Odoo Access Management System

Control exactly who can see and touch every part of your ERP

Access Management System is a complete permissions layer for your Odoo environment. Lock down any menu, field, button, report, or chatter thread by user, by group, by company, or by time schedule, without writing code.

Access Management System
What It Is

An access control layer built for how ERP teams actually work

Every growing ERP deployment hits the same wall: default user groups are too blunt. You can put someone in "Sales / User" or "Sales / Manager," but you can't stop that same user from seeing a competitor's margin field, exporting a customer list, or deleting a paid invoice without custom development.

The Access Management System closes that gap. It's a standalone access control system that sits on top of your Odoo environment and lets you restrict access at the exact level it matters: a single menu, a single field, a single button, a report, or even a chatter thread. Rules can be scoped to a user, a group, a company, or a time window, and they take effect immediately with no server restart, no code.

It's built for teams that have outgrown default permissions but don't want to maintain custom security code and it runs across Odoo Community, Enterprise, and Odoo.sh, versions 15 through 19.

PROTECTED
Access Management
+ Access rules
Field rules
+ Actions

Permission overview

Control exactly what each role can see and do.

Menus & navigation
14 restrictions configured
Fields & records
Sensitive data protected
Buttons & actions
Delete and export limited
USER ROLE
Sales Manager
Active
Changes applied instantly
Why Teams Run It

Default permission groups are broad.
This system is precise

Default access groups are all-or-nothing at the model level. This system adds a fine-grained layer on top down to a single field or button, without a line of custom code.

01
Built for consistency
RELIABILITY

Built for consistency

A lean, well-tested engine keeps access rules behaving consistently across every view type list, form, kanban, and pivot.

02
Built for consistency
SPEED

No performance tax

Rules apply at render time without adding noticeable load to page rendering, even on record-heavy views.

03
Built for consistency
COST

Lower maintenance overhead

Fewer moving parts than a custom-built access layer means fewer support tickets and less time spent maintaining permissions by hand.

Who Runs It

Built for the access problems
real ERP teams run into

One precise control layer, shaped around the way different teams, locations, and responsibilities actually operate.

ACCESS MAP
8 SCENARIOS
01
HR & Payroll
PEOPLE OPERATIONS

HR & Payroll

Hide salary, payslip, and contract fields from anyone outside HR, while keeping the rest of the Employees workspace visible to managers.

02
Multi-branch retail
MULTI-COMPANY

Multi-branch retail

Give each store manager access only to their own company's records with multi-company rules, without duplicating user accounts.

03
Implementation teams
PROJECT DELIVERY

Implementation teams

Ship client-ready environments with locked-down menus and buttons that match each client's internal approval process.

04
Finance & accounting
SENSITIVE RECORDS

Finance & accounting

Make ledger and invoice fields read-only for non-finance staff and hide export or delete buttons on sensitive financial records.

05
Contractors & temp staff
TEMPORARY ACCESS

Contractors & temp staff

Grant time-boxed access that revokes itself automatically on a contract's end date no follow-up cleanup required.

06
Shift-based teams
SCHEDULED RULES

Shift-based teams

Restrict logins and record access to a defined working schedule, respecting each user's own time zone.

07
Sales organizations
REVENUE TEAMS

Sales organizations

Hide margin, cost, and internal-note fields from junior reps while letting managers see the full picture.

08
Compliance-driven teams
GOVERNANCE

Compliance-driven teams

Enforce least-privilege access across regulated data without maintaining a custom security build.

What's included

Eleven ways to shape
what a user sees

Every restriction can be scoped to a group, a specific user, a company, or a time window and combined freely for layered access control.

01
Model access rights

Model access rights

Control what a user can do on any record type, beyond default read/write/create/delete groups.

  • Hide any action or report
  • Hide any view
  • Hide create / edit / delete
  • Hide duplicate, export, import, print, spreadsheet
Model Access Rights
02
Menus & sub-menus

Menus & sub-menus

Remove entire workspaces or specific sub-menus from the navigation bar for users who don't need them.

  • Hide any menu or sub-menu
  • Hide an entire main app menu
  • Hide any tab inside a form
  • Hide kanban card links
03
Field-level security

Field-level security

The most requested capability: true field-level access control, applied to standard and custom fields alike.

  • Hide any field
  • Make a field read-only or required
  • Restrict quick-create / quick-edit
  • Remove external record links
04
Filters & group by

Filters & group by

Simplify a view or hide sensitive groupings by controlling what appears in the search panel.

  • Hide any filter or group-by option
  • Hide the search panel
  • Hide favourites
05
Button-level restrictions

Button-level restrictions

Hide any individual button, on the navbar or inside a form, without touching the rest of the view.

  • Hide any button on any view
  • Applies to navbar and form buttons alike
  • Hide Create, Edit, Delete, Duplicate buttons
  • Restrict custom wizard & action buttons
06
Chatter, record-wise

Chatter, record-wise

Keep internal discussions private by restricting chatter per record type instead of hiding it everywhere.

  • Hide the chatter on any record type
  • Hide send message
  • Hide log notes
  • Hide the activity scheduler
07
Multi-company support

Multi-company support

One login, different permissions per company, built for holding groups and multi-branch operations.

  • Different access rules per company
  • One user, different permissions per entity
  • Scope restrictions by active company
  • Seamless multi-branch compliance
08
Automatic access expiration

Automatic access expiration

Set a rule once, and let it revoke itself, ideal for contractors, interns, and temporary vendor access.

  • Auto-revoke access after a set date
  • No manual follow-up cleanup needed
  • Ideal for contractors & temporary vendors
  • Set start and end validity periods
09
Time & time-zone rules

Time & time-zone rules

Restrict logins and record access to a working schedule, evaluated in each user's own time zone.

  • Restrict access to a schedule
  • Respects each user's own time zone
  • Block off-hours logins automatically
  • Working hours & days based restrictions
Global Controls

Twelve switches that
apply system-wide

Flip these once at the user level instead of repeating the same restriction across every record type.

  • Read-only user (buttons, actions, chatter, filters)
  • Disable user login
  • Hide import
  • Hide action button
  • Hide whole chatter
  • Hide filter, group by, custom filter & group by
  • Disable developer mode
  • Hide export
  • Hide print button
  • Hide "Add a Property"
  • Hide send message / log note / activity
  • Hide search panel & favourites
Setup

Live in three steps

Set up Odoo access controls in minutes. Deploy the system, configure user permissions, and apply access rules instantly, without restarting Odoo.

01
Deploy the system

Deploy the system

Add it to your environment. It runs on Community, Enterprise, and Odoo.sh, across versions 15 through 19.

02
Enable Access Management

Enable Access Management

Open a user's settings and switch on "Access Management Manager" to bring up the permission rule builder.

03
Define the rule

Define the rule

Pick the element menu, field, button, chatter, report, choose who it applies to, and save. Changes apply instantly, no restart needed.

Comparison

Access Management System vs default permissions

Where standard user groups stop, this system continues

Capability Access Management System Default groups
Hide a whole workspace or menu Yes Yes
Hide a single field on a form Yes, no code Only via custom code
Hide a specific button Yes, no code Only via custom code
Restrict chatter per record type Yes No
Time / time-zone based access Yes No
Auto-expiring access Yes No
Different rules per company Yes Partial
Requires a developer to change No Usually
Technical Specification

Under the hood

Engineered for seamless integration, minimal footprint, and zero dependency overhead across modern Odoo environments.

COMPATIBLE WITH

Odoo 15, 16, 17, 18, 19

EDITIONS

Community & Enterprise, On-Premise and Odoo.sh

REQUIRES

Discuss, Invoicing, and Sales workspaces enabled

Access Management System

Access Management System

ADDITIONAL LIBRARIES

None required

LANGUAGES

English, German, Arabic, Spanish, French, Chinese

SUPPORT

Included for the life of your license

One System. Every Access Rule You'll Need.

Available for every supported Odoo version. One-time license, lifetime updates included.
Get Quote Now
Questions

Frequently asked

Everything you need to know before getting started.

Still have questions? Contact us

Odoo 15 through 19, on Community, Enterprise On-Premise, and Odoo.sh.

No, the system is built for self-hosted On-Premise and Odoo.sh deployments, not the odoo.com SaaS trial platform.

No. The system runs on a standard Odoo installation with no additional libraries.

Yes, updates for your version are included for life at no extra charge.

Yes. The system applies at the field's technical name, so custom fields can be hidden or made read-only the same way as standard fields.

Record-level visibility, like limiting an employee to their own attendance, contracts, or payslips depends on the underlying record rules. Combine the system's UI-level restrictions with those rules, or contact support for a scoped setup.

Yes. Multi-company support means the same user can have different access rules in each company they're a member of.

Yes, reach out to our team to scope a custom setup.

Transforming Businesses with Next-Gen Solutions

Our next-generation solutions are built to transform businesses and drive growth in the digital era.

Find Us

530, West Gate 2,
Ayodhya Chowk, 150 Feet Ring Road Rajkot, Gujarat 360006.

Find Us

131 South End, Croydon CRO 1BJ,
United Kingdom

Contact No.

HR : +91 90232 46069
Sales : +91 93288 25451

Contact No.

Sales : +44 7562 893296

Reach Us Read Blog Contact Us Submit Support Ticket Watch Video Tutorial