Access and permissions
Which permission each E-invoicing screen needs, who may see and change what, and the rules that keep people from approving their own work.
On this page (11)
Permissions by screen
| Screen | Menu | Permission needed |
|---|---|---|
| Dashboard | E-invoicing > E-invoicing > Dashboard | einvoicing.view (Start with the sandbox needs einvoicing.configure and einvoicing.secret; Process queue now needs einvoicing.operate) |
| Submissions | E-invoicing > E-invoicing > Submissions | einvoicing.view |
| Submission record | Submissions > open a row | einvoicing.view to read; einvoicing.operate (submit, retry, reconcile, validate); einvoicing.repair (rebuild, correct, validate); einvoicing.audit or operate to download payloads |
| Received e-invoices | E-invoicing > E-invoicing > Received e-invoices | einvoicing.view to read; einvoicing.inbound to upload, draft, reject and download. Menu is a company feature switch ('Received supplier e-invoices') |
| Alerts | E-invoicing > E-invoicing > Alerts | einvoicing.view; Acknowledge needs einvoicing.operate |
| Provider outages | E-invoicing > E-invoicing > Provider outages | einvoicing.view; report / close need einvoicing.operate; contingency needs einvoicing.activate |
| Submission monitor | E-invoicing > Reports > Submission monitor (R040) | einvoicing.view |
| Reject analysis | E-invoicing > Reports > Reject analysis | einvoicing.view |
| Unknown and deadline queue | E-invoicing > Reports > Unknown and deadline queue | einvoicing.view |
| Invoice-to-provider bridge | E-invoicing > Reports > Invoice-to-provider bridge | einvoicing.view |
| Credential health | E-invoicing > Reports > Credential health | einvoicing.view |
| Archive integrity | E-invoicing > Reports > Archive integrity | einvoicing.view |
| Event log | E-invoicing > Reports > Event log | einvoicing.audit (the menu item shows for einvoicing.view) |
| E-invoicing settings | E-invoicing > Configuration > Settings | einvoicing.view to open; einvoicing.configure to save |
| Onboarding | E-invoicing > Configuration > Onboarding | einvoicing.view; einvoicing.configure (draft, edit, request); einvoicing.activate (approve, reinstate, retire); einvoicing.secret (credentials, CSIDs) |
| Credentials | E-invoicing > Configuration > Credentials | einvoicing.view |
| Providers | E-invoicing > Configuration > Providers | einvoicing.view; einvoicing.configure to create/edit; einvoicing.activate to review/activate (not your own) |
| Country profiles | E-invoicing > Configuration > Country profiles | einvoicing.view; einvoicing.configure; einvoicing.activate for review/activate (not your own) |
| Retry and outage policies | E-invoicing > Configuration > Retry and outage policies | einvoicing.view; einvoicing.configure; einvoicing.activate |
| Code mappings | E-invoicing > Configuration > Code mappings | einvoicing.view; einvoicing.configure |
| Rejection codes | E-invoicing > Configuration > Rejection codes | einvoicing.view; einvoicing.configure |
| Partner endpoints | E-invoicing > Configuration > Partner endpoints | einvoicing.view; einvoicing.configure |
| Retention policies | E-invoicing > Configuration > Retention policies | einvoicing.view; einvoicing.configure; einvoicing.activate for review/activate |
| E-invoice smart button | Sales > Invoices / Credit notes > open a posted document | einvoicing.view (shows nothing when the app is off or the user lacks permission) |
All screens
| Rule | What the system does |
|---|---|
| View-only user cannot change anything | Lists and records readable; every write refused with 403 or no button: configure, operate, repair, inbound, secret and activate are all separate permissions |
Submissions
| Rule | What the system does |
|---|---|
| Roles are separated: operator, tax reviewer, auditor | Operator can Submit/Retry/Ask provider/Validate but not Rebuild/Correct; tax reviewer can Rebuild/Correct/Validate but not Submit; auditor can read everything and download payloads but change nothing |
| Company isolation (T016) | All answer 404 ('Submission not found.', 'Payload not found.', 'Onboarding not found.' ...); lists show only the current company; callback for the wrong company/provider: 404 'Not found.' |
| Provider callback authenticity | 403 'Signature check failed.' every time and nothing recorded; only the exact bytes signed with an Active callback secret of an Active onboarding of that provider are accepted; the route needs no user login by design |
| Commands are idempotent and cannot be replayed with a different body | 409 'This idempotency key was already used for a different request.'; nothing sent |
Providers
| Rule | What the system does |
|---|---|
| Author cannot review or activate their own sensitive record | Offered only to somebody who is neither author nor last editor: via API 'Somebody other than the person who prepared this configuration must approve it.'; code mappings, rejection codes and endpoints do not need a second person |
| Provider addresses cannot reach the internal network | All refused as in the provider address test; a request never follows a redirect ('The provider answered with a redirect, which is never followed.') and the address is re-checked before every call |
Onboarding
| Rule | What the system does |
|---|---|
| Requester cannot approve or reinstate own production onboarding | 'Somebody other than the person who prepared this onboarding must approve it.'; Reinstate likewise |
| Credential custodian, approver and requester are three duties | C: 'Somebody other than the person who prepared this credential must approve it.'; B bind: 'Binding a credential needs the custodian role.'; Compromised needs custodian or approver: 'Reporting a compromised key needs the custodian or approver role.'; Revoke needs custodian |
| Test credentials never serve production | 'A test credential cannot be bound to a production onboarding.'; the worker also refuses when provider, profile, onboarding and credential environments differ ('The provider, profile and submission are not in the same environment.') |
Credentials
| Rule | What the system does |
|---|---|
| Secrets never leave the vault | Only 'vault:xxxxxx…' reference, thumbprint, validity and health are shown; no token, private key or callback secret in any response, audit change line, event or export; a destroyed (compromised/revoked) secret is unreadable |
Submission record
| Rule | What the system does |
|---|---|
| Payload evidence needs operate or audit | View only: 'Downloading e-invoice evidence needs the auditor or operator role.'; audit/operate: file with hash header; wrong submission: 'Payload not found.' (404) |
Provider outages
| Rule | What the system does |
|---|---|
| Contingency approved by a second person with the approver permission | A: 'Somebody other than the person who prepared this outage's contingency must approve it.'; no activate: 'Approving a contingency needs the approver role.'; B accepted; the contingency does not issue anything |
Received e-invoices
| Rule | What the system does |
|---|---|
| Hostile files are never parsed | Refused before parsing as in the safety test; kept as evidence, no bill, no server slow-down |
Event log
| Rule | What the system does |
|---|---|
| Audit permission and audit trail | No Event log menu for view-only; audit users see events; every configuration, credential, onboarding, submission and inbound action leaves an audit line with the actor and no secret |
Settings
| Rule | What the system does |
|---|---|
| Field settings and feature switches are enforced by the server | Required: save refused; Hidden: an account sent or changed is refused; switched-off feature: change refused with capability_disabled while reads still pass |