This glossary explains the terms you meet in the Compliance apps. Each entry is a short definition. The linked pages explain how to do the task. Looking for an app name? See the comparison on the home page and Compliance Essentials.
A rule that stops users from running a specific action on a page. A user who is linked, through a permission set, to the Action Security can not run that action. See Securing actions.
The small button next to a field or cell that opens extra options for that field. In Field Security, the AssistEdit button on a linked permission set offers options for all security lines at once: delete the selected sets from the column, remove them from, copy them to, or replace them on all security lines. See Securing fields.
A separate 2-Control product for authorization management and monitoring. It reads data from Business Central through the web services of Compliance Essentials. See Web services.
In Advanced Permissions Management, the starting snapshot from which change tracking begins. Everything after the baseline is written to the change log. You can reset the baseline. The older data is then archived, not deleted. See Baseline reset.
The common name for the question "who last changed this line?". In Advanced Permissions Management the page Who Last Changed What answers it for every permission line of a set. See Change history.
An option in Field Validation for the validation type No. of related records. When it is on, the app also validates the records of the related table, not only the records of the main table. See Table relations.
A filter value that the app calculates at the moment of use, for example from the signed-in user. You use it in Filter Security, in Field Validation conditions and in table relations. See Filtering records and Field Validation.
A Field Validation rule that checks a field against a calculated filter, for example the current period or the signed-in user, instead of a fixed value. See Calculated validations.
In Advanced Permissions Management, one filterable page with every logged permission change. You filter by date, permission set, Changed By, change type and review status. See Reviewing changes.
A record that shows who changed what and when. Business Central keeps its own change log. Field Security, Filter Security and Field Validation show the entries for their setup. Advanced Permissions Management keeps its own change log of permission changes. See Release notes for where entries were added.
A requirement that must be met before a rule runs. In Field Validation, the rules of a validation only run when its conditions are met. A table relation can have conditions too. See Creating validations.
The AI-assisted feature in Business Central. In the Compliance apps it helps you generate a Field Security, a Filter Security, a regular expression or a Field Validation proposal from a text prompt. You can change the proposal before you save it. See Securing fields and Field Validation.
The highest severity of a quality check in Advanced Permissions Management. The other severities are Info and Warning. For example, a permission on all objects without an Exclude relation is Critical. See Quality checks.
Data that an app loads when you choose Load Default Data on its setup page. Field Security loads the list of Action Securities, the pages that support Filter Security and examples of calculated filters. Advanced Permissions Management loads its permission library and the quality rules. See Install and set up Field Security and Install and set up Advanced Permissions Management.
The overview that shows which users and permission sets a Field Security or Filter Security applies to. Its former name is Calculate Summary. See Effective security.
A link between two permission sets that removes the permissions of the referenced set from the effective result. It is the opposite of an include relation. Advanced Permissions Management uses exclude relations to limit broad permission sets, and its quality check takes them into account. See Quality checks.
The overview pages that list all Field Securities, or all Filter Securities, with the number of linked and not linked permission sets. Before release 7.1 they were called Field Security List and Filter Security List. See Securing fields and Filtering records.
The feature of Compliance Field Security that makes individual fields of a table editable or not editable, based on the permission sets linked to the security. See Securing fields.
The feature of Compliance Field Security that limits which records of a table a user can see or use, based on filters and the permission sets linked to the security. See Filtering records.
The results of a check. In Advanced Permissions Management, a quality check reports findings per permission set. In Field Validation, the Field Validation Results page lists the findings: the rules that were broken. See Quality checks and Creating validations.
A review status in Advanced Permissions Management. A change is Open, Reviewed or Flagged. Flagged means it needs follow-up. See Reviewing changes.
The part of an on-premises license that unlocks an app. Each app needs its own granule and the granule of Compliance Essentials. See On-premises license requirements.
A link between two permission sets that makes a set inherit all permissions of the referenced set. See also Exclude relation. See Advanced Permissions Management.
A permission that lets a user write to a table only through an object that has permission to write to it. The user needs two permissions: the indirect permission on the table and the permission to run the object that writes to it. See Securing fields.
The Business Central feature that runs a task on a schedule in the background. Inventory Reconciliation uses it to update the analysis. Compliance Essentials has a codeunit for a job queue that adds users from Microsoft 365. See Schedule the update job.
The right to use a Compliance app after the trial. The app checks the license after you register it in each environment. See Troubleshooting.
A permission set that you linked to a security line. The security applies to users who have that permission set. Older texts say assigned instead of linked. A not linked permission set has permission to modify the table, but is not linked to the security. See Securing fields.
The calculation in Field Security that lists the users or permission sets that a security does not cover. The column Cause Permission Set ID shows why. See Effective security.
A named group of permissions that you assign to users. A system permission set comes with an app and is read-only. A user-defined permission set is created or copied by an administrator and can be edited. See Advanced Permissions Management.
In Advanced Permissions Management, the list of moments at which a permission set changed. Quick successive edits by the same user are grouped into one moment. Use the history to compare versions and to choose a version for a rollback. See Change history.
The state of a permission set at one point in time, as stored by Advanced Permissions Management. You can compare two versions line by line, or restore a user-defined set to an earlier version. See Change history.
A rule-based analysis in Advanced Permissions Management that checks a permission set for risky or untidy patterns. It reports findings as Info, Warning or Critical. The same input always gives the same result. See Quality checks.
In Advanced Permissions Recorder, the capture of the permissions that a Business Central session uses while a user performs a task. You can save the result as a new permission set, or add it to or overwrite an existing one. See Record permissions.
A string of characters that defines a search pattern, used in Field Validation to validate the format of an input value. See Regular expressions.
The step in which you register an installed Compliance app for an environment, so that the app can be matched with a trial or license. See Troubleshooting.
In Advanced Permissions Management, a review of the permission changes in a date range and scope. Each change gets a status: Open, Reviewed or Flagged. A review is an evidence record. It does not block or undo the change. See Reviewing changes.
The start page of a Business Central profile. Advanced Permissions Management has its own Role Center with a headline and tiles for the changes that need attention. See Dashboard and Role Center.
In Advanced Permissions Management, restoring a user-defined permission set to an earlier version from its history. It changes live permissions immediately. See Rollback.
A broad permission that an Exclude relation limits is scoped. A quality check reports a scoped broad permission as a Warning instead of Critical, and asks you to verify that the excludes cover everything. See Quality checks.
One line within a Field Security or Filter Security. It holds the field or filter that is secured and the permission sets it applies to. See Securing fields.
In Advanced Permissions Recorder, the number of the Business Central session that you record. It can be your own session or the session of a user who is logged on. See Record permissions.
The guided steps that start after you install an app. They cover registration and the first settings. If you skip them, open the setup page of the app instead. See Finish the setup wizard.
The detailed entries behind an account. In Inventory Reconciliation, the inventory subledger consists of the value entries. The app compares it with the general ledger. See Reconcile inventory accounts.
The standard Business Central permission set that gives all permissions. You need an account with SUPER permissions to install apps, register them and assign permission sets. See Getting started.
A definition that tells Field Validation and Filter Security how two tables in Business Central are related, so that a check or filter can use values from the related table. See Table relations.
The period of 30 days in which you can use a Compliance app before you need a license. The trial starts when you register. See Troubleshooting.
A permission set that is assigned to all users, for example a LOGIN, BASIC or ALL set. In Advanced Permissions Recorder you use it to refine a recording, so the new set does not repeat permissions that every user already has. See Record permissions.
The permission set that users need to work with a Compliance app, for example 2C FIELDSEC USE for Field Security. Without it, users cannot use the app. See Getting started.
Business Central web services that Compliance Essentials delivers, for example for the Authorization Box. See the list on Compliance Essentials.
In Advanced Permissions Management, a simulation of a proposed permission change. It shows which permission sets and users would be affected before anything is saved. See What-if analysis.
Last reviewed: October 2026.