Skip to main content

Troubleshoot document and batch security errors in COINS ERP+

Resolve common document and batch security errors in COINS ERP+, including DM130, SY132, cross-user batch access, timesheet visibility and ESS portal access problems.

Written by Sunil

This article covers common errors related to document group security and batch security in COINS ERP+. For guidance on setting up document group security from scratch, see How to implement document security. For a full explanation of how batch security levels and prime groups work, see Batch Security in Coins ERP+.


Error DM130: not authorised to delete a document

This error appears when a user tries to delete a document from the Document Capture Workbench or a similar screen and does not have the required security level or AP security permissions.

  1. Confirm the user has the required function permission to delete documents in the relevant module, deleting documents requires a specific delete function access right, separate from view access.

  2. Check the user's AP security at group and subgroup level. Delete access on a document may be controlled by AP security settings independently of document group security.

  3. If the user has the correct document group access but still sees DM130, compare their security configuration with a user who can delete successfully and identify any differences.

  4. If the issue affects only documents auto-indexed via Document Capture, confirm that the document group security code list for the user includes the group assigned during auto-indexing.

📌Note: Document group security and function permissions are evaluated independently. A user needs both the correct document group access AND the relevant function permission to delete a document.


Error SY132: not authorised to amend another user's batch

This error appears when a user tries to edit or post a batch created by another user and does not meet the security level and prime group requirements for cross-user batch access.

To access another user's batch, the editing user must have BOTH of the following:

  • An equal or higher security level (0–9) than the user who created the batch.

  • Access to the batch creator's prime group — either as their own prime group or as an additional group on their user record.

Check the security level

  1. Go to System, then User Maintenance, then User Workbench.

  2. Open the record of the user who is receiving SY132.

  3. Check their Security Level field.

  4. Open the record of the user who created the batch and note their Security Level.

  5. If the editing user's level is lower than the creator's, increase it to match or exceed the creator's level.

Check the prime group

  1. Note the Prime Group on the record of the user who created the batch.

  2. Open the record of the user receiving SY132 and check whether the creator's prime group appears in their list of security groups.

  3. If it does not, add the creator's prime group as an additional group on the editing user's record.

Allow same-security-level users to access each other's batches (SY/EQACCESS)

By default, a user must have a strictly higher security level than the batch creator to access their batches. To allow users with the same security level to access each other's batches within the same group, set the SY/EQACCESS parameter to Y.

  1. Go to System, then Global Parameters.

  2. Search for SY/EQACCESS.

  3. Set the value to Y.

  4. Save the change.

⚠️Important: Setting SY/EQACCESS to Y allows all users with the same security level who share a prime group to see and edit each other's batches. Confirm with your system administrator that this is appropriate for your organisation before changing this parameter.


Timesheet or employee records not visible to a manager

If a manager or team leader cannot see their direct reports' timesheets or employee records, the cause is usually a blank Subordinates list in Timesheet Input Group Security.

  1. Go to Payroll, then Setup, then Timesheet Input Group Security.

  2. Open the record for the affected manager.

  3. Check the Subordinates list. If it is blank, the manager will only be able to see their own timesheet.

  4. Add the usernames of the employees whose timesheets the manager should be able to view.

  5. Save the record.

📌Note: The Subordinates list must be configured for each manager individually. Changes take effect immediately — no restart is required.


ESS Portal Approver Workbench not visible

If a user is listed as an ESS TS Manager in HR setup but cannot see the ESS Portal Approver Workbench, the cause is usually a missing portal user link or a missing portal role.

  1. Go to the ESS Portal configuration in COINS ERP+.

  2. Confirm the affected user has a Portal User link — without this, the user cannot access portal workbenches even if they have the correct HR setup.

  3. Check that the Employee Self Service Portal User Role is assigned to the user.

  4. If either is missing, add the Portal User link and assign the role, then ask the user to log out and back in to the portal.


Contract or job records not visible to a user

If a user cannot see a specific contract or job record despite appearing to have the correct access, the contract security configuration may be incomplete.

  1. Go to the user's contract security record.

  2. Check the Security List field. If it is blank, the user has no access to any contracts via contract security.

  3. To grant access to all contracts, set the Security List field to * (asterisk).

  4. To grant access to a specific contract only, enter the contract code in the Code field.

  5. Save the record and ask the user to regenerate the security file if prompted.

📌Note: Contract security and document group security are evaluated independently. A user can have contract security access to a record but still be blocked from viewing attached documents if they lack the correct document group access.


Raise a support ticket

Raise a support ticket if:

  • Error DM130 persists after confirming function permissions and AP security settings.

  • Error SY132 persists after checking the security level and prime group configuration.

  • A contract security change does not take effect after saving and regenerating the security file.

Include the username affected, the error code and message, the module or screen where the error occurred, and a comparison of the affected user's settings against a user who does not have the error.

Did this answer your question?