Skip to Content
Odoo Menu
  • Sign in
  • Try it free
  • Apps
    Finance
    • Accounting
    • Invoicing
    • Expenses
    • Spreadsheet (BI)
    • Documents
    • Sign
    Sales
    • CRM
    • Sales
    • POS Shop
    • POS Restaurant
    • Subscriptions
    • Rental
    Websites
    • Website Builder
    • eCommerce
    • Blog
    • Forum
    • Live Chat
    • eLearning
    Supply Chain
    • Inventory
    • Manufacturing
    • PLM
    • Purchase
    • Maintenance
    • Quality
    Human Resources
    • Employees
    • Recruitment
    • Time Off
    • Appraisals
    • Referrals
    • Fleet
    Marketing
    • Social Marketing
    • Email Marketing
    • SMS Marketing
    • Events
    • Marketing Automation
    • Surveys
    Services
    • Project
    • Timesheets
    • Field Service
    • Helpdesk
    • Planning
    • Appointments
    Productivity
    • Discuss
    • Approvals
    • IoT
    • VoIP
    • Knowledge
    • WhatsApp
    Third party apps Odoo Studio Odoo Cloud Platform
  • Industries
    Retail
    • Book Store
    • Clothing Store
    • Furniture Store
    • Grocery Store
    • Hardware Store
    • Toy Store
    Food & Hospitality
    • Bar and Pub
    • Restaurant
    • Fast Food
    • Guest House
    • Beverage Distributor
    • Hotel
    Real Estate
    • Real Estate Agency
    • Architecture Firm
    • Construction
    • Estate Management
    • Gardening
    • Property Owner Association
    Consulting
    • Accounting Firm
    • Odoo Partner
    • Marketing Agency
    • Law firm
    • Talent Acquisition
    • Audit & Certification
    Manufacturing
    • Textile
    • Metal
    • Furnitures
    • Food
    • Brewery
    • Corporate Gifts
    Health & Fitness
    • Sports Club
    • Eyewear Store
    • Fitness Center
    • Wellness Practitioners
    • Pharmacy
    • Hair Salon
    Trades
    • Handyman
    • IT Hardware & Support
    • Solar Energy Systems
    • Shoe Maker
    • Cleaning Services
    • HVAC Services
    Others
    • Nonprofit Organization
    • Environmental Agency
    • Billboard Rental
    • Photography
    • Bike Leasing
    • Software Reseller
    Browse all Industries
  • Community
    Learn
    • Tutorials
    • Documentation
    • Certifications
    • Training
    • Blog
    • Podcast
    Empower Education
    • Education Program
    • Scale Up! Business Game
    • Visit Odoo
    Get the Software
    • Download
    • Compare Editions
    • Releases
    Collaborate
    • Github
    • Forum
    • Events
    • Translations
    • Become a Partner
    • Services for Partners
    • Register your Accounting Firm
    Get Services
    • Find a Partner
    • Find an Accountant
    • Meet an advisor
    • Implementation Services
    • Customer References
    • Support
    • Upgrades
    Github Youtube Twitter Linkedin Instagram Facebook Spotify
    +1 (650) 691-3277
    Get a demo
  • Pricing
  • Help

Odoo is the world's easiest all-in-one management software.
It includes hundreds of business apps:

  • CRM
  • e-Commerce
  • Accounting
  • Inventory
  • PoS
  • Project
  • MRP
All apps
You need to be registered to interact with the community.
All Posts People Badges
Tags (View all)
odoo accounting v14 pos v15
About this forum
You need to be registered to interact with the community.
All Posts People Badges
Tags (View all)
odoo accounting v14 pos v15
About this forum
Help

How do I restrict users to only one model in Odoo?

This question has been flagged
The question has been closed for reason: duplicate post
by Ray Carnes (ray) on 12/22/2024 15:51:35
security.xmlodoo17securityGroups
1567 Views
Avatar
Jugert Mucoimaj

I have tried almost everything and I need to limit users to see other models but just one. How can I do it using security rules in xml?


<odoo>
<data noupdate="1">
<!-- Payroll Admin Group -->
<record id="group_payroll_admin" model="res.groups">
<field name="name">Payroll Admin</field>
<field name="category_id" ref="base.module_category_human_resources"/>
</record>

<!-- Payroll User Group -->
<record id="group_payroll_user" model="res.groups">
<field name="name">Payroll User</field>
<field name="category_id" ref="base.module_category_human_resources"/>
</record>

<record id="group_attendance_user" model="res.groups">
<field name="name">Attendance User</field>
<field name="category_id" ref="base.module_category_human_resources"/>
</record>

<!-- Attendance User Group -->
<record id="group_attendance_user" model="res.groups">
<field name="name">Attendance User</field>
<field name="category_id" ref="base.module_category_human_resources"/>
</record>

<!-- Attendance Admin Group -->
<record id="group_attendance_admin" model="res.groups">
<field name="name">Attendance Admin</field>
<field name="category_id" ref="base.module_category_human_resources"/>
</record>

<!-- Record Rules -->
<!-- Admins have full access to payroll -->
<record id="payroll_admin_rule" model="ir.rule">
<field name="name">Payroll Admin Full Access</field>
<field name="model_id" ref="model_payroll_calculator"/>
<field name="groups" eval="[(4, ref('automatic_payroll.group_payroll_admin'))]"/>
<field name="domain_force">[]</field>
<field name="perm_read" eval="1"/>
<field name="perm_write" eval="1"/>
<field name="perm_create" eval="1"/>
<field name="perm_unlink" eval="1"/>
</record>

<!-- Users can only manage their payroll -->
<record id="payroll_user_rule" model="ir.rule">
<field name="name">Payroll User Limited Access</field>
<field name="model_id" ref="model_payroll_calculator"/>
<field name="groups" eval="[(4, ref('automatic_payroll.group_payroll_user'))]"/>
<field name="domain_force">[('create_uid', '=', user.id)]</field>
<field name="perm_read" eval="1"/>
<field name="perm_write" eval="1"/>
<field name="perm_create" eval="1"/>
<field name="perm_unlink" eval="0"/>
</record>

<!-- Admins have full access to payroll lines -->
<record id="payroll_line_admin_rule" model="ir.rule">
<field name="name">Payroll Line Admin Full Access</field>
<field name="model_id" ref="model_payroll_calculator_line"/>
<field name="groups" eval="[(4, ref('automatic_payroll.group_payroll_admin'))]"/>
<field name="domain_force">[]</field>
<field name="perm_read" eval="1"/>
<field name="perm_write" eval="1"/>
<field name="perm_create" eval="1"/>
<field name="perm_unlink" eval="1"/>
</record>

<!-- Users can only view payroll lines they own -->
<record id="payroll_line_user_rule" model="ir.rule">
<field name="name">Payroll Line User Limited Access</field>
<field name="model_id" ref="model_payroll_calculator_line"/>
<field name="groups" eval="[(4, ref('automatic_payroll.group_payroll_user'))]"/>
<field name="domain_force">[('create_uid', '=', user.id)]</field>
<field name="perm_read" eval="1"/>
<field name="perm_write" eval="1"/>
<field name="perm_create" eval="1"/>
<field name="perm_unlink" eval="0"/>
</record>

<!-- Admins have full access to contract templates -->
<record id="contract_template_admin_rule" model="ir.rule">
<field name="name">Contract Template Admin Full Access</field>
<field name="model_id" ref="model_contract_template"/>
<field name="groups" eval="[(4, ref('automatic_payroll.group_payroll_admin'))]"/>
<field name="domain_force">[]</field>
<field name="perm_read" eval="1"/>
<field name="perm_write" eval="1"/>
<field name="perm_create" eval="1"/>
<field name="perm_unlink" eval="1"/>
</record>

<!-- Users can only view contract templates they own -->
<record id="contract_template_user_rule" model="ir.rule">
<field name="name">Contract Template User Limited Access</field>
<field name="model_id" ref="model_contract_template"/>
<field name="groups" eval="[(4, ref('automatic_payroll.group_payroll_user'))]"/>
<field name="domain_force">[]</field>
<field name="perm_read" eval="1"/>
<field name="perm_write" eval="1"/>
<field name="perm_create" eval="1"/>
<field name="perm_unlink" eval="0"/>
</record>

<!-- Restrict Payroll User Group from accessing other modules -->
<record id="rule_payroll_user_restrict" model="ir.rule">
<field name="name">Restrict Payroll User Access</field>
<field name="model_id" ref="base.model_res_users"/>
<field name="groups" eval="[(4, ref('automatic_payroll.group_payroll_user'))]"/>
<field name="domain_force">[('id', '=', False)]</field>
<field name="perm_read" eval="1"/>
<field name="perm_write" eval="0"/>
<field name="perm_create" eval="0"/>
<field name="perm_unlink" eval="0"/>
</record>

<!-- Model Access Rights -->
<!-- Attendance User Access -->
<record id="access_attendance_user" model="ir.model.access">
<field name="name">Access Attendance User</field>
<field name="model_id" ref="hr_attendance.model_hr_attendance"/>
<field name="group_id" ref="group_attendance_user"/>
<field name="perm_read" eval="1"/>
<field name="perm_write" eval="1"/>
<field name="perm_create" eval="1"/>
<field name="perm_unlink" eval="0"/>
</record>

<!-- Attendance Admin Access -->
<record id="access_attendance_admin" model="ir.model.access">
<field name="name">Access Attendance Admin</field>
<field name="model_id" ref="hr_attendance.model_hr_attendance"/>
<field name="group_id" ref="group_attendance_admin"/>
<field name="perm_read" eval="1"/>
<field name="perm_write" eval="1"/>
<field name="perm_create" eval="1"/>
<field name="perm_unlink" eval="1"/>
</record>

<!-- Record Rules -->
<!-- Restrict Attendance User to Attendance Module -->
<record id="rule_attendance_user_access" model="ir.rule">
<field name="name">Attendance User Restricted Access</field>
<field name="model_id" ref="base.model_ir_ui_menu"/>
<field name="groups" eval="[(4, ref('group_attendance_user'))]"/>
<field name="domain_force" eval="[('id', '=', ref('hr_attendance.menu_hr_attendance_kiosk_mode'))]"/>
<field name="perm_read" eval="1"/>
<field name="perm_write" eval="0"/>
<field name="perm_create" eval="0"/>
<field name="perm_unlink" eval="0"/>
</record>

<!-- Restrict Attendance User to Attendance Models -->
<record id="rule_attendance_user_model_access" model="ir.rule">
<field name="name">Attendance User Model Restriction</field>
<field name="model_id" ref="base.model_ir_model_access"/>
<field name="groups" eval="[(4, ref('group_attendance_user'))]"/>
<field name="domain_force">[('model_id.model', 'in', ['hr.attendance'])]</field>
</record>

<!-- Allow Attendance User to Read Their Own User Record -->
<record id="rule_attendance_user_read_own_user" model="ir.rule">
<field name="name">Allow Attendance User to Read Own User</field>
<field name="model_id" ref="base.model_res_users"/>
<field name="groups" eval="[(4, ref('group_attendance_user'))]"/>
<field name="domain_force">[('id', '=', user.id)]</field>
<field name="perm_read" eval="1"/>
<field name="perm_write" eval="0"/>
<field name="perm_create" eval="0"/>
<field name="perm_unlink" eval="0"/>
</record>

</data>
</odoo>
Avatar
Discard
Enjoying the discussion? Don't just read, join in!

Create an account today to enjoy exclusive features and engage with our awesome community!

Sign up
Related Posts Replies Views Activity
Adding a new security group to an existing module Solved
security.xml odoo18 securityGroups Odoov18
Avatar
Avatar
Avatar
2
Dec 25
396
Error while posting invoice to ZATCA odoo sh Solved
odoo17
Avatar
Avatar
Avatar
Avatar
3
Jul 25
3293
How to send a real-time notification to POS UI using bus.bus in Odoo 17?
odoo17
Avatar
Avatar
1
Jun 25
5729
Odoo time-sheets rights to add
odoo17
Avatar
Avatar
2
May 25
3206
POS is not recognizing short barcodes like "95" or "96" (Code 39 or custom short codes)
odoo17
Avatar
1
May 25
2202
Community
  • Tutorials
  • Documentation
  • Forum
Open Source
  • Download
  • Github
  • Runbot
  • Translations
Services
  • Odoo.sh Hosting
  • Support
  • Upgrade
  • Custom Developments
  • Education
  • Find an Accountant
  • Find a Partner
  • Become a Partner
About us
  • Our company
  • Brand Assets
  • Contact us
  • Jobs
  • Events
  • Podcast
  • Blog
  • Customers
  • Legal • Privacy
  • Security
الْعَرَبيّة Català 简体中文 繁體中文 (台灣) Čeština Dansk Nederlands English Suomi Français Deutsch हिंदी Bahasa Indonesia Italiano 日本語 한국어 (KR) Lietuvių kalba Język polski Português (BR) română русский язык Slovenský jazyk slovenščina Español (América Latina) Español ภาษาไทย Türkçe українська Tiếng Việt

Odoo is a suite of open source business apps that cover all your company needs: CRM, eCommerce, accounting, inventory, point of sale, project management, etc.

Odoo's unique value proposition is to be at the same time very easy to use and fully integrated.

Website made with

Odoo Experience on YouTube

1. Use the live chat to ask your questions.
2. The operator answers within a few minutes.

Live support on Youtube
Watch now