Access and permissions

Which permission each Administration screen needs, who may see and change what, and the rules that keep people from approving their own work.

On this page (18)

Permissions by screen

ScreenMenuPermission needed
System usersAdministration > Users > System usersmember.view (list), member.manage (changes); screen only for company admins
User recordSystem users > open a usermember.manage
RolesAdministration > Users > Rolesmember.view / member.manage
Field accessAdministration > Users > Field accessmember.manage
Record accessAdministration > Users > Record accessmember.manage
Exceptions and limitsAdministration > Users > Exceptions and limitsmember.manage
Access reviewAdministration > Users > Access reviewmember.view / member.manage
API keysAdministration > Users > API keysmember.manage; screen only for company admins
SettingsAdministration > Settingscompany.view; danger zone admin only
Custom fieldsAdministration > Configuration > Custom fieldscompany.manage + admin to add; company.view to read
Sensitive-change alertsAdministration > Audit > Sensitive-change alertsaudit.view
Audit evidenceAdministration > Audit > Audit evidenceaudit.view (verify), audit.manage (seal)
Retention and legal holdsAdministration > Audit > Retention and legal holdsaudit.manage
Alert rulesAdministration > Audit > Alert rulesaudit.manage
Email sendingAdministration > Configuration > Email sendingcompany.manage + admin
WhatsAppAdministration > Configuration > WhatsAppcompany.manage + admin; global = installation owner
MenusAdministration > Configuration > Menuscompany.manage (admin in the screen)
SequencesAdministration > Configuration > Sequencescompany.manage + admin to change
Payment termsAdministration > Masters > Payment termsreference.manage
Payment methodsAdministration > Masters > Payment methodsreference.manage
Price listsAdministration > Masters > Price listsreference.manage
DimensionsAdministration > Dimensions > Cost centres / Departments / Projects / Profit centresreference.manage
CompaniesAdministration > Workspace > CompaniesWrite access; create needs can_create_company
Company and branch switchersHeader barMembership
BranchesAdministration > Workspace > Branchesreference.manage
Apps catalogueAdministration > Workspace > Appscompany.manage
App pageApps > open an appapps.configure (propose), apps.config.approve (approve)

System users

RuleWhat the system does
Cannot switch off your own accountOptions not offered; via API 'You cannot switch off your own account.'
Last administrator is protectedRefused: '<username> is the only administrator of this company...' / 'That is the last administrator of that company.'
Only a superuser changes a superuserRefused: 'Only a superuser can change a superuser.'
Machine users cannot sign inRefused: 'This is an integration account. It cannot sign in here.'
Wrong password does not reveal statusGeneric wrong-password message only; the status is not revealed
Access windowRefused: 'This account can be used from YYYY-MM-DD.'; set Access ends = yesterday -> 'This account's access has ended...'

All Users screens

RuleWhat the system does
Viewer/member cannot change accessNo edit buttons; any change refused 'You do not have permission for this action.'

Roles

RuleWhat the system does
Permission via role, not membershipServer allows the first; check what the screen shows (buttons follow the membership role) - log any mismatch

Field access

RuleWhat the system does
Hidden field is gone everywhereThe value is absent in all of them

API keys

RuleWhat the system does
A key cannot manage keysRefused: 'Keys are managed by a person, not by another key.'
Key secret shown onceOnly the prefix is visible; the full key cannot be shown again

Access review

RuleWhat the system does
No self-reviewRefused: 'Somebody else has to review your access.'

Settings

RuleWhat the system does
Danger zone only for adminsNo Danger zone; clear endpoint refused

Custom fields

RuleWhat the system does
Only admins add fieldsNo button; API refused 'Company administration is required.'

Audit

RuleWhat the system does
Audit screens need audit.viewAudit menu entries hidden; endpoints refused
Audit events cannot be editedRefused: 'The audit trail is append-only...'
RuleWhat the system does
Two people for a releaseRefused: 'Somebody other than the person who placed it releases a hold.'

Email / WhatsApp

RuleWhat the system does
Secrets never shownFields empty with 'Saved - leave blank to keep'; API returns only has_secret / has_token

WhatsApp

RuleWhat the system does
Shared connection only for the installation ownerRefused with the installation message

Masters / Branches

RuleWhat the system does
reference.manage neededNo New/Save; any save refused 'You do not have permission for this action.'

Companies

RuleWhat the system does
Create needs the rightButton hidden; API 'You do not have permission to create companies.'
Company code never changesRefused: 'Company code cannot change after creation.'

Company switcher

RuleWhat the system does
Only your companiesRefused: 'You do not belong to any of those companies.'

Apps

RuleWhat the system does
Install/turn off needs company.manageRefused

App configuration

RuleWhat the system does
Proposer cannot approveRefused: 'Somebody other than the person who proposed it must review a configuration change.'
Protected features stay onRefused: 'A protected control cannot be turned off.'
Turned-off feature refuses writes, keeps readsPOST 409 'capability_disabled'; GET still works