Access and permissions

Which permission each Fixed Assets screen needs, who may see and change what, and the rules that keep people from approving their own work.

On this page (7)

Permissions by screen

ScreenMenuPermission needed
AssetsFixed Assets > Assetsasset.view (list); asset.manage (New)
Asset recordFixed Assets > Assets > open an assetasset.view; asset.manage; asset.approve for Capitalise
Change dialogsAsset record > Transfer / Impairment / Estimate change / Disposalasset.manage (propose); asset.approve (decide)
Physical check dialogAsset record > Record a checkasset.manage
Depreciation runsFixed Assets > Depreciation runsasset.view; asset.manage; asset.approve
Asset changesFixed Assets > Changes to approveasset.view (list); asset.approve (decide)
Asset roll-forwardFixed Assets > Reporting > Asset roll-forwardasset.view
Asset registerFixed Assets > Reporting > Asset registerasset.view
Asset categoriesFixed Assets > Configuration > Asset categoriesasset.view; asset.manage; asset.approve to Activate
Depreciation booksFixed Assets > Configuration > Depreciation booksasset.view; asset.manage

Assets

RuleWhat the system does
View-only user cannot create or changeThe list and records are readable; New and every action button are absent; the server refuses the write (HTTP 403).
Menu hidden without asset.viewMenu entries are hidden and API calls are refused with HTTP 403.
Company isolationThe company 1 call returns 'Record not found.' (404); each company shows only its own assets, categories, books, runs and changes; the roll-forward reads only the active company's ledger.

Asset record

RuleWhat the system does
Maker cannot capitalise own asset (also superuser)Both refused: 'Somebody other than whoever prepared a capitalisation must approve it.' (SELF_APPROVAL, 403). Separation of duties binds superusers too.
Capitalise needs asset.approveHTTP 403. The preparer role (manage) cannot approve; the Capitalise button is hidden.
Edit conflict (revision)The second save fails: 'This record changed; reload it and try again.' (409); no silent overwrite. Same on categories, runs and changes.
Journals cannot be posted into a locked periodBoth refused with 'This accounting period is locked.' (the disposal as 'Depreciation up to the disposal could not be posted: ...' when rows are blocked); nothing half-booked.

Depreciation runs

RuleWhat the system does
Run proposer cannot approve; manage cannot approveFirst: SELF_APPROVAL 'Somebody other than whoever prepared a depreciation run must approve it.' Second: HTTP 403 (route needs asset.approve).
Audit trailEach saved asset, capitalisation, run proposal / posting / cancellation, change proposal / approval / rejection and category activation has an audit entry with user and time.

Changes to approve

RuleWhat the system does
Approve / Reject buttons only for approversOnly the asset.approve user sees Approve and Reject on 'To approve' rows; the other sees the status badge only. The server refuses approve/reject from the other user (403).
Maker cannot approve own disposalRefused: 'Somebody other than whoever prepared this disposal must approve it.' (SELF_APPROVAL). Same for transfer, impairment and estimate.

Asset categories

RuleWhat the system does
Category activation is maker-checkerA refused (SELF_APPROVAL); B succeeds. A user without approve cannot activate: 'Approving a category needs the fixed-asset approval right.'
Standard-accounts needs asset.manageHTTP 403; no accounts added to the chart.

Asset roll-forward

RuleWhat the system does
Book belongs to the companyRefused: 'Choose one of this company's books.'