Een veelgestelde vraag: "Waarom ziet een medewerker met alleen facturatie-toegang cijfers in het dashboard waar hij niets mee te maken heeft?" Het antwoord zit in hoe Odoo rechten (groepen) stapelt — en hoe dashboards dat samenspel interpreteren.
Hoe Odoo rechten structureert
Odoo werkt met access groups per module. Facturatie kent bijvoorbeeld: Billing, Accountant, Adviser. Een gebruiker die alleen "Billing" heeft, kan facturen boeken, maar zou geen P&L moeten zien.
Het probleem ontstaat als iemand ook Dashboard of Reporting rechten heeft op een hogere laag — dan krijgt hij alsnog grafieken te zien met data waar zijn groepsrechten normaal gesproken niet bij zouden komen.
Controleren welke rechten iemand heeft
Als admin: Instellingen → Gebruikers & Bedrijven → Gebruikers. Open de gebruiker. In het tabblad Toegangsrechten ziet u per module welke rol actief is. Extra rechten staan onder Overig en Technisch.
Wat u meestal moet uitschakelen
- Dashboard/Reporting rechten op modules waar ze niet in moeten werken
- User access rights staat soms standaard aan voor portalgebruikers — altijd uitzetten
- Technical Features moet alleen bij echte beheerders staan
Record Rules voor fijnmazige controle
Voor echt granulaire controle (bijv. "medewerker A ziet alleen zijn eigen projecten") gebruikt u Record Rules. Via Instellingen → Technisch → Record Rules kunt u per model een filter instellen dat geldt voor specifieke groepen. Zo kan een accountmanager alleen de orders van zijn eigen klanten zien, ook al opent hij het Verkoop-rapport.
Praktische tip
Maak in Odoo.sh altijd eerst een staging-kopie en test rechten uit met testgebruikers (zet de impersonate-functie aan in developer mode). Zo ziet u precies wat een gebruiker wel en niet ziet, vóórdat u het live zet.
Vragen over uw Odoo implementatie? Doe de gratis Business Scan.
Start de Business Scan →A frequently asked question: "Why does an employee with only billing access see figures in the dashboard that have nothing to do with them?" The answer lies in how Odoo stacks permissions (groups) — and how dashboards interpret that interplay.
How Odoo structures permissions
Odoo works with access groups per module. Billing, for example, has: Billing, Accountant, Adviser. A user who only has "Billing" can post invoices, but should not see a P&L.
The problem arises when someone also has Dashboard or Reporting permissions at a higher layer — then they still get to see charts with data that their group permissions would normally not have access to.
Checking which permissions someone has
As admin: Settings → Users & Companies → Users. Open the user. On the Access Rights tab you see per module which role is active. Extra permissions are under Other and Technical.
What you usually need to disable
- Dashboard/Reporting permissions on modules they should not work in
- User access rights is sometimes enabled by default for portal users — always turn it off
- Technical Features should only be granted to genuine administrators
Record Rules for fine-grained control
For truly granular control (e.g. "employee A only sees their own projects") you use Record Rules. Via Settings → Technical → Record Rules you can set a filter per model that applies to specific groups. This way an account manager can only see the orders of their own customers, even if they open the Sales report.
Practical tip
In Odoo.sh always create a staging copy first and test permissions with test users (enable the impersonate function in developer mode). This way you see exactly what a user does and does not see, before you put it live.
Questions about your Odoo implementation? Take the free Business Scan.
Start the Business Scan →