Access and permissions
Which permission each Sales screen needs, who may see and change what, and the rules that keep people from approving their own work.
On this page (21)
Permissions by screenSales > Orders > QuotationsQuotation recordSales order recordCustomer invoicesPrice approvalsChanges tabBlanket agreementsCredit holdsPrices & margin tabSales > Reporting > Gross marginCustomersSales > Configuration > SettingsSales settingsQuotation templates / Reasons / Commission plansApplications > Sales > FeaturesApplications > Sales > FieldsSales ordersSales > ReportingPublic quotation acceptance pageQuotation tab
Permissions by screen
| Screen | Menu | Permission needed |
|---|---|---|
| Sales dashboard | Sales > Dashboard | dashboard.sales (menu) |
| Quotations | Sales > Orders > Quotations | document.view (list), document.draft (create / edit) |
| Quotation / sales order record | Quotations / Sales orders > open a record | document.view / document.draft / document.confirm / document.cancel / document.deliver / document.invoice |
| Sales orders | Sales > Orders > Sales orders | document.view |
| Price approvals | Sales > Orders > Price approvals | document.view (list); sales.price.approve (decide) |
| Credit holds | Sales > Orders > Credit holds | document.view |
| Blanket agreements | Sales > Orders > Blanket agreements | document.view / document.draft (save) / document.confirm (activate) |
| Customer invoices | Sales > Invoicing > Customer invoices | document.view / document.draft / document.invoice (post) / payment.record (receipt) / document.reverse |
| Credit notes | Sales > Invoicing > Credit notes | document.view / document.confirm / document.invoice |
| Customers | Sales > Customers | partner.view / partner.manage |
| Products | Sales > Products | product.view / product.manage |
| Sales order register | Sales > Reporting > Sales order register | document.view |
| Sales analysis (R017) | Sales > Reporting > Sales analysis | report.view |
| Sales gross margin (R018) | Sales > Reporting > Gross margin | report.view + sales.margin.reveal (or product.cost.view); menu needs sales.margin.reveal |
| Open sales orders (R019) | Sales > Reporting > Open orders | report.view |
| Delivery performance (R020) | Sales > Reporting > Delivery performance | report.view |
| Returns and credits (R021) | Sales > Reporting > Returns and credits | report.view |
| Quotation conversion | Sales > Reporting > Quotation conversion | report.view |
| Commissions | Sales > Reporting > Commissions | report.view |
| Sales settings | Sales > Configuration > Settings | sales.configure (menu and save); document.view (read) |
| Quotation templates | Sales > Configuration > Quotation templates | document.view (list); sales.configure (save) |
| Return and cancellation reasons | Sales > Configuration > Return and cancellation reasons | document.view (list); sales.configure (save) |
| Commission plans | Sales > Configuration > Commission plans | sales.configure (menu and save) |
| Product masters | Sales > Configuration > Product categories / Brands / Units of measure / Product groups / Manufacturers / Variant attributes | product.manage |
| Custom fields | Sales > Configuration > Custom fields | member.manage |
| Sales app configuration | Administration > Applications > Sales > Features / Fields | company administrator (configuration rights) |
| Public quotation acceptance page | Customer link /api/v1/public/quotations/<token> (no sign-in) | none (token in the link) |
Sales > Orders > Quotations
| Rule | What the system does |
|---|---|
| A user with only document.view sees the lists but cannot create | Lists and records open; New / Save are hidden or refused 403 'You do not have permission for this action.' |
Quotation record
| Rule | What the system does |
|---|---|
| Sales user (document.view + document.draft) cannot confirm | Refused 403 with the confirm right named; the order stays Draft; no delivery order is raised |
| Confirm is limited by the person's order limit | 8,000.00 refused with the approval-limit reason; 3,000.00 confirms |
| Edit conflict (two tabs) | Second save refused 'This record changed. Reload it before saving.'; nothing is overwritten |
| A free line (100% discount) needs a reason | Refused '<description> is given away free: say why on the line.' - confirm is not an approval |
Sales order record
| Rule | What the system does |
|---|---|
| Cancel needs document.cancel | Refused for the first (403); allowed for the manager; credit reservation released |
| Deliver, invoice, reverse each need their own right | document.deliver, document.invoice and document.reverse are checked separately; each refusal is 403, nothing changes |
| Delete only a draft; Archive keeps the record | Delete refused 'Only a draft can be deleted. Cancel it, or archive it.'; archive needs write access |
| No membership means no data | 404 'Record not found.' on every one |
| Record scope by branch limits what a person sees | Branch B orders are absent from the list and refused by URL |
| Customer blocked or blacklisted cannot be sold to | Refused 'Customer transaction hold: Sales orders...' / '<name> is blacklisted: <reason>.'; releasing the hold allows it |
Customer invoices
| Rule | What the system does |
|---|---|
| Receipt needs payment.record; posting needs document.invoice | Each refused until the matching right is given |
| A posted invoice cannot be edited or deleted | No edit or delete; corrections are by Credit this invoice or Reverse; Reverse needs the reversal right and no payments first |
| Credit note posting follows the billing approval policy | Refused before any write ('needs approval'); after a different person approves it posts |
| Journals follow the order's company | Journal exists only in company A with A's accounts and numbering |
Price approvals
| Rule | What the system does |
|---|---|
| Maker-checker: the person who asked cannot approve | Refused: 'Somebody other than the person who priced or asked must decide this.' |
| The person who last saved the prices cannot approve | Refused with the same sentence, because A is recorded as the one who priced it (the last 'sale.saved' author) |
| Approving needs sales.price.approve, not just a sales role | Refused 403: 'Approving a price exception needs the sales price approval right.' |
| Approval is tied to the prices as they were | 409 'The quotation has changed since this was asked for; ask again.'; the request is cancelled; confirm stays held |
| A rejection must give a reason; a decided request cannot be decided twice | 'Say why it is rejected.'; 'This approval is already approved.' |
Changes tab
| Rule | What the system does |
|---|---|
| Maker-checker on change orders | Refused 'Somebody other than the person who asked must approve this change.'; a user without document.confirm refused 403 'Approving a change order needs the right to confirm orders.' |
Blanket agreements
| Rule | What the system does |
|---|---|
| Maker-checker on activation | A refused 'Somebody other than the person who drafted it must activate the agreement.'; B activates and is recorded as Activated by |
Credit holds
| Rule | What the system does |
|---|---|
| Credit limit cannot be bypassed by the sales manager | Confirm refused until an approved, unexpired credit override exists; the hold is recorded in Credit holds |
| Credit re-check at dispatch and invoicing cannot be skipped | Both refused with 'Credit check: ...'; the order is placed on credit hold; the posting is not written |
Prices & margin tab
| Rule | What the system does |
|---|---|
| Cost and margin are hidden without margin rights | Lines have no cost or margin fields; a low-margin warning only says 'Margin is under the minimum.' |
Sales > Reporting > Gross margin
| Rule | What the system does |
|---|---|
| Gross margin report hidden and refused | Menu hidden; the call is refused 'Gross margin needs the right to see sales margins.'; the same user can open R017 |
| Product cost permission also reveals margin | Data returned (either right is enough); the menu entry still needs sales.margin.reveal |
Customers
| Rule | What the system does |
|---|---|
| Credit limit shown only with credit.limit.reveal | The credit limit and available credit are masked or absent for that user |
| Customer from another company cannot be used on a quotation | Refused; the customer or product is not found in this company |
Sales > Configuration > Settings
| Rule | What the system does |
|---|---|
| Saving settings needs sales.configure | Menu hidden; save refused 403; with the right the change is saved and audited |
Sales settings
| Rule | What the system does |
|---|---|
| Every settings change is audited with before and after | One 'sales.settings' event lists only the fields that changed with their old and new values; a save that changes nothing writes no event |
| Settings values are validated server-side | 'Enter a percentage between 0 and 100.', 'Enter between 0 and 3650 days.', 'Choose one of the listed options.'; nothing saved |
| Settings edit conflict | Second save refused because the revision is stale |
Quotation templates / Reasons / Commission plans
| Rule | What the system does |
|---|---|
| Masters need sales.configure to save | All three refused 403; the lists can still be read with document.view |
Applications > Sales > Features
| Rule | What the system does |
|---|---|
| Only Branch on sales documents is a real switch | Only 'Branch on sales documents' is configurable (default on, depends on Sales orders); every other capability is shown with its status and has no switch |
Applications > Sales > Fields
| Rule | What the system does |
|---|---|
| Field modes are enforced by the server, not just the screen | Hidden: value refused; Required: confirm refused '<label> is required by this company before this step.'; the same for Delivery date, Sales team and Incoterm place |
| Branch Hidden is blocked when it would break numbering or access rules | Refused with the impact reasons (branches numbering documents, posting rules requiring a branch, access rules limiting people to their branch) |
| Proposing a field change and approving it are separate rights | Proposal waits; approval needs apps.config.approve (and a different person where the platform enforces it) |
Sales orders
| Rule | What the system does |
|---|---|
| Company isolation of orders | 'Record not found.' (404); never the other company's data; lists show only the active company |
Sales > Reporting
| Rule | What the system does |
|---|---|
| Reports respect the 'Companies read together' switch only for companies the user belongs to | Only member companies appear; figures never include a company the user cannot access |
Public quotation acceptance page
| Rule | What the system does |
|---|---|
| Link works without sign-in but reveals only the one version | Valid token shows that quotation only; a wrong token shows 'not found' style page; no other quotation, customer or company data is reachable |
| Only the latest, unexpired, unchanged version can be accepted | Each refused with 'replaced by a newer offer', 'This offer expired on <date>' or 'The quotation has changed since it was sent'; no Accept form is shown |
| Acceptance needs a name and cannot be repeated or forged as staff | 'Say who accepted it.'; the second accept shows the same acceptance; channel is recorded as by link vs recorded by staff with who recorded it |
| Content is escaped | Text is shown as text; no script runs |
Quotation tab
| Rule | What the system does |
|---|---|
| Record acceptance by staff keeps its evidence | 'Say what the acceptance was - a signed copy, an email.'; with evidence it is stored with the recording user |