Short answers to common questions about Advanced Permissions Management (APM), and a table of symptoms with their cause and fix. For the full steps, follow the links.
| What you see | Likely cause | What to do |
|---|---|---|
| A page asks "Compliance Advanced Permissions Management must be registered before you can use it. Do you want to register now?" | The app is not registered yet. | Choose Yes and complete the registration, or choose Register on the setup page. See License and registration. |
| A page asks "Your trial or contract ... has expired. Do you want to request a license now?" | The trial has ended. Recording continues, but the pages need a license. | Choose Request License on the setup page. |
| "... is not available in the trial of Compliance Advanced Permissions Management." | The function needs a license, for example generating permission sets. | Choose Request License. See the function table. |
| The license status still says Trial after you bought a license. | The license is not matched to your account yet. | Choose Refresh License Information on the setup page. Matching usually takes 24 to 48 hours. |
| Last License Check Error shows an HTTP error. | The environment cannot reach the registration service. | Allow the extension to make HTTP requests in Business Central. Meanwhile the app grants temporary access. |
| A permission change does not change the counters. | The counters follow the change, or Disable Automatic Count Recalculation is on. | Choose Refresh Permission Set Version. The change itself is always logged in full. |
| Check for App Changes finds nothing. | No system permission set differs from the baseline since the last check. | Nothing to do. See App updates. |
| The baseline reset is blocked. | A review is still open: "The baseline cannot be reset while permission reviews are still open". | Complete or abandon the open reviews. A scheduled reset is not blocked. |
| You cannot start a review. | There are no recorded changes in the period, a review of the same scope overlaps, or To is in the future. | Change the period or the scope. If a change belongs to another open review, the app offers to open it. |
| You cannot complete a review. | A change in scope is still Open. | Use Review All or Review Selected Changes for the remaining changes. |
| The Role Center does not switch. | Business Central loads the profile at sign-in. | Sign out and in again. |
| Rollback is not available for a set. | The set is a system set, or you may not change permission sets in Business Central. | Roll back user-defined sets only. See Roles and permissions. |
No. Business Central cannot hold back a change until it is reviewed. The review is the evidence that someone looked at it and what was concluded. Use rollback to undo a change. See Reviewing changes.
Completed reviews with their comments, and an export of the Change Explorer for the period. See Audit and evidence.
A background job checks every hour for changes to system permission sets and logs them as App Update. It needs a trial or license. Check for App Changes runs the check immediately. The job runs as the user who scheduled it: check its status on the setup page, fast tab Background Job, and choose Schedule Background Job when it is not running. See App updates.
Standard Business Central logs changes to permission sets you created yourself, in a technical log that is not built for review. It does not log changes to system permission sets. APM records both. See the comparison.
Yes. Recording starts at installation and does not depend on registration. To look at the changes you need a registered trial or a license.
No. Both only read. Rollback, the what-if cleanup action and a baseline reset do write data.
No. It is a fixed, rule-based set of checks. The same input always gives the same result.
When an Exclude relation scopes the broad permission down, the finding is a Warning that asks you to verify the excludes. Without an Exclude it is Critical. See Quality checks.
No. Rollback works for user-defined permission sets only. It restores permission lines and relations, not renames, and it does not change which users have the set. See Rollback.
It is archived, not deleted, and included automatically in the history, comparisons and reviews that span the reset. See Baseline reset.
Without a license, in a registered trial, you can use all pages of the app. A few functions need a license: generating permission sets, Copilot names and descriptions, the what-if cleanup, copy, import and export of permission sets, and the scheduled baseline reset. Users who bought APM through AppSource count as licensed. See License and registration.
Changes keep being recorded, the pages ask for a license, and your data is kept. See what happens when the trial ends.
Yes. When Field Security or Field Validation is installed, APM shows extra counters and columns automatically. No setup is needed.
Business Central 27 or later, online. APM is available for the cloud only; on-premises is available on request (support@2-controlware.com). See the release notes.
Contact support@2-controlware.com. Include the name of the app and the environment.
Last reviewed: October 2026.