Access and permissions

Which permission each Purchasing screen needs, who may see and change what, and the rules that keep people from approving their own work.

On this page (35)

Permissions by screen

ScreenMenuPermission needed
Purchase dashboardPurchase > Dashboarddashboard.purchase (menu and API); without it the 'not allowed' panel shows
Purchase requisitionsPurchase > Orders > Purchase requisitionspurchase.view (list); purchase.requisition.create (New)
Purchase requisition recordPurchase requisitions > open / Newpurchase.requisition.create (edit, submit, cancel); purchase.requisition.approve (approve, return)
Requisitions to orderPurchase > Orders > Requisitions to orderpurchase.view (list); document.draft (Create RFQ)
Requests for quotationPurchase > Orders > Requests for quotationdocument.view (list), document.draft (create/edit), document.confirm (Approve order)
Purchase ordersPurchase > Orders > Purchase ordersdocument.view, document.cancel, document.invoice (one-step post)
Procurement panelPurchase order > Procurement tabdocument.view (panel); purchase.order.approve (approve); document.draft (others)
Goods receipt for a POPurchase order > Receipts > receiptinventory.operate; over receipt: inventory.receipt.exception.approve
Calls for tendersPurchase > Orders > Calls for tenderspurchase.view (list and record); purchase.tender.manage (New, edit, issue, close, cancel, quotes)
Call for tenders recordCalls for tenders > open / Newpurchase.tender.manage (all steps at the route); purchase.tender.award as well for Award (service)
Supplier's quote dialogCall for tenders > Suppliers and their quotes > Enter quotepurchase.tender.manage
Reverse auctionsPurchase > Orders > Reverse auctionspurchase.view (list); purchase.tender.manage (New and every step)
New reverse auction dialogReverse auctions > Newpurchase.tender.manage
Auction record dialogReverse auctions > open a rowpurchase.tender.manage (route); purchase.tender.award as well for Award (service)
Shop a cataloguePurchase > Orders > Shop a cataloguepurchase.requisition.create (menu, list, start, make requisition)
Cart dialogShop a catalogue > open a cartpurchase.requisition.create (own carts only)
Punch-out cataloguesPurchase > Configuration > Punch-out cataloguespurchase.configure (menu, create, edit); reading the list needs only purchase.requisition.create
Purchase agreementsPurchase > Orders > Purchase agreementspurchase.view (list); purchase.configure (New, edit, Close and, at the route, Put in force); purchase.policy.approve (Put in force, service)
Agreement dialogPurchase agreements > open / Newpurchase.configure
Supplier rebatesPurchase > Orders > Supplier rebatespurchase.view (list); purchase.configure (New and, at the route, every action); purchase.policy.approve (Put in force, service)
Shipping noticesPurchase > Orders > Shipping noticespurchase.view (list); purchase.asn.manage (New, edit, receive, cancel)
Shipping notice dialogShipping notices > open / Newpurchase.asn.manage; Receive also needs inventory.operate
Inbound shipmentsPurchase > Reporting > Inbound shipmentspurchase.view
Vendor billsPurchase > Billing > Vendor billsdocument.view / document.draft / document.confirm; posting also runs the match; purchase.match.release; stock.adjust (capitalise)
Bill matching panelVendor bill > Matching tabpurchase.view (read); document.draft (Match again); purchase.match.release (Release)
Debit notesPurchase > Billing > Debit notesdocument.view / document.draft / document.confirm
Bills on holdPurchase > Billing > Bills on holdpurchase.view (list); purchase.match.release (Release)
Three-way match exceptionsPurchase > Reporting > Three-way match exceptionspurchase.view; purchase.match.release
Retentions heldPurchase > Billing > Retentions heldpurchase.view (list); purchase.retention.release (Release)
Early paymentsPurchase > Billing > Early paymentspurchase.view (list); payment.prepare (offer, settle, withdraw)
Payment holdsFinance > Payment holds (applies to supplier bills)journal.view (list); payment.prepare (place); payment.approve (release)
SuppliersPurchase > Supplierspartner.view (list), partner.manage (create and change)
Supplier recordPurchase > Suppliers > open a supplierpartner.manage; partner.bank.reveal to see full IBAN / account numbers
Open purchase ordersPurchase > Reporting > Open purchase ordersreport.view
Overdue supplier receiptsPurchase > Reporting > Overdue supplier receiptsreport.view
Supplier spendPurchase > Reporting > Supplier spendreport.view
Supplier performancePurchase > Reporting > Supplier performancereport.view
Received not invoiced (GRNI)Purchase > Reporting > Received not invoicedreport.view
Shipping notices (staff side)Purchase > Reporting > Inbound shipments / Purchase > Orders > Shipping noticespurchase.view (list), purchase.asn.manage (create, change, cancel, receive), inventory.operate (Receive)
Consignment stockPurchase > Reporting > Consignment stockreport.view
Purchase settingsPurchase > Configuration > Purchase settingspurchase.view (open), purchase.configure (the switches), purchase.policy.approve (the tiers)
Receipt tolerancesPurchase > Configuration > Receipt tolerancespurchase.view (list), purchase.configure (change)
Bill matching policiesPurchase > Configuration > Bill matching policiespurchase.view (list), purchase.configure (write), purchase.policy.approve (Put in force, retire an active policy)
Approved suppliers (supplier qualification)Purchase > Configuration > Approved supplierspurchase.view (list), purchase.configure (write), purchase.policy.approve (Approve, Block, Exception)
Punch-out cataloguesPurchase > Configuration > Punch-out cataloguespurchase.configure (list and change); purchase.requisition.create (shop)
Supplier portal loginsPurchase > Configuration > Supplier portal loginspurchase.portal.manage
Supplier applicationsPurchase > Configuration > Supplier applicationspurchase.portal.manage (the screen); partner.manage (to approve)
Supplier changesPurchase > Configuration > Supplier changespurchase.portal.manage; partner.manage to approve; partner.bank.reveal to approve a bank account
Supplier registration formPublic link (no sign-in): /api/v1/public/supplier-registration/{key}None (the secret key in the link is the access); opened and renewed in Purchase settings
Purchasing feature switches and field settingsAdministration > Applications > Purchasing > FeaturesCompany admin (platform configuration right)
Portal homeSupplier portal > Homepurchase.portal (login linked to an active supplier)
Portal tenders and auctionsSupplier portal > Calls for tenders / Auctionspurchase.portal
Portal purchase ordersSupplier portal > Purchase orderspurchase.portal
Portal shipping noticesSupplier portal > Shipping noticespurchase.portal
Portal invoices sentSupplier portal > Invoices sentpurchase.portal
Portal bills and paymentsSupplier portal > Bills and paymentspurchase.portal
Portal early payment offersSupplier portal > Early payment offerspurchase.portal
Portal My detailsSupplier portal > My detailspurchase.portal

Purchase dashboard

RuleWhat the system does
Dashboard permissionMenu hidden; page shows the not-allowed panel; API 'You do not have permission for this action.'

Purchase requisitions

RuleWhat the system does
Create needs purchase.requisition.createNo New, Submit or Cancel; API create refused 'You do not have permission for this action.'

Purchase requisition

RuleWhat the system does
Approve/return needs purchase.requisition.approveRefused 'Approving a requisition needs the requisition approval right.' / 'Returning a requisition needs the requisition approval right.'

Procurement panel

RuleWhat the system does
PO approval right and no self-approval'Approving purchase orders needs the order approval right.' / 'Somebody other than whoever raised this order must approve it.'

Purchase order

RuleWhat the system does
Buyer may not confirm own orderRefused 'Somebody other than whoever raised this purchase order must approve it.'
Confirm and cancel rights and order limitApprove order / Cancel refused 403; above the order limit refused by the approval limit

All

RuleWhat the system does
Company isolation'Record not found.' / 'Choose each requisition line once.'

Calls for tenders

RuleWhat the system does
View versus manageList and records readable; no New button; writes refused 403 (route needs purchase.tender.manage)

Call for tenders record

RuleWhat the system does
Sealed prices are absent, not hiddenQuote lines carry no price, quantity offered or award fields; the comparison returns 403 'sealed'
Whoever raised it does not award it (maker-checker)403 'Somebody other than whoever raised this call for tenders must award it.'
Award needs the award right as well403 'Awarding a call for tenders needs the award right.'

Reverse auctions

RuleWhat the system does
Award right and auction creatorB refused 'Somebody other than whoever raised this auction must award it.'; no award right: 'Awarding needs the award right.'

Supplier portal auction

RuleWhat the system does
A supplier sees and bids only its own auctionsRecord not found (404); bids as a non-bidder refused the same way

Shop a catalogue

RuleWhat the system does
Carts are private; the return link is a secret404 for the cart; 'This cart link is not valid.' for the key; keys are 24 random bytes and used or old sessions take nothing

Punch-out catalogues

RuleWhat the system does
Password stored sealed and never returnedpassword_set true only; the password is never sent back; it is posted only to the shop's https address
Shop password is sealedOnly 'password set' is returned; the value is never shown or returned; the screen needs purchase.configure.

Purchase agreements

RuleWhat the system does
Writer cannot put own agreement in force403 'Somebody other than whoever wrote the agreement must put it in force.'

Supplier rebates

RuleWhat the system does
Writer cannot put own rebate in force403 'Somebody other than whoever wrote it must put a rebate agreement in force.'; no approval right: 'Putting a rebate in force needs the procurement approval right.'

Bills on hold

RuleWhat the system does
Maker-checker on releasing a holdAll refused 'Somebody other than whoever raised the bill or its order must release this hold.' (a superuser is still a person here)
Release right and draft bills only'Releasing a matching hold needs the release right.' (route 403 first); 'The bill is no longer a draft.'

Retentions held

RuleWhat the system does
Maker-checker on releasing a retentionRefused with the 'somebody other' message; 'Releasing a retention needs the retention release right.'

Early payments

RuleWhat the system does
Offering needs payment.prepare; supplier sees only its own403 for the user; 404 'Record not found.' for the supplier

Payment holds

RuleWhat the system does
Place and release rightsRelease needs payment.approve; Place needs payment.prepare; list needs journal.view

Vendor bills

RuleWhat the system does
Duplicate supplier invoice is blocked across usersOnly one posts; the other: 'is already on <bill>. A supplier invoice is posted once.' (unique claim)

All screens

RuleWhat the system does
Company isolationRecord not found (404); lists show only the current company; suppliers and products from another company are refused
Edit conflictsSecond save: 'This record changed; reload it and try again.' (409); the payment hold says 'Somebody changed this hold. Reload it and look again.'

Shipping notices

RuleWhat the system does
Receiving from a notice needs the inventory right as wellReceive button hidden; by API the receive action is refused 403 (the route checks purchase.asn.manage and inventory.operate)

Purchase settings

RuleWhat the system does
Switches need purchase.configureCheck boxes are disabled and Save is hidden; the API refuses the save (403).
Approval tiers need purchase.policy.approveInputs are disabled, no Add / Save tiers buttons; the API refuses 'Changing approval tiers needs the procurement approval right.'
Company isolation'Record not found.' (404) everywhere; lists show only company A.

Bill matching policies

RuleWhat the system does
Maker-checker on policies'Somebody other than the author must activate this policy.' / 'Activating a matching policy needs the policy approval right.' (403)

Approved suppliers

RuleWhat the system does
Maker-checker on qualification'Somebody other than whoever wrote it must approve a supplier qualification.' (403); Block, Exception and Archive need purchase.policy.approve ('Deciding a supplier qualification needs the procurement approval right.').

Supplier changes

RuleWhat the system does
Bank account approval is a finance rightServer refuses with 'A new bank account is approved by somebody who may see bank details (finance).'; IBAN / account number are masked in the dialog.

Supplier applications

RuleWhat the system does
Approving needs contact rights'Approving a supplier needs the right to manage contacts.' (403)

Supplier portal logins

RuleWhat the system does
Portal login is limited to the portalOnly the portal menu is available; staff screens and routes refuse (no purchase.view / document.view).
Closed login loses accessMembership is removed; the portal says the login is not linked / refuses access.

Portal purchase orders

RuleWhat the system does
A supplier cannot see another supplier's records'Record not found.' (404) for every type; lists show only A's records; same for another company.

Portal tenders and auctions

RuleWhat the system does
Sealed tenders stay sealedOnly A's own quote and versions are shown; no comparison and no other price anywhere in the portal.

Supplier registration form

RuleWhat the system does
Public form opens nothing elseOnly the form and the application POST work; a wrong or retired key answers 'This registration link is not open.'; the page is no-store / noindex.
Spam controls'The application could not be accepted.'; 'Too many applications today; please try again tomorrow.' (429)

Portal My details

RuleWhat the system does
A supplier cannot change its record directlyRefused; only a change request is possible and nothing moves until staff approve.

Purchase reports

RuleWhat the system does
Reports need report.viewThe menu entries are hidden for the report.view reports and the API answers 403.

Purchasing > Features

RuleWhat the system does
Switches are enforced on the serverRefused with capability_disabled even though the screen is gone; GET still works.

Shipping notices (staff)

RuleWhat the system does
Receive needs warehouse rightsRefused (inventory.operate is checked on top of purchase.asn.manage).