{"id":22107,"date":"2026-08-04T11:07:28","date_gmt":"2026-08-04T11:07:28","guid":{"rendered":"https:\/\/tenthplanet.in\/idempiere\/?p=22107"},"modified":"2026-08-13T04:50:12","modified_gmt":"2026-08-13T04:50:12","slug":"how-to-configure-role-access-update-in-idempiere","status":"publish","type":"post","link":"https:\/\/tenthplanet.in\/idempiere\/how-to-configure-role-access-update-in-idempiere\/","title":{"rendered":"How to Configure Role Access Update in iDempiere"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">The Role Access Update window in iDempiere rebuilds access records that control which windows, forms, processes and reports a role can open. Running it correctly prevents staff from seeing broken menus or missing functions during store operations.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Process Flow<\/strong><\/h2>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"374\" src=\"https:\/\/tenthplanet.in\/idempiere\/wp-content\/uploads\/sites\/13\/2026\/07\/TenthPlanet-iDempiere-RoleAccessUpdate-1024x374.png\" alt=\"\" class=\"wp-image-22113\" title=\"\" srcset=\"https:\/\/tenthplanet.in\/idempiere\/wp-content\/uploads\/sites\/13\/2026\/07\/TenthPlanet-iDempiere-RoleAccessUpdate-1024x374.png 1024w, https:\/\/tenthplanet.in\/idempiere\/wp-content\/uploads\/sites\/13\/2026\/07\/TenthPlanet-iDempiere-RoleAccessUpdate-300x110.png 300w, https:\/\/tenthplanet.in\/idempiere\/wp-content\/uploads\/sites\/13\/2026\/07\/TenthPlanet-iDempiere-RoleAccessUpdate-768x280.png 768w, https:\/\/tenthplanet.in\/idempiere\/wp-content\/uploads\/sites\/13\/2026\/07\/TenthPlanet-iDempiere-RoleAccessUpdate.png 1402w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Business Rules<\/strong><\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Roles marked as Manual access are skipped entirely; the process makes no changes for them.<\/li>\n\n\n\n<li>Selecting a specific Role updates access records for that role only.<\/li>\n\n\n\n<li>Leaving Role blank updates every active role in the current tenant.<\/li>\n\n\n\n<li>Running from the System tenant with no Role selected updates all tenants.<\/li>\n\n\n\n<li>Reset Existing Access deletes and rebuilds all access records before inserting new ones.<\/li>\n\n\n\n<li>Leaving Reset Existing Access unchecked only inserts access records that are missing.<\/li>\n\n\n\n<li>Run as Job queues the update as a background process instead of running inline.<\/li>\n\n\n\n<li>Only active windows, processes, forms, workflows and info windows are eligible for access.<\/li>\n\n\n\n<li>The Role&#8217;s User Level (System, Client, Client+Organization or Organization) decides which access levels are granted.<\/li>\n\n\n\n<li>Organization-level roles never receive windows whose name contains &#8220;(all)&#8221;.<\/li>\n\n\n\n<li>Document Action access is rebuilt for every active document type regardless of the Role&#8217;s User Level.<\/li>\n<\/ul>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><tbody><tr><td><strong>Note:<\/strong> The process rebuilds six access tables in a single run &#8211; AD_Window_Access, AD_Process_Access, AD_Form_Access, AD_WorkFlow_Access, AD_Document_Action_Access and AD_InfoWindow_Access<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Prerequisites<\/strong><\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Role window configured with the required window, process, form and report flags.<\/li>\n\n\n\n<li>Role&#8217;s User Level (System, Client, Client+Organization or Organization) set correctly.<\/li>\n\n\n\n<li>Users assigned to the Role that needs updated access.<\/li>\n\n\n\n<li>New windows, processes or reports already added to the application dictionary.<\/li>\n\n\n\n<li>Manual access flag on the Role reviewed if custom, hand-maintained access is required.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Navigation<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Menu \u2192 General Rules \u2192 Security \u2192 Role Access Update<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Configuration Steps<\/strong><\/h2>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>Step 1: Select the Role to Update<\/strong><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Open the Role field and pick the target role, for example POTS User. Leave it blank only when every active role in the tenant must be refreshed.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"298\" src=\"https:\/\/tenthplanet.in\/idempiere\/wp-content\/uploads\/sites\/13\/2026\/07\/TenthPlanet-iDempiere-GeneralRules-RoleAccessUpdate-1-1024x298.png\" alt=\"\" class=\"wp-image-22118\" title=\"\" srcset=\"https:\/\/tenthplanet.in\/idempiere\/wp-content\/uploads\/sites\/13\/2026\/07\/TenthPlanet-iDempiere-GeneralRules-RoleAccessUpdate-1-1024x298.png 1024w, https:\/\/tenthplanet.in\/idempiere\/wp-content\/uploads\/sites\/13\/2026\/07\/TenthPlanet-iDempiere-GeneralRules-RoleAccessUpdate-1-300x87.png 300w, https:\/\/tenthplanet.in\/idempiere\/wp-content\/uploads\/sites\/13\/2026\/07\/TenthPlanet-iDempiere-GeneralRules-RoleAccessUpdate-1-768x224.png 768w, https:\/\/tenthplanet.in\/idempiere\/wp-content\/uploads\/sites\/13\/2026\/07\/TenthPlanet-iDempiere-GeneralRules-RoleAccessUpdate-1-1536x448.png 1536w, https:\/\/tenthplanet.in\/idempiere\/wp-content\/uploads\/sites\/13\/2026\/07\/TenthPlanet-iDempiere-GeneralRules-RoleAccessUpdate-1-2048x597.png 2048w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-table\"><table><thead><tr><td><strong>Field<\/strong><\/td><td><strong>Sample Value<\/strong><\/td><td><strong>Description<\/strong><\/td><\/tr><\/thead><tbody><tr><td>Role<\/td><td>POTS User<\/td><td>Role whose access records will be rebuilt<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>Step 2: Decide Between Reset and Incremental Update<\/strong><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Check Reset Existing Access to delete and recreate every access record for the role. Leave it unchecked to only add missing records and keep current permissions intact.<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table><thead><tr><td><strong>Field<\/strong><\/td><td><strong>Sample Value<\/strong><\/td><td><strong>Description<\/strong><\/td><\/tr><\/thead><tbody><tr><td>Reset Existing Access<\/td><td>Unchecked<\/td><td>Adds missing access without removing current permissions<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>Step 3: Choose Immediate or Scheduled Execution<\/strong><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Check Run as Job to execute the process in the background, or leave it unchecked for a small, single-role update that finishes immediately.<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table><thead><tr><td><strong>Field<\/strong><\/td><td><strong>Sample Value<\/strong><\/td><td><strong>Description<\/strong><\/td><\/tr><\/thead><tbody><tr><td>Run as Job<\/td><td>Unchecked<\/td><td>Executes the process in the background as a scheduled job<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>Step 4: Run the Process and Review the Log<\/strong><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Click Start to execute. Review the process log for the count of windows, forms and reports added per role before closing the window.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>Reference: Access Tables Rebuilt by This Process<\/strong><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Each run inserts only the access records that are missing for the Role, based on the access level derived from its User Level.<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table><thead><tr><td><strong>Access Table<\/strong><\/td><td><strong>Controls<\/strong><\/td><td><strong>Access Level Rule Applied<\/strong><\/td><\/tr><\/thead><tbody><tr><td>AD_Window_Access<\/td><td>Windows available to the role<\/td><td>Matches role&#8217;s access level; excludes &#8220;(all)&#8221; windows for Organization level<\/td><\/tr><tr><td>AD_Process_Access<\/td><td>Processes and reports the role can run<\/td><td>Matches role&#8217;s access level<\/td><\/tr><tr><td>AD_Form_Access<\/td><td>Custom forms the role can open<\/td><td>Matches role&#8217;s access level<\/td><\/tr><tr><td>AD_WorkFlow_Access<\/td><td>Workflows the role can start<\/td><td>Matches role&#8217;s access level<\/td><\/tr><tr><td>AD_Document_Action_Access<\/td><td>Document actions per document type<\/td><td>Applied to every active document type, independent of access level<\/td><\/tr><tr><td>AD_InfoWindow_Access<\/td><td>Info windows the role can query<\/td><td>Matches role&#8217;s access level<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"298\" src=\"https:\/\/tenthplanet.in\/idempiere\/wp-content\/uploads\/sites\/13\/2026\/07\/TenthPlanet-iDempiere-GeneralRules-RoleAccessUpdate-2-1024x298.png\" alt=\"\" class=\"wp-image-22117\" title=\"\" srcset=\"https:\/\/tenthplanet.in\/idempiere\/wp-content\/uploads\/sites\/13\/2026\/07\/TenthPlanet-iDempiere-GeneralRules-RoleAccessUpdate-2-1024x298.png 1024w, https:\/\/tenthplanet.in\/idempiere\/wp-content\/uploads\/sites\/13\/2026\/07\/TenthPlanet-iDempiere-GeneralRules-RoleAccessUpdate-2-300x87.png 300w, https:\/\/tenthplanet.in\/idempiere\/wp-content\/uploads\/sites\/13\/2026\/07\/TenthPlanet-iDempiere-GeneralRules-RoleAccessUpdate-2-768x224.png 768w, https:\/\/tenthplanet.in\/idempiere\/wp-content\/uploads\/sites\/13\/2026\/07\/TenthPlanet-iDempiere-GeneralRules-RoleAccessUpdate-2-1536x448.png 1536w, https:\/\/tenthplanet.in\/idempiere\/wp-content\/uploads\/sites\/13\/2026\/07\/TenthPlanet-iDempiere-GeneralRules-RoleAccessUpdate-2-2048x597.png 2048w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">the records inserted is determined by the access level of the user<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table><thead><tr><th>User Level<\/th><th>Allowed Access Levels<\/th><th>Typical Purpose<\/th><\/tr><\/thead><tbody><tr><td><strong>System<\/strong><\/td><td><code>4<\/code>, <code>6<\/code>, <code>7<\/code><\/td><td>Application dictionary and global system administration<\/td><\/tr><tr><td><strong>Client<\/strong><\/td><td><code>2<\/code>, <code>3<\/code>, <code>6<\/code>, <code>7<\/code><\/td><td>Tenant-wide administration and business configuration<\/td><\/tr><tr><td><strong>Client + Organization<\/strong><\/td><td><code>1<\/code>, <code>2<\/code>, <code>3<\/code>, <code>6<\/code>, <code>7<\/code><\/td><td>Most business users and client administrators<\/td><\/tr><tr><td><strong>Organization<\/strong><\/td><td><code>1<\/code>, <code>3<\/code>, <code>7<\/code><\/td><td>Day-to-day operational users within one organization<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Common Issues and Resolutions<\/strong><\/h2>\n\n\n\n<figure class=\"wp-block-table\"><table><thead><tr><td><strong>Issue<\/strong><\/td><td><strong>Cause<\/strong><\/td><td><strong>Resolution<\/strong><\/td><\/tr><\/thead><tbody><tr><td>Process updates roles across every tenant<\/td><td>Role left blank while logged in as System Administrator<\/td><td>Select a specific Role or switch to the retail tenant first<\/td><\/tr><tr><td>Role permissions do not change after running<\/td><td>Role is marked as Manual access<\/td><td>Uncheck Manual on the Role or update access by hand<\/td><\/tr><tr><td>Duplicate or stale access records appear<\/td><td>Process run repeatedly without resetting<\/td><td>Run once with Reset Existing Access checked to clean up<\/td><\/tr><tr><td>Only the System role gets updated<\/td><td>Known behavior when run as System Administrator with no Role set<\/td><td>Expected result; select the correct tenant and role explicitly<\/td><\/tr><tr><td>Selected role gets no updates at all<\/td><td>Role is marked as Manual access, so the process exits immediately<\/td><td>Uncheck Manual on the Role if automatic access is required<\/td><\/tr><tr><td>Organization-level role is missing store-wide windows<\/td><td>Windows named with &#8220;(all)&#8221; are excluded for Organization-level roles by design<\/td><td>Use a Client or Client+Organization level role for store-wide windows<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Next Steps<\/strong><\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Configure the Role window with the required window, process and report access.<\/li>\n\n\n\n<li>Assign updated Roles to Users in the User window.<\/li>\n\n\n\n<li>Review Organization Access and Login Preferences for affected users.<\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>The Role Access Update window in iDempiere rebuilds access records that control which windows, forms, processes and reports a role [&hellip;]<\/p>\n","protected":false},"author":3,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[10,91],"tags":[],"class_list":["post-22107","post","type-post","status-publish","format-standard","hentry","category-idempiere-product","category-idempiere-general-rules"],"_links":{"self":[{"href":"https:\/\/tenthplanet.in\/idempiere\/wp-json\/wp\/v2\/posts\/22107","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/tenthplanet.in\/idempiere\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/tenthplanet.in\/idempiere\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/tenthplanet.in\/idempiere\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/tenthplanet.in\/idempiere\/wp-json\/wp\/v2\/comments?post=22107"}],"version-history":[{"count":6,"href":"https:\/\/tenthplanet.in\/idempiere\/wp-json\/wp\/v2\/posts\/22107\/revisions"}],"predecessor-version":[{"id":22591,"href":"https:\/\/tenthplanet.in\/idempiere\/wp-json\/wp\/v2\/posts\/22107\/revisions\/22591"}],"wp:attachment":[{"href":"https:\/\/tenthplanet.in\/idempiere\/wp-json\/wp\/v2\/media?parent=22107"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/tenthplanet.in\/idempiere\/wp-json\/wp\/v2\/categories?post=22107"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/tenthplanet.in\/idempiere\/wp-json\/wp\/v2\/tags?post=22107"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}