Access and permissions
Which permission each Fixed Assets screen needs, who may see and change what, and the rules that keep people from approving their own work.
On this page (7)
Permissions by screen
| Screen | Menu | Permission needed |
|---|---|---|
| Assets | Fixed Assets > Assets | asset.view (list); asset.manage (New) |
| Asset record | Fixed Assets > Assets > open an asset | asset.view; asset.manage; asset.approve for Capitalise |
| Change dialogs | Asset record > Transfer / Impairment / Estimate change / Disposal | asset.manage (propose); asset.approve (decide) |
| Physical check dialog | Asset record > Record a check | asset.manage |
| Depreciation runs | Fixed Assets > Depreciation runs | asset.view; asset.manage; asset.approve |
| Asset changes | Fixed Assets > Changes to approve | asset.view (list); asset.approve (decide) |
| Asset roll-forward | Fixed Assets > Reporting > Asset roll-forward | asset.view |
| Asset register | Fixed Assets > Reporting > Asset register | asset.view |
| Asset categories | Fixed Assets > Configuration > Asset categories | asset.view; asset.manage; asset.approve to Activate |
| Depreciation books | Fixed Assets > Configuration > Depreciation books | asset.view; asset.manage |
Assets
| Rule | What the system does |
|---|---|
| View-only user cannot create or change | The list and records are readable; New and every action button are absent; the server refuses the write (HTTP 403). |
| Menu hidden without asset.view | Menu entries are hidden and API calls are refused with HTTP 403. |
| Company isolation | The company 1 call returns 'Record not found.' (404); each company shows only its own assets, categories, books, runs and changes; the roll-forward reads only the active company's ledger. |
Asset record
| Rule | What the system does |
|---|---|
| Maker cannot capitalise own asset (also superuser) | Both refused: 'Somebody other than whoever prepared a capitalisation must approve it.' (SELF_APPROVAL, 403). Separation of duties binds superusers too. |
| Capitalise needs asset.approve | HTTP 403. The preparer role (manage) cannot approve; the Capitalise button is hidden. |
| Edit conflict (revision) | The second save fails: 'This record changed; reload it and try again.' (409); no silent overwrite. Same on categories, runs and changes. |
| Journals cannot be posted into a locked period | Both refused with 'This accounting period is locked.' (the disposal as 'Depreciation up to the disposal could not be posted: ...' when rows are blocked); nothing half-booked. |
Depreciation runs
| Rule | What the system does |
|---|---|
| Run proposer cannot approve; manage cannot approve | First: SELF_APPROVAL 'Somebody other than whoever prepared a depreciation run must approve it.' Second: HTTP 403 (route needs asset.approve). |
| Audit trail | Each saved asset, capitalisation, run proposal / posting / cancellation, change proposal / approval / rejection and category activation has an audit entry with user and time. |
Changes to approve
| Rule | What the system does |
|---|---|
| Approve / Reject buttons only for approvers | Only the asset.approve user sees Approve and Reject on 'To approve' rows; the other sees the status badge only. The server refuses approve/reject from the other user (403). |
| Maker cannot approve own disposal | Refused: 'Somebody other than whoever prepared this disposal must approve it.' (SELF_APPROVAL). Same for transfer, impairment and estimate. |
Asset categories
| Rule | What the system does |
|---|---|
| Category activation is maker-checker | A refused (SELF_APPROVAL); B succeeds. A user without approve cannot activate: 'Approving a category needs the fixed-asset approval right.' |
| Standard-accounts needs asset.manage | HTTP 403; no accounts added to the chart. |
Asset roll-forward
| Rule | What the system does |
|---|---|
| Book belongs to the company | Refused: 'Choose one of this company's books.' |