“Why can’t they see it?” — diagnosing permissions
Instead of guessing from names, open the effective permissions for the specific person. Remember that a change may take up to five minutes to take effect.
Step 1: effective permissions
The user list’s row menu has an Effective permissions action. It shows the calculated result for that person: the module matrix and list of field permissions, after combining all of their roles.
This is the one place that tells the truth. Role names and permission names can be misleading (Permission traps — why granting access sometimes changes nothing); the calculated result is not.
The action is available to company administrators and the superadministrator.
Step 2: check whether it is a delay
Permissions are cached in two places:
- the server keeps the result for 5 minutes;
- the browser refreshes its view of permissions every 5 minutes.
A change usually takes effect immediately, but in the worst case it may take up to five minutes. Before looking for a fault, ask the user to refresh the page and wait a moment. Signing out and back in can speed things up.
Step 3: checklist
In order, starting with the most common:
- Is this definitely the right company? Permissions are calculated for the active company. Someone who switched companies sees that company’s permissions (My companies — active company and switching context).
- Do they have any role at all? An account without a role opens normally and shows nothing.
- Does the module have read access? A field permission will not work without read access to its module (Field permissions — individual fields and individual actions).
- Does the action require “create”? Buttons that start operations often require create permission, not write permission (Module permissions — read, write, and create).
- Do the menu and data use the same permission? An empty table on a working screen is usually this mismatch (Permission traps — why granting access sometimes changes nothing).
- Is this a module that was not granted during rollout? Receiving, Assistant, Change log, and Advanced were not granted automatically to anyone.
- Is privacy masking enabled? Without it, hiding customer data does not work at all.
Step 4: when someone can see too much
The reverse is simpler because there is one rule: permissions add up and there are no denials (Role — what it is and how permissions are calculated). If someone can see something, one of their roles grants it — or they are a company administrator.
Check all their roles, not just the most recently assigned one. Adding a “restricted” role will not remove anything.
For the platform administrator
If the menu and access to a screen behave inconsistently, report it to NOXTI support. Include the screen name, the user’s role, and the access-denied message.
Want to see this with your orders? We’ll show you NOXTI with your sales channels and warehouse.
Book a demo