Skip to content
BlogInternal permissions

Roles and permissions: who views, changes and approves in your system

A hidden menu does not prove an action is blocked. Define permissions by task and verify each role's outcome.

Test worksheet: Internal roles: viewing, changing and approving

A hidden menu does not prove an action is blocked. Define permissions by task and verify each role's outcome. Record inputs, expected outcome, evidence, owner and observed result.

Download CSV worksheet
In this guide

Start with decisions that affect money or data

“Administrator” and “employee” are often too broad. In a distributor, sales needs to prepare a discount, finance can approve it and the warehouse fulfills the approved order. Write these actions before naming roles. Include information exports and rule changes: both can affect the business even without directly modifying an order.

Business Central distinguishes read, insert, modify, delete and execute permissions. OWASP recommends least privilege, default denial and permission validation on every request. Test the outcome of an action rather than the existence of a button. Combinations of roles also need review.

Fictional example: discount on order P-606

Sales requests a 12% discount for P-606. The rehearsal rule lets sales propose it, but finance must approve discounts above 8%. The same person cannot approve their own request. These fictional thresholds test the process; they are neither margin advice nor an already implemented capability.

If the salesperson receives a temporary supervisor role too, requester and approver separation must remain. A denied attempt keeps the previous price and leaves an identifiable request. A finance approval records who decided and which order version they reviewed. A subsequent quantity change requires the agreed review rather than silently reusing an old approval.

ActionSalesFinanceWarehouse
View orderYes, for its workYes, for reviewYes, fulfillment details
Request 12%YesNot needed for this rehearsalNo
Approve own requestNoNoNo
Approve another person's requestNoYes, under agreed criteriaNo
Change a user's permissionNoNot merely as an approverNo

Test each account's effective permission

Use rehearsal accounts with a single role, then actual combinations. Check an action started before a permission change and completed afterward. Define when revocation takes effect in the product and what happens to pending work. Recording that dependency is more useful than promising an untested immediate effect.

CaseExpected resultEvidence
Sales requests 12% for P-606Pending request without applied discountOrder and request
Sales attempts self-approvalDenied with unchanged priceAttempt and comparison
Finance approves another person's requestDiscount applied once to the reviewed versionDecision and version
Warehouse attempts price changeDenied even with knowledge of the routeRequest and final state
Finance role is removedNew attempt cannot retain the removed permissionTime and effective-access test
Approval retried after lost responseSame decision without duplicate changeApproval reference

Give exceptions a duration and owner

Holiday cover may need temporary permissions. Record reason, start, end and who verifies their removal. If nobody can approve during an absence, agree on an alternate; sharing a password is not a substitute. Emergency access needs a separate procedure and a subsequent check of actions taken.

Review access inherited from groups, roles and integrations. Effective permissions may depend on licensing, configuration and custom rules. If the current product supports the matrix, configure and test it before requesting another system. If a critical separation is missing, document the specific case when comparing alternatives.

Keep a matrix you can maintain

Update the matrix when a task changes, not just when someone joins. Link actions to a change audit log, test employee offboarding and retain owners for digital keys. Customer portals have another boundary: they must also prevent access to other customers' information.

The downloadable worksheet proposes ten internal tests and leaves results empty. Bring approval rules, current roles and an anonymized exception to a free consultation for cybersecurity. We can review which actions need verifiable control and which depend on system configuration.

Review who changes and who approves

A request that needs a separate approver tests roles better than a screen list. Bring it to a free consultation with allowed actions and temporary cover so we can define which requests should succeed or be rejected.

  • Actions that view, change, approve or export
  • Current roles and groups with temporary cover
  • One request requiring a different person to approve
Book a free consultationAsk on WhatsApp

Related

Frequently asked questions

It does not demonstrate authorization. A user may attempt the action through another screen or a direct request. Check that the system denies the change and preserves the correct data using the product's available functions and tests.

Not merely because of the job title. Identify necessary actions and separate user administration, business approval and viewing. Permission to approve discounts does not automatically justify changing the rules that limit them.

Run the matrix with effective group and role combinations. Check permissions that accumulate or exclude each other and self-approval restrictions. An individual account may have more access than any one role viewed separately.

Define who can temporarily own the decision and for how long. If work must wait for approval, make that explicit. Sharing credentials removes attribution and does not create a valid substitution rule.

Sources

  1. Define granular permissionsMicrosoft
  2. Authorization Cheat SheetOWASP

Last updated:

Keep reading

Free consultation

Do you know who can get into your business accounts?

We review your systems, accounts and settings and tell you what to fix first. From $600 MXN per hour. We reply the same business day.

  • Free, no commitment
  • Proposal in 1 business day
  • Delivered in stages