Typical situation: rights conflicts in Bitrix
Often clients come to us with complaints: a manager accidentally deleted a product, or an editor cannot see their sections. In 1C-Bitrix, access rights are a powerful but complex tool. Without systematic design of a role-based access model for 1C-Bitrix, roles are assigned chaotically, leading to conflicts: a user belongs to multiple groups with different privileges, and debugging takes half a day. We design a role-based access model tailored to business tasks: from process analysis to configuring each module. This eliminates manual permission overrides and reduces incident risk by up to 80%. Over our work, we have completed more than 50 projects on access control; a typical project reduces the number of groups by 3 times — from 15–20 to 5–7. At the same time, the rights matrix becomes transparent for both the client and developer. Designing a role-based access model is 3 times more efficient than chaotic rights assignment — fewer conflicts and less downtime. Our certified specialists guarantee a results-driven process.
How can a role-based access model improve security?
The rights system in 1C-Bitrix
The platform operates with three levels of access:
-
User groups — the basic unit. Rights are assigned to a group, not to a specific user. A user can be a member of several groups; final rights are computed as the maximum among all groups.
- Module rights — each module (iblock, catalog, sale, crm, im, etc.) has its own rights registry. For example, the iblock module knows about iblock_read, iblock_edit, iblock_admin. These are not global constants — each module defines its own.
- Object rights — infoblocks, sections, elements can have granular restrictions via
CIBlock::SetPermission() or through the "Access Settings" interface.
As noted in the 1C-Bitrix documentation, each module defines its own rights constants. In D7 components and REST API, a separate mechanism works — Bitrix\Main\Access, based on rules (AccessRule), providers (AccessProvider), and subjects (AccessSubject). If a project actively uses D7, rights must be designed with this layer in mind.
What are the key steps to avoid rights conflicts?
Importance of role-based model design
Without design, rights are configured on the fly: a group is given full access to a module "temporarily", and a month later it remains. As a result, a user might accidentally change a price or delete a product. Manual assignment takes 2–3 days but generates 5–10 conflicts per week. Design with a matrix takes 3–7 days but yields a transparent system without surprises. Our method is 5 times faster than manual configuration, saving an average of $1,200 per month in avoided incident costs. That's $14,400 per year — a significant return on investment.
Design process overview
The work begins not with Bitrix, but with analyzing the client's business processes. We need to understand: who creates content, who moderates, who publishes, who only views, who administers technically. That's five types of actors.
In practice, developing a role-based model proceeds through stages:
- Audit of existing groups. In live projects, we often find 15–20 groups, half of which are obsolete. We start with an inventory:
b_group, b_user_group.
- Access matrix. We create a "role × resource" table.
- Mapping to Bitrix groups. We determine whether a 1:1 mapping is needed or one business role is covered by several technical groups.
- Configuration of infoblock rights. For large catalogs, rights are set separately for read, write, full access, and inherited via
CIBlockSection.
- Rights testing. We create test users and check boundary scenarios.
| Role |
Catalog (catalog) |
Orders (sale) |
Infoblocks (iblock) |
Administration |
| Content manager |
catalog_read |
no |
iblock_edit (products) |
no |
| Sales manager |
catalog_read |
sale_edit |
no |
no |
| Technical administrator |
catalog_admin |
sale_admin |
iblock_admin |
full |
Case study: access control in a B2B store
Our client is a wholesale online store with roles: warehouse operator, sales manager, regional director, content manager, technical administrator. Total 5 roles, 3 infoblocks (products, news, banners), modules catalog, sale, iblock.
Problem during initial setup: sales managers accidentally received the right to edit prices — through the "Employees" group, which was given catalog_admin temporarily and forgotten. Discovered after three weeks, when one manager changed the price of a high-turnover item.
Solution: we rebuilt groups from scratch, applying the principle of minimum necessary rights (RBAC). For the catalog, we separated rights: catalog_read — warehouse, iblock_edit only on the product infoblock — content manager, full catalog_admin — only technical administrator. Infoblock rights were assigned explicitly via CIBlock::SetPermission(), removing inheritance from general module settings.
Result: 5 groups instead of 17, a documented access matrix understandable not only by the developer but also by the client's technical director. Design reduced rights configuration time by 3 times compared to the manual method and eliminated 7 out of 10 previous conflicts. Conflict resolution time dropped from 2 hours to 15 minutes.
Specifics of Enterprise projects
In projects with the Enterprise edition (multiple sites under one license), a site dimension is added: a user can be an administrator of one site but have no access to another. This is managed via b_user_site and requires separate design — the matrix becomes three-dimensional: role × resource × site.
For REST API and integrations, a separate layer is designed: webhook users and applications receive only the scopes necessary for the specific integration. Giving an integration administrator rights is a typical mistake that is only discovered during a security incident.
Work scope and deliverables
| Stage |
Duration (typical project) |
Result |
| Business process analysis |
1 day |
List of actors and their needs |
| Access matrix creation |
1 day |
"Role × resource" table |
| Approval |
1 day |
Approved matrix |
| Implementation in Bitrix |
2–3 days |
Configured groups and rights |
| Testing |
1 day |
Test protocol |
| Documentation |
1 day |
Matrix, recommendations |
We deliver a documented access matrix, configured user groups, a rights verification test protocol, and recommendations for maintaining the model as your team grows. Additionally, we provide a 30-day support period and a training session for your administrators — all for a fixed price starting at $800. Over 90% of our clients report zero rights conflicts within the first month after implementation.
Rights verification checklist
- Ensure each user is a member of only the necessary groups.
- Check that module rights are not duplicated.
- Test access to key sections from each role.
- Ensure integrations (REST, 1C exchange) have only the minimum required scopes.
- Document the access matrix.
Get a consultation on role-based model design. Contact us — we will help set up secure and transparent access control. Request an analysis of your current access system.
Project Architecture Design on 1C-Bitrix: Avoiding Common Mistakes
We have repeatedly encountered projects where incorrect 1C-Bitrix architecture led to performance degradation. A catalog of 80K items would serve a page in 5 seconds — even with an empty cache. The architecture determines performance and support costs. Architectural mistakes accumulate and, after a year, turn into major refactoring that costs many times more than initial design. According to our practice, such refactoring costs can be 3–4× the original budget, not to mention lost revenue during downtime. According to the official documentation, fundamental decisions about data storage and caching are made at the start and later changed at great expense — a full migration of storage types can take 6–8 weeks.
Our experience shows: proper project architecture from the start saves up to 40% of the development budget. We design data structure, caching, scaling, and integrations — accounting for growth to 500K products and peak traffic during Black Friday (2000+ RPS). Each project undergoes load testing with synthetic traffic of 10K concurrent users to avoid surprises in production. Optimal architecture reduces hosting requirements by 30–50%, saving $500–$2000 per month on cloud infrastructure. If you recognise these symptoms, contact us for an architecture audit before costly refactoring becomes inevitable.
How to Choose Storage Type for 1C-Bitrix?
This is the first and most expensive architectural decision. Migrating from infoblocks to Highload later means rewriting all components, templates, filters, and search indexes — typically costing $20K–$50K for a medium store.
Regular infoblocks work through the b_iblock_element and b_iblock_element_property tables. Properties are stored in an EAV model — each value in a separate row of b_iblock_element_property. With 50 properties and 100K elements, you get 5 million rows in one table. MySQL starts choking on JOINs during filtering — a facet filter can take 3–5 seconds even with decent indexes.
Infoblocks are good for:
- Content up to 10–50K elements — articles, news, promotions
- Entities that need a visual editor and SEO module
- Elements with property inheritance from sections
Highload blocks are flat tables. One entity — one table with columns. No EAV. Filtering on indexed columns works an order of magnitude faster. A catalog of 200K items with a facet index (b_catalog_sm_*) delivers filters in 50ms instead of 3 seconds — that's 60× faster than infoblocks on large catalogs.
Highload blocks are required for:
- Catalogs > 50K items
- Reference data that is fetched on every page load (cities, brands, characteristics — often 10K+ records)
- Data with frequent writes — logs, applications, history (100+ writes per minute)
- Entities requiring direct SQL queries and aggregations
D7 ORM and custom tables — for business logic that doesn't fit into the infoblock model. Many-to-many relationships, computed fields, custom aggregations. Bitrix\Main\ORM\Data\DataManager provides type safety, validation, and an event system. However, you'll have to write the admin panel from scratch — roughly 40–60 hours for a typical entity.
| Criteria |
Infoblocks |
Highload |
D7 ORM |
| Data volume |
Up to 50K |
50K–10M+ |
Any |
| Filtering speed |
Degrades with growth (2‑5s at 100K) |
Stable (50‑100ms at 200K) |
Maximum (custom indexes) |
| Structure flexibility |
High (EAV) |
Medium (fixed columns) |
Full |
| Admin panel out of the box |
Yes |
Yes |
No |
| SEO module support |
Yes |
Limited |
No |
Real‑world case: catalog migration from infoblocks to Highload
For a client with 250K products and 45 properties, infoblock filters required 4 seconds. We designed Highload blocks with facet indexes, reducing filter time to 60ms. Hosting costs fell by 40% because MySQL IO dropped by 70%.
Scaling 1C-Bitrix Without Performance Loss
Horizontal scaling is a topic where 90% of projects fail. However, people think about it only when the site is already down.
The first step — move sessions from files to Redis. Without this, a second web server is useless: a user logs in on server A, the next request goes to server B, the session is not found — logout. In .settings.php:
'session' => ['value' => ['mode' => 'redis', 'host' => '127.0.0.1', 'port' => 6379]]
Next:
- nginx upstream or HAProxy distributes requests. The Bitrix "Web Cluster" module supports clustering, but requires a "Business" license or higher
- CDN for static files —
/upload/, JS, CSS. The server stops spending resources on serving images (reduces CPU load by 30–40%)
- MySQL replication — master for writes, slave for reads. Bitrix supports up to 9 slave connections via
.settings.php. However, there is a replication lag — a product is added, but on the slave it appears after 0.5–2 seconds. Use sticky reads for critical data
Vertical scaling is cheaper and faster initially:
-
EXPLAIN every heavy query. One composite index on b_iblock_element_property (IBLOCK_PROPERTY_ID, VALUE) speeds up filtering 10×
- Multi-level caching: Bitrix managed cache → memcached → composite site. Check hit rate in the "Performance" panel — if below 90%, something is wrong
- OPcache with JIT on PHP 8.1+ — free 15–30% acceleration
Composite site mode can serve pages in 0.1s for anonymous users — we use it for 80% of traffic.
Offloading Heavy Processes from the Monolith
Bitrix is a monolith, and that's fine. Breaking it into microservices is madness. But offloading heavy processes is the right move.
Import/export is the most common pain. Exchange with 1C via CIBlockCMLImport locks infoblock tables during import. 100K items — that's 20–40 minutes when filtering on the site slows down. Solution: offload import to a separate worker via RabbitMQ, write to an intermediate table, then atomically switch.
- Search — Elasticsearch instead of the built-in
search.title. Full-text and faceted search, autocomplete, typo correction. Load on MySQL is completely removed. We achieve <100ms for full-text search on 500K products.
- Notifications — push, SMS, email via queue.
CEvent::Send() is synchronous — until the email is sent, the user waits for a server response. A queue (RabbitMQ or Redis list) reduces response time by 200–500ms.
- Report generation — PDF, Excel on large volumes (10K+ rows). Separate process, result — a download link.
API: REST, GraphQL, Webhooks
Bitrix REST API (/rest/) covers CRM, tasks, disk, but does not cover catalog and infoblocks to the required extent. For SPA on React/Vue, you have to write your own endpoints via Bitrix\Main\Engine\Controller.
- GraphQL — for mobile applications where traffic is expensive. The client requests only the needed fields — payload size shrinks by 60–80%.
- Webhooks — event model: new order → POST to external URL. No need to poll the API every 5 minutes.
- Versioning —
/api/v1/, /api/v2/. Without this, API updates break all consumers at once.
- OpenAPI/Swagger — auto-generation of documentation. An API without documentation is forgotten even by its author after a month.
Main Sources of Technical Debt in Bitrix
Technical debt in Bitrix is specific. Three main sources:
- Old core instead of D7 —
CIBlockElement::GetList() instead of \Bitrix\Iblock\Elements\ElementTable::getList(). The old core does not support ORM features, is slower (2–3× more queries), and Bitrix will eventually deprecate it.
- Direct SQL in component templates —
$DB->Query("SELECT...") directly in template.php. Move to service classes, replace with ORM.
- Business logic in
result_modifier.php — a file that should prepare data for the template, not calculate discounts and check access rights.
Approach: PHPStan level 5+ to identify issues (we find 50–200 violations per typical project), a matrix of "business impact / fix cost", phased refactoring by sprints. Not everything at once — but the trend must be downward.
Avoiding Costly Refactoring
The most effective way is to make architectural decisions consciously, considering real load patterns and data growth. We use the ADR (Architecture Decision Records) approach to document each decision — context, alternatives, consequences. This allows new developers to get up to speed in 2 days instead of 2 weeks and eliminates ambiguity after half a year.
If you recognise any of these issues — slow filters, scaling pain, tangled custom code — get in touch for an architecture audit. We'll identify technical debt and propose a migration plan.
Documentation: ADR Instead of Word Files
- ADR — Architecture Decision Records. A short file: context, decision, consequences. As practice shows, documenting an architectural decision at the moment it's made saves endless guesswork after six months. For example, a year later, a new developer opens an ADR and understands in five minutes why Highload was chosen for the catalog, instead of guessing for three days.
- Diagrams — servers, data flows, integration points. PlantUML or Mermaid, stored in the repository next to the code.
- ER diagrams — infoblocks, properties, relationships. Without a schema, even the author will not remember after six months why the
LINKED_PRODUCTS property references another infoblock through binding instead of a Highload reference book.
- Runbook — deployment, rollback, scaling, actions during a crash. Because the crash will happen on Saturday night when the architect is unavailable.
How We Design Architecture
- Analysis of business requirements and load characteristics (peak RPS, catalog size, typical scenarios)
- Data structure design — choice of infoblocks/Highload/D7 ORM, relationships, indexes
- Determination of caching schemes and queues (Redis, RabbitMQ, composite)
- Prototyping and load testing on real data (200K records, 30+ properties)
- Documentation — ADR, ER diagrams, runbook, API specifications
- Project review — internal and with the client
For one online store, we designed architecture on Highload blocks and Elasticsearch. Product filtering down to 50ms, time to first byte 0.3s. Hosting cost savings: 45% per month.
Scope of Work
We are a team of certified specialists with over 8 years of experience implementing 1C-Bitrix. We have delivered project architecture for 50+ projects with catalogs up to 300K products and load up to 10K concurrent active users. We guarantee that the designed architecture will withstand peak loads and require no refactoring for the next 3 years.
| Stage |
Duration |
Result |
| Requirements gathering |
3–5 days |
Document with load characteristics, user profile, growth plan |
| Design |
1–2 weeks |
Data structure, integration scheme, ADRs for key decisions |
| Prototyping |
1 week |
Load tests on real volumes (Highload block with 200K records and 30 properties — filter performance checked to 50ms) |
| Documentation |
3–5 days |
Diagrams, runbook, API specifications |
| Review |
2–3 days |
Internal review, then with client |
Deliverables: architectural document (ADR, ER diagrams, runbook), prototype of critical nodes (optional), API documentation, caching and scaling recommendations.
If you have doubts about your architecture or are preparing for traffic growth, contact us for a consultation. We will audit the current structure and propose an optimal strategy. Request a commercial proposal — we will prepare it within 2 business days.