SEPA payment import: who may see the recipients
Two permission sets in 365 business Banking separate who only approves and executes a payroll file from who may see each recipient line.
A payroll file names every person and their salary. Users who approve or carry out the payment usually do not need this information. For this reason, SEPA payment import has two permission sets that differ in one point only: whether the lines are readable.
Two permission sets
| Permission set | Sees | May |
|---|---|---|
| Banking SEPA Import (no recipient details) | the header: file, status, Number of Payment Instructions, Total Amount, bank account, approval status, Carried Out At, Carried Out By | import, Parse, Validate, request approval, Reopen, Carry Out Payment, Print Payment Proof, delete |
| Banking SEPA Import (with recipient details) | in addition every line with name, IBAN, amount and message, and the Line Errors FactBox | the same, plus Verification of Payee (VoP), Update Execution Dates and Make Collective Payment |
The Banking (Base) set does not include SEPA payment import. Anyone who works with payment imports needs one of the two sets in addition. All permission sets of 365 business Banking are listed in Permissions and licenses.
What is hidden
With Banking SEPA Import (no recipient details), the SEPA Payment Import card does not show the following elements:
- the Lines part and with it the line actions Update Execution Dates and Make Collective Payment,
- the Line Errors FactBox, because its messages name the line and thus the recipient,
- the Verification of Payee (VoP) action, because its result is written to the lines.
Permission, not just hiding
The set grants permission for the lines only indirectly. Business Central reads the lines to parse, validate and pay. However, the person cannot read them on a page, through Edit in Excel or through the API. The SEPA Payment Proof reads only amount and currency from the lines, to total them per currency. It only shows the count and the total.
Without the lines, this person also cannot see which line has an error. If an import has the status Error, a user with the full set must check the lines.
Recommendation
- Approvers and the accounting staff who trigger the payment get Banking SEPA Import (no recipient details). For approval, the total amount and the count are relevant, and both are visible to these users.
- Only assign Banking SEPA Import (with recipient details) to users who must check the file's content (typically payroll) or who must resolve errors in the lines and have the recipients verified.
- Assign the sets like any other permission set. See Assign permissions on Microsoft Learn.
See also
- SEPA payment import
- Approval and verification of payee
- Payment proof and retention
- Permissions and licenses
