Skip to main content
Question

Super access role - reduced functionality from 24R2

  • August 25, 2026
  • 1 reply
  • 33 views

Osthewha
Sidekick (Customer)
Forum|alt.badge.img+8

We want to make a complaint for functionality removed from the super access role. 

We have had 2 authorizers (at least) per supplier invoice for years, and uptil 24R2, our accounting-department have had the opportunity to remove authorizations, make correction for example for VAT, and then authorize again, without sending the already approved invoiced on a second round to our endusers.

The change made in this role, has made the control function for our accounting department, AND for our end users, much worse, since the invoices is now sent out TWICE!.

 

I hope that IFS will reconsider the functionality in the super access role.

1 reply

lisvse
Hero (Employee)
Forum|alt.badge.img+11
  • Hero (Employee)
  • August 26, 2026

Hi, 

This is done intentionally. From 24R2 and onwards it is not possible to be only one “user id” that authorizes if you have “Two Authorizers Required”. This was possible up until 24R1. If you had two different invoice posting authorizers a user with super access could authorize both. Which means it was only one user id that authorized the two different invoice posting authorizers. We got complaints from several customers about this and did a development. Here is the requirement description. 

 

Description

Customer has reported the issue of two Authorization requirement is not working the application when Authorizers are granted with the superior Authorizer access , According to them this two Authorizers requirement is required by Swedish law, each transaction goes through 2 sets of eyes (4-eye principle). Since IFS is not giving a warning or stopping them from authorizing the posting lines the 4-eye principle is not being followed, its a breach in the security

According to current application behavior when Two Authorizers Required is enabled under company it means that two invoice posting authorizers are required if the posting proposal exceeds the specified amount. The role of at least one invoice posting authorizer should be authorizer.

So that when an invoice to be Authorized, system checks whether two invoice posting authorizers are available and not users who perform the actual authorization.

Hope this clarifies what we have done.

There is a functionality called “Administrator User”. This is a role an invoice posting authorizer could have. This means that a posting can be changed by that invoice posting authorizer even it is authorized. Check if this solves your problem with having to send it out for authorization again. Then the user can do changes without unauthorize. 

Best regards, 

Linda