{"id":22129,"date":"2026-08-03T11:46:39","date_gmt":"2026-08-03T11:46:39","guid":{"rendered":"https:\/\/tenthplanet.in\/idempiere\/?p=22129"},"modified":"2026-08-13T04:50:20","modified_gmt":"2026-08-13T04:50:20","slug":"how-to-review-the-all-role-window-in-idempiere","status":"publish","type":"post","link":"https:\/\/tenthplanet.in\/idempiere\/how-to-review-the-all-role-window-in-idempiere\/","title":{"rendered":"How to Review the All Role Window in iDempiere"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">The Role window in iDempiere defines the security profile assigned to every user, controlling what data, organizations, and functions they can access.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Because this window is read-only for users, it is primarily used to review existing role configurations before assigning them, ensuring transactions, reports, and accounting data stay properly restricted.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Process Flow<\/strong><\/h2>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"446\" src=\"https:\/\/tenthplanet.in\/idempiere\/wp-content\/uploads\/sites\/13\/2026\/07\/TenthPlanet-iDempeire-GeneralRules-AllRoles-1024x446.png\" alt=\"\" class=\"wp-image-22131\" title=\"\" srcset=\"https:\/\/tenthplanet.in\/idempiere\/wp-content\/uploads\/sites\/13\/2026\/07\/TenthPlanet-iDempeire-GeneralRules-AllRoles-1024x446.png 1024w, https:\/\/tenthplanet.in\/idempiere\/wp-content\/uploads\/sites\/13\/2026\/07\/TenthPlanet-iDempeire-GeneralRules-AllRoles-300x131.png 300w, https:\/\/tenthplanet.in\/idempiere\/wp-content\/uploads\/sites\/13\/2026\/07\/TenthPlanet-iDempeire-GeneralRules-AllRoles-768x335.png 768w, https:\/\/tenthplanet.in\/idempiere\/wp-content\/uploads\/sites\/13\/2026\/07\/TenthPlanet-iDempeire-GeneralRules-AllRoles-1536x669.png 1536w, https:\/\/tenthplanet.in\/idempiere\/wp-content\/uploads\/sites\/13\/2026\/07\/TenthPlanet-iDempeire-GeneralRules-AllRoles-2048x892.png 2048w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Business Rules<\/strong><\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Only Active roles can be assigned to users for login.<\/li>\n\n\n\n<li>User Level determines whether a role sees System, Client, or Organization data.<\/li>\n\n\n\n<li>Client+Organization level restricts a role to its assigned store only.<\/li>\n\n\n\n<li>Can Export controls whether a role may extract data to file.<\/li>\n\n\n\n<li>Can Report controls whether a role may run standard reports.<\/li>\n\n\n\n<li>Show Accounting controls visibility of GL and financial postings.<\/li>\n\n\n\n<li>Access all Orgs allows a role to view data across multiple stores.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Prerequisites<\/strong><\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Tenant (Client) configured for the retail business.<\/li>\n\n\n\n<li>Organization or store record configured.<\/li>\n\n\n\n<li>User accounts created in the User window.<\/li>\n\n\n\n<li>Org Access and Document Action Access reviewed for each role.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Navigation<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Menu \u2192 General Rules \u2192 Security \u2192 Role<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Configuration Steps<\/strong><\/h2>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>Step 1: Review Tenant and Name Fields<\/strong><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Check the Tenant (All) and Name fields, e.g., &#8216;POTS&#8217; and &#8216;POTS Admin&#8217;, match the intended store or business unit.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"249\" src=\"https:\/\/tenthplanet.in\/idempiere\/wp-content\/uploads\/sites\/13\/2026\/07\/TenthPlanet-iDempiere-AllRoles-1024x249.png\" alt=\"\" class=\"wp-image-22132\" title=\"\" srcset=\"https:\/\/tenthplanet.in\/idempiere\/wp-content\/uploads\/sites\/13\/2026\/07\/TenthPlanet-iDempiere-AllRoles-1024x249.png 1024w, https:\/\/tenthplanet.in\/idempiere\/wp-content\/uploads\/sites\/13\/2026\/07\/TenthPlanet-iDempiere-AllRoles-300x73.png 300w, https:\/\/tenthplanet.in\/idempiere\/wp-content\/uploads\/sites\/13\/2026\/07\/TenthPlanet-iDempiere-AllRoles-768x187.png 768w, https:\/\/tenthplanet.in\/idempiere\/wp-content\/uploads\/sites\/13\/2026\/07\/TenthPlanet-iDempiere-AllRoles.png 1453w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>Step 2: Verify User Level and Preference Level<\/strong><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Confirm User Level matches the intended scope (e.g., Client+Organization for store-level roles) and Preference Level is set correctly.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>Step 3: Check Function Permission Checkboxes<\/strong><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Review Can Export, Can Report, Show Accounting, and Access Advanced to confirm they match the role&#8217;s intended responsibilities.<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table><thead><tr><td><strong>Field<\/strong><\/td><td><strong>Sample Value<\/strong><\/td><td><strong>Description<\/strong><\/td><\/tr><\/thead><tbody><tr><td>Tenant (All)<\/td><td>POTS<\/td><td>Client\/tenant the role belongs to<\/td><\/tr><tr><td>Name<\/td><td>POTS Admin<\/td><td>Role display name shown at login<\/td><\/tr><tr><td>User Level<\/td><td>Client+Organization<\/td><td>Defines System, Client, or Organization data scope<\/td><\/tr><tr><td>Preference Level<\/td><td>Client<\/td><td>Level at which user preferences and defaults apply<\/td><\/tr><tr><td>Can Export<\/td><td>Checked<\/td><td>Allows exporting grid data to file<\/td><\/tr><tr><td>Can Report<\/td><td>Checked<\/td><td>Allows running standard reports<\/td><\/tr><tr><td>Show Accounting<\/td><td>Checked<\/td><td>Allows viewing GL and accounting facts<\/td><\/tr><tr><td>Access Advanced<\/td><td>Checked<\/td><td>Enables access to advanced tabs and fields<\/td><\/tr><tr><td>Active<\/td><td>Checked<\/td><td>Role is enabled and assignable to users<\/td><\/tr><tr><td>Role Type<\/td><td>Blank<\/td><td>Optional classification, e.g., Manager, Cashier<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>Step 4: Confirm Active Status<\/strong><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Verify the Active checkbox is ticked for any role currently in use by store staff.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>Step 5: Cross-check Role Type for Store Assignment<\/strong><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Confirm Role Type is set consistently so store onboarding staff can assign the correct role without confusion.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Common Issues and Resolutions<\/strong><\/h2>\n\n\n\n<figure class=\"wp-block-table\"><table><thead><tr><td><strong>Issue<\/strong><\/td><td><strong>Cause<\/strong><\/td><td><strong>Resolution<\/strong><\/td><\/tr><\/thead><tbody><tr><td>Role not available at login<\/td><td>Active checkbox unticked<\/td><td>Activate the role in the Role window<\/td><\/tr><tr><td>User sees data from other stores<\/td><td>Access all Orgs enabled<\/td><td>Disable Access all Orgs for store-level roles<\/td><\/tr><tr><td>Staff cannot export reports<\/td><td>Can Export unchecked<\/td><td>Enable Can Export for the role<\/td><\/tr><tr><td>Role changes not applied to user<\/td><td>Active session cached old role<\/td><td>Ask user to log out and log back in<\/td><\/tr><tr><td>Duplicate or unclear role names<\/td><td>No naming convention used<\/td><td>Standardize names, e.g., Store-Cashier, Store-Manager<\/td><\/tr><tr><td>New store staff cannot access org data<\/td><td>Organization missing from role access<\/td><td>Add the organization in the Org Access tab<\/td><\/tr><tr><td>Inconsistent report results between roles<\/td><td>Different Preference Level settings<\/td><td>Align Preference Level across similar roles<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Next Steps<\/strong><\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Configure User window to assign reviewed roles to staff.<\/li>\n\n\n\n<li>Set up Org Access tab for store-specific data restrictions.<\/li>\n\n\n\n<li>Review Document Action Access for transaction-level permissions.<\/li>\n\n\n\n<li>Configure Client Info for tenant-wide retail settings.<\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>The Role window in iDempiere defines the security profile assigned to every user, controlling what data, organizations, and functions they [&hellip;]<\/p>\n","protected":false},"author":3,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[91,10],"tags":[],"class_list":["post-22129","post","type-post","status-publish","format-standard","hentry","category-idempiere-general-rules","category-idempiere-product"],"_links":{"self":[{"href":"https:\/\/tenthplanet.in\/idempiere\/wp-json\/wp\/v2\/posts\/22129","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/tenthplanet.in\/idempiere\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/tenthplanet.in\/idempiere\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/tenthplanet.in\/idempiere\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/tenthplanet.in\/idempiere\/wp-json\/wp\/v2\/comments?post=22129"}],"version-history":[{"count":2,"href":"https:\/\/tenthplanet.in\/idempiere\/wp-json\/wp\/v2\/posts\/22129\/revisions"}],"predecessor-version":[{"id":22133,"href":"https:\/\/tenthplanet.in\/idempiere\/wp-json\/wp\/v2\/posts\/22129\/revisions\/22133"}],"wp:attachment":[{"href":"https:\/\/tenthplanet.in\/idempiere\/wp-json\/wp\/v2\/media?parent=22129"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/tenthplanet.in\/idempiere\/wp-json\/wp\/v2\/categories?post=22129"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/tenthplanet.in\/idempiere\/wp-json\/wp\/v2\/tags?post=22129"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}