How to Use All User Roles in iDempiere

The User Roles window defines the security and access level for every iDempiere user in a retail deployment. It controls what stores, functions, and financial data staff such as cashiers, store admins, and regional managers can access.

Process Flow

TenthPlanet iDempiere AllUserRoles

Business Rules

  • Only Active roles can be assigned to users for system login.
  • User Level determines access scope: Client, Organization, or Client+Organization.
  • Can Export and Can Report control data extraction and report visibility per role.
  • Show Accounting restricts financial ledger data to authorized roles only.
  • Access Advanced exposes advanced configuration windows to selected roles.
  • Personal Lock and Personal Access restrict records to the creating user.
  • Preference Level controls whether user preferences apply at Client, Org, or User scope.
  • Access all Orgs grants a role visibility across every store organization.

Prerequisites

  • Tenant (Client) configured, e.g. POTS.
  • Organization(s) representing stores or regions configured.
  • System Users created and available for role assignment.
  • Org structure and Business Partner setup completed for scoping access.

Navigation

Menu → General Rules → Security → All User Role

Configuration Steps

Step 1: Define Role Identity

Enter a descriptive Name (e.g. Store Cashier) and an optional Description explaining the role’s intended use.

FieldSample ValueDescription
NamePOTS AdminIdentifies the role for assignment to users
Description(optional)Explains the intended purpose of the role
TenthPlanet iDempiere GeneralRules AllUserRoles

Step 2: Set User Level and Scope

Select the appropriate User Level for the role and set the Preference Level to control where saved preferences apply.

FieldSample ValueDescription
User LevelClient+OrganizationRole can operate at both chain and store level
Preference LevelClientUser preferences saved apply chain-wide

Step 3: Configure Access Permissions

Enable only the checkboxes required for the role’s function. Leave sensitive options like Show Accounting unchecked for store-floor staff.

FieldSample ValueDescription
ManualUncheckedRole is not manually maintained outside templates
Role TemplateUncheckedRole is not used as a template for other roles
Access all OrgsUncheckedRestricts visibility to assigned organizations only
Use User Org AccessUncheckedOrg access follows role, not individual user
Can ExportCheckedAllows the role to export data
Can ReportCheckedAllows the role to run and view reports
Show AccountingCheckedAllows the role to view accounting/financial data
Personal LockUncheckedRecords are not locked to the creating user
Personal AccessUncheckedRecords are not restricted to the creating user
Access AdvancedCheckedGrants access to advanced configuration windows
Maintain Change LogUncheckedChange log tracking is not enforced for this role

Step 4: Set Role Type

Leave Role Type blank unless the organization uses role classification for reporting.

Step 5: Activate the Role

Check the Active box, then save the record to make the role available for user assignment.

FieldSample ValueDescription
ActiveCheckedEnables the role for assignment and login

Common Issues and Resolutions

IssueCauseResolution
User cannot log in with assigned roleRole marked inactiveActivate the role record and save
Staff can view other stores’ dataAccess all Orgs enabled incorrectlyDisable Access all Orgs; restrict via Org Access tab
Cashier can view accounting reportsShow Accounting checked for cashier roleUncheck Show Accounting for non-finance roles
Export button missing for managerCan Export not enabledEnable the Can Export checkbox and save
User preferences not saved per storePreference Level set to ClientChange Preference Level to Organization
Role changes not reflected for userCached role session in browserAsk the user to log out and log back in
New windows not visible after updateMenu or window access not grantedGrant window access via the role’s Window Access tab

Next Steps

  • Configure Org Access, Window Access, and Process Access tabs for the role.
  • Assign the completed role to Users via the User window.
  • Set up Document Type access per role for POS transactions.