Report permissions — two layers and four mismatches
You need the Reports module and a separate permission for each report. There are also four places where the menu and the data are protected by different permissions.
Two layers, both required
- Reports module — granted in the module permissions grid.
- Separate permission for a specific report — granted in the field-permissions catalogue, in the Reports group (Field permissions — individual fields and individual actions).
There are about twenty-five of these, one for each screen.
Without the module, you will not see the section
A role with permission for a specific report, but without the Reports module, will not see any report section in the menu — even though the URL itself would let it in.
When granting access to reports, always grant both.
Four mismatches between menu and data
These are places where the menu item is protected by a different permission from the data itself:
| Report | Menu requires | Data requires |
|---|---|---|
| Dashboard | dashboard report permission | Orders module |
| Accuracy (menu Reports → AI → Accuracy) | accuracy report permission | Integrations module |
| All HR reports | HR report permissions | Attendance module |
| PIM quality | PIM quality report permission | Reports module only |
There are two opposite symptoms:
- An empty screen despite report permission — the permission for the module containing the data is missing. This is how AI accuracy and HR reports behave.
- Data available without report permission — hiding a menu item does not protect the data. This is the case for Dashboard and PIM quality.
The second case matters when assigning roles: a person with access to orders can read the company’s aggregated sales results, even if Dashboard is not visible in their menu (Dashboard — what is not obvious at first glance).
Four HR reports share one permission
Attendance, absences, overtime, and schedule completion share one permission. Granting it opens all four (HR dashboards — what each one shows).
Two HR reports require warehouse permission
Employee productivity (HR) and Working time utilisation are protected by the permission for warehouse picking reports. A role limited to HR will see a group with two fewer items.
Working time utilisation is the trickiest: it requires warehouse permission for the menu and the Attendance module for the data. Its name gives no hint.
Permissions added later were not added to existing roles
Permissions for warehouse reports, live sales, and orders by stage were added after those screens were introduced. Existing roles did not receive them automatically.
The symptom from that period was explicit: administrators could see these items, while operators were denied access (Permission traps — why granting access sometimes changes nothing).
Diagnosis
- Does the role have the Reports module? Without it, there is no menu section.
- Does it have permission for this specific report?
- Does it have the module containing the data — Orders, Integrations, or Attendance (see table above)?
- Is it one of the two HR reports protected by warehouse permission?
The fastest way to know: open Effective permissions for the user (“Why can’t they see it?” — diagnosing permissions).
Want to see this with your orders? We’ll show you NOXTI with your sales channels and warehouse.
Book a demo