Most videos are about one minute long. Each video shows one feature with real Business Central screens, a voice and subtitles. Choose an app below. The link under each video goes to the page that explains the feature in steps.
Advanced Permissions Management is new in release 7.2. Start with the tour, then watch the feature videos.
The dashboard, change tracking, history, review, quality check, what-if analysis and rollback. See Advanced Permissions Management.
Who changed this permission? When? And did anyone ever review it? These are the questions every auditor asks, and they are hard to answer. Standard Business Central logs changes to your own permission sets in a technical log that is not built for review. Changes to system permission sets are not logged at all. Yet any administrator, and any app update, can change permissions at any time. Advanced Permissions Management, by 2-Controlware, turns that information into something you can read, review, and act on. This is your starting point: the role center. It tells you at once how many permission changes are waiting for review. See how many permission sets you have, which ones are in use, and which carry broad permissions. And follow your reviews: unreviewed changes, open reviews, and completed reviews. Start with the dashboard. It lists every permission set, how many permissions it contains, how often it changed, and how many users depend on it. Every change is counted the moment it happens, so nothing slips by unnoticed. Watch what happens when we change something. In standard Business Central, we add delete permissions to a sales permission set, just like an administrator would. Back in the dashboard, the change is already counted, without anyone having to report it. The change log shows who did it, when, and exactly what changed, before and after. Nothing to configure, and nothing to interpret. The same applies to the system permission sets that Microsoft and apps provide, which standard Business Central does not log at all. When an app update widens access, it is recorded and attributed to the update, instead of slipping through unnoticed. Who last touched the vendor permissions? One click shows a name and a date on every line, so you always know who to ask. Version compare puts any two moments side by side, so you can see how a permission set looked before and after, even across a baseline reset. History is archived, never lost. Then comes the part auditors ask for first: review. Group the recent changes into a review period, and work through them as a queue. Flag a change as suspicious, and record your decision: a mitigating control, or the action to change the permission. and close the session. A review does not block a change, but it is your permanent record that someone looked, and what they concluded. Quality analysis checks your permission sets against fixed rules, so you do not have to read every line yourself. Both of these sets give access to every table. The legacy set is critical. The base layer is not critical: excluded permissions limit its broad access, so it is scoped and only a warning. Same pattern, real difference in risk. Open one set for the detail, and every finding is explained. This wildcard on all table data is the real problem: it grants write access to every table. The other lines show which objects are affected, their business domain, and why they were flagged. Planning a change? Simulate it first. Remove a permission from a set, and let the analysis show what would happen. Removing read access to items from one small lookup set affects nine permission sets and four users. You see that, and exactly who is affected, before anything is saved. And if a mistake does get through, you can roll back user-defined sets to the previous version. Preview exactly what will be removed, confirm, and it is done. The rollback itself is logged too, so the audit trail stays complete. Advanced Permissions Management for Business Central. Every permission change visible, explainable, and reversible. Start your thirty-day trial today.
See who changed what, and compare two versions. See Change history.
Advanced Permissions Management. Change history. A permission set changed last week. Who did it, and what exactly was different? In standard Business Central, answering that takes a lot of digging. Every permission line shows the person who changed it last, and when. Here, access to vendors was changed on September twenty-seventh, and you see the new permissions right next to it. Every other line has its own name and time. Nothing is anonymous, and nothing has to be reconstructed. Pick any two moments in time, and the two versions appear side by side. You see what was added, removed or changed. That is audit evidence, without a spreadsheet. Every change has a name and a time. Advanced Permissions Management, by 2-Controlware. Try it for thirty days.
An app update changes a system permission set, and the change is recorded with the permissions before and after. See App updates.
Advanced Permissions Management. App update detection. An app update can quietly change Microsoft's own permission sets, and give users more access than before. Standard Business Central does not log those changes at all. So would you ever notice? Advanced Permissions Management does notice. It checks your installed apps in the background, every hour by default, and records every difference as an app update. Take this line. An update gave a system permission set the permission to modify customers. You see the set, the table, and the permissions before and after. Three changes here, none of them in standard Business Central. Every one stays on record, ready to be reviewed and signed off. No more surprises after an update. See what Microsoft changed. Advanced Permissions Management, by 2-Controlware. Try it for thirty days.
Open the changes that wait for review, flag one with a comment and see it leave the open list. See Reviewing changes.
Advanced Permissions Management. Period review. Recording permission changes is not enough for an audit. Someone also has to look at them, and write down what they concluded. Open the changes that are waiting for review. Each line shows who changed which permission set, and when. Select a change, flag it, and add a comment that says why. Here, delete access on vendors was not approved. Confirm, and the change leaves the open list, recorded with your name, the time, and your comment. A review is evidence. It never blocks the change itself. Every permission change reviewed, with a reason. Advanced Permissions Management, by 2-Controlware. Try it for thirty days.
Remove a permission and see which permission sets and users can be affected, before you save anything. See What-if analysis.
Advanced Permissions Management. What-if impact. Permission sets include other permission sets, so one small change can reach much further than you expect. Take access to items away from this lookup set, and who will feel it? Without a simulation, you can only guess. Open the what-if analysis on any permission set. Try a change on its permission lines, without touching the real set. Here we remove read access to items. The proposed change is listed, and nothing is saved. Analyze, and the answer comes in plain language. Nine permission sets and four users can be affected. Expand the impact, and you see exactly which sets and which users, with the permissions before and after. Decide with the facts, not after the users call. Know the impact before you change anything. Advanced Permissions Management, by 2-Controlware. Try it for thirty days.
A critical legacy set, a broad but scoped set, and the findings explained per object. See Quality checks.
Advanced Permissions Management. The quality check. Which of your permission sets carry too much risk? Reading thousands of permission lines by hand is not realistic. So pick the sets, and let the quality check read them for you. The checks follow fixed rules. It is rule-based, not artificial intelligence, so the same sets always give the same answer. This legacy set is critical. It grants write access to every table, including delete, and nothing limits it. Open the details, and every finding is explained per object. The wildcard line, in red, is the critical one. This base layer is broad too, but it is only a warning. Exclude relations carve the sensitive tables out of it, and you are asked to verify them. One critical finding, and seven warnings, each one explained. Start where the risk is highest. Find risky permission sets in minutes. Advanced Permissions Management, by 2-Controlware. Try it for thirty days.
Restore a permission set after an unwanted permission, with a preview before anything changes. See Rollback.
Advanced Permissions Management. Rollback. Someone changed this permission set by mistake, and now a user can delete vendors. A mistake you cannot undo is a risk. How do you get back to the last good version? Choose Rollback on the permission set. The wizard asks which earlier version you want to return to. Pick the last version you trust. Every change moment is kept in the history. Before anything happens, you see exactly what will change. One permission is modified, and one is removed. Confirm that this changes live permissions, and restore. The permission set is back at the version you chose. Undo a mistake in minutes. Advanced Permissions Management, by 2-Controlware. Try it for thirty days.
Choose a prefix and language, pick sets from the library, generate them and check the result with the quality check. See Permission set generator.
Advanced Permissions Management. The permission set generator. Building permission sets by hand takes weeks. So most Business Central environments end up with super users and oversized sets. That is where the real risk lives. The permission set generator builds a solid, task-based foundation in minutes. Choose a naming prefix and a language. English, Dutch, German, French or Spanish. Pick from a curated library of ready-made permission sets. Inspect any set before you generate it, switch off what you do not need, and it is simply not generated, Need something that is not in the library? Add your own set. Give it a code, a name, and the process it belongs to, then list the objects and the permissions it needs. It is generated exactly like the library sets, with the same carve-out. Then generate, in one click. The smart part is how the sets fit together. A broad base set gives everyone convenient access. Every specific task set is automatically excluded from it, so the precise definition always wins where it applies. Open the broad set, and look at its lines. Sensitive data is protected by default. Ledger entries and posted documents are always restricted, even in the broadest set. Run the quality check, and the broad set is recognized for what it is: deliberately restricted, not wide open. From weeks of work to a secure baseline in minutes. Advanced Permissions Management, by 2-Controlware. Start your thirty-day trial.
A user changes a job title. Field Security locks the field and refuses the change with your own message. See Field Security.
Compliance Field Security. Lock a single field. Anyone who may edit an employee can change the job title. Standard Business Central cannot protect just that one field. So the title is changed, and saved. Nobody is asked why, and nothing is stopped. With Compliance Field Security, you secure one field of one table. Here, the job title of the employee. Everything else on the employee stays editable. Only that one field is locked. You write the message people will see, so they know who to ask. And you choose who is locked out, by linking permission sets. After the next sign-in, the rule is active. Same user, same employee, same field. Now the same user tries the same change. It is refused, with the message you wrote yourself. Nothing is saved. Protect the fields that matter. Compliance Field Security, by 2-Controlware. Try it for thirty days.
The Employee list shows every employee. Then a Filter Security limits a user to the production employees. See Filtering records.
Compliance Field Security. Filter security. Everyone who opens the employee list sees every employee. Whatever the department, and whether it is their business or not. Filter security cuts a table into parts. Here, the employee table. The line says which records are visible: only those where the job title starts with production. Plain filters and wildcards are enough. No programming is needed. You set a starting date, and the rule is active from that day. Then you link the permission sets that get this limited view. After the next sign-in, the same user sees only the two production employees. The other records are not deleted. They are simply out of sight, for this user. Everyone sees what they should. Compliance Field Security, by 2-Controlware. Try it for thirty days.
Link a permission set to the Release action. After the next sign-in the action is blocked. See Block actions with Action Security.
Compliance Field Security. Action security. Some actions are too important for everyone. Business Central cannot switch off a single button. Action security can. Take the release action on the sales order. Today every user may press it. Open the permission sets linked to this action. Add the permission set of the users who may not release orders. Pick the set from the list, and confirm. Nothing else is needed. From now on the action is blocked for everyone with this permission set. After the next sign-in, a user opens an order that is still open. The user presses release. Business Central stops the action and tells the user why. The order stays open. Sensitive actions, in your hands. Compliance Field Security, by 2-Controlware. Try it for thirty days.
More: Create a Field Security with Copilot (demo on YouTube).
The same rule as a warning and as an error. A warning informs the user and the change is saved. An error reverses the change until the data is correct. See Field Validation.
Warning or error? With Field Validation, you decide how strict a rule is. A customer without a phone number is hard to reach. But how strict should your system be about it? Every validation has a type. This one says a customer must have a phone number, and the type is Warning. A user clears the phone number. Field Validation tells them at once which rule is broken. But a warning only informs. The user can carry on, and the change is saved. Now the same rule, with one change. The type is set to Error. Again the phone number is cleared, and again the rule is reported. But this time the change is reversed. The customer cannot be saved until the data is correct. Warnings guide, errors protect. Choose the right level for every rule. Field Validation, by 2-Controlware. Try it for thirty days.
Check Table lists the customers that break a new rule. You open a customer card to correct one and calculate again. See Creating validations.
Clean up existing data. Field Validation also finds the records that already break a rule. A new rule protects everything users type from now on. This one says that every customer needs a country code. But what about the customers that are already in the system? Choose Check Table. Field Validation runs the rule over all existing records, and lists every customer that breaks it. Here, three. Select one, and open the related page. You land on the customer card, with the empty country code right in front of you. Enter the country code and close the card. That customer is now correct. Calculate again, and that customer is gone from the list. Two to go. Work through the list, and your old data is clean. Check Table turns a new rule into a clean-up list for the data you already have. Field Validation, by 2-Controlware. Better data, without code. Try it for thirty days.
Rules on the sales header and the sales lines, set up as errors. A sales order that breaks the rules cannot be released until you correct it. See Table relations.
Validate sales orders at the moment they are released. Header and lines, without code. Before an order is released, the data must be right. The external document number starts with the year and month. The posting date is today or later. Name and address are filled in. And every item line has a quantity, a price, a location, and the right description. Standard Business Central checks a fixed set of fields on release. Your own rules mean custom code, for every rule. With Field Validation, you set these rules per table, without code. This validation is for the sales header, table thirty-six. The type is Error, so a record that breaks a rule is stopped. The key setting is the condition. The rules only run when the status is not Open, so a draft stays free to edit. The starting date switches the validation on. The lines hold the rules. A regular expression checks the document number: year and month, a dash, then anything. The posting date may not be before today. Customer name and address are mandatory. The same for the lines: table thirty-seven, the sales line. Only item lines are checked. And a table relation to the header gives each line the status of its order. With that relation, the line rules also run when the order header changes. A starting date switches it on. Quantity and unit price must be above zero. The description must equal the description on the item, a related field rule across tables. And the location is mandatory. Rules load at sign-in, so we sign in again. Now we test with an order that breaks the rules. We release the order. It is stopped. The header rules and the line rules both fire, and every problem is listed with the message we wrote. The user corrects the document number, the posting date, and the address. And then the quantity and the location on the lines. Release once more, and it goes through. The same works on any table, as a warning or an error, per company or permission set. Field Validation, by 2-Controlware. Better data, without code.
Advanced Permissions Recorder. Find the permissions a task needs. A user must post sales invoices. Which permissions does that need? Guess too few and the user gets errors. Guess too many and the access is a risk. Open Record Permissions. Choose the session of the user who will do the task. Name the new permission set. All object types and all permissions are switched on, so nothing is missed. Choose Start and confirm. Now the user does the task in their own session. Back in the recorder, choose Update Recorded Permissions. Every object that was used is listed, with the permissions it needed. When the task is done, choose Stop to save the set. The new permission set holds exactly what the task needed. Check it, assign it, and keep it up to date. Record the permissions, do not guess. Advanced Permissions Recorder, by 2-Controlware. Free after registration.
See Advanced Permissions Recorder.
Watch the overview of the 2-Controlware software (older video, on YouTube).
There is no video for Inventory Reconciliation. See Inventory Reconciliation.
Last reviewed: October 2026.