How to Review the All Role Window in iDempiere

The Role window in iDempiere defines the security profile assigned to every user, controlling what data, organizations, and functions they can access.

Because this window is read-only for users, it is primarily used to review existing role configurations before assigning them, ensuring transactions, reports, and accounting data stay properly restricted.

Process Flow

TenthPlanet iDempeire GeneralRules AllRoles

Business Rules

  • Only Active roles can be assigned to users for login.
  • User Level determines whether a role sees System, Client, or Organization data.
  • Client+Organization level restricts a role to its assigned store only.
  • Can Export controls whether a role may extract data to file.
  • Can Report controls whether a role may run standard reports.
  • Show Accounting controls visibility of GL and financial postings.
  • Access all Orgs allows a role to view data across multiple stores.

Prerequisites

  • Tenant (Client) configured for the retail business.
  • Organization or store record configured.
  • User accounts created in the User window.
  • Org Access and Document Action Access reviewed for each role.

Navigation

Menu → General Rules → Security → Role

Configuration Steps

Step 1: Review Tenant and Name Fields

Check the Tenant (All) and Name fields, e.g., ‘POTS’ and ‘POTS Admin’, match the intended store or business unit.

TenthPlanet iDempiere AllRoles

Step 2: Verify User Level and Preference Level

Confirm User Level matches the intended scope (e.g., Client+Organization for store-level roles) and Preference Level is set correctly.

Step 3: Check Function Permission Checkboxes

Review Can Export, Can Report, Show Accounting, and Access Advanced to confirm they match the role’s intended responsibilities.

FieldSample ValueDescription
Tenant (All)POTSClient/tenant the role belongs to
NamePOTS AdminRole display name shown at login
User LevelClient+OrganizationDefines System, Client, or Organization data scope
Preference LevelClientLevel at which user preferences and defaults apply
Can ExportCheckedAllows exporting grid data to file
Can ReportCheckedAllows running standard reports
Show AccountingCheckedAllows viewing GL and accounting facts
Access AdvancedCheckedEnables access to advanced tabs and fields
ActiveCheckedRole is enabled and assignable to users
Role TypeBlankOptional classification, e.g., Manager, Cashier

Step 4: Confirm Active Status

Verify the Active checkbox is ticked for any role currently in use by store staff.

Step 5: Cross-check Role Type for Store Assignment

Confirm Role Type is set consistently so store onboarding staff can assign the correct role without confusion.

Common Issues and Resolutions

IssueCauseResolution
Role not available at loginActive checkbox untickedActivate the role in the Role window
User sees data from other storesAccess all Orgs enabledDisable Access all Orgs for store-level roles
Staff cannot export reportsCan Export uncheckedEnable Can Export for the role
Role changes not applied to userActive session cached old roleAsk user to log out and log back in
Duplicate or unclear role namesNo naming convention usedStandardize names, e.g., Store-Cashier, Store-Manager
New store staff cannot access org dataOrganization missing from role accessAdd the organization in the Org Access tab
Inconsistent report results between rolesDifferent Preference Level settingsAlign Preference Level across similar roles

Next Steps

  • Configure User window to assign reviewed roles to staff.
  • Set up Org Access tab for store-specific data restrictions.
  • Review Document Action Access for transaction-level permissions.
  • Configure Client Info for tenant-wide retail settings.