This worked example shows how to go from "that user should not be able to do this" to a documented answer, using the pages of Advanced Permissions Management (APM). The names in the example are made up.
During a check, you see that a purchasing clerk can delete vendors. Nobody remembers granting it. You want to know four things: which permission set gives it, who changed it and when, what else the change touches, and what the decision is.
Before you start: APM is installed and registered, and the change happened after the baseline.
You now see the line before (read, insert, modify) and after (read, insert, modify, delete). Nothing has to be reconstructed.
Open the Change Explorer and filter Changed By on App Update for the same period. If the change is there, a system permission set was changed by an app update, and the person is not the cause. If not, a user made the change. See Permission changes caused by app updates.
Before you fix anything, run a what-if analysis on the set. Remove the delete line in the proposal and choose Analyze Impact. In the example, the summary says that 9 permission sets and 4 users can be affected. That tells you who to talk to first, and that a quick fix in a broad set would reach many people.
Start a period review for the period, or open your running review, and select the change.
| Decision | What you do |
|---|---|
| The change was agreed | Set the status Reviewed and add a comment with the reason and who agreed. |
| The change was wrong | Set the status Flagged, add a comment, and roll the set back to the version before the change. Roll back works for user-defined sets. |
| You do not know yet | Set the status Flagged and ask the person. Add their answer as a comment when you have it. |
The result: the change, the person, the decision and the date are on record, in the review that you can show later.
A flagged change is not undone by flagging it. The review status is a record. Use rollback, or change the set in Business Central, to actually remove the permission.
Use this checklist a few weeks before the auditor arrives.
Last reviewed: October 2026.