Skip to main content

Window: Role

[Created: 11/06/1999 - Updated: 10/03/2022 ]
Description: Maintain User Responsibilities
Help: The Role Window allows you to define the different roles that users of this system will have. Roles control access to windows, tasks, reports, etc. For a tenant an Administrator and User role are predefined. You may add additional roles to control access for specific functionality or data.You can add users to the role.Note that access information is cached and requires re-login or reset of cache.

Tab: Role

[Created: 11/06/1999 - Updated: 15/01/2024 ]
Description: Define responsibility roles
Help: Define the role and add the organizations the role has access to. You can give users access to this role and modify the access of this role to windows, forms, processes and reports as well as tasks. If the Role User Level is Manual, the assigned access rights are not automatically updated (e.g. if a role has a restricted number of Windows/Processes it can access). You need to add organizational access unless the role has access to all organizations. The SuperUser and the user creating a new role are assigned to the role automatically. If you select an Organization Tree, the user has access to the leaves of summary organizations.Note: You cannot change the System Administrator role.
Tab Level: 0

Table 10: Role - Fields

Table: Report Parameters

NameDescriptionHelpTechnical Info
TenantTenant for this installation.A Tenant is a company or a legal entity. You cannot share data between Tenants.ad_role.AD_Client_ID numeric(10)
Table Direct
OrganizationOrganizational entity within tenantAn organization is a unit of your tenant or legal entity - examples are store, department. You can share data between organizations.ad_role.AD_Org_ID numeric(10)
Table Direct
NameAlphanumeric identifier of the entityThe name of an entity (record) is used as an default search option in addition to the search key. The name is up to 60 characters in length.ad_role.Name character varying(60)
String
DescriptionOptional short description of the recordA description is limited to 255 characters.ad_role.Description character varying(255)
String
User LevelSystem Tenant OrganizationThe User Level field determines if users of this Role will have access to System level data, Organization level data, Tenant level data or Tenant and Organization level data.ad_role.UserLevel character(3)
List
ManualThis is a manual processThe Manual check box indicates if the process will done manually.ad_role.IsManual character(1)
Yes-No
ActiveThe record is active in the systemThere are two methods of making records unavailable in the system: One is to delete the record, the other is to de-activate the record. A de-activated record is not available for selection, but available for reports.There are two reasons for de-activating and not deleting records:(1) The system requires the record for audit purposes.(2) The record is referenced by other records. E.g., you cannot delete a Business Partner, if there are invoices for this partner record existing. You de-activate the Business Partner and prevent that this record is used for future entries.ad_role.IsActive character(1)
Yes-No
Master RoleA master role cannot be assigned to users, it is intended to define access to menu option and documents and inherit to other rolesad_role.IsMasterRole character(1)
Yes-No
Auto expand menuIf ticked, the menu is automatically expandedad_role.IsMenuAutoExpand character(1)
Yes-No
Maintain Change LogMaintain a log of changesIf selected, a log of all changes is maintained.ad_role.IsChangeLog character(1)
Yes-No
CurrencyThe Currency for this recordIndicates the Currency to be used when processing or reporting on this recordad_role.C_Currency_ID numeric(10)
Table Direct
Approval AmountThe approval amount limit for this roleThe Approval Amount field indicates the amount limit this Role has for approval of documents.ad_role.AmtApproval numeric
Amount
Approval Amount AccumulatedThe approval amount limit for this role accumulated on a periodThe Approval Amount field indicates the amount limit this Role has for approval of documents within a period limit.ad_role.AmtApprovalAccum numeric
Amount
Days Approval AccumulatedThe days approval indicates the days to take into account to verify the accumulated approval amount.The Days Approval Accumulated field indicates the days to take into account to verify the accumulated approval amount.ad_role.DaysApprovalAccum numeric(10)
Integer
Approve own DocumentsUsers with this role can approve their own documentsIf a user cannot approve their own documents (orders, etc.), it needs to be approved by someone else.ad_role.IsCanApproveOwnDoc character(1)
Yes-No
Role Typead_role.RoleType character varying(2)
List
Preference LevelDetermines what preferences the user can setPreferences allow you to define default values. If set to None, you cannot set any preference nor value preference. Only if set to Tenant, you can see the Record Info Change Log.ad_role.PreferenceType character(1)
List
Menu TreeTree of the menuMenu access treead_role.AD_Tree_Menu_ID numeric(10)
Table
Access Advancedad_role.IsAccessAdvanced character(1)
Yes-No
Access all OrgsAccess all Organizations (no org access control) of the tenantWhen selected, the role has access to all organizations of the tenant automatically. This also increases performance where you have many organizations.ad_role.IsAccessAllOrgs character(1)
Yes-No
Use User Org AccessUse Org Access defined by user instead of Role Org AccessYou can define the access to Organization either by Role or by User. You would select this, if you have many organizations.ad_role.IsUseUserOrgAccess character(1)
Yes-No
Personal LockAllow users with role to lock access to personal recordsIf enabled, the user with the role can prevent access of others to personal records. If a record is locked, only the user or people who can read personal locked records can see the record.ad_role.IsPersonalLock character(1)
Yes-No
Personal AccessAllow access to all personal recordsUsers of this role have access to all records locked as personal.ad_role.IsPersonalAccess character(1)
Yes-No
Can ReportUsers with this role can create reportsYou can restrict the ability to report on data.ad_role.IsCanReport character(1)
Yes-No
Can ExportUsers with this role can export dataYou can restrict the ability to export data from iDempiere.ad_role.IsCanExport character(1)
Yes-No
Tenant AdministratorThis role is a tenant administratorad_role.IsClientAdministrator character(1)
Yes-No
Show AccountingUsers with this role can see accounting informationThis allows to prevent access to any accounting information.ad_role.IsShowAcct character(1)
Yes-No
Overwrite Price LimitOverwrite Price Limit if the Price List enforces the Price LimitThe Price List allows to enforce the Price Limit. If set, a user with this role can overwrite the price limit (i.e. enter any price).ad_role.OverwritePriceLimit character(1)
Yes-No
Confirm Query RecordsRequire Confirmation if more records will be returned by the query (If not defined 500)Enter the number of records the query will return without confirmation to avoid unnecessary system load. If 0, the system default of 500 is used.ad_role.ConfirmQueryRecords numeric(10)
Integer
Max Query RecordsIf defined, you cannot query more records as defined - the query criteria needs to be changed to query less recordsEnter the number of records a user will be able to query to avoid unnecessary system load. If 0, no restrictions are imposed.ad_role.MaxQueryRecords numeric(10)
Integer
Organization TreeTrees are used for (financial) reporting and security access (via role)Trees are used for (finanial) reporting and security access (via role)ad_role.AD_Tree_Org_ID numeric(10)
Table
Allow Info Accountad_role.Allow_Info_Account character(1)
Yes-No
Allow Info Schedulead_role.Allow_Info_Schedule character(1)
Yes-No
Allow Info Productad_role.Allow_Info_Product character(1)
Yes-No
Allow Info BPartnerad_role.Allow_Info_BPartner character(1)
Yes-No
Allow Info Orderad_role.Allow_Info_Order character(1)
Yes-No
Allow Info Invoicead_role.Allow_Info_Invoice character(1)
Yes-No
Allow Shipment Infoad_role.Allow_Info_InOut character(1)
Yes-No
Allow Info Paymentad_role.Allow_Info_Payment character(1)
Yes-No
Allow Info Assetad_role.Allow_Info_Asset character(1)
Yes-No
Allow Info Resourcead_role.Allow_Info_Resource character(1)
Yes-No
Predefined Context VariablesPredefined context variables to inject when opening a menu entry or a windowad_role.PredefinedContextVariables character varying(4000)
String

Tab: Org Access

[Created: 27/01/2001 - Updated: 10/03/2022 ]
Description: Maintain Role Org Access
Help: Add the tenant and organizations the user has access to. Entries here are ignored, if User Org Access is selected or the role has access to all roles.Note that access information is cached and requires re-login or reset of cache.
Tab Level: 1

Table 20: Org Access - Fields

Table: Report Parameters

NameDescriptionHelpTechnical Info
TenantTenant for this installation.A Tenant is a company or a legal entity. You cannot share data between Tenants.ad_role_orgaccess.AD_Client_ID numeric(10)
Table Direct
OrganizationOrganizational entity within tenantAn organization is a unit of your tenant or legal entity - examples are store, department. You can share data between organizations.ad_role_orgaccess.AD_Org_ID numeric(10)
Table Direct
RoleResponsibility RoleThe Role determines security and access a user who has this Role will have in the System.ad_role_orgaccess.AD_Role_ID numeric(10)
Table Direct
ActiveThe record is active in the systemThere are two methods of making records unavailable in the system: One is to delete the record, the other is to de-activate the record. A de-activated record is not available for selection, but available for reports.There are two reasons for de-activating and not deleting records:(1) The system requires the record for audit purposes.(2) The record is referenced by other records. E.g., you cannot delete a Business Partner, if there are invoices for this partner record existing. You de-activate the Business Partner and prevent that this record is used for future entries.ad_role_orgaccess.IsActive character(1)
Yes-No
Read OnlyField is read onlyThe Read Only indicates that this field may only be Read. It may not be updated.ad_role_orgaccess.IsReadOnly character(1)
Yes-No

Tab: User Assignment

[Created: 11/06/1999 - Updated: 04/09/2012 ]
Description: Users with this Role
Help: The User Assignment Tab displays Users who have been defined for this Role.
Tab Level: 1

Table 30: User Assignment - Fields

Table: Report Parameters

NameDescriptionHelpTechnical Info
TenantTenant for this installation.A Tenant is a company or a legal entity. You cannot share data between Tenants.ad_user_roles.AD_Client_ID numeric(10)
Table Direct
OrganizationOrganizational entity within tenantAn organization is a unit of your tenant or legal entity - examples are store, department. You can share data between organizations.ad_user_roles.AD_Org_ID numeric(10)
Table Direct
RoleResponsibility RoleThe Role determines security and access a user who has this Role will have in the System.ad_user_roles.AD_Role_ID numeric(10)
Search
User/ContactUser within the system - Internal or Business Partner ContactThe User identifies a unique user in the system. This could be an internal user or a business partner contactad_user_roles.AD_User_ID numeric(10)
Search
ActiveThe record is active in the systemThere are two methods of making records unavailable in the system: One is to delete the record, the other is to de-activate the record. A de-activated record is not available for selection, but available for reports.There are two reasons for de-activating and not deleting records:(1) The system requires the record for audit purposes.(2) The record is referenced by other records. E.g., you cannot delete a Business Partner, if there are invoices for this partner record existing. You de-activate the Business Partner and prevent that this record is used for future entries.ad_user_roles.IsActive character(1)
Yes-No

Tab: Window Access

[Created: 15/07/2000 - Updated: 02/01/2000 ]
Description: Window Access
Help: The Window Access Tab defines the Windows and type of access that this Role is granted.
Tab Level: 1

Table 40: Window Access - Fields

Table: Report Parameters

NameDescriptionHelpTechnical Info
TenantTenant for this installation.A Tenant is a company or a legal entity. You cannot share data between Tenants.ad_window_access.AD_Client_ID numeric(10)
Table Direct
OrganizationOrganizational entity within tenantAn organization is a unit of your tenant or legal entity - examples are store, department. You can share data between organizations.ad_window_access.AD_Org_ID numeric(10)
Table Direct
RoleResponsibility RoleThe Role determines security and access a user who has this Role will have in the System.ad_window_access.AD_Role_ID numeric(10)
Table Direct
WindowData entry or display windowThe Window field identifies a unique Window in the system.ad_window_access.AD_Window_ID numeric(10)
Table Direct
ActiveThe record is active in the systemThere are two methods of making records unavailable in the system: One is to delete the record, the other is to de-activate the record. A de-activated record is not available for selection, but available for reports.There are two reasons for de-activating and not deleting records:(1) The system requires the record for audit purposes.(2) The record is referenced by other records. E.g., you cannot delete a Business Partner, if there are invoices for this partner record existing. You de-activate the Business Partner and prevent that this record is used for future entries.ad_window_access.IsActive character(1)
Yes-No
Read WriteField is read / writeThe Read Write indicates that this field may be read and updated.ad_window_access.IsReadWrite character(1)
Yes-No

Tab: Process Access

[Created: 15/07/2000 - Updated: 02/01/2000 ]
Description: Process Access
Help: The Process Access Tab defines the Processes and type of access that this Role is granted.
Tab Level: 1

Table 50: Process Access - Fields

Table: Report Parameters

NameDescriptionHelpTechnical Info
TenantTenant for this installation.A Tenant is a company or a legal entity. You cannot share data between Tenants.ad_process_access.AD_Client_ID numeric(10)
Table Direct
OrganizationOrganizational entity within tenantAn organization is a unit of your tenant or legal entity - examples are store, department. You can share data between organizations.ad_process_access.AD_Org_ID numeric(10)
Table Direct
RoleResponsibility RoleThe Role determines security and access a user who has this Role will have in the System.ad_process_access.AD_Role_ID numeric(10)
Table Direct
ProcessProcess or ReportThe Process field identifies a unique Process or Report in the system.ad_process_access.AD_Process_ID numeric(10)
Table Direct
ActiveThe record is active in the systemThere are two methods of making records unavailable in the system: One is to delete the record, the other is to de-activate the record. A de-activated record is not available for selection, but available for reports.There are two reasons for de-activating and not deleting records:(1) The system requires the record for audit purposes.(2) The record is referenced by other records. E.g., you cannot delete a Business Partner, if there are invoices for this partner record existing. You de-activate the Business Partner and prevent that this record is used for future entries.ad_process_access.IsActive character(1)
Yes-No
Read WriteField is read / writeThe Read Write indicates that this field may be read and updated.ad_process_access.IsReadWrite character(1)
Yes-No

Tab: Form Access

[Created: 15/07/2000 - Updated: 02/01/2000 ]
Description: Form Access
Help: The Form Access Tab defines the Forms and type of access that this Role is granted.
Tab Level: 1

Table 60: Form Access - Fields

Table: Report Parameters

NameDescriptionHelpTechnical Info
TenantTenant for this installation.A Tenant is a company or a legal entity. You cannot share data between Tenants.ad_form_access.AD_Client_ID numeric(10)
Table Direct
OrganizationOrganizational entity within tenantAn organization is a unit of your tenant or legal entity - examples are store, department. You can share data between organizations.ad_form_access.AD_Org_ID numeric(10)
Table Direct
RoleResponsibility RoleThe Role determines security and access a user who has this Role will have in the System.ad_form_access.AD_Role_ID numeric(10)
Table Direct
Special FormSpecial FormThe Special Form field identifies a unique Special Form in the system.ad_form_access.AD_Form_ID numeric(10)
Table Direct
ActiveThe record is active in the systemThere are two methods of making records unavailable in the system: One is to delete the record, the other is to de-activate the record. A de-activated record is not available for selection, but available for reports.There are two reasons for de-activating and not deleting records:(1) The system requires the record for audit purposes.(2) The record is referenced by other records. E.g., you cannot delete a Business Partner, if there are invoices for this partner record existing. You de-activate the Business Partner and prevent that this record is used for future entries.ad_form_access.IsActive character(1)
Yes-No
Read WriteField is read / writeThe Read Write indicates that this field may be read and updated.ad_form_access.IsReadWrite character(1)
Yes-No

Tab: Info Access

[Created: 08/01/2013 - Updated: 08/01/2013 ]
Description:
Help:
Tab Level: 1

Table 65: Info Access - Fields

Table: Report Parameters

NameDescriptionHelpTechnical Info
TenantTenant for this installation.A Tenant is a company or a legal entity. You cannot share data between Tenants.ad_infowindow_access.AD_Client_ID numeric(10)
Table Direct
OrganizationOrganizational entity within tenantAn organization is a unit of your tenant or legal entity - examples are store, department. You can share data between organizations.ad_infowindow_access.AD_Org_ID numeric(10)
Table Direct
RoleResponsibility RoleThe Role determines security and access a user who has this Role will have in the System.ad_infowindow_access.AD_Role_ID numeric(10)
Table Direct
Info WindowInfo and search/select WindowThe Info window is used to search and select records as well as display information relevant to the selection.ad_infowindow_access.AD_InfoWindow_ID numeric(10)
Table Direct
ActiveThe record is active in the systemThere are two methods of making records unavailable in the system: One is to delete the record, the other is to de-activate the record. A de-activated record is not available for selection, but available for reports.There are two reasons for de-activating and not deleting records:(1) The system requires the record for audit purposes.(2) The record is referenced by other records. E.g., you cannot delete a Business Partner, if there are invoices for this partner record existing. You de-activate the Business Partner and prevent that this record is used for future entries.ad_infowindow_access.IsActive character(1)
Yes-No

Tab: Workflow Access

[Created: 15/07/2000 - Updated: 02/01/2000 ]
Description: Workflow Access
Help: The Workflow Access Tab defines the Workflows and type of access that this Role is granted.
Tab Level: 1

Table 70: Workflow Access - Fields

Table: Report Parameters

NameDescriptionHelpTechnical Info
TenantTenant for this installation.A Tenant is a company or a legal entity. You cannot share data between Tenants.ad_workflow_access.AD_Client_ID numeric(10)
Table Direct
OrganizationOrganizational entity within tenantAn organization is a unit of your tenant or legal entity - examples are store, department. You can share data between organizations.ad_workflow_access.AD_Org_ID numeric(10)
Table Direct
RoleResponsibility RoleThe Role determines security and access a user who has this Role will have in the System.ad_workflow_access.AD_Role_ID numeric(10)
Table Direct
WorkflowWorkflow or combination of tasksThe Workflow field identifies a unique Workflow in the system.ad_workflow_access.AD_Workflow_ID numeric(10)
Table Direct
ActiveThe record is active in the systemThere are two methods of making records unavailable in the system: One is to delete the record, the other is to de-activate the record. A de-activated record is not available for selection, but available for reports.There are two reasons for de-activating and not deleting records:(1) The system requires the record for audit purposes.(2) The record is referenced by other records. E.g., you cannot delete a Business Partner, if there are invoices for this partner record existing. You de-activate the Business Partner and prevent that this record is used for future entries.ad_workflow_access.IsActive character(1)
Yes-No
Read WriteField is read / writeThe Read Write indicates that this field may be read and updated.ad_workflow_access.IsReadWrite character(1)
Yes-No

Tab: Task Access

[Created: 04/09/2000 - Updated: 02/01/2000 ]
Description: Task Access
Help: The Task Access Tab defines the Task and type of access that this Role is granted.
Tab Level: 1

Table 80: Task Access - Fields

Table: Report Parameters

NameDescriptionHelpTechnical Info
TenantTenant for this installation.A Tenant is a company or a legal entity. You cannot share data between Tenants.ad_task_access.AD_Client_ID numeric(10)
Table Direct
OrganizationOrganizational entity within tenantAn organization is a unit of your tenant or legal entity - examples are store, department. You can share data between organizations.ad_task_access.AD_Org_ID numeric(10)
Table Direct
RoleResponsibility RoleThe Role determines security and access a user who has this Role will have in the System.ad_task_access.AD_Role_ID numeric(10)
Table Direct
OS TaskOperation System TaskThe Task field identifies a Operation System Task in the system.ad_task_access.AD_Task_ID numeric(10)
Table Direct
ActiveThe record is active in the systemThere are two methods of making records unavailable in the system: One is to delete the record, the other is to de-activate the record. A de-activated record is not available for selection, but available for reports.There are two reasons for de-activating and not deleting records:(1) The system requires the record for audit purposes.(2) The record is referenced by other records. E.g., you cannot delete a Business Partner, if there are invoices for this partner record existing. You de-activate the Business Partner and prevent that this record is used for future entries.ad_task_access.IsActive character(1)
Yes-No
Read WriteField is read / writeThe Read Write indicates that this field may be read and updated.ad_task_access.IsReadWrite character(1)
Yes-No

Tab: Document Action Access

[Created: 29/08/0001 - Updated: 29/08/0001 ]
Description: Define access to document type / document action / role combinations.
Help: Define access to document type / document action / role combinations.
Tab Level: 1

Table 90: Document Action Access - Fields

Table: Report Parameters

NameDescriptionHelpTechnical Info
TenantTenant for this installation.A Tenant is a company or a legal entity. You cannot share data between Tenants.ad_document_action_access.AD_Client_ID numeric(10)
Table Direct
OrganizationOrganizational entity within tenantAn organization is a unit of your tenant or legal entity - examples are store, department. You can share data between organizations.ad_document_action_access.AD_Org_ID numeric(10)
Table Direct
RoleResponsibility RoleThe Role determines security and access a user who has this Role will have in the System.ad_document_action_access.AD_Role_ID numeric(10)
Table Direct
Document TypeDocument type or rulesThe Document Type determines document sequence and processing rulesad_document_action_access.C_DocType_ID numeric(10)
Table Direct
Reference ListReference List based on TableThe Reference List field indicates a list of reference values from a database tables. Reference lists populate drop down list boxes in data entry screensad_document_action_access.AD_Ref_List_ID numeric(10)
Table Direct
ActiveThe record is active in the systemThere are two methods of making records unavailable in the system: One is to delete the record, the other is to de-activate the record. A de-activated record is not available for selection, but available for reports.There are two reasons for de-activating and not deleting records:(1) The system requires the record for audit purposes.(2) The record is referenced by other records. E.g., you cannot delete a Business Partner, if there are invoices for this partner record existing. You de-activate the Business Partner and prevent that this record is used for future entries.ad_document_action_access.IsActive character(1)
Yes-No

Tab: Included roles

[Created: 27/07/2009 - Updated: 04/09/2012 ]
Description:
Help:
Tab Level: 1

Table 100: Included roles - Fields

Table: Report Parameters

NameDescriptionHelpTechnical Info
SequenceMethod of ordering records; lowest number comes firstThe Sequence indicates the order of recordsad_role_included.SeqNo numeric(10)
Integer
ActiveThe record is active in the systemThere are two methods of making records unavailable in the system: One is to delete the record, the other is to de-activate the record. A de-activated record is not available for selection, but available for reports.There are two reasons for de-activating and not deleting records:(1) The system requires the record for audit purposes.(2) The record is referenced by other records. E.g., you cannot delete a Business Partner, if there are invoices for this partner record existing. You de-activate the Business Partner and prevent that this record is used for future entries.ad_role_included.IsActive character(1)
Yes-No
RoleResponsibility RoleThe Role determines security and access a user who has this Role will have in the System.ad_role_included.AD_Role_ID numeric(10)
Search
Included Rolead_role_included.Included_Role_ID numeric(10)
Table

Tab: Document Status Access

[Created: 28/06/2021 - Updated: 28/06/2021 ]
Description:
Help:
Tab Level: 1

Table 130: Document Status Access - Fields

Table: Report Parameters

NameDescriptionHelpTechnical Info
TenantTenant for this installation.A Tenant is a company or a legal entity. You cannot share data between Tenants.pa_documentstatusaccess.AD_Client_ID numeric(10)
Table Direct
OrganizationOrganizational entity within tenantAn organization is a unit of your tenant or legal entity - examples are store, department. You can share data between organizations.pa_documentstatusaccess.AD_Org_ID numeric(10)
Search
RoleResponsibility RoleThe Role determines security and access a user who has this Role will have in the System.pa_documentstatusaccess.AD_Role_ID numeric(10)
Table Direct
User/ContactUser within the system - Internal or Business Partner ContactThe User identifies a unique user in the system. This could be an internal user or a business partner contactpa_documentstatusaccess.AD_User_ID numeric(10)
Search
Document Statuspa_documentstatusaccess.PA_DocumentStatus_ID numeric(10)
Table Direct
ActiveThe record is active in the systemThere are two methods of making records unavailable in the system: One is to delete the record, the other is to de-activate the record. A de-activated record is not available for selection, but available for reports.There are two reasons for de-activating and not deleting records:(1) The system requires the record for audit purposes.(2) The record is referenced by other records. E.g., you cannot delete a Business Partner, if there are invoices for this partner record existing. You de-activate the Business Partner and prevent that this record is used for future entries.pa_documentstatusaccess.IsActive character(1)
Yes-No