{"id":22122,"date":"2026-08-03T11:46:58","date_gmt":"2026-08-03T11:46:58","guid":{"rendered":"https:\/\/tenthplanet.in\/idempiere\/?p=22122"},"modified":"2026-08-13T04:50:19","modified_gmt":"2026-08-13T04:50:19","slug":"how-to-use-all-user-roles-in-idempiere","status":"publish","type":"post","link":"https:\/\/tenthplanet.in\/idempiere\/how-to-use-all-user-roles-in-idempiere\/","title":{"rendered":"How to Use All User Roles in iDempiere"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">The User Roles window defines the security and access level for every iDempiere user in a retail deployment. It controls what stores, functions, and financial data staff such as cashiers, store admins, and regional managers can access.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Process Flow<\/strong><\/h2>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"230\" src=\"https:\/\/tenthplanet.in\/idempiere\/wp-content\/uploads\/sites\/13\/2026\/07\/TenthPlanet-iDempiere-AllUserRoles-1024x230.png\" alt=\"\" class=\"wp-image-22124\" title=\"\" srcset=\"https:\/\/tenthplanet.in\/idempiere\/wp-content\/uploads\/sites\/13\/2026\/07\/TenthPlanet-iDempiere-AllUserRoles-1024x230.png 1024w, https:\/\/tenthplanet.in\/idempiere\/wp-content\/uploads\/sites\/13\/2026\/07\/TenthPlanet-iDempiere-AllUserRoles-300x67.png 300w, https:\/\/tenthplanet.in\/idempiere\/wp-content\/uploads\/sites\/13\/2026\/07\/TenthPlanet-iDempiere-AllUserRoles-768x172.png 768w, https:\/\/tenthplanet.in\/idempiere\/wp-content\/uploads\/sites\/13\/2026\/07\/TenthPlanet-iDempiere-AllUserRoles.png 1523w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Business Rules<\/strong><\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Only Active roles can be assigned to users for system login.<\/li>\n\n\n\n<li>User Level determines access scope: Client, Organization, or Client+Organization.<\/li>\n\n\n\n<li>Can Export and Can Report control data extraction and report visibility per role.<\/li>\n\n\n\n<li>Show Accounting restricts financial ledger data to authorized roles only.<\/li>\n\n\n\n<li>Access Advanced exposes advanced configuration windows to selected roles.<\/li>\n\n\n\n<li>Personal Lock and Personal Access restrict records to the creating user.<\/li>\n\n\n\n<li>Preference Level controls whether user preferences apply at Client, Org, or User scope.<\/li>\n\n\n\n<li>Access all Orgs grants a role visibility across every store organization.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Prerequisites<\/strong><\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Tenant (Client) configured, e.g. POTS.<\/li>\n\n\n\n<li>Organization(s) representing stores or regions configured.<\/li>\n\n\n\n<li>System Users created and available for role assignment.<\/li>\n\n\n\n<li>Org structure and Business Partner setup completed for scoping access.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Navigation<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Menu \u2192 General Rules \u2192 Security \u2192 All User Role<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Configuration Steps<\/strong><\/h2>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>Step 1: Define Role Identity<\/strong><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Enter a descriptive Name (e.g. Store Cashier) and an optional Description explaining the role&#8217;s intended use.<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table><thead><tr><td><strong>Field<\/strong><\/td><td><strong>Sample Value<\/strong><\/td><td><strong>Description<\/strong><\/td><\/tr><\/thead><tbody><tr><td>Name<\/td><td>POTS Admin<\/td><td>Identifies the role for assignment to users<\/td><\/tr><tr><td>Description<\/td><td>(optional)<\/td><td>Explains the intended purpose of the role<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"456\" src=\"https:\/\/tenthplanet.in\/idempiere\/wp-content\/uploads\/sites\/13\/2026\/07\/TenthPlanet-iDempiere-GeneralRules-AllUserRoles-1024x456.png\" alt=\"\" class=\"wp-image-22126\" title=\"\" srcset=\"https:\/\/tenthplanet.in\/idempiere\/wp-content\/uploads\/sites\/13\/2026\/07\/TenthPlanet-iDempiere-GeneralRules-AllUserRoles-1024x456.png 1024w, https:\/\/tenthplanet.in\/idempiere\/wp-content\/uploads\/sites\/13\/2026\/07\/TenthPlanet-iDempiere-GeneralRules-AllUserRoles-300x134.png 300w, https:\/\/tenthplanet.in\/idempiere\/wp-content\/uploads\/sites\/13\/2026\/07\/TenthPlanet-iDempiere-GeneralRules-AllUserRoles-768x342.png 768w, https:\/\/tenthplanet.in\/idempiere\/wp-content\/uploads\/sites\/13\/2026\/07\/TenthPlanet-iDempiere-GeneralRules-AllUserRoles-1536x684.png 1536w, https:\/\/tenthplanet.in\/idempiere\/wp-content\/uploads\/sites\/13\/2026\/07\/TenthPlanet-iDempiere-GeneralRules-AllUserRoles-2048x912.png 2048w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>Step 2: Set User Level and Scope<\/strong><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Select the appropriate User Level for the role and set the Preference Level to control where saved preferences apply.<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table><thead><tr><td><strong>Field<\/strong><\/td><td><strong>Sample Value<\/strong><\/td><td><strong>Description<\/strong><\/td><\/tr><\/thead><tbody><tr><td>User Level<\/td><td>Client+Organization<\/td><td>Role can operate at both chain and store level<\/td><\/tr><tr><td>Preference Level<\/td><td>Client<\/td><td>User preferences saved apply chain-wide<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>Step 3: Configure Access Permissions<\/strong><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Enable only the checkboxes required for the role&#8217;s function. Leave sensitive options like Show Accounting unchecked for store-floor staff.<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table><thead><tr><td><strong>Field<\/strong><\/td><td><strong>Sample Value<\/strong><\/td><td><strong>Description<\/strong><\/td><\/tr><\/thead><tbody><tr><td>Manual<\/td><td>Unchecked<\/td><td>Role is not manually maintained outside templates<\/td><\/tr><tr><td>Role Template<\/td><td>Unchecked<\/td><td>Role is not used as a template for other roles<\/td><\/tr><tr><td>Access all Orgs<\/td><td>Unchecked<\/td><td>Restricts visibility to assigned organizations only<\/td><\/tr><tr><td>Use User Org Access<\/td><td>Unchecked<\/td><td>Org access follows role, not individual user<\/td><\/tr><tr><td>Can Export<\/td><td>Checked<\/td><td>Allows the role to export data<\/td><\/tr><tr><td>Can Report<\/td><td>Checked<\/td><td>Allows the role to run and view reports<\/td><\/tr><tr><td>Show Accounting<\/td><td>Checked<\/td><td>Allows the role to view accounting\/financial data<\/td><\/tr><tr><td>Personal Lock<\/td><td>Unchecked<\/td><td>Records are not locked to the creating user<\/td><\/tr><tr><td>Personal Access<\/td><td>Unchecked<\/td><td>Records are not restricted to the creating user<\/td><\/tr><tr><td>Access Advanced<\/td><td>Checked<\/td><td>Grants access to advanced configuration windows<\/td><\/tr><tr><td>Maintain Change Log<\/td><td>Unchecked<\/td><td>Change log tracking is not enforced for this role<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>Step 4: Set Role Type<\/strong><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Leave Role Type blank unless the organization uses role classification for reporting.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>Step 5: Activate the Role<\/strong><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Check the Active box, then save the record to make the role available for user assignment.<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table><thead><tr><td><strong>Field<\/strong><\/td><td><strong>Sample Value<\/strong><\/td><td><strong>Description<\/strong><\/td><\/tr><\/thead><tbody><tr><td>Active<\/td><td>Checked<\/td><td>Enables the role for assignment and login<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Common Issues and Resolutions<\/strong><\/h2>\n\n\n\n<figure class=\"wp-block-table\"><table><thead><tr><td><strong>Issue<\/strong><\/td><td><strong>Cause<\/strong><\/td><td><strong>Resolution<\/strong><\/td><\/tr><\/thead><tbody><tr><td>User cannot log in with assigned role<\/td><td>Role marked inactive<\/td><td>Activate the role record and save<\/td><\/tr><tr><td>Staff can view other stores&#8217; data<\/td><td>Access all Orgs enabled incorrectly<\/td><td>Disable Access all Orgs; restrict via Org Access tab<\/td><\/tr><tr><td>Cashier can view accounting reports<\/td><td>Show Accounting checked for cashier role<\/td><td>Uncheck Show Accounting for non-finance roles<\/td><\/tr><tr><td>Export button missing for manager<\/td><td>Can Export not enabled<\/td><td>Enable the Can Export checkbox and save<\/td><\/tr><tr><td>User preferences not saved per store<\/td><td>Preference Level set to Client<\/td><td>Change Preference Level to Organization<\/td><\/tr><tr><td>Role changes not reflected for user<\/td><td>Cached role session in browser<\/td><td>Ask the user to log out and log back in<\/td><\/tr><tr><td>New windows not visible after update<\/td><td>Menu or window access not granted<\/td><td>Grant window access via the role&#8217;s Window Access tab<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Next Steps<\/strong><\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Configure Org Access, Window Access, and Process Access tabs for the role.<\/li>\n\n\n\n<li>Assign the completed role to Users via the User window.<\/li>\n\n\n\n<li>Set up Document Type access per role for POS transactions.<\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>The User Roles window defines the security and access level for every iDempiere user in a retail deployment. It controls [&hellip;]<\/p>\n","protected":false},"author":3,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[91,10],"tags":[],"class_list":["post-22122","post","type-post","status-publish","format-standard","hentry","category-idempiere-general-rules","category-idempiere-product"],"_links":{"self":[{"href":"https:\/\/tenthplanet.in\/idempiere\/wp-json\/wp\/v2\/posts\/22122","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/tenthplanet.in\/idempiere\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/tenthplanet.in\/idempiere\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/tenthplanet.in\/idempiere\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/tenthplanet.in\/idempiere\/wp-json\/wp\/v2\/comments?post=22122"}],"version-history":[{"count":5,"href":"https:\/\/tenthplanet.in\/idempiere\/wp-json\/wp\/v2\/posts\/22122\/revisions"}],"predecessor-version":[{"id":27132,"href":"https:\/\/tenthplanet.in\/idempiere\/wp-json\/wp\/v2\/posts\/22122\/revisions\/27132"}],"wp:attachment":[{"href":"https:\/\/tenthplanet.in\/idempiere\/wp-json\/wp\/v2\/media?parent=22122"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/tenthplanet.in\/idempiere\/wp-json\/wp\/v2\/categories?post=22122"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/tenthplanet.in\/idempiere\/wp-json\/wp\/v2\/tags?post=22122"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}