Access and permissions
Which permission each Administration screen needs, who may see and change what, and the rules that keep people from approving their own work.
On this page (18)
Permissions by screen
| Screen | Menu | Permission needed |
|---|---|---|
| System users | Administration > Users > System users | member.view (list), member.manage (changes); screen only for company admins |
| User record | System users > open a user | member.manage |
| Roles | Administration > Users > Roles | member.view / member.manage |
| Field access | Administration > Users > Field access | member.manage |
| Record access | Administration > Users > Record access | member.manage |
| Exceptions and limits | Administration > Users > Exceptions and limits | member.manage |
| Access review | Administration > Users > Access review | member.view / member.manage |
| API keys | Administration > Users > API keys | member.manage; screen only for company admins |
| Settings | Administration > Settings | company.view; danger zone admin only |
| Custom fields | Administration > Configuration > Custom fields | company.manage + admin to add; company.view to read |
| Sensitive-change alerts | Administration > Audit > Sensitive-change alerts | audit.view |
| Audit evidence | Administration > Audit > Audit evidence | audit.view (verify), audit.manage (seal) |
| Retention and legal holds | Administration > Audit > Retention and legal holds | audit.manage |
| Alert rules | Administration > Audit > Alert rules | audit.manage |
| Email sending | Administration > Configuration > Email sending | company.manage + admin |
| Administration > Configuration > WhatsApp | company.manage + admin; global = installation owner | |
| Menus | Administration > Configuration > Menus | company.manage (admin in the screen) |
| Sequences | Administration > Configuration > Sequences | company.manage + admin to change |
| Payment terms | Administration > Masters > Payment terms | reference.manage |
| Payment methods | Administration > Masters > Payment methods | reference.manage |
| Price lists | Administration > Masters > Price lists | reference.manage |
| Dimensions | Administration > Dimensions > Cost centres / Departments / Projects / Profit centres | reference.manage |
| Companies | Administration > Workspace > Companies | Write access; create needs can_create_company |
| Company and branch switchers | Header bar | Membership |
| Branches | Administration > Workspace > Branches | reference.manage |
| Apps catalogue | Administration > Workspace > Apps | company.manage |
| App page | Apps > open an app | apps.configure (propose), apps.config.approve (approve) |
System users
| Rule | What the system does |
|---|---|
| Cannot switch off your own account | Options not offered; via API 'You cannot switch off your own account.' |
| Last administrator is protected | Refused: '<username> is the only administrator of this company...' / 'That is the last administrator of that company.' |
| Only a superuser changes a superuser | Refused: 'Only a superuser can change a superuser.' |
| Machine users cannot sign in | Refused: 'This is an integration account. It cannot sign in here.' |
| Wrong password does not reveal status | Generic wrong-password message only; the status is not revealed |
| Access window | Refused: 'This account can be used from YYYY-MM-DD.'; set Access ends = yesterday -> 'This account's access has ended...' |
All Users screens
| Rule | What the system does |
|---|---|
| Viewer/member cannot change access | No edit buttons; any change refused 'You do not have permission for this action.' |
Roles
| Rule | What the system does |
|---|---|
| Permission via role, not membership | Server allows the first; check what the screen shows (buttons follow the membership role) - log any mismatch |
Field access
| Rule | What the system does |
|---|---|
| Hidden field is gone everywhere | The value is absent in all of them |
API keys
| Rule | What the system does |
|---|---|
| A key cannot manage keys | Refused: 'Keys are managed by a person, not by another key.' |
| Key secret shown once | Only the prefix is visible; the full key cannot be shown again |
Access review
| Rule | What the system does |
|---|---|
| No self-review | Refused: 'Somebody else has to review your access.' |
Settings
| Rule | What the system does |
|---|---|
| Danger zone only for admins | No Danger zone; clear endpoint refused |
Custom fields
| Rule | What the system does |
|---|---|
| Only admins add fields | No button; API refused 'Company administration is required.' |
Audit
| Rule | What the system does |
|---|---|
| Audit screens need audit.view | Audit menu entries hidden; endpoints refused |
| Audit events cannot be edited | Refused: 'The audit trail is append-only...' |
Legal holds
| Rule | What the system does |
|---|---|
| Two people for a release | Refused: 'Somebody other than the person who placed it releases a hold.' |
Email / WhatsApp
| Rule | What the system does |
|---|---|
| Secrets never shown | Fields empty with 'Saved - leave blank to keep'; API returns only has_secret / has_token |
| Rule | What the system does |
|---|---|
| Shared connection only for the installation owner | Refused with the installation message |
Masters / Branches
| Rule | What the system does |
|---|---|
| reference.manage needed | No New/Save; any save refused 'You do not have permission for this action.' |
Companies
| Rule | What the system does |
|---|---|
| Create needs the right | Button hidden; API 'You do not have permission to create companies.' |
| Company code never changes | Refused: 'Company code cannot change after creation.' |
Company switcher
| Rule | What the system does |
|---|---|
| Only your companies | Refused: 'You do not belong to any of those companies.' |
Apps
| Rule | What the system does |
|---|---|
| Install/turn off needs company.manage | Refused |
App configuration
| Rule | What the system does |
|---|---|
| Proposer cannot approve | Refused: 'Somebody other than the person who proposed it must review a configuration change.' |
| Protected features stay on | Refused: 'A protected control cannot be turned off.' |
| Turned-off feature refuses writes, keeps reads | POST 409 'capability_disabled'; GET still works |