Skip to content
Tally & AccountingBeginner

How to Create a Secure Data Entry User Role in TallyPrime Using Standard Security (Without TDL)

In many organizations, data entry operators should be allowed to enter accounting transactions without having unrestricted access to company data, configurat...

BI
Bison Technical Team Enterprise IT specialists
Updated 23 Jul 2026 5 min read 0 views

In many organizations, data entry operators should be allowed to enter accounting transactions without having unrestricted access to company data, configuration settings, or sensitive financial reports. TallyPrime includes a powerful built-in Security Control system that enables administrators to create customized user roles and restrict access to specific voucher types, reports, masters, and company features.

This article explains how to configure a Data Entry user role in TallyPrime using only the standard features available in the software, without requiring any custom TDL (Tally Definition Language).

Advertisement

Objective

Create a secure Data Entry role that can:

  • Create, Alter, Display, and Delete:
    • Sales Vouchers
    • Purchase Vouchers
    • Receipt Vouchers
    • Payment Vouchers
    • Journal Vouchers
    • Contra Vouchers
  • Create new Stock Items during voucher entry.
  • Create new Ledgers whenever required.
  • Prevent access to company administration, security settings, backup, restore, and unwanted voucher types.

Prerequisites

Before creating user roles, ensure:

  • TallyPrime is activated.
  • You have Administrator rights.
  • Security Control is enabled for the company.

Step 1 – Enable Security Control

Open:

Gateway of Tally

Alt + K
→ Company
→ Users and Passwords
→ Security Control

Configure:

  • Use Security Control = Yes
  • Set Administrator Password

Save the configuration.


Step 2 – Create a New Security Role

Navigate to:

Alt + K
→ Users and Passwords
→ Types of Security

Create a new role.

Example Role Name:

DATA ENTRY

Base the role on:

Data Entry

This provides a suitable starting point.


Step 3 – Configure Voucher Type Security

Open:

Voucher Types

Allow Full Access only for:

Voucher Type Permission
Sales Full Access
Purchase Full Access
Receipt Full Access
Payment Full Access
Journal Full Access
Contra Full Access

Restrict all other voucher types:

  • Credit Note
  • Debit Note
  • Sales Order
  • Purchase Order
  • Receipt Note
  • Delivery Note
  • Rejections In
  • Rejections Out
  • Stock Journal
  • Physical Stock
  • Memorandum Voucher
  • Payroll Vouchers
  • Any custom voucher types not required

Set these voucher types to No Access.


Step 4 – Configure Accounts Masters

Open:

Accounts Masters

Recommended settings:

Master Permission
Ledgers Full Access
Groups Display Only

This allows:

  • Creating new ledgers
  • Altering ledgers
  • Selecting ledgers during voucher entry

At the same time, Group creation and modification remain protected.


Step 5 – Configure Inventory Masters

Navigate to:

Inventory Masters

Recommended permissions:

Master Permission
Stock Items Full Access
Stock Groups Display Only
Units Display Only
Godowns Display Only
Price Levels Display Only
Voucher Classes No Access

This configuration enables users to press Alt+C while entering Sales or Purchase vouchers to create new stock items whenever necessary.


Step 6 – Restrict Company Administration

Disable access to:

  • Company Alteration
  • Security Control
  • Backup
  • Restore
  • Rewrite Company
  • Split Company
  • Import
  • Synchronization
  • User Management

Set all these permissions to No Access.


Step 7 – Restrict Features and Configuration

Prevent users from modifying company settings.

Disable:

  • F11 Features
  • F12 Configuration

Permission:

No Access

Step 8 – Restrict Banking (Optional)

If users do not handle banking operations:

Banking

Permission:

No Access

Step 9 – Restrict Payroll

If Payroll is not part of the user's responsibility:

Payroll

No Access

Step 10 – Configure Report Access

Recommended permissions:

Report Permission
Day Book Display
Ledger Display
Stock Summary Display
Outstanding Reports Display (if required)
Trial Balance Display
Balance Sheet No Access
Profit & Loss No Access
Ratio Analysis No Access

This keeps sensitive financial information protected while allowing operational work.


Step 11 – Create User

Navigate to:

Alt + K
→ Users and Passwords
→ Users

Create a new user.

Assign:

  • Username
  • Password
  • Security Level = DATA ENTRY

Save the user.


Final Permissions Summary

Allowed

  • Sales Voucher
  • Purchase Voucher
  • Receipt Voucher
  • Payment Voucher
  • Journal Voucher
  • Contra Voucher
  • Ledger Creation
  • Stock Item Creation
  • Voucher Modification
  • Voucher Deletion

Restricted

  • Credit Note
  • Debit Note
  • Stock Journal
  • Sales Order
  • Purchase Order
  • Delivery Note
  • Receipt Note
  • Physical Stock
  • Payroll
  • Company Alteration
  • Backup
  • Restore
  • Security Settings
  • F11 Features
  • F12 Configuration

Standard TallyPrime Limitation

While standard TallyPrime Security is highly capable, it has an important limitation.

If Full Access is granted to:

  • Ledgers
  • Stock Items

the user can also open the Ledger Creation and Stock Item Creation screens directly from the Gateway of Tally.

Standard Security cannot restrict master creation only during voucher entry.

This behavior is by design.


When is TDL Required?

A custom TDL becomes necessary if you want to:

  • Allow Stock Item creation only through Sales/Purchase vouchers.
  • Allow Ledger creation only while entering vouchers.
  • Hide Ledger Creation menus.
  • Hide Stock Item menus.
  • Restrict specific ledger groups.
  • Restrict creation under selected stock groups.
  • Disable menu access while allowing Alt+C.
  • Implement workflow approvals.
  • Apply business-specific validation rules.

Best Practices

  • Always assign individual user accounts.
  • Use strong passwords for administrators.
  • Review user permissions periodically.
  • Restrict financial reports where possible.
  • Back up company data before modifying security settings.
  • Test permissions using a non-administrator account before deployment.
  • Document every custom security role for future maintenance.

Conclusion

TallyPrime's built-in Security Control provides an effective way to create secure Data Entry roles without requiring any customization. By allowing access only to the required voucher types and restricting company administration, organizations can reduce accidental changes while enabling efficient day-to-day accounting operations.

For businesses requiring finer control—such as permitting master creation only during voucher entry—a custom TDL remains the recommended solution.


Frequently Asked Questions (FAQ)

1. Can I allow only Sales and Purchase vouchers?

Yes. Voucher Type Security allows access to individual voucher types.

2. Can I prevent access to Credit Note and Debit Note?

Yes. Set those voucher types to No Access.

3. Can users create stock items during Sales Entry?

Yes. Grant Full Access to Stock Items.

4. Can users create ledgers during voucher entry?

Yes. Grant Full Access to Ledgers.

5. Can I stop users from opening the Ledger Creation menu while still allowing Alt+C?

No. This is not possible using standard TallyPrime Security. A custom TDL is required.

6. Can I restrict F11 and F12?

Yes. Both can be denied through Security Control.

7. Can I block Backup and Restore?

Yes. These permissions can be disabled for non-administrator users.

8. Can I allow only Display access to financial reports?

Yes. Report permissions can be configured individually.

9. Is TDL mandatory for user security?

No. Standard Security is sufficient for most businesses. TDL is only needed for advanced restrictions.

10. Is this configuration suitable for multi-user environments?

Yes. It works in both single-user and multi-user TallyPrime environments.

 

#TallyPrime #Tally #AccountingSoftware #BusinessAccounting #DataEntry #TallySecurity #UserRoles #VoucherSecurity #SalesVoucher #PurchaseVoucher #ReceiptVoucher #PaymentVoucher #JournalVoucher #ContraVoucher #StockItems #LedgerManagement #InventoryManagement #GST #Finance #Bookkeeping #Accounts #BusinessSoftware #ERP #SMB #Accounting #TallyTips #TallyTutorial #TallyGuide #TDL #WithoutTDL #UserPermissions #AccessControl #SecurityControl #BusinessSecurity #Inventory #FinancialManagement #AccountingSystem #IndianBusiness #CA #Accountant #Taxation #Audit #SoftwareGuide #ITSupport #EnterpriseSoftware #OfficeAutomation #BusinessProcess #Productivity #ERPSoftware #FinanceManagement

YOUR FEEDBACK

Was this guide useful?

Your answer helps us keep BISONKB accurate and practical.

BISON AI

Ask about “How to Create a Secure Data Entry User Role in TallyPrime Using Standard Security (Without TDL)”

This interface is ready to connect to your preferred AI provider. No article or user data is sent until that service is configured.

THE BISON BRIEF

Practical IT knowledge, once a week.

New troubleshooting guides, scripts and infrastructure notes. No noise.

By subscribing, you agree to our privacy policy.