system does |
|---|---|
| Four-eyes everywhere the code has it | Each refused with its 'Somebody other than ...' message |
Year-end close
| Rule | What the system does |
|---|---|
| Reverse needs period.reopen | Refused |
Currencies
| Rule | What the system does |
|---|---|
| Only a superuser changes decimals | Refused: 'Only an administrator of the deployment may change a currency's decimal places...' |
Exchange revaluation
| Rule | What the system does |
|---|---|
| Company isolation | Nothing of the other company; 'Record not found.' |
Payments and receipts
| Rule | What the system does |
|---|---|
| Record permission | Refused; nothing posted; payment.record is the code the server checks |
| Reverse is a separate permission | First refused; second succeeds and posts the reversing entry |
| Optimistic locking on edits | Second gets 'Somebody changed this write-off. Reload it and look again.' (same for dispute, hold, group, promise levels) |
Register payment dialog
| Rule | What the system does |
|---|---|
| Idempotent key | Second is refused as a 409: 'This payment key was already used for different details.' |
| Company isolation | 'Record not found.' or 'Choose the customer or supplier whose money this is.'; no cross-company data returned |
Open items
| Rule | What the system does |
|---|---|
| Allocate is a money permission | Refused (payment.record needed); viewing open items works |
Payment holds
| Rule | What the system does |
|---|---|
| Place versus lift (segregation) | Placer cannot lift unless he also holds payment.approve; lifting needs a reason |
Payment proposal record
| Rule | What the system does |
|---|---|
| Preparer cannot approve | 'Somebody other than the person who prepared this proposal has to approve it.' |
| Releaser independence | 'The person who releases a payment is neither the person who prepared it nor the one who approved it.' The preparer is always refused |
| Authorised signers | 'You are not an authorised signer of <bank account>.' |
| Bank file tamper check | Release pays nothing, withdraws the approval and holds the line; a fresh independent approval is needed |
| Bank file and bank details visibility | Download refused ('Only somebody who approves or releases payments can download the bank file.'); bank detail shown masked |
Write-offs (customer and supplier)
| Rule | What the system does |
|---|---|
| Approver is not the requester | 'Somebody other than the person who asked has to approve a write-off.' |
| Approve, reverse and tolerance permissions | Approve needs journal.approve; reverse needs journal.reverse; tolerances need account.manage |
| Cancel scope | 'Only the person who asked, or an approver, can cancel this.' |
Bank reconciliation workspace
| Rule | What the system does |
|---|---|
| Maker-checker on reconciliation | On: refused 'You submitted this reconciliation, so someone else has to approve it (maker-checker).' Off: same person may approve (policy change needs bankrec.configure) |
| Second approver on bank reconciliation | Refused while the policy (or rule) has the second approver on; allowed only when the policy sets it off. |
| View, prepare, configure and approve are separate | View reads only; prepare matches, validates, submits; approve approves or returns; configure edits policy, rules, import profiles. Missing right -> 403. |
Credit overrides
| Rule | What the system does |
|---|---|
| Override approver is not the requester | 'Somebody other than the person who asked has to approve a credit override.' |
| Blocked customers | 'A blocked or blacklisted customer cannot be given a credit override.' |
Credit groups
| Rule | What the system does |
|---|---|
| Credit limits are confidential | The list is refused; limits are not shown |
Expected credit loss runs
| Rule | What the system does |
|---|---|
| Matrix maker-checker | 'Somebody other than the person who built this matrix has to approve it.' |
| Provision poster is not the preparer | 'Somebody other than the person who prepared the provision has to post it.' |
Collection policy and dunning levels
| Rule | What the system does |
|---|---|
| Collections permissions | Contacts and runs need collections.manage; the policy and levels need collections.configure |
| Fees need a legal confirmation on record | Switching on is audited with the reviewer's note; switching off is audited; both need collections.configure |
Customer statements
| Rule | What the system does |
|---|---|
| Reports are read-only and permission-gated | Refused; with the right they read only their company's data |
Budgets (list)
| Rule | What the system does |
|---|---|
| Viewing needs report.view; changing needs budget.manage | The list opens; New budget is hidden and the API answers 403 for create, lines, version, discard. |
| Company isolation | 'Record not found.' |
Budget page
| Rule | What the system does |
|---|---|
| Budget approval needs budget.approve and a second person | Builder: 'Somebody other than the person who built this budget has to approve it.' Without the right: 403. |
Budget overrides
| Rule | What the system does |
|---|---|
| Override approval is maker-checker | 'Somebody other than the person who asked has to approve a budget override.' |
| Override scope is bounded | An override works only for its own account, before it ends, and until Used reaches May exceed by. |
Budget control policies
| Rule | What the system does |
|---|---|
| Block policy cannot be bypassed from other screens | Every posting goes through the same check (ledger.post_journal); only reversal, year-end, opening, FX and ECL journals skip it. |
Budget commitments
| Rule | What the system does |
|---|---|
| Releasing needs budget.manage and a reason | 403; 'Say why it is released or cancelled.' |
Treasury register
| Rule | What the system does |
|---|---|
| View, manage and release are separate rights | View: read lists and instrument pages. Manage: register, edit, change status, drawings. Release: the Release action only. Missing right -> 403. |
| Company isolation | 'Record not found.' |
| Fields switch finance.treasury.notes | Refused; with Required, an instrument without notes is refused. |
Instrument page
| Rule | What the system does |
|---|---|
| Release is maker-checker where the type says so | 'Somebody other than the person who registered this instrument has to release it.' Untick the type's second-person rule and A can release. |
| Releasing through the status route needs the release right | 403 'Releasing an instrument needs the treasury release right.' |
| Collateral is masked for view-only users | Collateral details are hidden and replaced by 'held (details are restricted)'; the JSON has masked true and empty fields. |
Bank accounts
| Rule | What the system does |
|---|---|
| Bank details are sealed and masked | Only the masked IBAN, last 4 of the account number and has_iban / has_swift flags are returned; the full values are never sent. |
| Changing a beneficiary leaves a trail | Beneficiary version rises, History shows who and when, audit 'bank_account.beneficiary_changed'. Only reference.manage can change (403 otherwise). |
Import statement
| Rule | What the system does |
|---|---|
| Importing needs journal.prepare | 403. |
Bank statements
| Rule | What the system does |
|---|---|
| Company isolation | 'Record not found.' |
Cash forecast
| Rule | What the system does |
|---|---|
| Saving a version needs journal.prepare, reading report.view | Calculate works; saving is refused 403. |
Report runner
| Rule | What the system does |
|---|---|
| Running needs report.view, export needs report.export, PDF needs doc.print | Run works; export 403; PDF 403 without doc.print. |
| Company isolation of filters and results | 'An account in the filter is not in this company.' and no foreign rows. |
Exchange and audit reports
| Rule | What the system does |
|---|---|
| Journal Audit needs audit.view | 403; the other reports remain available. |
Taxes
| Rule | What the system does |
|---|---|
| Tax codes: read for members, change needs reference.manage | 403 for each; list readable. |
Fiscal positions
| Rule | What the system does |
|---|---|
| Fiscal positions need reference.manage to change | 403; position list readable. |
Accounting settings
| Rule | What the system does |
|---|---|
| Fiscal start month and lock need period.lock | 403. |
Valid combinations
| Rule | What the system does |
|---|---|
| Dimension rules change who can post | Postings that passed yesterday are refused with the rule name; only reference.manage can add or remove it. |
Finance Features
| Rule | What the system does |
|---|---|
| Configuration changes are two-person | Self review refused; missing right gives 403; every proposal and decision is audited. |
| Protected controls cannot be turned off | 'A protected control cannot be turned off.' |