Access and permissions

Which permission each E-invoicing screen needs, who may see and change what, and the rules that keep people from approving their own work.

On this page (11)

Permissions by screen

ScreenMenuPermission needed
DashboardE-invoicing > E-invoicing > Dashboardeinvoicing.view (Start with the sandbox needs einvoicing.configure and einvoicing.secret; Process queue now needs einvoicing.operate)
SubmissionsE-invoicing > E-invoicing > Submissionseinvoicing.view
Submission recordSubmissions > open a roweinvoicing.view to read; einvoicing.operate (submit, retry, reconcile, validate); einvoicing.repair (rebuild, correct, validate); einvoicing.audit or operate to download payloads
Received e-invoicesE-invoicing > E-invoicing > Received e-invoiceseinvoicing.view to read; einvoicing.inbound to upload, draft, reject and download. Menu is a company feature switch ('Received supplier e-invoices')
AlertsE-invoicing > E-invoicing > Alertseinvoicing.view; Acknowledge needs einvoicing.operate
Provider outagesE-invoicing > E-invoicing > Provider outageseinvoicing.view; report / close need einvoicing.operate; contingency needs einvoicing.activate
Submission monitorE-invoicing > Reports > Submission monitor (R040)einvoicing.view
Reject analysisE-invoicing > Reports > Reject analysiseinvoicing.view
Unknown and deadline queueE-invoicing > Reports > Unknown and deadline queueeinvoicing.view
Invoice-to-provider bridgeE-invoicing > Reports > Invoice-to-provider bridgeeinvoicing.view
Credential healthE-invoicing > Reports > Credential healtheinvoicing.view
Archive integrityE-invoicing > Reports > Archive integrityeinvoicing.view
Event logE-invoicing > Reports > Event logeinvoicing.audit (the menu item shows for einvoicing.view)
E-invoicing settingsE-invoicing > Configuration > Settingseinvoicing.view to open; einvoicing.configure to save
OnboardingE-invoicing > Configuration > Onboardingeinvoicing.view; einvoicing.configure (draft, edit, request); einvoicing.activate (approve, reinstate, retire); einvoicing.secret (credentials, CSIDs)
CredentialsE-invoicing > Configuration > Credentialseinvoicing.view
ProvidersE-invoicing > Configuration > Providerseinvoicing.view; einvoicing.configure to create/edit; einvoicing.activate to review/activate (not your own)
Country profilesE-invoicing > Configuration > Country profileseinvoicing.view; einvoicing.configure; einvoicing.activate for review/activate (not your own)
Retry and outage policiesE-invoicing > Configuration > Retry and outage policieseinvoicing.view; einvoicing.configure; einvoicing.activate
Code mappingsE-invoicing > Configuration > Code mappingseinvoicing.view; einvoicing.configure
Rejection codesE-invoicing > Configuration > Rejection codeseinvoicing.view; einvoicing.configure
Partner endpointsE-invoicing > Configuration > Partner endpointseinvoicing.view; einvoicing.configure
Retention policiesE-invoicing > Configuration > Retention policieseinvoicing.view; einvoicing.configure; einvoicing.activate for review/activate
E-invoice smart buttonSales > Invoices / Credit notes > open a posted documenteinvoicing.view (shows nothing when the app is off or the user lacks permission)

All screens

RuleWhat the system does
View-only user cannot change anythingLists and records readable; every write refused with 403 or no button: configure, operate, repair, inbound, secret and activate are all separate permissions

Submissions

RuleWhat the system does
Roles are separated: operator, tax reviewer, auditorOperator can Submit/Retry/Ask provider/Validate but not Rebuild/Correct; tax reviewer can Rebuild/Correct/Validate but not Submit; auditor can read everything and download payloads but change nothing
Company isolation (T016)All answer 404 ('Submission not found.', 'Payload not found.', 'Onboarding not found.' ...); lists show only the current company; callback for the wrong company/provider: 404 'Not found.'
Provider callback authenticity403 'Signature check failed.' every time and nothing recorded; only the exact bytes signed with an Active callback secret of an Active onboarding of that provider are accepted; the route needs no user login by design
Commands are idempotent and cannot be replayed with a different body409 'This idempotency key was already used for a different request.'; nothing sent

Providers

RuleWhat the system does
Author cannot review or activate their own sensitive recordOffered only to somebody who is neither author nor last editor: via API 'Somebody other than the person who prepared this configuration must approve it.'; code mappings, rejection codes and endpoints do not need a second person
Provider addresses cannot reach the internal networkAll refused as in the provider address test; a request never follows a redirect ('The provider answered with a redirect, which is never followed.') and the address is re-checked before every call

Onboarding

RuleWhat the system does
Requester cannot approve or reinstate own production onboarding'Somebody other than the person who prepared this onboarding must approve it.'; Reinstate likewise
Credential custodian, approver and requester are three dutiesC: 'Somebody other than the person who prepared this credential must approve it.'; B bind: 'Binding a credential needs the custodian role.'; Compromised needs custodian or approver: 'Reporting a compromised key needs the custodian or approver role.'; Revoke needs custodian
Test credentials never serve production'A test credential cannot be bound to a production onboarding.'; the worker also refuses when provider, profile, onboarding and credential environments differ ('The provider, profile and submission are not in the same environment.')

Credentials

RuleWhat the system does
Secrets never leave the vaultOnly 'vault:xxxxxx…' reference, thumbprint, validity and health are shown; no token, private key or callback secret in any response, audit change line, event or export; a destroyed (compromised/revoked) secret is unreadable

Submission record

RuleWhat the system does
Payload evidence needs operate or auditView only: 'Downloading e-invoice evidence needs the auditor or operator role.'; audit/operate: file with hash header; wrong submission: 'Payload not found.' (404)

Provider outages

RuleWhat the system does
Contingency approved by a second person with the approver permissionA: 'Somebody other than the person who prepared this outage's contingency must approve it.'; no activate: 'Approving a contingency needs the approver role.'; B accepted; the contingency does not issue anything

Received e-invoices

RuleWhat the system does
Hostile files are never parsedRefused before parsing as in the safety test; kept as evidence, no bill, no server slow-down

Event log

RuleWhat the system does
Audit permission and audit trailNo Event log menu for view-only; audit users see events; every configuration, credential, onboarding, submission and inbound action leaves an audit line with the actor and no secret

Settings

RuleWhat the system does
Field settings and feature switches are enforced by the serverRequired: save refused; Hidden: an account sent or changed is refused; switched-off feature: change refused with capability_disabled while reads still pass