Journal Entry security is applied based on the security profiles set for the journal's associated model.

When you open the Journals module, the New Query dialog lets you select members or automatically fills in default values from the JE Configuration member value. If you don’t have access to a selected or prepopulated member, the field remains blank, and a message appears: 

Insufficient member access for dimension <DimensionName>. Please contact the System Administrator.

A journal entry can only be accessed for reading by a user if they have read access to all members of the entry, including recurring from/to dates. Similarly, a user can only have write access to a journal entry if they have write access to all members and dates associated with it. 

When defining model security, the same rules apply for enforcing security when creating or editing a journal entry. This means that when selecting members for a journal entry, you can only select from those allowed by your write-security profile.

In the journal header, the Permissions column displays a pencil with a line through it when a user has only read access to all members in the entry's header and details. This indicates that the user lacks write access to at least one member in either the header or details.

When duplicating a Journal Entry (JE), any members the user lacks permission to access the source JE are blanked out.

For example, if a user has Read access to USA and Canada but Write access only to Canada, both USA and Canada JEs appear in the JE Query. However, if the user duplicates a USA journal entry, the Entity member is blank due to insufficient write access.

ConditionBehavior
Full write access to all members of the entryCan edit, post, update, and attach files.
Read- access to any members of the entryEntry is viewable but can't be modified.
No access to any members of the entryThe entry doesn't appear at all.
ActionRead AccessWrite Access
View Header and Detail sectionsRequiredNot required
Create new entryNot requiredRequired 
Edit Header and DetailRequiredRequired
Import, edit, post, and attach filesNot requiredRequired
View entries for closed periodsRequiredNot required
Create entries for closed periodsNot RequiredRequired
ScenariosDescription
Selectable membersThe Journal Entry module automatically filters members based on security settings.
Parent membersVisible or writeable only if the profile allows access to that member or a child member.
Leaf membersNot visible or writeable if outside the selected parent-child relationship access scope.
Grayed-out parent membersGrayed out if the selection is restricted.
Fixed Members

If an entry is assigned a fixed member that the user lacks access to, it won’t be displayed. 

A warning message specifies the missing access.

Manual entry of restricted membersResults in an invalid option error.
Property-based filteringRestricted members may still appear, but users will receive a message upon selection.