Limit what people can see and do
Hide or mask fields, narrow which records a role reaches, add dated exceptions and set approval ceilings.
Before you begin
Roles decide what a person may do. These four screens refine that. They sit under Administration > Users:
- Field access hides, masks or locks one field.
- Record access narrows which rows a role or person reaches.
- Exceptions and limits adds a dated allow or refuse, and approval amount ceilings.
You need member.manage. Viewers and plain members see no change buttons; any change they attempt is refused with 'You do not have permission for this action.'
Restrict a field
- Open Field access and click Restrict a field.
- Choose the Record: Contacts, Products, Orders and invoices, Journal entries, Transfers, Receipt exceptions, Leads and opportunities, Employees or Personal details.
- Choose the Field of that record, for example Phone.
- Choose Applies to: a role or a person. A rule for a person wins over their roles. A person from another company is refused: 'That person is not a member of this company.'
- Choose the Restriction: Hidden (the field is not in the record), Masked (shown as ●●●●) or Read-only.
- Optionally type Why (up to 200 characters).
- Save.
A hidden field is gone everywhere for the holder: on the record, in lists, in exports and in search. Restricting the same record, field and subject again updates the existing rule rather than adding a second. Click Lift to remove a rule.
Narrow a record
- Open Record access and click Narrow a record.
- Choose the Record and Applies to (role or person).
- Choose Reaches. The list shows only what that record supports: Nothing, Their own, Their team's, Their department's, Their branch's, Where they are placed, or The whole company. The default is the whole company (for CRM, their team).
- Add Why and save.
A holder of the narrowed role sees only those rows, even if they know the address of another record. Lift returns the record to its default.
Add an exception
An exception lets one person do something their roles do not allow, or stops them doing something they would be allowed to. It has an end date.
- Open Exceptions and limits and click Add an exception.
- Choose the Person. Empty gives 'Name the person this is about.'
- Choose the Record and the Action.
* Everything on this recordcovers all actions. - Choose the Effect: Allow or Refuse. A refusal beats every role.
- Choose Until. The date must be in the future ('That expiry has already passed.'). It is stored as the end of that day in UTC, which is early the next morning in Dubai.
- Add Why (up to 300 characters) and save.
After the date, the exception shows Expired and stops applying. Withdraw ends one early; Remove deletes it.
Set an approval limit
- Click Set an approval limit.
- Choose the Person.
- Choose what they are Approving: Order limit, Journal limit or Receipt exception limit.
- Type Up to, an amount of 0 or more. A negative number is refused: 'A limit cannot be negative.'
- Add Why and save.
The person may approve at or below the amount and is refused above it. Remove the limit to allow any amount.
Worked example
Omar approves journals for the finance team. You set Journal limit to AED 5,000 for him and add an Allow exception on Journal entries for Layla until next Friday while he is on leave. Omar can approve a journal of AED 4,800 but is refused one of AED 6,000. Layla, who has no limit, can approve both during the exception, but cannot approve her own entries.
What happens next
Rules take effect for the person's next request. The Why? inspector in Access review shows the result for each record.
Good to know
- Field and record rules can be placed on a role or a person. Use a role where several people share the need.
- The Data access tab of a user (branches, warehouses, departments, sales teams) is separate and is described in Manage a user account.