Skip to Content
Q&A

Dashboard Permissions in Odoo: Who Can View Which Figures?

If an employee with only billing permissions can also view management figures, there is a problem with the roles.

Terug naar alle Q&A
October 30, 2025 by
Dashboard Permissions in Odoo: Who Can View Which Figures?
DAADit Group, Nick

Een veelgestelde vraag: "Waarom ziet een medewerker met alleen facturatie-toegang cijfers in het dashboard waar hij niets mee te maken heeft?" Denk aan de administratief medewerker die ineens de omzet per vestiging kan bekijken. Het antwoord zit in hoe Odoo rechten (groepen) stapelt — en hoe dashboards dat samenspel interpreteren.

Hoe Odoo rechten structureert

Odoo werkt met access groups per module. Facturatie kent bijvoorbeeld: Billing, Accountant, Adviser. Een gebruiker die alleen "Billing" heeft, kan facturen boeken, maar zou geen winst- en verliesrekening moeten zien.

Het probleem ontstaat als iemand ook Dashboard- of Reporting-rechten heeft op een hogere laag — dan krijgt hij alsnog grafieken te zien met data waar zijn groepsrechten normaal gesproken niet bij zouden komen. Rechten stapelen in Odoo: de ruimste groep wint.

Controleren welke rechten iemand heeft

Als admin: Instellingen → Gebruikers & Bedrijven → Gebruikers. Open de gebruiker. In het tabblad Toegangsrechten ziet u per module welke rol actief is. Extra rechten staan onder Overig en Technisch — juist daar zitten vaak de verrassingen, omdat die vinkjes ooit "tijdelijk even" zijn aangezet.

Wat u meestal moet uitschakelen

  • Dashboard/Reporting-rechten op modules waar de gebruiker niet in hoort te werken
  • User access rights staat soms standaard aan voor portalgebruikers — altijd uitzetten
  • Technical Features hoort alleen bij echte beheerders te staan

Record Rules voor fijnmazige controle

Voor echt granulaire controle (bijvoorbeeld "medewerker A ziet alleen zijn eigen projecten") gebruikt u Record Rules. Via Instellingen → Technisch → Record Rules stelt u per model een filter in dat geldt voor specifieke groepen. Zo ziet een accountmanager alleen de orders van zijn eigen klanten, ook als hij het Verkoop-rapport opent. Let op: record rules zijn krachtig maar onverbiddelijk — test ze grondig voordat u ze op een hele afdeling loslaat.

Test voordat u live gaat

Maak in Odoo.sh altijd eerst een staging-kopie en test rechten met testgebruikers. Zet in developer mode de impersonate-functie aan: dan logt u in als de betreffende gebruiker en ziet u exact wat hij wel en niet ziet, voordat de wijziging live gaat. Plan daarna een halfjaarlijkse rechten-audit in — rollen slijten sneller dan u denkt.

Praktische tip: leg per functie (verkoop binnendienst, magazijn, administratie) één standaard rechtenprofiel vast en wijk daar alleen gemotiveerd van af. Hulp nodig bij het opschonen van uw rechtenstructuur? Neem contact op met DAADit Group of doe de gratis Business Scan.

Start de Business Scan →

A frequently asked question: "Why does an employee with only billing access see figures in the dashboard that have nothing to do with them?" Think of the admin clerk who can suddenly browse revenue per branch. The answer lies in how Odoo stacks permissions (groups) — and how dashboards interpret that interplay.

How Odoo structures permissions

Odoo works with access groups per module. Billing, for example, has: Billing, Accountant, Adviser. A user who only has "Billing" can post invoices, but should not see a profit and loss statement.

The problem arises when someone also has Dashboard or Reporting permissions at a higher layer — then they still get to see charts with data that their group permissions would normally not reach. Permissions stack in Odoo: the broadest group wins.

Checking which permissions someone has

As admin: Settings → Users & Companies → Users. Open the user. On the Access Rights tab you see per module which role is active. Extra permissions live under Other and Technical — that is exactly where the surprises usually hide, because those boxes were once ticked "just temporarily".

What you usually need to disable

  • Dashboard/Reporting permissions on modules the user should not work in
  • User access rights is sometimes enabled by default for portal users — always turn it off
  • Technical Features should only be granted to genuine administrators

Record Rules for fine-grained control

For truly granular control (e.g. "employee A only sees their own projects") you use Record Rules. Via Settings → Technical → Record Rules you set a filter per model that applies to specific groups. This way an account manager only sees the orders of their own customers, even when opening the Sales report. Note: record rules are powerful but unforgiving — test them thoroughly before rolling them out to a whole department.

Test before you go live

On Odoo.sh, always create a staging copy first and test permissions with test users. Enable the impersonate function in developer mode: you then log in as the user in question and see exactly what they can and cannot see, before the change goes live. After that, schedule a permissions audit every six months — roles drift faster than you think.

Practical tip: define one standard permissions profile per role (inside sales, warehouse, administration) and deviate only with a documented reason. Need help cleaning up your permissions structure? Contact DAADit Group or take the free Business Scan.

Start de Business Scan →

Vraag niet beantwoord?

Onze Odoo-consultants denken graag met u mee. Plan een vrijblijvend kennismakingsgesprek.

Plan een afspraak
Closing the Fiscal Year in Odoo: Checklist for a Flawless Year-End Closing
From temporary closure to permanent lockdown—here’s how to do it without any surprises.