Permissions & roles
CommissionCentral has four role-based permission sets. They map to the people who work with commissions. Assign them through Users → Permission Sets, or through user groups or Entra security groups. The procedure is the same as for any Business Central permission set.
The four roles
| Permission set (caption) | Object name | Intended user | Grants |
|---|---|---|---|
| CommissionCentral - Admin/Implementer | TigCM Comm. Admin |
System administrator / implementer | Full scope: edit the setup; author plans, agents, networks, and manager teams; run and post payment batches; run both commission reports; install/upgrade and demo data. Full write to the setup. Append-only writes to the ledger. |
| CommissionCentral - Manager | TigCM Comm. Manager |
Sales manager | Maintains agent assignments, networks, and manager teams. Reads the whole team’s commission ledger. Runs the Commission Audit and Commission Summary reports. Reads payment batches, but does not post them. |
| CommissionCentral - Finance | TigCM Comm. Finance |
Finance / A/P / payroll | Posts manual adjustments and reversals. Places holds and releases entries. Runs and posts payment batches. Creates draw advances. Runs both commission reports. Append-only writes to the ledger. |
| CommissionCentral - Rep | TigCM Comm. Rep |
Sales representative | Read-only access to commission ledger entries. No setup, plan, agent, or payment access. |
Rep data isolation (V1). The Rep set grants read access to commission data. A restriction to only the rep’s own entries (per-row isolation) comes with the salesperson self-service portal in a later release. In V1, use your tenant’s security filters if you must limit rep visibility.
Composition (for administrators)
Non-assignable building blocks compose the four assignable roles. The object lists then live in one place:
| Building block | Object name | Contents |
|---|---|---|
| Ledger read | TigCM Comm. Ledger Read |
Read on the ledger + detail tables and the ledger list page |
| Read pages | TigCM Comm. Read Pages |
Execute on the ledger card and detail pages |
| Plan | TigCM Comm. Plan |
Plans, rate rules, tiers, rate matrix |
| Agent | TigCM Comm. Agent |
Agent assignments, networks, manager teams |
| Engine | TigCM Comm. Engine |
Commission journal and engine codeunits |
Assign only the four role sets. Each role set includes its building blocks automatically.
Suggested assignments
- Implementer / BC admin → Admin/Implementer during the rollout. Narrow the access when the rollout is complete.
- Sales managers → Manager.
- Commission accountant / payroll / A/P → Finance.
- Sales reps → Rep.
A user who both configures and pays (a small team) can hold Admin/Implementer. That set is a superset of the others.
Figure: the four CommissionCentral permission sets in Permission Sets.