Channel Partner Blog

“Who Approved That?” Now Has an Easy Answer

28 September 2026

New read-only APIs let auditors and IT teams analyse permissions and approval workflows in Power BI — turning audit season from a scramble into a query.

Every finance leader knows the moment. The auditor sends through the list: who can post journals, who approved this batch of payments, which users hold which permissions, and can you prove the separation of duties actually held all year? Answering used to mean screenshots, exported spreadsheets, and a few uncomfortable hours reconstructing a story from scattered evidence.

With the 2026 Wave 1 release, Business Central makes that story far easier to tell. Microsoft has introduced read-only APIs on the permission system and the approval workflow system — letting auditors and IT teams query exactly who can do what, and who approved what, directly into tools like Power BI.

What's New

Two complementary sets of read-only APIs arrived, both generally available from 14 June 2026:

•      Permission APIs. Query the permission system — permission set object, scope and extension information; permission set–to–security group mappings; and permission set–to–user mappings. In plain terms: a clear, queryable picture of who has access to what.

•      Approval workflow APIs. Query the workflow approval system — workflows, workflow-to-user mappings, and the full workflow, user, and action history. In plain terms: a complete, auditable trail of who approved what, and when.

Both API sets are strictly read-only — they expose information for analysis without any ability to change it — and both can feed Power BI reports, or even agents built with Microsoft Copilot Studio and the MCP Server for Business Central.

Why This Matters

For any business that takes governance seriously — and especially those in regulated sectors or subject to external audit — this is a quietly significant upgrade:

•      Audit-ready, on demand. Instead of assembling evidence manually each audit cycle, you can build a standing Power BI report that answers the auditor's questions in real time.

•      Stronger separation of duties. Permission mappings make it straightforward to spot where one person holds conflicting access — the classic internal-control risk — before it becomes an audit finding.

•      Accountability you can demonstrate. A full approval history turns “we think it was approved correctly” into “here is exactly who approved it, and when.”

•      Security by design. Access to these APIs is gated behind a dedicated new permission set — so the audit capability itself is controlled, and not handed to standard users.

Before and After: Audit Season at a Firm in Accra

Before: The external auditors request a breakdown of user permissions and a sample of approval trails. The finance and IT teams spend the better part of a week pulling screenshots, exporting permission sets, and manually piecing together who approved which payments. Some evidence is incomplete, and a couple of separation-of-duties questions can't be answered cleanly.

After: IT has built a Power BI dashboard on the new read-only APIs. When the auditors arrive, permissions, security-group mappings, and the full approval history are already there — current, complete, and filterable. The questions that used to take days are answered in minutes, and the conversation shifts from “can you find it?” to “what would you like to see?”

At a glance

What: Read-only APIs for analysing permissions and approval workflows

General availability: 14 June 2026 (2026 Release Wave 1, version 28)

Permission APIs: Permission sets, security-group mappings, user mappings

Approval APIs: Workflows, user mappings, and full action history

Consume with: Power BI, Microsoft Copilot Studio, MCP Server — gated by a dedicated permission set

Why Resellers Should Pay Attention

For CSP resellers and partners, this opens a genuinely valuable service line. Building a governance and audit Power BI dashboard on these APIs is exactly the kind of high-value, repeatable engagement that deepens a customer relationship — and because the same dashboard pattern applies across many customers, it is work you can productise. It is also a natural conversation with any customer who has ever grumbled about audit preparation, internal controls, or proving separation of duties. Pair it with the new MCP server capabilities, and there is room to build genuinely intelligent compliance agents on top.

This release reflects a maturing platform philosophy: Business Central is not only automating the doing, but increasingly the proving — giving businesses the tools to demonstrate good governance, not just practise it. For African businesses operating under tightening regulatory and audit expectations, that is a direction worth getting ahead of.

Let's Talk

If audit preparation, internal controls, or proving separation of duties is a recurring headache, these new APIs are the foundation of a much smoother process. 4Sight's Dynamics Africa Services team can design and build a governance and audit Power BI dashboard on your Business Central environment — so the next audit is a query, not a scramble.

Contact us on: channel@4sight.cloud

Book a governance and audit dashboard consultation with 4Sight.

References

[1] Use new APIs for analyzing permissions for auditors and IT staff (2026 release wave 1 plan) — Microsoft Learn

learn.microsoft.com/en-us/dynamics365/release-plan/2026wave1/smb/dynamics365-business-central/use-new-apis-analyzing-permissions-auditors-it-staff

[2] Use new APIs for analyzing approval workflows for auditors and IT staff (2026 release wave 1 plan) — Microsoft Learn

learn.microsoft.com/en-us/dynamics365/release-plan/2026wave1/smb/dynamics365-business-central/use-new-apis-analyzing-approval-workflows-auditors-it-staff

[3] Use approval workflows — Microsoft Learn

learn.microsoft.com/en-us/dynamics365/business-central/across-use-workflows

[4] Update 28.0 for Business Central 2026 release wave 1 — Microsoft Learn

learn.microsoft.com/en-us/dynamics365/business-central/dev-itpro/whatsnew/whatsnew-update-28-0