Skip to Content

Top seller on the Odoo Apps Store Browse 100+ Odoo Apps

Click any field in Odoo and decide which roles may see it

Build Odoo access rights as roles by pointing at the screen instead of writing code. Hide a cost field, lock a posted invoice, or limit a dropdown to one team's records. Rules are checked when the record is saved, so imports and connected apps follow them too.

  • Odoo 17.0 – 19.0
  • Community & Enterprise
  • Odoo.sh · On-premise
  • Not for Odoo Online

Top seller on the Odoo Apps Store

sales on the Odoo Apps Store
3,000+
apps published
100+
countries running them
100+

Odoo access rights before and after Smart Access Manager

Without the connector by hand

  1. Ask a developer to write XML to hide a cost field.
  2. Write record rules by hand for each team's records.
  3. Open each user's form one by one to change their groups.
  4. Build a spreadsheet of who has access when an auditor asks.
  5. Trust that nobody edits a posted invoice.
  6. Remember to check that nobody holds two conflicting jobs.
  7. Archive or delete the account when someone leaves suddenly.

With the connector automatic

  1. Turn on the Inspector, click the field, pick hide or read-only.
  2. Draw the filter in Odoo's filter editor and pick the operations.
  3. Tick several people on the Access Board and assign in one go.
  4. Click Generate Now for a PDF, and a monthly pack is built for you.
  5. A saved condition locks the invoice while its status is Posted.
  6. Conflicting roles are refused at assignment, and a weekly check reviews users.
  7. Revoke Access removes every role and ends all open sessions.

Smart Access Manager features

Click the element you want restricted

You set a restriction by clicking the thing you want to restrict. Switch the Inspector on from the top bar, then move your cursor over the screen: fields light up blue, buttons green, tabs violet and menus orange. Click one, choose the role, then choose what should happen to it. There is no developer mode and no XML to edit, and the rule applies on the next page load.

Odoo form with the Smart Access Manager Inspector active, highlighting a field as the cursor hovers over it

Hand out roles from one screen

Assigning access happens on a single board instead of user by user. Every user is listed down one side and every role in the middle, so you tick several people and give them a role together. A ready-made template can be applied to a role, which then shows as APPLIED. Conflicts are flagged while you work, and roles a person holds indirectly are shown too.

Smart Access Manager Access Board in Odoo with users on the left and roles in the middle for assignment

Hide sensitive fields from a role

A junior salesperson can work on a quotation without ever seeing its margin. Pick the record type, select the fields and set the effect to hide. The value is removed from the data and not only from the form, so it cannot be exported, grouped or totaled, and it reads as empty through an outside connection. Filters and Group By entries that used the field go with it.

Odoo sales order shown before and after a Smart Access Manager rule hides the margin field

Limit what a dropdown offers

Sometimes the field is fine and only its choices are wrong. Filter Field Values narrows the records a dropdown may point at, so a salesperson picks from their own customers and an operator picks from the warehouse they were given. The condition is applied to the field's search, so people can still type in the dropdown, but records outside the allowed set never appear. Relational fields only.

Smart Access Manager rule in Odoo limiting a dropdown to the records one role is allowed to select

Show each role only its own records

Point a role at its own slice of the data. Draw the condition in Odoo's own filter editor, then choose whether matching records are the only ones the role sees or the ones it never sees. You also choose which operations the filter covers, so a role can read every sales order while editing only its own. Filters from several roles combine, and this only narrows access.

Odoo sales order list filtered by a Smart Access Manager Domain Access rule to matching records only

Lock records once they reach a state

Some rules belong to the record, not to the person. Write a condition such as status is Posted or total above 10,000, then say what happens while it holds: the whole record locks, only the fields you name freeze, deletion is refused, or chosen fields, buttons and tabs disappear. Each record is checked on its own, so one line in a list can be locked while the next stays editable.

Smart Access Manager conditional rule in Odoo freezing selected fields once the record matches the condition

Make the whole database read-only

One switch turns Odoo view-only for a role. Users still open everything their normal rights allow, but nothing is created, changed or deleted anywhere, while their own Preferences and notifications keep working. The same screen carries database-wide blocks for export, import and archiving, plus the print menu and the spreadsheet route. A global block wins over any permission you granted on a single record type.

Global Read-Only switch in Smart Access Manager with an Odoo record shown view-only for that role

Close an account in one action

When a laptop goes missing you can shut a person out immediately. Revoke Access on the user form takes away every Smart Access role, stops them signing back in, and ends all of their open sessions. Odoo asks you to confirm first, then shows an Access Revoked ribbon on the user. Restore Access reverses it, and you assign the roles again yourself.

Odoo user form with the Smart Access Manager kill switch and the Access Revoked ribbon

Keep conflicting duties apart

The pairs of jobs nobody should hold together are refused the moment someone tries. Name the role combinations once, for example creating a vendor and approving its payments. Assignments made from the role form, the board, a temporary grant or an approved request are then blocked, with a message naming both roles. A Security Officer can allow an exception, but only with a written justification kept beside the approval.

Conflict rule in Smart Access Manager listing role pairs Odoo refuses to assign to the same user

Answer auditors with plain-language records

Every access change is written down in words anyone can read: when it happened, who made it, which users and roles were touched, and what changed. From the same data a Security Officer produces PDFs such as the Access Matrix, Privileged Users or the permission change history for a chosen period. A monthly audit pack is created for the previous month without anyone asking for it.

Smart Access Manager activity log in Odoo listing access changes with user, role and what changed

Supported Odoo versions

Odoo versionEditionsHosting PriceLatest release
19.0 Community & Enterprise Odoo.sh · On-premise €129 19.0.1.0.0 Buy
18.0 Community & Enterprise Odoo.sh · On-premise €129 No release notes Buy
17.0 Community & Enterprise Odoo.sh · On-premise €129 No release notes Buy

Support for Smart Access Manager

The developers who build the app answer your tickets.

Free app support from purchase
60 days
First response in working hours, typical
4–6 hours
Support hours, 10:00–18:00 IST
Mon–Fri

How to set up roles and restrictions in Odoo

  1. Step 1

    Create a role

    Add a role and give it a name your business uses, or start from one of the ready-made templates. Everything you restrict later sits in this one bundle, which you then hand to people.

  2. Step 2

    Set record permissions

    Under Permissions, add a line per record type and tick view, edit, create or delete. Read-only covers look-only access in one click. Add a Domain Access line when the role should reach part of the records.

  3. Step 3

    Click what to hide

    Turn on the Inspector from the top bar and click the field, button, tab or menu that should go. Choose the role and the effect, and the rule is written for you.

  4. Step 4

    Assign the role to people

    Open the Access Board, tick the users who need the role and assign them in one go. One person's access can also be managed from their user form, including a grant that expires.

  5. Step 5

    Add the compliance checks

    A Security Officer sets which role pairs must stay apart, reviews risk scores and alerts, and generates audit PDFs for a period. A weekly check also reviews users against those rules.

Questions before you buy

Not answered here? Talk to the team.

It ships for Odoo 17.0, 18.0 and 19.0. Odoo Enterprise is supported on-premise and on Odoo.sh, and Odoo Community is supported as well. Odoo Online, the SaaS hosting, is not supported, so plan for a database where you can install apps yourself.

Not while they keep their admin permissions. Block Login, Global Read-Only, Block External API and the kill switch are refused for users who hold Settings or Access Rights permissions, and the role will not save. Remove those permissions from the user first, then assign the role. This stops anyone locking the database out of its own settings.

Record permissions are generous and field rules are strict. For a record type, an operation is allowed if any of the user's roles allows it, so keep a must-stay-read-only rule in a role only that person has, or use Global Read-Only, which no other role overrides. Among field rules the strictest wins: hidden beats read-only, read-only beats required.

No. Record Permissions and Domain Access only take access away. If Odoo's standard access rights already keep someone out of a record type, no role here will let them in. Treat it as a finer second layer on top of the groups a user already has.

Yes, when you leave the screen selection empty. The rule then covers the field's data everywhere, including exports and calls from outside Odoo. If you do name specific screens, the rule only changes how the field appears on them, so a field can be hidden in the list and still visible on the form.

Yes. Granted Role Access hands a role over temporarily, shows its status, sends expiry reminders, and can be revoked before the end date. Users can also raise an access request that is approved or rejected. Temporary grants pass through the same duty-conflict check as ordinary assignments.

Yes, with a business-hours window on the role. You pick the weekdays, the start and end times, and the timezone the window is read in, which should be your business timezone rather than the server's. A login outside the window is refused with a clear message, and an open session ends on the user's next action.

Yes. Block External API refuses XML-RPC and JSON-RPC calls for that user while the web interface keeps working, which suits a person who should not have programmatic access. For an integration account, restrict a single record type on the API side with the XML-RPC / JSON-RPC option on a Record Permissions line.

Talk to the team that built it

Contact us
100%