SecurityLast Updated: June 2026

Here’s a scenario that plays out more often than it should. A new employee starts in your accounts payable department. Someone in IT sets them up with a login, copies permissions from a coworker, and calls it done. Six months later, you discover that the employee has access to vendor records, bank accounts, and payroll data they never needed to touch. Nobody caught it because nobody reviewed it.

That’s not a technology problem. That’s a process problem, and Acumatica gives you the tools to fix it, as long as you know how to use them.

Acumatica’s security model is built on roles, not individual user settings. That distinction matters. Instead of configuring access one person at a time, you define what a role can do, then assign users to the appropriate roles. Change the role, and every user in it inherits the change. It’s cleaner, faster to audit, and far less likely to drift into the kind of permission creep that creates real risk.

How Acumatica Security Roles Actually Work

Acumatica uses a role-based access control (RBAC) model. Every user belongs to one or more roles, and those roles determine what screens, reports, and actions are available to them.

Roles in Acumatica are additive, meaning if a user belongs to two roles, they get the combined permissions of both. That’s useful when you have someone who wears multiple hats, say, a warehouse supervisor who also needs to run purchasing reports. You don’t build a custom role from scratch. You assign both relevant roles and let Acumatica combine them.

Out of the box, Acumatica ships with a set of predefined roles that map to common job functions: Administrator, Auditor, Financial Supervisor, and others. These are solid starting points, but most companies end up modifying. Your business isn’t generic, and your security roles probably shouldn’t be either.

Setting Up and Personalizing Security Roles

Employee Chart

 

 

 

 

 

 

 

 

You’ll find role management under the System section of Acumatica, inside the Security area. From the Roles screen, you can view existing roles, clone them, or create new ones from scratch.

Here’s the reality: the access rights configuration is granular. Screen by screen, action by action. You can allow a user to view a record but not edit it or create purchase orders but not approve them. That level of precision is genuinely valuable, but it also means the initial setup requires real thought. Don’t rush it.

A few things worth knowing before you start building roles:

The “Allow” and “Deny” logic in Acumatica is explicit. If a screen isn’t included in a role’s access rights, the user simply won’t see it. You don’t have to actively block everything, but you do need to actively grant access to what people need.

Field-level security is available, and it’s worth using for sensitive data. You can restrict the visibility of specific fields on a screen without hiding the entire screen. If your sales team needs to see customer records but shouldn’t see payment terms or credit limits, that’s configurable.

For a deeper look at configuring access rights, Acumatica’s documentation on role-based access walks through the mechanics in detail.

Assigning Users to Roles in Acumatica

Acumatica User Roles

 

 

 

 

 

 

 

 

 

 

Once your roles are built, assigning them to users is pretty straightforward. From the Users screen, you pull up an individual user’s record, navigate to the Roles tab, and check the boxes for the roles they need.

The mistake most companies make here is treating role assignments as a one-time event. People change jobs. They get promoted, move to different departments, and take on temporary projects. If you don’t have a process to review and update role assignments when that happens, you end up back where you started, with people holding access they shouldn’t have.

Technology isn’t the hard part. Acumatica makes the mechanics of user permissions manageable. The hard part is governance. Who owns the process of reviewing roles? How often does it happen? What triggers a review when an employee changes roles?

Those are questions worth answering before you go live, not after an audit.

Using Restriction Groups for Row-Level Security

Standard Acumatica security roles control access to screens and actions. Restriction groups go one level deeper, controlling which specific records a user can see within a screen.

This is where things get useful for multi-entity businesses or companies with sensitive customer segments. You can configure restriction groups so that users in one branch or division only see their own data, even though they’re working in the same Acumatica environment as everyone else.

Restriction groups apply across several record types: customers, vendors, inventory items, financial periods, and more. The Acumatica help center covers restriction group setup in detail if you want to dig into the specifics.

Common Mistakes to Avoid

Checklist

 

 

 

 

 

 

 

 

We see a few things happen again and again when our clients configure Acumatica user permissions for the first time.

  1. Cloning the Administrator role because it’s easier than building from scratch. That’s a shortcut that creates significant risk. Administrator access is broad by design. Most users don’t need it and shouldn’t have it.
  2. Skipping the audit trail review. Acumatica logs user activity, and that data is valuable. Set aside time to review it periodically. If someone is accessing screens they don’t routinely need for their job, that’s worth understanding.
  3. Not testing roles before go-live. Build a test user for each major role you create and walk through the relevant workflows. Access issues are much easier to fix before they affect real data and real people.

Getting Acumatica Security Roles Right from the Start

Configuring Acumatica security roles correctly upfront saves a lot of cleanup later. It also gives your business a real audit trail, limits exposure if credentials are ever compromised, and keeps sensitive financial and operational data where it belongs.

If you’re implementing Acumatica for the first time or cleaning up a permission structure that’s grown unwieldy, this is one area where getting outside help pays off. The configuration work isn’t especially complex, but the planning behind it, mapping roles to actual job functions and business rules, takes experience.

CAL Business Solutions works with mid-sized businesses across manufacturing, distribution, and professional services to implement and configure Acumatica the right way.

Contact Us