The 1C:Enterprise developers forum

#1
People who like this: 0 Yes / 0 No
Active user
Rating: 4
Joined: Apr 2, 2025
Company:

New configuration.

SSL [v.3.1.11.392] merged (full functionality).

After running the app for the first time, I am adding a new first user 'Developer', myself, which system assigned as administrator automatically.

Now I want to add another new user "Sales director" with rights to be able to create other users, sales managers, and assign them access rights.

How to create a user with rights who can create other users and assign them access groups and access group profiles?

Edited: Bahrom - May 07, 2026 11:45 AM
 
#2
People who like this: 0 Yes / 0 No
Administrator
Rating: 31
Joined: Oct 3, 2019
Company:

Hello Bahrom,

In general, the “Sales Director” role does not usually imply permission to create new users, manage access rights, or assign access group profiles. This is normally an administrative function and is usually performed by a system administrator.

So, by default, a user created as “Sales Director” will most likely not be able to create other users or assign them access rights.

If this is required by your business process, then I would suggest creating a separate access group or access group profile for this purpose. In this profile, you need to include the required administrative rights related to user management, access groups, and access group profiles. Then you can add the “Sales Director” user to this access group.

Also, please keep in mind that if you give the Sales Director permission to create new users, he may be able to create any users, not only members of his own department.

In other words, by default, the right to create users usually means the right to create any user.

This can probably be changed by modifying the application code, but honestly, I do not think this is a best practice. In real-life systems, administrative permissions are usually concentrated in the hands of the system administrator.

 
Subscribe
Users browsing this topic (guests: 1, registered: 0, hidden: 0)