Access and permissions

Which permission each Master Data screen needs, who may see and change what, and the rules that keep people from approving their own work.

On this page (23)

Permissions by screen

ScreenMenuPermission needed
Master Data DashboardMaster Data > Master Data > Dashboardmdm.view; adopt needs mdm.steward
PartiesMaster Data > Master Data > Partiesmdm.view (list); mdm.steward (create)
Party recordMaster Data > Master Data > Parties > open a partymdm.view to read; mdm.steward to change; mdm.release to release or rename a shared party
Change requestsMaster Data > Master Data > Bank and tax changesmdm.view to list; mdm.finance.approve (bank) or mdm.tax.approve (registration) to decide
Product templatesMaster Data > Products > Templates and variantsmdm.view; product.manage to create
Template recordMaster Data > Products > Templates and variants > open a templateproduct.manage (validate, archive, variants); mdm.steward (approve, release)
AttributesMaster Data > Products > Attributesmdm.view; mdm.steward to create
BarcodesMaster Data > Products > Barcodesmdm.view; product.manage to register
Customer item codesMaster Data > Products > Customer item codesmdm.view; product.manage; feature switch 'Customer and supplier item codes'
Supplier item codesMaster Data > Products > Supplier item codesmdm.view; product.manage; same feature switch
Tracking policies and mediaMaster Data > Products > Tracking policies and mediamdm.view; product.manage (propose, upload); mdm.steward (activate)
Site defaultsMaster Data > Products > Site defaultsmdm.view; product.manage
Account mappingsMaster Data > Products > Account mappingsmdm.view; product.manage to draft; mdm.finance.approve to activate
SubstitutesMaster Data > Products > Substitutesmdm.view; product.manage to propose; mdm.steward to approve; feature switch 'Substitutes'
CataloguesMaster Data > Products > Cataloguesmdm.view; mdm.publish; feature switch 'Channel catalogues and assortments'
Duplicates and mergesMaster Data > Stewardship > Duplicates and mergesmdm.view; mdm.steward (scan, dismiss, propose); mdm.merge.approve (decide); feature switch 'Duplicates and merges'
ImportsMaster Data > Stewardship > Importsmdm.import (menu and every action); feature switch 'Governed imports'
Data qualityMaster Data > Stewardship > Data qualitymdm.view; mdm.steward
Field securityMaster Data > Stewardship > Field securityMenu needs mdm.steward; list mdm.view
Completeness reportMaster Data > Reports > Completeness and errorsmdm.view
Duplicate review reportMaster Data > Reports > Duplicate reviewmdm.view
Product catalogue reportMaster Data > Reports > Product cataloguemdm.view
UOM and barcode auditMaster Data > Reports > UOM and barcode auditmdm.view
Expiry-policy coverageMaster Data > Reports > Expiry-policy coveragemdm.view
Sensitive changes reportMaster Data > Reports > Sensitive changesmdm.view
LanguagesMaster Data > References > Languagesmdm.view
Time zonesMaster Data > References > Time zonesmdm.view
CurrenciesMaster Data > References > Currenciesmdm.view
Channel read side(no menu) Public catalogue API /api/v1/catalogue/{key}/productsNo sign-in; the catalogue key is the access
Master Data features and field settingsApplications > Master Data > FeaturesCompany configuration permission
Contacts listContacts > Contactspartner.view (list); partner.manage (create / edit)
Customer 360 recordContacts > Contacts > open a contactpartner.view; partner.manage to edit; partner.bank.reveal for full bank numbers; credit.limit.reveal for limits, risk, guarantees and reviews
Record credit review dialogCustomer 360 > Finance & Credit > Record credit reviewpartner.manage
Custom fieldsContacts > Configuration > Custom fields (also Catalogue > Configuration > Custom fields)Any member reads; company administrator (membership role admin) adds and changes
CountriesContacts > Configuration > CountriesSigned-in user reads; administrator of at least one company edits (shared by all companies)
States & regionsContacts > Configuration > States & regionsAs Countries
Cities & areasContacts > Configuration > Cities & areasAs Countries
Products listCatalogue > Catalogueproduct.view; product.manage to create; product.cost.view to see cost
Product recordCatalogue > Catalogue > open a productproduct.view; product.manage edit / archive / duplicate / documents / variants; product.cost.view cost, accounts, stock value; document.draft quick sale / purchase; inventory.operate reorder rules
Product dialogsProduct record > dialogsproduct.manage (duplicate); document.draft (quick documents); product.view (labels)
Stock on handCatalogue > Reporting > Stock on handproduct.view (and inventory read for the pivot)
Product categoriesCatalogue > Configuration > Product categoriesproduct.view (read); reference.manage (create / change)
BrandsCatalogue > Configuration > Brandsproduct.view / reference.manage
Units of measureCatalogue > Configuration > Units of measureproduct.view / reference.manage
Product groupsCatalogue > Configuration > Product groupsproduct.view / reference.manage
ManufacturersCatalogue > Configuration > Manufacturersproduct.view / reference.manage
Variant attributesCatalogue > Configuration > Variant attributesproduct.view / reference.manage

Master Data app

RuleWhat the system does
Menu permissionsNo mdm.view: app / menus not offered and API 403. mdm.view only: every menu except Imports (mdm.import) and Field security (mdm.steward); all change buttons refused by the server

All screens

RuleWhat the system does
View-only user cannot changeEach refused '<action> needs the <permission> permission.' e.g. 'Creating a party needs the mdm.steward permission.', 'Registering a barcode needs the product.manage permission.', 'Publishing to a channel needs the mdm.publish permission.'

Parties

RuleWhat the system does
Company isolation of parties404 'Party not found.' - a company reaches a party only through its own release, superusers included

Party record

RuleWhat the system does
Bank details maskedIBAN and account number show only the last 4 characters (••••3456); with partner.bank.reveal the full value
Edit conflictTab 2 refused 'This record changed since you opened it. Reload it and try again.'

Bank and tax changes

RuleWhat the system does
Maker-checker binds superusersRefused 'Somebody other than the person who prepared this change must decide it.'
Domain separationRefused 'Deciding a registration change needs mdm.tax.approve.' / 'Deciding a bank account change needs mdm.finance.approve.'
Approve a changed proposalRefused 'The proposal you are approving is not the one on record...'

Duplicates and merges

RuleWhat the system does
Merge separation of dutiesRefused 'Somebody other than the person who prepared this merge must decide it.'
Different legal entities never mergedRefused at proposal and again at decision 'Their registration numbers differ; not merged.'

Template record

RuleWhat the system does
Approve separate from prepareRefused 'Somebody other than the person who prepared this template must decide it.'
Concurrent variant creationOne variant created; the other gets 409 '<code> already has the variant ...' - no half-made product

Account mappings

RuleWhat the system does
Finance decides mappingsRefused 'Activating an account mapping is Finance's decision (mdm.finance.approve).'
Another company's accountRefused 'Choose an account of this company's chart.'

Substitutes / Data quality

RuleWhat the system does
Self-approval refusedRefused 'Somebody other than the person who prepared this substitute must decide it.' / '...this exception must decide it.'

Tracking policies and media

RuleWhat the system does
Live-lot tracking change needs a second personRefused 'Somebody other than the person who prepared this tracking change must decide it.'
Media isolation and safety404 'Media not found.'; SVG refused; served media has nosniff and CSP default-src 'none'

Site defaults

RuleWhat the system does
Another company's warehouse403 'That warehouse is not one of this company's sites.'

Public catalogue API

RuleWhat the system does
No internal data leaksPayload has code, names, unit, price, tax rate, barcode, description, channel image ids - never cost, supplier, accounts or bank data; unknown key -> 404 'Catalogue not found.'
Unreleased product not sellableRefused '<code> is not available in this catalogue.'

Imports

RuleWhat the system does
Import needs mdm.importRefused 'Importing masters needs the mdm.import permission.' / 'Committing an import needs the mdm.import permission.'

Field security

RuleWhat the system does
Restricted field hidden and protectedField absent everywhere; their save keeps the stored value
Custom field cannot shadow a core fieldRefused ''x_iban' would shadow the protected field 'iban'. Choose another key.'

Master Data features

RuleWhat the system does
Protected capabilitiesNot offered as switches (always on)

Contacts list

RuleWhat the system does
View permissionScreen empty / refused 'You do not have permission for this action.'; with partner.view the list shows

Customer 360

RuleWhat the system does
View-only user cannot changeOpen a contact; try Edit; send PATCH partners/{id} by API
Bank numbers maskedOpen Finance & Credit; Edit; change another field; Save
Credit figures maskedOpen Finance & Credit and Overview
Field access rules from AdministrationSign in with that role; open a contact; save it
Record access (own records only)Sign in as that user; open Contacts; open another user's contact by URL
Company isolationIn A, open a contact id of company B by URL; PATCH it; set payment_term_id / fiscal_position_id / payer to B's records
Audit of sensitive changesChange the credit limit, TRN and a bank IBAN; open History and the audit log

Record credit review dialog

RuleWhat the system does
Review history cannot be editedSend a PATCH whose profile.credit_reviews is empty or altered

Product record

RuleWhat the system does
Product view vs manageOpen a product; try Edit, Duplicate, Archive, upload a document; PATCH products/{id} by API
Cost visibilityOpen a product, its Accounting tab, Purchase summary, supplier grid, Stock value; send cost in a PATCH
Company isolationIn A, open B's product by URL; set category / warehouse / account / supplier to B's ids by API
Uploaded files are safeUpload a product image that is an HTML file renamed .png; a document of type .exe

Product record > Company Access

RuleWhat the system does
Sharing respects rights in the other companyShare a product with B

Product configuration masters

RuleWhat the system does
Masters need reference.managePOST / PATCH product-masters/category by API

Countries / States / Cities

RuleWhat the system does
Shared geography editingPOST geo/countries by API