Skip to Content
Nexuro Digital
  • Home
  • Services
    Digital marketing
    • AI Search (GEO)Cited by ChatGPT, Perplexity & Google AI
    • SEOConversion-focused SEO
    • SEO consultingFor your in-house teams
    • Google Ads (SEA)Profitable campaigns
    • Data AnalyticsMake sense of your data
    • Server-side TrackingReliable data & GDPR
    Odoo
    • Official Odoo PartnerImplementation & ERP/CRM
    • Odoo website creationConnected to your ERP
    • Odoo consultant in BelgiumLocal expertise
    • Peppol & invoicing2026 compliance
    • Support & TicketingResponsive follow-up
    Resources
    • Blog, La Croissance ConnectéeOur tips
    • Our workClient case studies
    • White paper2026 data strategy
    • Areas we serveOur cities in Belgium
    Discuss your project
  • Our work
  • Blog
  • About us
  • Contact
  • 0
  • 0471 46 57 86 
  • English (US) Français (BE)
Nexuro Digital
  • 0
    • Home
    • Services
    • Our work
    • Blog
    • About us
    • Contact
  • 0471 46 57 86 
  • English (US) Français (BE)
  • All Blogs
  • The Nexuro Blog
  • Access Rights in Odoo : An Overview
  • Access Rights in Odoo : An Overview

    Mastering Access Control: A necessity to secure your data in Odoo
    April 12, 2023 by
    Timothy Jacqmin
    En brefL'essentiel en quelques points
    ✓

    Odoo access rights rely on 3 layers: access groups, model-level rights (ACL) and record rules.

    ✓

    Groups define the role; ACLs set read, write, create and delete per model; record rules filter which records are visible.

    ✓

    Properly configured, they protect sensitive data without slowing daily work.

    ✓

    Golden rule: apply least privilege and test with a non-admin account.

    Odoo is a powerful and flexible enterprise management software that offers a range of features to support business operations. One of the key aspects of Odoo is its security system, which enables you to control access to various parts of the system based on the roles and permissions of individual users.

    Access rights in Odoo refer to the permissions that control what a user can and cannot do in the system. With access rights, you can set up different levels of access for different users or groups of users, ensuring that sensitive information and critical business processes are protected from unauthorised access.

    In this article, we'll take a closer look at the access rights system in Odoo, including how to manage user roles, set up access rules, and create custom access groups.

    The 3 levels of access control in Odoo

    LevelWhat it controlsExample
    Access groupsThe role and the features or menus a user can reach« Sales / Administrator »
    Model access rights (ACL)Allowed operations per model: read, write, create, deleteRead orders without being able to delete them
    Record rulesWhich specific records are visible or editable, via a domainSee only your own opportunities

    User Roles in Odoo

    In Odoo, user roles are used to define the set of permissions that a user has in the system. There are several built-in user roles in Odoo, including:

    • Administrator: this role has full access to all parts of the system, including the ability to manage users, install and uninstall modules, and configure system settings.
    • Employee: this role has limited access to the system, primarily to view and edit their own personal information and timesheets.
    • Manager: this role has access to most parts of the system, including the ability to manage sales, purchases, and inventory.

    You can also create custom user roles in Odoo to define specific sets of permissions for different groups of users.

    Access Rules in Odoo

    Access rules in Odoo are used to control access to specific records in the system, such as customers, products, and orders. Access rules are defined by creating a domain that specifies the conditions under which a user should be granted access to a particular record.

    For example, you might create an access rule that grants access to all customer records for users in the sales team, but restricts access to customer records for users in other teams.

    Custom Access Groups in Odoo

    In addition to user roles and access rules, Odoo also allows you to create custom access groups. Access groups are used to define sets of permissions that can be assigned to multiple user roles and access rules, making it easier to manage access rights for large groups of users.

    You can then assign the access group to multiple user roles and access rules, ensuring that the same set of permissions is applied consistently across the system.

    In conclusion, managing access rights in Odoo is an essential part of ensuring the security and integrity of your business data. By setting up user roles, access rules, and custom access groups, you can control access to sensitive information and critical business processes, while ensuring that your users have the access they need to perform their jobs effectively.

    With these tools at your disposal, you can customise the access rights in Odoo to meet the specific needs of your organisation and keep your data safe and secure.

    Frequently asked questions

    What are access rights in Odoo?

    They determine what each user can see and do, by combining 3 layers: access groups (the role), model-level rights (read, write, create, delete) and record rules (which specific records are visible).

    What's the difference between access groups and record rules?

    An access group defines a role and the features a user can reach (e.g. « Sales / User »). A record rule filters, within a module, which records a user can see — for example only their own opportunities, via a domain.

    How do I give a user access to a module?

    In Settings ▸ Users, open the user's form and assign the access group matching the module (e.g. « Accounting / Accountant »). Developer mode lets you fine-tune model-level rights.

    Can a user see only their own data?

    Yes, thanks to record rules: a domain restricts access to records linked to the user (« only my opportunities »).

    How do I test and secure access rights?

    Apply least privilege, then test with a non-admin account (or « Log in as »). A regular audit prevents overly broad access that exposes your data.

    in The Nexuro Blog
    # Article Odoo Integration
    Written by
    Timothy Jacqmin

    Timothy Jacqmin is co-founder of Nexuro Digital, a Belgian agency specialised in digital marketing (SEO, SEA, data) and Odoo integration. He helps SMEs connect their acquisition to their ERP and drive growth with data.

    About Nexuro →

    Read Next
    How can UX help build user loyalty and improve customer satisfaction?
    Our office
    • 55 rue des Bruyères​
      B-1325 Chaumont-Gistoux
      ​
      BE 0803.435.558

    Réseaux sociaux


    Connect with us
    • contact us
    • bj@nexuro-digital.com
    • 0471/46.57.86
    •     whatsapp

    ​Our services

    Official Odoo Partner
    E-invoicing - Peppol

    Digital marketing

    SEA

    SEO

    Data Analytics

    Digital Marketing Agency

    Useful links

    • Home
    • Blog
    • About us
    • Our achievements
    • Privacy policy
    • Legal notice
    • Disclaimer
    • Website cookie policy
    • Terms of sale

    ​
    English (US) | Français (BE)
    Powered by Odoo - The #1 Open Source eCommerce