{"id":22171,"date":"2026-07-28T06:41:25","date_gmt":"2026-07-28T06:41:25","guid":{"rendered":"https:\/\/tenthplanet.in\/idempiere\/?p=22171"},"modified":"2026-08-13T04:51:05","modified_gmt":"2026-08-13T04:51:05","slug":"how-role-data-access-window-works-in-idempiere","status":"publish","type":"post","link":"https:\/\/tenthplanet.in\/idempiere\/how-role-data-access-window-works-in-idempiere\/","title":{"rendered":"How Role Data Access Window Works in iDempiere"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\"><strong>Introduction<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The Role Data Access window lets an administrator fine-tune what a specific Role can see or change, going beyond the general access already granted through the Role and Organization setup.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">It is used in System Administration, whenever a business needs a role restricted on a particular table, a single field, or a single record, instead of an entire window or menu.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">These rules directly affect daily transactions and reporting, because a restricted role will not be able to view, edit, or report on the data covered by the rule.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Process Flow<\/strong><\/h2>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"170\" src=\"https:\/\/tenthplanet.in\/idempiere\/wp-content\/uploads\/sites\/13\/2026\/07\/Role-Data-Access.drawio-1024x170.png\" alt=\"TenthPlanet-iDempiere-SystemAdimin-RoleDataAccess-ProcessFlow\" class=\"wp-image-22256\" title=\"\" srcset=\"https:\/\/tenthplanet.in\/idempiere\/wp-content\/uploads\/sites\/13\/2026\/07\/Role-Data-Access.drawio-1024x170.png 1024w, https:\/\/tenthplanet.in\/idempiere\/wp-content\/uploads\/sites\/13\/2026\/07\/Role-Data-Access.drawio-300x50.png 300w, https:\/\/tenthplanet.in\/idempiere\/wp-content\/uploads\/sites\/13\/2026\/07\/Role-Data-Access.drawio-768x127.png 768w, https:\/\/tenthplanet.in\/idempiere\/wp-content\/uploads\/sites\/13\/2026\/07\/Role-Data-Access.drawio-1536x255.png 1536w, https:\/\/tenthplanet.in\/idempiere\/wp-content\/uploads\/sites\/13\/2026\/07\/Role-Data-Access.drawio-2048x340.png 2048w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Business Rules<\/strong><\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Rules set here apply only to the specific Role selected, not to every role in the tenant.<\/li>\n\n\n\n<li>A Table Access rule works together with, and can further limit, the role&#8217;s standard access level.<\/li>\n\n\n\n<li>Include with Read Only means the role can view the table but cannot add or change records.<\/li>\n\n\n\n<li>Exclude with Read Only removes edit rights while the role can still view the data.<\/li>\n\n\n\n<li>Exclude without Read Only removes both view and edit rights to the table.<\/li>\n\n\n\n<li>Column Access rules hide or restrict one field without restricting the whole table.<\/li>\n\n\n\n<li>Record Access rules apply to individual records, most often created through the Lock feature.<\/li>\n\n\n\n<li>Role details shown at the top of this window are for reference only and cannot be edited here.<\/li>\n\n\n\n<li>Access changes are cached, so affected users must log out and log back in to see the change.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Prerequisites<\/strong><\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Role already created and saved in the Role window.<\/li>\n\n\n\n<li>Organization and Client setup completed for the tenant.<\/li>\n\n\n\n<li>Table, Column, and Window entries available in the Application Dictionary.<\/li>\n\n\n\n<li>Login using System Administrator, or a role with System Admin menu access.<\/li>\n\n\n\n<li>Records to be restricted already exist, if Record Access is being configured.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Navigation<\/strong><\/h2>\n\n\n\n<pre class=\"wp-block-code\" style=\"font-size:15px\"><code><strong>Menu \u2192 System Admin \u2192 General Rules \u2192 Security \u2192 Role Data Access<\/strong><\/code><\/pre>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"485\" src=\"https:\/\/tenthplanet.in\/idempiere\/wp-content\/uploads\/sites\/13\/2026\/07\/TenthPlanet-iDempiere-SystemAdimin-RoleDataAccess-1-1024x485.png\" alt=\"TenthPlanet-iDempiere-SystemAdimin-RoleDataAccess-1\" class=\"wp-image-22258\" title=\"\" srcset=\"https:\/\/tenthplanet.in\/idempiere\/wp-content\/uploads\/sites\/13\/2026\/07\/TenthPlanet-iDempiere-SystemAdimin-RoleDataAccess-1-1024x485.png 1024w, https:\/\/tenthplanet.in\/idempiere\/wp-content\/uploads\/sites\/13\/2026\/07\/TenthPlanet-iDempiere-SystemAdimin-RoleDataAccess-1-300x142.png 300w, https:\/\/tenthplanet.in\/idempiere\/wp-content\/uploads\/sites\/13\/2026\/07\/TenthPlanet-iDempiere-SystemAdimin-RoleDataAccess-1-768x364.png 768w, https:\/\/tenthplanet.in\/idempiere\/wp-content\/uploads\/sites\/13\/2026\/07\/TenthPlanet-iDempiere-SystemAdimin-RoleDataAccess-1-1536x728.png 1536w, https:\/\/tenthplanet.in\/idempiere\/wp-content\/uploads\/sites\/13\/2026\/07\/TenthPlanet-iDempiere-SystemAdimin-RoleDataAccess-1-2048x970.png 2048w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><br>Opening the window shows the selected Role&#8217;s details at the top of the screen, displayed for reference only. Below this, three tabs appear: Table Access, Column Access, and Record Access, where the actual restriction rules are added, reviewed, or removed.<\/p>\n\n\n\n<pre class=\"wp-block-code\" style=\"font-size:15px\"><code><strong>Note:<\/strong> The Role panel at the top of this window is read-only by design, for every role that opens it, including System Administrator. Role details such as name and preference level are maintained in the separate Role window, not here.<\/code><\/pre>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"746\" src=\"https:\/\/tenthplanet.in\/idempiere\/wp-content\/uploads\/sites\/13\/2026\/07\/TenthPlanet-iDempiere-SystemAdimin-RoleDataAccess-2-1024x746.png\" alt=\"TenthPlanet-iDempiere-SystemAdimin-RoleDataAccess-2\" class=\"wp-image-22259\" title=\"\" srcset=\"https:\/\/tenthplanet.in\/idempiere\/wp-content\/uploads\/sites\/13\/2026\/07\/TenthPlanet-iDempiere-SystemAdimin-RoleDataAccess-2-1024x746.png 1024w, https:\/\/tenthplanet.in\/idempiere\/wp-content\/uploads\/sites\/13\/2026\/07\/TenthPlanet-iDempiere-SystemAdimin-RoleDataAccess-2-300x219.png 300w, https:\/\/tenthplanet.in\/idempiere\/wp-content\/uploads\/sites\/13\/2026\/07\/TenthPlanet-iDempiere-SystemAdimin-RoleDataAccess-2-768x560.png 768w, https:\/\/tenthplanet.in\/idempiere\/wp-content\/uploads\/sites\/13\/2026\/07\/TenthPlanet-iDempiere-SystemAdimin-RoleDataAccess-2-1536x1119.png 1536w, https:\/\/tenthplanet.in\/idempiere\/wp-content\/uploads\/sites\/13\/2026\/07\/TenthPlanet-iDempiere-SystemAdimin-RoleDataAccess-2-2048x1492.png 2048w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Configuration Steps<\/strong><\/h2>\n\n\n\n<h3 class=\"wp-block-heading\"><strong><strong>Step 1: Select the Role to Restrict<\/strong><\/strong><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Every rule created in this window applies to one Role at a time, so the correct role must be selected before any restriction is added.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>Instructions<\/strong><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Use Select Query or the navigation arrows to open the target Role, for example POTS Admin. Confirm the correct Tenant and Organization appear before proceeding.<\/p>\n\n\n\n<figure class=\"wp-block-table is-style-stripes\"><table><thead><tr><td><strong>Field<\/strong><\/td><td><strong>Sample Value<\/strong><\/td><td><strong>Description<\/strong><\/td><\/tr><\/thead><tbody><tr><td>Tenant<\/td><td>POTS<\/td><td>Business entity the role belongs to.<\/td><\/tr><tr><td>Organization<\/td><td>*<\/td><td>Organization scope; * means all organizations.<\/td><\/tr><tr><td>Name<\/td><td>POTS Admin<\/td><td>Role being restricted.<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\"><strong><strong>Step 2: Review the Role Reference Panel<\/strong><\/strong><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Before adding rules, confirm the role&#8217;s existing permission flags, since these settings affect how far a new restriction reaches.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>Instructions<\/strong><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Check flags such as Show Accounting, Can Report, Can Export, and Access all Orgs. These fields are read-only here and must be changed in the Role window instead.<\/p>\n\n\n\n<figure class=\"wp-block-table is-style-stripes\"><table><thead><tr><td><strong>Field<\/strong><\/td><td><strong>Sample Value<\/strong><\/td><td><strong>Description<\/strong><\/td><\/tr><\/thead><tbody><tr><td>Preference Level<\/td><td>Client<\/td><td>Level at which preference values apply for this role.<\/td><\/tr><tr><td>Access all Orgs<\/td><td>Unchecked<\/td><td>Whether the role can see every organization.<\/td><\/tr><tr><td>Can Export<\/td><td>Checked<\/td><td>Whether the role is allowed to export data.<\/td><\/tr><tr><td>Can Report<\/td><td>Checked<\/td><td>Whether the role is allowed to run reports.<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\"><strong><strong>Step 3: Restrict Table Access<\/strong><\/strong><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Table Access rules stop a role from viewing or changing an entire table, useful when a role should never touch sensitive information such as costing or payroll data.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>Instructions<\/strong><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Open the Table Access tab, click the New Record icon, choose the Table, mark Active, and set Exclude or Read Only depending on the level of restriction needed. Save the record.<\/p>\n\n\n\n<figure class=\"wp-block-table is-style-stripes\"><table><thead><tr><td><strong>Field<\/strong><\/td><td><strong>Sample Value<\/strong><\/td><td><strong>Purpose<\/strong><\/td><\/tr><\/thead><tbody><tr><td>Table<\/td><td>M_Product<\/td><td>Table the rule applies to.<\/td><\/tr><tr><td>Active<\/td><td>Checked<\/td><td>Enables the rule immediately.<\/td><\/tr><tr><td>Exclude<\/td><td>Checked<\/td><td>Removes access instead of granting it.<\/td><\/tr><tr><td>Read Only<\/td><td>Checked<\/td><td>Allows viewing without allowing edits.<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\"><strong><strong>Step 4: Restrict Column Access<\/strong><\/strong><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Column Access rules hide or lock a single field, useful when only one piece of information, such as a cost or margin field, needs to stay hidden from a role.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>Instructions<\/strong><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Open the Column Access tab, click the New Record icon, select the Table and the specific Column, then mark Exclude or Read Only as required. Save the record.<\/p>\n\n\n\n<figure class=\"wp-block-table is-style-stripes\"><table><thead><tr><td><strong>Field<\/strong><\/td><td><strong>Sample Value<\/strong><\/td><td><strong>Purpose<\/strong><\/td><\/tr><\/thead><tbody><tr><td>Table<\/td><td>M_Product<\/td><td>Table that owns the restricted column.<\/td><\/tr><tr><td>Column<\/td><td>PriceCost<\/td><td>Specific field being restricted.<\/td><\/tr><tr><td>Read Only<\/td><td>Checked<\/td><td>Column stays visible but cannot be edited.<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>Step 5: Restrict Record Access<\/strong><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Record Access rules restrict a single record rather than a whole table, commonly used to keep one sensitive document private to certain roles.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>Instructions<\/strong><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Open the record to restrict, use the Lock toolbar button while holding Ctrl to create a Record Access entry, then confirm the entry under the Record Access tab for the selected role.<\/p>\n\n\n\n<figure class=\"wp-block-table is-style-stripes\"><table><thead><tr><td><strong>Field<\/strong><\/td><td><strong>Sample Value<\/strong><\/td><td><strong>Purpose<\/strong><\/td><\/tr><\/thead><tbody><tr><td>Table<\/td><td>C_Invoice<\/td><td>Table that owns the locked record.<\/td><\/tr><tr><td>Record<\/td><td>Invoice 1000123<\/td><td>Specific record being restricted.<\/td><\/tr><tr><td>Exclude<\/td><td>Checked<\/td><td>Removes this role&#8217;s access to the record.<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>Step 6: Apply the Changes<\/strong><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">New or changed rules do not affect an active session immediately, since role access information is cached for performance.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>Instructions<\/strong><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Ask affected users to log out and log back in, or reset the cache from System Administration, then confirm the restriction behaves as expected.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong><strong>Common Issues and Resolutions<\/strong><\/strong><\/h2>\n\n\n\n<figure class=\"wp-block-table is-style-stripes\"><table><thead><tr><td><strong>Issue<\/strong><\/td><td><strong>Cause<\/strong><\/td><td><strong>Resolution<\/strong><\/td><\/tr><\/thead><tbody><tr><td>Restriction not taking effect<\/td><td>Access information is cached<\/td><td>Log out and log back in, or reset the cache from System Administration.<\/td><\/tr><tr><td>Role panel fields cannot be edited<\/td><td>Role tab in this window is read-only by design<\/td><td>Edit role details, such as name or flags, in the Role window instead.<\/td><\/tr><tr><td>Role suddenly loses access to related windows<\/td><td>Include rule was added without its supporting tables<\/td><td>Add the related supporting tables, or restrict access using functionality instead of Include rules.<\/td><\/tr><tr><td>Record Access entry not created<\/td><td>Lock button was used without holding Ctrl<\/td><td>Hold Ctrl while clicking Lock to generate a Record Access entry for the role.<\/td><\/tr><tr><td>Restricted table still reachable<\/td><td>User navigated using the Zoom function<\/td><td>Add a Table Access rule here, since menu removal alone does not block data access.<\/td><\/tr><tr><td>Column still visible in a print or export<\/td><td>Column Access rule not linked to that report<\/td><td>Check whether the report or process reads the column directly and restrict it separately if needed.<\/td><\/tr><tr><td>Read Only not enforced on a record<\/td><td>A broader Table Access rule overrides the record rule<\/td><td>Review Table Access and Record Access together, since table-level rules are evaluated first.<\/td><\/tr><tr><td>Wrong role restricted<\/td><td>Similar role names in the same tenant<\/td><td>Confirm Tenant, Organization, and Role name before saving any new rule.<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Next Steps<\/strong><\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Review the Role window to manage menu access and organization access.<\/li>\n\n\n\n<li>Check Table Access levels defined at the system level for each table.<\/li>\n\n\n\n<li>Test the restriction by logging in as a user assigned to the affected role.<\/li>\n\n\n\n<li>Document each restriction rule for future audit and support reference.<\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>Introduction The Role Data Access window lets an administrator fine-tune what a specific Role can see or change, going beyond [&hellip;]<\/p>\n","protected":false},"author":3,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[91,10],"tags":[],"class_list":["post-22171","post","type-post","status-publish","format-standard","hentry","category-idempiere-general-rules","category-idempiere-product"],"_links":{"self":[{"href":"https:\/\/tenthplanet.in\/idempiere\/wp-json\/wp\/v2\/posts\/22171","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/tenthplanet.in\/idempiere\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/tenthplanet.in\/idempiere\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/tenthplanet.in\/idempiere\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/tenthplanet.in\/idempiere\/wp-json\/wp\/v2\/comments?post=22171"}],"version-history":[{"count":3,"href":"https:\/\/tenthplanet.in\/idempiere\/wp-json\/wp\/v2\/posts\/22171\/revisions"}],"predecessor-version":[{"id":22264,"href":"https:\/\/tenthplanet.in\/idempiere\/wp-json\/wp\/v2\/posts\/22171\/revisions\/22264"}],"wp:attachment":[{"href":"https:\/\/tenthplanet.in\/idempiere\/wp-json\/wp\/v2\/media?parent=22171"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/tenthplanet.in\/idempiere\/wp-json\/wp\/v2\/categories?post=22171"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/tenthplanet.in\/idempiere\/wp-json\/wp\/v2\/tags?post=22171"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}