Access and permissions
Which permission each Master Data screen needs, who may see and change what, and the rules that keep people from approving their own work.
On this page (23)
Permissions by screenMaster Data appAll screensPartiesParty recordBank and tax changesDuplicates and mergesTemplate recordAccount mappingsSubstitutes / Data qualityTracking policies and mediaSite defaultsPublic catalogue APIImportsField securityMaster Data featuresContacts listCustomer 360Record credit review dialogProduct recordProduct record > Company AccessProduct configuration mastersCountries / States / Cities
Permissions by screen
| Screen | Menu | Permission needed |
|---|---|---|
| Master Data Dashboard | Master Data > Master Data > Dashboard | mdm.view; adopt needs mdm.steward |
| Parties | Master Data > Master Data > Parties | mdm.view (list); mdm.steward (create) |
| Party record | Master Data > Master Data > Parties > open a party | mdm.view to read; mdm.steward to change; mdm.release to release or rename a shared party |
| Change requests | Master Data > Master Data > Bank and tax changes | mdm.view to list; mdm.finance.approve (bank) or mdm.tax.approve (registration) to decide |
| Product templates | Master Data > Products > Templates and variants | mdm.view; product.manage to create |
| Template record | Master Data > Products > Templates and variants > open a template | product.manage (validate, archive, variants); mdm.steward (approve, release) |
| Attributes | Master Data > Products > Attributes | mdm.view; mdm.steward to create |
| Barcodes | Master Data > Products > Barcodes | mdm.view; product.manage to register |
| Customer item codes | Master Data > Products > Customer item codes | mdm.view; product.manage; feature switch 'Customer and supplier item codes' |
| Supplier item codes | Master Data > Products > Supplier item codes | mdm.view; product.manage; same feature switch |
| Tracking policies and media | Master Data > Products > Tracking policies and media | mdm.view; product.manage (propose, upload); mdm.steward (activate) |
| Site defaults | Master Data > Products > Site defaults | mdm.view; product.manage |
| Account mappings | Master Data > Products > Account mappings | mdm.view; product.manage to draft; mdm.finance.approve to activate |
| Substitutes | Master Data > Products > Substitutes | mdm.view; product.manage to propose; mdm.steward to approve; feature switch 'Substitutes' |
| Catalogues | Master Data > Products > Catalogues | mdm.view; mdm.publish; feature switch 'Channel catalogues and assortments' |
| Duplicates and merges | Master Data > Stewardship > Duplicates and merges | mdm.view; mdm.steward (scan, dismiss, propose); mdm.merge.approve (decide); feature switch 'Duplicates and merges' |
| Imports | Master Data > Stewardship > Imports | mdm.import (menu and every action); feature switch 'Governed imports' |
| Data quality | Master Data > Stewardship > Data quality | mdm.view; mdm.steward |
| Field security | Master Data > Stewardship > Field security | Menu needs mdm.steward; list mdm.view |
| Completeness report | Master Data > Reports > Completeness and errors | mdm.view |
| Duplicate review report | Master Data > Reports > Duplicate review | mdm.view |
| Product catalogue report | Master Data > Reports > Product catalogue | mdm.view |
| UOM and barcode audit | Master Data > Reports > UOM and barcode audit | mdm.view |
| Expiry-policy coverage | Master Data > Reports > Expiry-policy coverage | mdm.view |
| Sensitive changes report | Master Data > Reports > Sensitive changes | mdm.view |
| Languages | Master Data > References > Languages | mdm.view |
| Time zones | Master Data > References > Time zones | mdm.view |
| Currencies | Master Data > References > Currencies | mdm.view |
| Channel read side | (no menu) Public catalogue API /api/v1/catalogue/{key}/products | No sign-in; the catalogue key is the access |
| Master Data features and field settings | Applications > Master Data > Features | Company configuration permission |
| Contacts list | Contacts > Contacts | partner.view (list); partner.manage (create / edit) |
| Customer 360 record | Contacts > Contacts > open a contact | partner.view; partner.manage to edit; partner.bank.reveal for full bank numbers; credit.limit.reveal for limits, risk, guarantees and reviews |
| Record credit review dialog | Customer 360 > Finance & Credit > Record credit review | partner.manage |
| Custom fields | Contacts > Configuration > Custom fields (also Catalogue > Configuration > Custom fields) | Any member reads; company administrator (membership role admin) adds and changes |
| Countries | Contacts > Configuration > Countries | Signed-in user reads; administrator of at least one company edits (shared by all companies) |
| States & regions | Contacts > Configuration > States & regions | As Countries |
| Cities & areas | Contacts > Configuration > Cities & areas | As Countries |
| Products list | Catalogue > Catalogue | product.view; product.manage to create; product.cost.view to see cost |
| Product record | Catalogue > Catalogue > open a product | product.view; product.manage edit / archive / duplicate / documents / variants; product.cost.view cost, accounts, stock value; document.draft quick sale / purchase; inventory.operate reorder rules |
| Product dialogs | Product record > dialogs | product.manage (duplicate); document.draft (quick documents); product.view (labels) |
| Stock on hand | Catalogue > Reporting > Stock on hand | product.view (and inventory read for the pivot) |
| Product categories | Catalogue > Configuration > Product categories | product.view (read); reference.manage (create / change) |
| Brands | Catalogue > Configuration > Brands | product.view / reference.manage |
| Units of measure | Catalogue > Configuration > Units of measure | product.view / reference.manage |
| Product groups | Catalogue > Configuration > Product groups | product.view / reference.manage |
| Manufacturers | Catalogue > Configuration > Manufacturers | product.view / reference.manage |
| Variant attributes | Catalogue > Configuration > Variant attributes | product.view / reference.manage |
Master Data app
| Rule | What the system does |
|---|---|
| Menu permissions | No mdm.view: app / menus not offered and API 403. mdm.view only: every menu except Imports (mdm.import) and Field security (mdm.steward); all change buttons refused by the server |
All screens
| Rule | What the system does |
|---|---|
| View-only user cannot change | Each refused '<action> needs the <permission> permission.' e.g. 'Creating a party needs the mdm.steward permission.', 'Registering a barcode needs the product.manage permission.', 'Publishing to a channel needs the mdm.publish permission.' |
Parties
| Rule | What the system does |
|---|---|
| Company isolation of parties | 404 'Party not found.' - a company reaches a party only through its own release, superusers included |
Party record
| Rule | What the system does |
|---|---|
| Bank details masked | IBAN and account number show only the last 4 characters (••••3456); with partner.bank.reveal the full value |
| Edit conflict | Tab 2 refused 'This record changed since you opened it. Reload it and try again.' |
Bank and tax changes
| Rule | What the system does |
|---|---|
| Maker-checker binds superusers | Refused 'Somebody other than the person who prepared this change must decide it.' |
| Domain separation | Refused 'Deciding a registration change needs mdm.tax.approve.' / 'Deciding a bank account change needs mdm.finance.approve.' |
| Approve a changed proposal | Refused 'The proposal you are approving is not the one on record...' |
Duplicates and merges
| Rule | What the system does |
|---|---|
| Merge separation of duties | Refused 'Somebody other than the person who prepared this merge must decide it.' |
| Different legal entities never merged | Refused at proposal and again at decision 'Their registration numbers differ; not merged.' |
Template record
| Rule | What the system does |
|---|---|
| Approve separate from prepare | Refused 'Somebody other than the person who prepared this template must decide it.' |
| Concurrent variant creation | One variant created; the other gets 409 '<code> already has the variant ...' - no half-made product |
Account mappings
| Rule | What the system does |
|---|---|
| Finance decides mappings | Refused 'Activating an account mapping is Finance's decision (mdm.finance.approve).' |
| Another company's account | Refused 'Choose an account of this company's chart.' |
Substitutes / Data quality
| Rule | What the system does |
|---|---|
| Self-approval refused | Refused 'Somebody other than the person who prepared this substitute must decide it.' / '...this exception must decide it.' |
Tracking policies and media
| Rule | What the system does |
|---|---|
| Live-lot tracking change needs a second person | Refused 'Somebody other than the person who prepared this tracking change must decide it.' |
| Media isolation and safety | 404 'Media not found.'; SVG refused; served media has nosniff and CSP default-src 'none' |
Site defaults
| Rule | What the system does |
|---|---|
| Another company's warehouse | 403 'That warehouse is not one of this company's sites.' |
Public catalogue API
| Rule | What the system does |
|---|---|
| No internal data leaks | Payload has code, names, unit, price, tax rate, barcode, description, channel image ids - never cost, supplier, accounts or bank data; unknown key -> 404 'Catalogue not found.' |
| Unreleased product not sellable | Refused '<code> is not available in this catalogue.' |
Imports
| Rule | What the system does |
|---|---|
| Import needs mdm.import | Refused 'Importing masters needs the mdm.import permission.' / 'Committing an import needs the mdm.import permission.' |
Field security
| Rule | What the system does |
|---|---|
| Restricted field hidden and protected | Field absent everywhere; their save keeps the stored value |
| Custom field cannot shadow a core field | Refused ''x_iban' would shadow the protected field 'iban'. Choose another key.' |
Master Data features
| Rule | What the system does |
|---|---|
| Protected capabilities | Not offered as switches (always on) |
Contacts list
| Rule | What the system does |
|---|---|
| View permission | Screen empty / refused 'You do not have permission for this action.'; with partner.view the list shows |
Customer 360
| Rule | What the system does |
|---|---|
| View-only user cannot change | Open a contact; try Edit; send PATCH partners/{id} by API |
| Bank numbers masked | Open Finance & Credit; Edit; change another field; Save |
| Credit figures masked | Open Finance & Credit and Overview |
| Field access rules from Administration | Sign in with that role; open a contact; save it |
| Record access (own records only) | Sign in as that user; open Contacts; open another user's contact by URL |
| Company isolation | In A, open a contact id of company B by URL; PATCH it; set payment_term_id / fiscal_position_id / payer to B's records |
| Audit of sensitive changes | Change the credit limit, TRN and a bank IBAN; open History and the audit log |
Record credit review dialog
| Rule | What the system does |
|---|---|
| Review history cannot be edited | Send a PATCH whose profile.credit_reviews is empty or altered |
Product record
| Rule | What the system does |
|---|---|
| Product view vs manage | Open a product; try Edit, Duplicate, Archive, upload a document; PATCH products/{id} by API |
| Cost visibility | Open a product, its Accounting tab, Purchase summary, supplier grid, Stock value; send cost in a PATCH |
| Company isolation | In A, open B's product by URL; set category / warehouse / account / supplier to B's ids by API |
| Uploaded files are safe | Upload a product image that is an HTML file renamed .png; a document of type .exe |
Product record > Company Access
| Rule | What the system does |
|---|---|
| Sharing respects rights in the other company | Share a product with B |
Product configuration masters
| Rule | What the system does |
|---|---|
| Masters need reference.manage | POST / PATCH product-masters/category by API |
Countries / States / Cities
| Rule | What the system does |
|---|---|
| Shared geography editing | POST geo/countries by API |