Access and permissions
Which permission each Purchasing screen needs, who may see and change what, and the rules that keep people from approving their own work.
On this page (35)
Permissions by screenPurchase dashboardPurchase requisitionsPurchase requisitionProcurement panelPurchase orderAllCalls for tendersCall for tenders recordReverse auctionsSupplier portal auctionShop a cataloguePunch-out cataloguesPurchase agreementsSupplier rebatesBills on holdRetentions heldEarly paymentsPayment holdsVendor billsAll screensShipping noticesPurchase settingsBill matching policiesApproved suppliersSupplier changesSupplier applicationsSupplier portal loginsPortal purchase ordersPortal tenders and auctionsSupplier registration formPortal My detailsPurchase reportsPurchasing > FeaturesShipping notices (staff)
Permissions by screen
| Screen | Menu | Permission needed |
|---|---|---|
| Purchase dashboard | Purchase > Dashboard | dashboard.purchase (menu and API); without it the 'not allowed' panel shows |
| Purchase requisitions | Purchase > Orders > Purchase requisitions | purchase.view (list); purchase.requisition.create (New) |
| Purchase requisition record | Purchase requisitions > open / New | purchase.requisition.create (edit, submit, cancel); purchase.requisition.approve (approve, return) |
| Requisitions to order | Purchase > Orders > Requisitions to order | purchase.view (list); document.draft (Create RFQ) |
| Requests for quotation | Purchase > Orders > Requests for quotation | document.view (list), document.draft (create/edit), document.confirm (Approve order) |
| Purchase orders | Purchase > Orders > Purchase orders | document.view, document.cancel, document.invoice (one-step post) |
| Procurement panel | Purchase order > Procurement tab | document.view (panel); purchase.order.approve (approve); document.draft (others) |
| Goods receipt for a PO | Purchase order > Receipts > receipt | inventory.operate; over receipt: inventory.receipt.exception.approve |
| Calls for tenders | Purchase > Orders > Calls for tenders | purchase.view (list and record); purchase.tender.manage (New, edit, issue, close, cancel, quotes) |
| Call for tenders record | Calls for tenders > open / New | purchase.tender.manage (all steps at the route); purchase.tender.award as well for Award (service) |
| Supplier's quote dialog | Call for tenders > Suppliers and their quotes > Enter quote | purchase.tender.manage |
| Reverse auctions | Purchase > Orders > Reverse auctions | purchase.view (list); purchase.tender.manage (New and every step) |
| New reverse auction dialog | Reverse auctions > New | purchase.tender.manage |
| Auction record dialog | Reverse auctions > open a row | purchase.tender.manage (route); purchase.tender.award as well for Award (service) |
| Shop a catalogue | Purchase > Orders > Shop a catalogue | purchase.requisition.create (menu, list, start, make requisition) |
| Cart dialog | Shop a catalogue > open a cart | purchase.requisition.create (own carts only) |
| Punch-out catalogues | Purchase > Configuration > Punch-out catalogues | purchase.configure (menu, create, edit); reading the list needs only purchase.requisition.create |
| Purchase agreements | Purchase > Orders > Purchase agreements | purchase.view (list); purchase.configure (New, edit, Close and, at the route, Put in force); purchase.policy.approve (Put in force, service) |
| Agreement dialog | Purchase agreements > open / New | purchase.configure |
| Supplier rebates | Purchase > Orders > Supplier rebates | purchase.view (list); purchase.configure (New and, at the route, every action); purchase.policy.approve (Put in force, service) |
| Shipping notices | Purchase > Orders > Shipping notices | purchase.view (list); purchase.asn.manage (New, edit, receive, cancel) |
| Shipping notice dialog | Shipping notices > open / New | purchase.asn.manage; Receive also needs inventory.operate |
| Inbound shipments | Purchase > Reporting > Inbound shipments | purchase.view |
| Vendor bills | Purchase > Billing > Vendor bills | document.view / document.draft / document.confirm; posting also runs the match; purchase.match.release; stock.adjust (capitalise) |
| Bill matching panel | Vendor bill > Matching tab | purchase.view (read); document.draft (Match again); purchase.match.release (Release) |
| Debit notes | Purchase > Billing > Debit notes | document.view / document.draft / document.confirm |
| Bills on hold | Purchase > Billing > Bills on hold | purchase.view (list); purchase.match.release (Release) |
| Three-way match exceptions | Purchase > Reporting > Three-way match exceptions | purchase.view; purchase.match.release |
| Retentions held | Purchase > Billing > Retentions held | purchase.view (list); purchase.retention.release (Release) |
| Early payments | Purchase > Billing > Early payments | purchase.view (list); payment.prepare (offer, settle, withdraw) |
| Payment holds | Finance > Payment holds (applies to supplier bills) | journal.view (list); payment.prepare (place); payment.approve (release) |
| Suppliers | Purchase > Suppliers | partner.view (list), partner.manage (create and change) |
| Supplier record | Purchase > Suppliers > open a supplier | partner.manage; partner.bank.reveal to see full IBAN / account numbers |
| Open purchase orders | Purchase > Reporting > Open purchase orders | report.view |
| Overdue supplier receipts | Purchase > Reporting > Overdue supplier receipts | report.view |
| Supplier spend | Purchase > Reporting > Supplier spend | report.view |
| Supplier performance | Purchase > Reporting > Supplier performance | report.view |
| Received not invoiced (GRNI) | Purchase > Reporting > Received not invoiced | report.view |
| Shipping notices (staff side) | Purchase > Reporting > Inbound shipments / Purchase > Orders > Shipping notices | purchase.view (list), purchase.asn.manage (create, change, cancel, receive), inventory.operate (Receive) |
| Consignment stock | Purchase > Reporting > Consignment stock | report.view |
| Purchase settings | Purchase > Configuration > Purchase settings | purchase.view (open), purchase.configure (the switches), purchase.policy.approve (the tiers) |
| Receipt tolerances | Purchase > Configuration > Receipt tolerances | purchase.view (list), purchase.configure (change) |
| Bill matching policies | Purchase > Configuration > Bill matching policies | purchase.view (list), purchase.configure (write), purchase.policy.approve (Put in force, retire an active policy) |
| Approved suppliers (supplier qualification) | Purchase > Configuration > Approved suppliers | purchase.view (list), purchase.configure (write), purchase.policy.approve (Approve, Block, Exception) |
| Punch-out catalogues | Purchase > Configuration > Punch-out catalogues | purchase.configure (list and change); purchase.requisition.create (shop) |
| Supplier portal logins | Purchase > Configuration > Supplier portal logins | purchase.portal.manage |
| Supplier applications | Purchase > Configuration > Supplier applications | purchase.portal.manage (the screen); partner.manage (to approve) |
| Supplier changes | Purchase > Configuration > Supplier changes | purchase.portal.manage; partner.manage to approve; partner.bank.reveal to approve a bank account |
| Supplier registration form | Public link (no sign-in): /api/v1/public/supplier-registration/{key} | None (the secret key in the link is the access); opened and renewed in Purchase settings |
| Purchasing feature switches and field settings | Administration > Applications > Purchasing > Features | Company admin (platform configuration right) |
| Portal home | Supplier portal > Home | purchase.portal (login linked to an active supplier) |
| Portal tenders and auctions | Supplier portal > Calls for tenders / Auctions | purchase.portal |
| Portal purchase orders | Supplier portal > Purchase orders | purchase.portal |
| Portal shipping notices | Supplier portal > Shipping notices | purchase.portal |
| Portal invoices sent | Supplier portal > Invoices sent | purchase.portal |
| Portal bills and payments | Supplier portal > Bills and payments | purchase.portal |
| Portal early payment offers | Supplier portal > Early payment offers | purchase.portal |
| Portal My details | Supplier portal > My details | purchase.portal |
Purchase dashboard
| Rule | What the system does |
|---|---|
| Dashboard permission | Menu hidden; page shows the not-allowed panel; API 'You do not have permission for this action.' |
Purchase requisitions
| Rule | What the system does |
|---|---|
| Create needs purchase.requisition.create | No New, Submit or Cancel; API create refused 'You do not have permission for this action.' |
Purchase requisition
| Rule | What the system does |
|---|---|
| Approve/return needs purchase.requisition.approve | Refused 'Approving a requisition needs the requisition approval right.' / 'Returning a requisition needs the requisition approval right.' |
Procurement panel
| Rule | What the system does |
|---|---|
| PO approval right and no self-approval | 'Approving purchase orders needs the order approval right.' / 'Somebody other than whoever raised this order must approve it.' |
Purchase order
| Rule | What the system does |
|---|---|
| Buyer may not confirm own order | Refused 'Somebody other than whoever raised this purchase order must approve it.' |
| Confirm and cancel rights and order limit | Approve order / Cancel refused 403; above the order limit refused by the approval limit |
All
| Rule | What the system does |
|---|---|
| Company isolation | 'Record not found.' / 'Choose each requisition line once.' |
Calls for tenders
| Rule | What the system does |
|---|---|
| View versus manage | List and records readable; no New button; writes refused 403 (route needs purchase.tender.manage) |
Call for tenders record
| Rule | What the system does |
|---|---|
| Sealed prices are absent, not hidden | Quote lines carry no price, quantity offered or award fields; the comparison returns 403 'sealed' |
| Whoever raised it does not award it (maker-checker) | 403 'Somebody other than whoever raised this call for tenders must award it.' |
| Award needs the award right as well | 403 'Awarding a call for tenders needs the award right.' |
Reverse auctions
| Rule | What the system does |
|---|---|
| Award right and auction creator | B refused 'Somebody other than whoever raised this auction must award it.'; no award right: 'Awarding needs the award right.' |
Supplier portal auction
| Rule | What the system does |
|---|---|
| A supplier sees and bids only its own auctions | Record not found (404); bids as a non-bidder refused the same way |
Shop a catalogue
| Rule | What the system does |
|---|---|
| Carts are private; the return link is a secret | 404 for the cart; 'This cart link is not valid.' for the key; keys are 24 random bytes and used or old sessions take nothing |
Punch-out catalogues
| Rule | What the system does |
|---|---|
| Password stored sealed and never returned | password_set true only; the password is never sent back; it is posted only to the shop's https address |
| Shop password is sealed | Only 'password set' is returned; the value is never shown or returned; the screen needs purchase.configure. |
Purchase agreements
| Rule | What the system does |
|---|---|
| Writer cannot put own agreement in force | 403 'Somebody other than whoever wrote the agreement must put it in force.' |
Supplier rebates
| Rule | What the system does |
|---|---|
| Writer cannot put own rebate in force | 403 'Somebody other than whoever wrote it must put a rebate agreement in force.'; no approval right: 'Putting a rebate in force needs the procurement approval right.' |
Bills on hold
| Rule | What the system does |
|---|---|
| Maker-checker on releasing a hold | All refused 'Somebody other than whoever raised the bill or its order must release this hold.' (a superuser is still a person here) |
| Release right and draft bills only | 'Releasing a matching hold needs the release right.' (route 403 first); 'The bill is no longer a draft.' |
Retentions held
| Rule | What the system does |
|---|---|
| Maker-checker on releasing a retention | Refused with the 'somebody other' message; 'Releasing a retention needs the retention release right.' |
Early payments
| Rule | What the system does |
|---|---|
| Offering needs payment.prepare; supplier sees only its own | 403 for the user; 404 'Record not found.' for the supplier |
Payment holds
| Rule | What the system does |
|---|---|
| Place and release rights | Release needs payment.approve; Place needs payment.prepare; list needs journal.view |
Vendor bills
| Rule | What the system does |
|---|---|
| Duplicate supplier invoice is blocked across users | Only one posts; the other: 'is already on <bill>. A supplier invoice is posted once.' (unique claim) |
All screens
| Rule | What the system does |
|---|---|
| Company isolation | Record not found (404); lists show only the current company; suppliers and products from another company are refused |
| Edit conflicts | Second save: 'This record changed; reload it and try again.' (409); the payment hold says 'Somebody changed this hold. Reload it and look again.' |
Shipping notices
| Rule | What the system does |
|---|---|
| Receiving from a notice needs the inventory right as well | Receive button hidden; by API the receive action is refused 403 (the route checks purchase.asn.manage and inventory.operate) |
Purchase settings
| Rule | What the system does |
|---|---|
| Switches need purchase.configure | Check boxes are disabled and Save is hidden; the API refuses the save (403). |
| Approval tiers need purchase.policy.approve | Inputs are disabled, no Add / Save tiers buttons; the API refuses 'Changing approval tiers needs the procurement approval right.' |
| Company isolation | 'Record not found.' (404) everywhere; lists show only company A. |
Bill matching policies
| Rule | What the system does |
|---|---|
| Maker-checker on policies | 'Somebody other than the author must activate this policy.' / 'Activating a matching policy needs the policy approval right.' (403) |
Approved suppliers
| Rule | What the system does |
|---|---|
| Maker-checker on qualification | 'Somebody other than whoever wrote it must approve a supplier qualification.' (403); Block, Exception and Archive need purchase.policy.approve ('Deciding a supplier qualification needs the procurement approval right.'). |
Supplier changes
| Rule | What the system does |
|---|---|
| Bank account approval is a finance right | Server refuses with 'A new bank account is approved by somebody who may see bank details (finance).'; IBAN / account number are masked in the dialog. |
Supplier applications
| Rule | What the system does |
|---|---|
| Approving needs contact rights | 'Approving a supplier needs the right to manage contacts.' (403) |
Supplier portal logins
| Rule | What the system does |
|---|---|
| Portal login is limited to the portal | Only the portal menu is available; staff screens and routes refuse (no purchase.view / document.view). |
| Closed login loses access | Membership is removed; the portal says the login is not linked / refuses access. |
Portal purchase orders
| Rule | What the system does |
|---|---|
| A supplier cannot see another supplier's records | 'Record not found.' (404) for every type; lists show only A's records; same for another company. |
Portal tenders and auctions
| Rule | What the system does |
|---|---|
| Sealed tenders stay sealed | Only A's own quote and versions are shown; no comparison and no other price anywhere in the portal. |
Supplier registration form
| Rule | What the system does |
|---|---|
| Public form opens nothing else | Only the form and the application POST work; a wrong or retired key answers 'This registration link is not open.'; the page is no-store / noindex. |
| Spam controls | 'The application could not be accepted.'; 'Too many applications today; please try again tomorrow.' (429) |
Portal My details
| Rule | What the system does |
|---|---|
| A supplier cannot change its record directly | Refused; only a change request is possible and nothing moves until staff approve. |
Purchase reports
| Rule | What the system does |
|---|---|
| Reports need report.view | The menu entries are hidden for the report.view reports and the API answers 403. |
Purchasing > Features
| Rule | What the system does |
|---|---|
| Switches are enforced on the server | Refused with capability_disabled even though the screen is gone; GET still works. |
Shipping notices (staff)
| Rule | What the system does |
|---|---|
| Receive needs warehouse rights | Refused (inventory.operate is checked on top of purchase.asn.manage). |