{"id":444501,"date":"2023-11-28T18:26:49","date_gmt":"2023-11-28T17:26:49","guid":{"rendered":"https:\/\/www.kafinea.com\/documentation\/uncategorized\/access-rights\/"},"modified":"2023-11-28T18:26:49","modified_gmt":"2023-11-28T17:26:49","password":"","slug":"access-rights","status":"publish","type":"docs","link":"https:\/\/www.kafinea.com\/en\/help\/settings\/access-rights\/","title":{"rendered":"Access Rights"},"content":{"rendered":"<blockquote class=\"bq-exemple\">\n<p>\ud83d\udccd <strong>Where to find this module?<\/strong><br \/><em>Settings &gt; User Management &gt; Access Rights<\/em><\/p>\n<\/blockquote>\n<hr>\n<h2>Introduction<\/h2>\n<p>Kafinea&#8217;s <strong>access rights<\/strong> system allows you to precisely control what each user can see and do in the application. It is based on four complementary levels: <\/p>\n<div style=\"overflow-x:auto\">\n<table>\n<thead>\n<tr>\n<th>Level<\/th>\n<th>Role<\/th>\n<th>Configuration Screen<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td><strong>Roles<\/strong><\/td>\n<td>Define the organizational hierarchy<\/td>\n<td><em>Settings &gt; User Management &gt; Roles<\/em><\/td>\n<\/tr>\n<tr>\n<td><strong>Profiles<\/strong><\/td>\n<td>Define permissions module by module<\/td>\n<td><em>Settings &gt; User Management &gt; Profiles<\/em><\/td>\n<\/tr>\n<tr>\n<td><strong>Sharing Rules<\/strong><\/td>\n<td>Define data visibility between users<\/td>\n<td><em>Settings &gt; User Management &gt; Sharing Rules<\/em><\/td>\n<\/tr>\n<tr>\n<td><strong>Groups<\/strong><\/td>\n<td>Group users for data sharing<\/td>\n<td><em>Settings &gt; User Management &gt; Groups<\/em><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<blockquote>\n<p><strong>Good to know<\/strong>: A <strong>standard administrator<\/strong> user has full access to all modules and all data, regardless of the configured roles, profiles, and sharing rules. There are two types of administrators in Kafinea: <\/p>\n<ul>\n<li><strong>Standard administrator<\/strong>: Full access to data and all system configuration.<\/li>\n<li><strong>Limited administrator<\/strong>: Data rights identical to a normal user (defined by their profile and role), but with access to system configuration\u2014except for permission management (users, profiles, roles, groups, sharing rules).<\/li>\n<\/ul>\n<p>Access restrictions only apply to non-administrator users (and to limited administrators regarding data).<\/p>\n<\/blockquote>\n<hr>\n<h2>1. Administrators<\/h2>\n<p>By default, access restrictions do not apply to administrators. Kafinea offers two types of administrative accounts: <\/p>\n<h3>Standard Administrator<\/h3>\n<p>The standard administrator has full authority over the entire application.<\/p>\n<ul>\n<li><strong>Data access<\/strong>: can view, modify, and delete any record in any module, regardless of hierarchy or sharing rules.<\/li>\n<li><strong>Configuration<\/strong>: full access to all settings screens (users, profiles, roles, module manager, system settings, etc.).<\/li>\n<li><strong>Security<\/strong>: this is the only profile that can enable or disable other administrator accounts.<\/li>\n<\/ul>\n<h3>Limited Administrator<\/h3>\n<p>The limited administrator is a hybrid profile designed to delegate settings management without risk of privilege escalation.<\/p>\n<ul>\n<li><strong>Data access<\/strong>: identical to a normal user\u2014their rights are defined by their profile and role. They only see what their profile authorizes. <\/li>\n<li><strong>Settings access<\/strong>: can access most configuration screens (workflows, SMTP, features, logs, etc.).<\/li>\n<li><strong>Restrictions<\/strong>: cannot access permission management\u2014the <strong>Users<\/strong>, <strong>Profiles<\/strong>, <strong>Roles<\/strong>, <strong>Groups<\/strong>, and <strong>Sharing Rules<\/strong> screens are hidden from them. This prevents any privilege escalation (they cannot grant themselves additional rights). <\/li>\n<li><strong>Recommended use<\/strong>: IT manager who manages workflows or SMTP, but should not access invoicing or accounting.<\/li>\n<\/ul>\n<blockquote class=\"bq-exemple\">\n<p><strong>Concrete example<\/strong>: an IT manager with the &#8220;Internal Support&#8221; profile (limited access to HR and accounting modules) can be a limited admin to manage workflows and SMTP, without ever being able to view payslips or modify other users&#8217; rights.<\/p>\n<\/blockquote>\n<blockquote>\n<p><strong>How to enable a limited administrator?<\/strong>: In a user&#8217;s record, check the <strong>Limited Admin<\/strong> box. This option is only available to standard administrators. <\/p>\n<\/blockquote>\n<hr>\n<h2>2. Roles<\/h2>\n<h3>Principle<\/h3>\n<p>A <strong>role<\/strong> defines a user&#8217;s position in the organization&#8217;s hierarchy. Roles are organized in a tree structure (organizational chart). This hierarchy determines <strong>which data a user can see<\/strong>:  <\/p>\n<ul>\n<li>A <strong>parent<\/strong> role can see the data of its <strong>child<\/strong> roles (subordinates)<\/li>\n<li>A <strong>child<\/strong> role only sees its own data (unless sharing rules allow otherwise)<\/li>\n<\/ul>\n<h3>Configuration<\/h3>\n<p>To manage roles: <em><strong>Settings &gt; User Management &gt; Roles<\/strong><\/em>.<\/p>\n<ol>\n<li>The screen displays the complete role tree<\/li>\n<li>Click on a role to edit it, or use the <strong>Add Role<\/strong> button to create a new one<\/li>\n<li>Each role must be attached to a parent role (except the root role)<\/li>\n<li>Associate one or more <strong>profiles<\/strong> with the role\u2014it is the profile that determines detailed permissions<\/li>\n<\/ol>\n<blockquote class=\"bq-important\">\n<p><strong>Important<\/strong>: Each user is associated with <strong>a single role<\/strong>. This role determines both their hierarchical position and their permissions (via the profiles associated with the role). <\/p>\n<\/blockquote>\n<h3>Hierarchy in Practice<\/h3>\n<p><strong>Example<\/strong>: a company with the following structure:<\/p>\n<pre><code>Directeur G\u00e9n\u00e9ral\n\u251c\u2500\u2500 Directeur Commercial\n\u2502   \u251c\u2500\u2500 Responsable Ventes France\n\u2502   \u2502   \u2514\u2500\u2500 Commercial France\n\u2502   \u2514\u2500\u2500 Responsable Ventes Export\n\u2502       \u2514\u2500\u2500 Commercial Export\n\u2514\u2500\u2500 Directeur Financier\n    \u251c\u2500\u2500 Comptable\n    \u2514\u2500\u2500 Contr\u00f4leur de gestion\n<\/code><\/pre>\n<p>In this configuration:<\/p>\n<ul>\n<li>The <strong>General Manager<\/strong> sees data from all roles<\/li>\n<li>The <strong>Sales Director<\/strong> sees data from their subordinates (Managers and Sales Representatives) but not from the Finance Director<\/li>\n<li>A <strong>France Sales Representative<\/strong> only sees their own data<\/li>\n<\/ul>\n<hr>\n<h2>3. Profiles<\/h2>\n<h3>Principle<\/h3>\n<p>A <strong>profile<\/strong> defines <strong>detailed permissions<\/strong> module by module. It is the core of the access rights system. A profile determines:  <\/p>\n<ol>\n<li><strong>Module access<\/strong>: is the module visible and accessible for this profile?<\/li>\n<li><strong>Authorized actions<\/strong>: create, view, modify, delete<\/li>\n<li><strong>Field access<\/strong>: for each module, which fields are visible and\/or editable<\/li>\n<li><strong>Global rights<\/strong>: &#8220;View All&#8221; and &#8220;Edit All&#8221; (optional)<\/li>\n<li><strong>Tool rights<\/strong>: import, export, duplicate merging, etc.<\/li>\n<\/ol>\n<h3>Configuration<\/h3>\n<p>To manage profiles: <em><strong>Settings &gt; User Management &gt; Profiles<\/strong><\/em>.<\/p>\n<ol>\n<li>Click on an existing profile to edit it, or click <strong>Add Profile<\/strong> to create a new one<\/li>\n<li>In the editing screen, you see the list of all modules with their options<\/li>\n<\/ol>\n<h3>Global Permissions<\/h3>\n<blockquote class=\"bq-note\">\n<p><strong>Note<\/strong>: These options are generally not visible in Kafinea&#8217;s default interface to avoid major configuration errors. They only appear if they are already active for an existing profile. <\/p>\n<\/blockquote>\n<p>At the top of a profile&#8217;s editing screen, two global options may be available:<\/p>\n<div style=\"overflow-x:auto\">\n<table>\n<thead>\n<tr>\n<th>Global Permission<\/th>\n<th>Effect<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td><strong>View All<\/strong><\/td>\n<td>The user can view <strong>all records<\/strong> in <strong>all modules<\/strong>, regardless of the owner. Sharing rules and role hierarchy no longer apply for viewing.<\/td>\n<\/tr>\n<tr>\n<td><strong>Edit All<\/strong><\/td>\n<td>The user can modify <strong>all records<\/strong> in <strong>all modules<\/strong>, regardless of the owner.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<blockquote>\n<p><strong>Warning<\/strong>: &#8220;View All&#8221; and &#8220;Edit All&#8221; are very powerful rights. They override sharing rules and role hierarchy. Reserve them for profiles that truly need them (e.g., management, administrative support).  <\/p>\n<\/blockquote>\n<h3>Permissions by Module<\/h3>\n<p>For each module, you can configure:<\/p>\n<p><strong>Module access<\/strong> (checkbox):<\/p>\n<ul>\n<li><strong>Checked<\/strong>: the module is accessible for this profile<\/li>\n<li><strong>Unchecked<\/strong>: the module is completely invisible and inaccessible<\/li>\n<\/ul>\n<p><strong>Available actions<\/strong> (when the module is accessible):<\/p>\n<div style=\"overflow-x:auto\">\n<table>\n<thead>\n<tr>\n<th>Action<\/th>\n<th>Description<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td><strong>Create<\/strong><\/td>\n<td>The user can create new records in this module<\/td>\n<\/tr>\n<tr>\n<td><strong>View Detail<\/strong><\/td>\n<td>The user can view detailed records<\/td>\n<\/tr>\n<tr>\n<td><strong>Edit<\/strong><\/td>\n<td>The user can modify existing records<\/td>\n<\/tr>\n<tr>\n<td><strong>Delete<\/strong><\/td>\n<td>The user can delete records<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<blockquote>\n<p><strong>Good to know<\/strong>: If a module is unchecked (access removed), <strong>all actions<\/strong> are automatically blocked, even if they were individually checked previously. Rechecking the module restores action permissions as they were configured. <\/p>\n<\/blockquote>\n<h3>Field-Level Permissions<\/h3>\n<p>For each accessible module, you can define the visibility of each field:<\/p>\n<div style=\"overflow-x:auto\">\n<table>\n<thead>\n<tr>\n<th>Level<\/th>\n<th>Description<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td><strong>Visible and Editable<\/strong><\/td>\n<td>The field is displayed and can be modified by the user<\/td>\n<\/tr>\n<tr>\n<td><strong>Read-Only<\/strong><\/td>\n<td>The field is displayed but cannot be modified<\/td>\n<\/tr>\n<tr>\n<td><strong>Hidden<\/strong><\/td>\n<td>The field is not displayed for this profile<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<blockquote>\n<p><strong>Good to know<\/strong>: Some system fields (such as the record name) cannot be hidden.<\/p>\n<\/blockquote>\n<h3>Utility Tool Rights<\/h3>\n<p>Each profile can also configure access to cross-functional tools:<\/p>\n<div style=\"overflow-x:auto\">\n<table>\n<thead>\n<tr>\n<th>Tool<\/th>\n<th>Description<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td><strong>Import<\/strong><\/td>\n<td>Import data from a CSV file<\/td>\n<\/tr>\n<tr>\n<td><strong>Export<\/strong><\/td>\n<td>Export data from a module<\/td>\n<\/tr>\n<tr>\n<td><strong>Duplicate Merging<\/strong><\/td>\n<td>Merge duplicate records<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<h3>Combining Multiple Profiles<\/h3>\n<p>A role can be associated with <strong>multiple profiles<\/strong>. In this case, permissions <strong>accumulate<\/strong> according to the <strong>most permissive<\/strong> principle: <\/p>\n<ul>\n<li>If profile A allows creation in the Invoices module and profile B prohibits it, the user <strong>can<\/strong> create (the most permissive right prevails)<\/li>\n<li>If profile A grants access to the Contacts module and profile B grants access to the Invoices module, the user has access to <strong>both<\/strong> modules<\/li>\n<\/ul>\n<blockquote>\n<p><strong>Tip<\/strong>: To simplify management, create thematic profiles (e.g., &#8220;Sales Access,&#8221; &#8220;Accounting Access&#8221;) that you combine according to each role&#8217;s needs, rather than creating a monolithic profile per role.<\/p>\n<\/blockquote>\n<hr>\n<h2>4. Sharing Rules<\/h2>\n<h3>Principle<\/h3>\n<p><strong>Sharing rules<\/strong> define the <strong>default data visibility<\/strong> between users. They complement the role hierarchy by specifying, module by module, whether users can see each other&#8217;s data. <\/p>\n<h3>Configuration<\/h3>\n<p>To manage sharing rules: <em><strong>Settings &gt; User Management &gt; Sharing Rules<\/strong><\/em>.<\/p>\n<h3>The Three Sharing Levels<\/h3>\n<div style=\"overflow-x:auto\">\n<table>\n<thead>\n<tr>\n<th>Rule<\/th>\n<th>Description<\/th>\n<th>Use Case<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td><strong>Private<\/strong><\/td>\n<td>Each user only sees their own records and those of their subordinates (according to role hierarchy)<\/td>\n<td>Sensitive data: HR, accounting, personal data<\/td>\n<\/tr>\n<tr>\n<td><strong>Public: Read-Only<\/strong><\/td>\n<td>All users can view records, but only the owner (and their superiors) can modify them<\/td>\n<td>Data to view but not modify by all: product catalog, shared contacts<\/td>\n<\/tr>\n<tr>\n<td><strong>Public: Read\/Write<\/strong><\/td>\n<td>All users can view and modify all records<\/td>\n<td>Collaborative data: projects, shared tasks<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<blockquote class=\"bq-important\">\n<p><strong>Important<\/strong>: Sharing rules define the <strong>default<\/strong> behavior. <strong>Exceptions<\/strong> can be added to grant additional access to specific roles, groups, or users. <\/p>\n<\/blockquote>\n<h3>Sharing Exceptions<\/h3>\n<p>When the default rule is &#8220;Private&#8221; or &#8220;Public: Read-Only,&#8221; you can create exceptions to extend access:<\/p>\n<ol>\n<li>In the sharing rules screen, click <strong>Add Exception<\/strong> for the desired module<\/li>\n<li>Choose <strong>who shares<\/strong> (a role, a group, or a role and its subordinates)<\/li>\n<li>Choose <strong>with whom<\/strong> (a role, a group, or a role and its subordinates)<\/li>\n<li>Choose the <strong>access level<\/strong>: read-only or read\/write<\/li>\n<\/ol>\n<p><strong>Example<\/strong>: The &#8220;Invoices&#8221; module is in &#8220;Private&#8221; mode. You want the collections team to be able to view invoices from the entire company. Create an exception that shares invoices from &#8220;All Roles and Subordinates&#8221; to the &#8220;Collections&#8221; group in &#8220;Read-Only.&#8221;  <\/p>\n<h3>Recalculating Sharing Rules<\/h3>\n<p>After modifying sharing rules, click the <strong>Recalculate<\/strong> button for the changes to take effect.<\/p>\n<blockquote>\n<p><strong>Warning<\/strong>: Recalculation may take a few seconds on instances with many users and data.<\/p>\n<\/blockquote>\n<hr>\n<h2>5. Groups<\/h2>\n<h3>Principle<\/h3>\n<p>A <strong>group<\/strong> is a set of users, roles, or other groups. Groups are primarily used to: <\/p>\n<ul>\n<li><strong>Assign records<\/strong> to a team rather than a single user<\/li>\n<li><strong>Create sharing exceptions<\/strong> to grant access to a cross-functional team<\/li>\n<\/ul>\n<h3>Configuration<\/h3>\n<p>To manage groups: <em><strong>Settings &gt; User Management &gt; Groups<\/strong><\/em>.<\/p>\n<p>A group can contain:<\/p>\n<ul>\n<li>Individual <strong>users<\/strong><\/li>\n<li>Entire <strong>roles<\/strong> (all users with that role)<\/li>\n<li><strong>Roles and subordinates<\/strong> (the role and all its children in the hierarchy)<\/li>\n<li>Other <strong>groups<\/strong> (nesting)<\/li>\n<\/ul>\n<p><strong>Example<\/strong>: The &#8220;Executive Committee&#8221; group contains the &#8220;Sales Director,&#8221; &#8220;Finance Director,&#8221; and &#8220;General Manager&#8221; roles.<\/p>\n<hr>\n<h2>6. How Permissions Are Evaluated<\/h2>\n<p>When a user tries to access a record or perform an action, Kafinea checks permissions in the following order:<\/p>\n<ol>\n<li><strong>Is the user a standard administrator?<\/strong>  \u2192 If yes, full data access, no further checks. For a <strong>limited administrator<\/strong>, the following checks apply normally. <\/li>\n<li><strong>Is the module active?<\/strong>  \u2192 If the module is disabled, no one (except administrators) has access<\/li>\n<li><strong>Does the profile allow module access?<\/strong>  \u2192 If none of the user&#8217;s profiles authorize the module, access denied<\/li>\n<li><strong>Is the action authorized by the profile?<\/strong>  \u2192 Check for the specific action (create, view, modify, delete)<\/li>\n<li><strong>Do the sharing rules allow access to this record?<\/strong>  \u2192 Check owner, hierarchy, and exceptions<\/li>\n<\/ol>\n<blockquote>\n<p><strong>Good to know<\/strong>: When a user has multiple profiles, Kafinea applies the <strong>most permissive<\/strong> principle: if at least one profile authorizes an action, it is authorized.<\/p>\n<\/blockquote>\n<hr>\n<h2>7. Common Configuration Scenarios<\/h2>\n<h3>Scenario 1: A Sales Representative Who Only Sees Their Clients<\/h3>\n<ol>\n<li>Create a <strong>profile<\/strong> &#8220;Sales Representative&#8221; with access to Contacts, Accounts, Quotes, Orders modules<\/li>\n<li>In the <strong>sharing rules<\/strong>, set the Contacts and Accounts modules to &#8220;Private&#8221;<\/li>\n<li>Create a <strong>role<\/strong> &#8220;Sales Representative&#8221; under the &#8220;Sales Manager&#8221; role<\/li>\n<li>Associate the &#8220;Sales Representative&#8221; profile with the role<\/li>\n<\/ol>\n<p><strong>Result<\/strong>: the sales representative only sees their own clients and those of any subordinates. Their manager, however, sees data from all their sales representatives. <\/p>\n<h3>Scenario 2: An Accountant with Read Access to Sales<\/h3>\n<ol>\n<li>Create a <strong>profile<\/strong> &#8220;Accounting&#8221; with full access to accounting modules (Invoices, Payments, etc.)<\/li>\n<li>Create a second <strong>profile<\/strong> &#8220;Sales Read&#8221; with read-only access to sales modules (Quotes, Orders)\u2014check &#8220;View Detail&#8221; but uncheck &#8220;Create,&#8221; &#8220;Edit,&#8221; and &#8220;Delete&#8221;<\/li>\n<li>Associate <strong>both profiles<\/strong> with the &#8220;Accountant&#8221; role<\/li>\n<\/ol>\n<p><strong>Result<\/strong>: the accountant can manage accounting freely while viewing quotes and orders without being able to modify them.<\/p>\n<h3>Scenario 3: A Cross-Functional Project Team<\/h3>\n<ol>\n<li>Create a <strong>group<\/strong> &#8220;Project Alpha Team&#8221; containing the relevant users<\/li>\n<li>In the <strong>sharing rules<\/strong> for the Projects module (in &#8220;Private&#8221; mode), add an exception granting &#8220;Read\/Write&#8221; access to the &#8220;Project Alpha Team&#8221; group<\/li>\n<\/ol>\n<p><strong>Result<\/strong>: team members can all collaborate on projects assigned to them, regardless of their hierarchical position.<\/p>\n<h3>Scenario 4: Restricting Access to Leave Requests<\/h3>\n<ol>\n<li>In the <strong>profile<\/strong> for the relevant role, ensure the &#8220;Leave Requests&#8221; module is <strong>checked<\/strong> (accessible)<\/li>\n<li>Verify that the &#8220;Create,&#8221; &#8220;View Detail,&#8221; and &#8220;Edit&#8221; actions are checked<\/li>\n<li>If the user still cannot modify requests, check the module&#8217;s <strong>sharing rules<\/strong><\/li>\n<\/ol>\n<blockquote>\n<p><strong>Good to know<\/strong>: If a module does not appear in the profile editing screen, this may mean the module is disabled. Contact your administrator to check the module&#8217;s status in <em><strong>Settings &gt; Module Manager<\/strong><\/em>. <\/p>\n<\/blockquote>\n<hr>\n<h2>8. Troubleshooting<\/h2>\n<h3>A User Does Not See a Module in the Menu<\/h3>\n<p><strong>Possible causes<\/strong>:<\/p>\n<ol>\n<li>The module is <strong>unchecked<\/strong> in their profile \u2192 Edit the profile in <em>Settings &gt; User Management &gt; Profiles<\/em> and check the module<\/li>\n<li>The module is <strong>disabled<\/strong> at the system level \u2192 Check in <em>Settings &gt; Module Manager<\/em><\/li>\n<li>The module is not in the user&#8217;s <strong>menu<\/strong> \u2192 Check the menu configuration<\/li>\n<\/ol>\n<h3>A User Cannot Modify a Record<\/h3>\n<p><strong>Possible causes<\/strong>:<\/p>\n<ol>\n<li>The &#8220;<strong>Edit<\/strong>&#8221; action is unchecked in their profile \u2192 Edit the profile and check &#8220;Edit&#8221; for the relevant module<\/li>\n<li>The record belongs to another user and the <strong>sharing rules<\/strong> do not allow modification \u2192 Check sharing rules or add an exception<\/li>\n<li>The record is <strong>locked<\/strong> \u2192 Some modules allow records to be locked (e.g., validated invoices)<\/li>\n<\/ol>\n<h3>A User Can Create but Not Modify<\/h3>\n<p><strong>Probable cause<\/strong>: The profile allows &#8220;Create&#8221; but not &#8220;Edit.&#8221; These two rights are independent. <\/p>\n<p><strong>Solution<\/strong>: Edit the profile in <em>Settings &gt; User Management &gt; Profiles<\/em>, check the &#8220;Edit&#8221; box for the relevant module, then save.<\/p>\n<h3>Shared Lists Are Not Visible to a User<\/h3>\n<p><strong>Possible causes<\/strong>:<\/p>\n<ol>\n<li>The relevant module is <strong>not accessible<\/strong> in the user&#8217;s profile \u2192 Lists for a module are only visible if the user has access to the module<\/li>\n<li>The module is <strong>disabled<\/strong> \u2192 Check in <em>Settings &gt; Module Manager<\/em><\/li>\n<\/ol>\n<h3>How to Check a User&#8217;s Effective Rights<\/h3>\n<p>To diagnose a rights issue, check in order:<\/p>\n<ol>\n<li>The user&#8217;s <strong>role<\/strong>: <em>Settings &gt; User Management &gt; Users<\/em> \u2192 view the assigned role<\/li>\n<li>The <strong>profiles<\/strong> associated with the role: <em>Settings &gt; User Management &gt; Roles<\/em> \u2192 view the role&#8217;s profiles<\/li>\n<li>The <strong>profile permissions<\/strong>: <em>Settings &gt; User Management &gt; Profiles<\/em> \u2192 edit the profile to see permissions module by module<\/li>\n<li>The <strong>sharing rules<\/strong>: <em>Settings &gt; User Management &gt; Sharing Rules<\/em> \u2192 check the module&#8217;s sharing mode<\/li>\n<\/ol>\n<blockquote class=\"bq-astuce\">\n<p><strong>Tip<\/strong>: If you are an administrator and use Kafinea&#8217;s AI assistant, you can directly ask questions like &#8220;Why can&#8217;t user john modify leave requests?&#8221; The assistant has a permission diagnostic tool that analyzes the configuration and tells you precisely the cause of the problem. <\/p>\n<\/blockquote>\n<hr>\n<h2>9. Best Practices<\/h2>\n<ul>\n<li><strong>Define your hierarchy first<\/strong>: create roles mirroring your organizational chart<\/li>\n<li><strong>Create reusable thematic profiles<\/strong>: &#8220;Sales,&#8221; &#8220;Accounting,&#8221; &#8220;HR,&#8221; rather than one profile per person<\/li>\n<li><strong>Apply the principle of least privilege<\/strong>: only grant the rights strictly necessary for each function<\/li>\n<li><strong>Use groups<\/strong> for cross-functional teams rather than modifying role hierarchy<\/li>\n<li><strong>Document your choices<\/strong>: note why each profile was configured in a certain way, to facilitate maintenance<\/li>\n<li><strong>Test rights<\/strong>: after a modification, log in with a test account having the modified profile to verify behavior<\/li>\n<\/ul>\n<hr>\n<h2>10. Frequently Asked Questions<\/h2>\n<p><strong>How Do I Grant Module Access to a Single User?<\/strong><br \/>\nCreate a specific profile with access to the desired module, then associate this profile with the user&#8217;s role. If other users have the same role and should not have this access, create a dedicated role for this user. <\/p>\n<p><strong>Are Rights Applied Immediately?<\/strong><br \/>\nYes, profile modifications are applied immediately. The affected user will see the changes upon their next page load. For sharing rules, remember to click the <strong>Recalculate<\/strong> button after your modifications.  <\/p>\n<p><strong>How Do I Allow Two Teams to Share Their Data?<\/strong><br \/>\nCreate a group containing members of both teams, then add an exception in the sharing rules to grant access to this group.<\/p>\n<p><strong>How Do I Completely Remove Access to a Module?<\/strong><br \/>\nEdit the user&#8217;s profile and uncheck the module. The module will disappear from the menu and all actions will be blocked. <\/p>\n<p><strong>What Happens When a User Has Multiple Profiles?<\/strong><br \/>\nPermissions accumulate according to the most permissive principle. If one profile authorizes an action and another prohibits it, the action is authorized. This is useful for combining thematic profiles (e.g., &#8220;Sales Access&#8221; + &#8220;Accounting Access&#8221;).  <\/p>\n<p><strong>A user says they don&#8217;t see the &#8220;Edit&#8221; button on a record. What should I check?<\/strong><br \/>\nCheck in this order: 1) Is the &#8220;Edit&#8221; action checked in the profile? 2) Is the record locked? 3) Do the sharing rules allow this user to modify this record?  <\/p>\n<hr>\n<h2>Glossary<\/h2>\n<div style=\"overflow-x:auto\">\n<table>\n<thead>\n<tr>\n<th>Term<\/th>\n<th>Definition<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td><strong>Role<\/strong><\/td>\n<td>Position in the organizational hierarchy, determines data visibility through subordination<\/td>\n<\/tr>\n<tr>\n<td><strong>Profile<\/strong><\/td>\n<td>Set of detailed permissions (access to modules, actions, fields) associated with one or more roles<\/td>\n<\/tr>\n<tr>\n<td><strong>Sharing Rule<\/strong><\/td>\n<td>Rule defining the default visibility of a module&#8217;s data between users<\/td>\n<\/tr>\n<tr>\n<td><strong>Group<\/strong><\/td>\n<td>Set of users, roles, or other groups, used for record assignment and sharing exceptions<\/td>\n<\/tr>\n<tr>\n<td><strong>Global Permission<\/strong><\/td>\n<td>Cross-cutting right (&#8220;View All&#8221; or &#8220;Modify All&#8221;) that overrides sharing rules and hierarchy<\/td>\n<\/tr>\n<tr>\n<td><strong>Sharing Exception<\/strong><\/td>\n<td>Additional rule that grants read or read\/write access to a specific role or group<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<hr>\n<h2>Related references \ud83d\udd17<\/h2>\n<ul>\n<li><a href=\"https:\/\/www.kafinea.com\/fr\/documentation\/parametrage\/les-utilisateurs\/\">Users<\/a><\/li>\n<li><a href=\"https:\/\/www.kafinea.com\/en\/documentation\/kafinea-interface\/the-layout-manager\/\">The Layout Manager<\/a><\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>\ud83d\udccd Where to find this module?Settings &gt; User Management &gt; Access Rights Introduction Kafinea&#8217;s access rights system allows you to precisely control what each user can see and do in the application. It is based on four complementary levels: Level Role Configuration Screen Roles Define the organizational hierarchy Settings &gt; User Management &gt; Roles Profiles&#8230;<\/p>\n","protected":false},"author":17,"featured_media":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"_uag_custom_page_level_css":"","_kad_post_transparent":"","_kad_post_title":"","_kad_post_layout":"","_kad_post_sidebar_id":"","_kad_post_content_style":"","_kad_post_vertical_padding":"","_kad_post_feature":"","_kad_post_feature_position":"","_kad_post_header":false,"_kad_post_footer":false,"_kad_post_classname":"","footnotes":""},"doc_category":[771],"doc_tag":[],"class_list":["post-444501","docs","type-docs","status-publish","hentry","doc_category-settings"],"year_month":"2026-08","word_count":2671,"total_views":"1","reactions":{"happy":"0","normal":"0","sad":"0"},"author_info":{"name":"Kenny Legros","author_nicename":"kenny-legros","author_url":"https:\/\/www.kafinea.com\/en\/author\/kenny-legros\/"},"doc_category_info":[{"term_name":"Settings","term_url":"https:\/\/www.kafinea.com\/en\/help\/settings\/"}],"doc_tag_info":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Help - Access Rights &#8226; Kafinea<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.kafinea.com\/en\/help\/settings\/access-rights\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Help - Access Rights &#8226; Kafinea\" \/>\n<meta property=\"og:description\" content=\"\ud83d\udccd Where to find this module?Settings &gt; User Management &gt; Access Rights Introduction Kafinea&#8217;s access rights system allows you to precisely control what each user can see and do in the application. It is based on four complementary levels: Level Role Configuration Screen Roles Define the organizational hierarchy Settings &gt; User Management &gt; Roles Profiles...\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.kafinea.com\/en\/help\/settings\/access-rights\/\" \/>\n<meta property=\"og:site_name\" content=\"Kafinea\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"13 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.kafinea.com\\\/en\\\/help\\\/settings\\\/access-rights\\\/\",\"url\":\"https:\\\/\\\/www.kafinea.com\\\/en\\\/help\\\/settings\\\/access-rights\\\/\",\"name\":\"Help - Access Rights &#8226; Kafinea\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.kafinea.com\\\/en\\\/#website\"},\"datePublished\":\"2023-11-28T17:26:49+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.kafinea.com\\\/en\\\/help\\\/settings\\\/access-rights\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.kafinea.com\\\/en\\\/help\\\/settings\\\/access-rights\\\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.kafinea.com\\\/en\\\/help\\\/settings\\\/access-rights\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Accueil\",\"item\":\"https:\\\/\\\/www.kafinea.com\\\/en\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Access Rights\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.kafinea.com\\\/en\\\/#website\",\"url\":\"https:\\\/\\\/www.kafinea.com\\\/en\\\/\",\"name\":\"Kafinea\",\"description\":\"Une solution unique pour toutes vos ambitions\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.kafinea.com\\\/en\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.kafinea.com\\\/en\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.kafinea.com\\\/en\\\/#organization\",\"name\":\"Kafinea\",\"url\":\"https:\\\/\\\/www.kafinea.com\\\/en\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.kafinea.com\\\/en\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.kafinea.com\\\/wp-content\\\/uploads\\\/2024\\\/10\\\/Logo-Kafinea-SVG-orange-bleu.svg\",\"contentUrl\":\"https:\\\/\\\/www.kafinea.com\\\/wp-content\\\/uploads\\\/2024\\\/10\\\/Logo-Kafinea-SVG-orange-bleu.svg\",\"width\":296.31,\"height\":66.48,\"caption\":\"Kafinea\"},\"image\":{\"@id\":\"https:\\\/\\\/www.kafinea.com\\\/en\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.linkedin.com\\\/company\\\/kafinea\\\/\"]}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Help - Access Rights &#8226; Kafinea","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.kafinea.com\/en\/help\/settings\/access-rights\/","og_locale":"en_US","og_type":"article","og_title":"Help - Access Rights &#8226; Kafinea","og_description":"\ud83d\udccd Where to find this module?Settings &gt; User Management &gt; Access Rights Introduction Kafinea&#8217;s access rights system allows you to precisely control what each user can see and do in the application. It is based on four complementary levels: Level Role Configuration Screen Roles Define the organizational hierarchy Settings &gt; User Management &gt; Roles Profiles...","og_url":"https:\/\/www.kafinea.com\/en\/help\/settings\/access-rights\/","og_site_name":"Kafinea","twitter_card":"summary_large_image","twitter_misc":{"Est. reading time":"13 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/www.kafinea.com\/en\/help\/settings\/access-rights\/","url":"https:\/\/www.kafinea.com\/en\/help\/settings\/access-rights\/","name":"Help - Access Rights &#8226; Kafinea","isPartOf":{"@id":"https:\/\/www.kafinea.com\/en\/#website"},"datePublished":"2023-11-28T17:26:49+00:00","breadcrumb":{"@id":"https:\/\/www.kafinea.com\/en\/help\/settings\/access-rights\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.kafinea.com\/en\/help\/settings\/access-rights\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.kafinea.com\/en\/help\/settings\/access-rights\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Accueil","item":"https:\/\/www.kafinea.com\/en\/"},{"@type":"ListItem","position":2,"name":"Access Rights"}]},{"@type":"WebSite","@id":"https:\/\/www.kafinea.com\/en\/#website","url":"https:\/\/www.kafinea.com\/en\/","name":"Kafinea","description":"Une solution unique pour toutes vos ambitions","publisher":{"@id":"https:\/\/www.kafinea.com\/en\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.kafinea.com\/en\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.kafinea.com\/en\/#organization","name":"Kafinea","url":"https:\/\/www.kafinea.com\/en\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.kafinea.com\/en\/#\/schema\/logo\/image\/","url":"https:\/\/www.kafinea.com\/wp-content\/uploads\/2024\/10\/Logo-Kafinea-SVG-orange-bleu.svg","contentUrl":"https:\/\/www.kafinea.com\/wp-content\/uploads\/2024\/10\/Logo-Kafinea-SVG-orange-bleu.svg","width":296.31,"height":66.48,"caption":"Kafinea"},"image":{"@id":"https:\/\/www.kafinea.com\/en\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.linkedin.com\/company\/kafinea\/"]}]}},"uagb_featured_image_src":{"full":false,"thumbnail":false,"medium":false,"medium_large":false,"large":false,"1536x1536":false,"2048x2048":false},"uagb_author_info":{"display_name":"Kenny Legros","author_link":"https:\/\/www.kafinea.com\/en\/author\/kenny-legros\/"},"uagb_comment_info":0,"uagb_excerpt":"\ud83d\udccd Where to find this module?Settings &gt; User Management &gt; Access Rights Introduction Kafinea&#8217;s access rights system allows you to precisely control what each user can see and do in the application. It is based on four complementary levels: Level Role Configuration Screen Roles Define the organizational hierarchy Settings &gt; User Management &gt; Roles Profiles...","_links":{"self":[{"href":"https:\/\/www.kafinea.com\/en\/wp-json\/wp\/v2\/docs\/444501","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.kafinea.com\/en\/wp-json\/wp\/v2\/docs"}],"about":[{"href":"https:\/\/www.kafinea.com\/en\/wp-json\/wp\/v2\/types\/docs"}],"author":[{"embeddable":true,"href":"https:\/\/www.kafinea.com\/en\/wp-json\/wp\/v2\/users\/17"}],"replies":[{"embeddable":true,"href":"https:\/\/www.kafinea.com\/en\/wp-json\/wp\/v2\/comments?post=444501"}],"version-history":[{"count":0,"href":"https:\/\/www.kafinea.com\/en\/wp-json\/wp\/v2\/docs\/444501\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.kafinea.com\/en\/wp-json\/wp\/v2\/media?parent=444501"}],"wp:term":[{"taxonomy":"doc_category","embeddable":true,"href":"https:\/\/www.kafinea.com\/en\/wp-json\/wp\/v2\/doc_category?post=444501"},{"taxonomy":"doc_tag","embeddable":true,"href":"https:\/\/www.kafinea.com\/en\/wp-json\/wp\/v2\/doc_tag?post=444501"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}