Permission traps — why granting access sometimes changes nothing
Eight cases where permissions behave differently from what their names suggest. Read this before designing roles for the first time, not afterwards.
Before reading the list: almost all eight cases can be resolved on one screen — by checking a specific person’s calculated permissions. It is worth knowing how to open it.
Step by step
Check what a person really has
- Go to Team and access → User accounts.
- Find the person using the Search users... field above the table or the All roles filter.
- In their row, click the three-dot menu and choose Effective permissions. This item is visible only to a company administrator and the superadministrator — if you cannot see it, ask an administrator.
- In the Effective permissions window, read the Module permissions table: Module, Read, Write, and Create columns. This is the combined result of all their roles, not the contents of one role.
- Below is the Field permissions table with Field and Access columns, if the person has any.
- Close the window with Close. The article “Why can’t they see it?” — diagnosing permissions describes this window in more detail.
Two messages in place of tables are self-explanatory:
- This user has no assigned permissions. Assign roles to grant access. — none of the traps applies; this person simply has no role.
- This user has full administrative access (manage everything). — this is a company administrator or superadministrator, so none of the module traps applies (Company administrator and superadministrator — who bypasses what).
Compare it with the role’s contents
- Go to the Roles and permissions tab and click the pencil icon, Edit role.
- On the Module permissions tab, find the module in question and compare its three columns with what the Effective permissions window showed.
- A module name that you cannot match to any menu item is a candidate for trap 4 or 8 below.
- The counter below the grid — Selected {n} of {total} permissions — tells you how many fields are selected in the whole window. The No permissions selected chip means the role grants nothing.
Give the system a moment after granting permission
The application refreshes a signed-in person’s permissions every five minutes. Before deciding the grant did not work, ask them to reload the page.
1. The menu shows something different from what the server allows
A classic in this system. A menu item may be protected by a different permission from the data behind it. Symptom: the user sees the screen, it loads correctly, but the table is empty with no message.
The best-known case is shipment tracking — the menu uses “Deliveries”, while the data uses “Shipments and labels” (Tracking permissions — the trap of two separate grants). Check permissions before deciding the data is missing.
2. Some modules were granted to nobody at rollout
Several permissions were added deliberately without granting them to anyone: Receiving, AI Assistant, Change log, and Advanced. On rollout day, nobody except administrators has them, and everyone else is denied until an administrator selects them.
If receiving goods “stopped working” after an update, this is the first place to check.
3. One permission was assigned only to roles with specific names
When introduced, the Shipments and labels permission was automatically granted only to roles literally named BOK and Warehouse. Companies whose roles had different names ended up with a module that nobody had.
4. Some entries in the grid do nothing
The role window may contain modules that no screen checks — leftovers from old versions, recreated with each installation. Selecting them unlocks nothing.
You can recognise them because the name does not match any menu item and selecting it changes nothing for the user.
5. Two permissions cannot be granted from the panel
Two actions have no separate entries in the field permissions catalogue: a full refresh of marketplace orders and editing synchronisation dates. In practice, they are available only to company administrators and the superadministrator.
6. “Order documents” hides buttons but does not block files
Removing this permission hides download links but does not secure the files themselves — the document URL is the key. Do not treat it as a security measure (Module permissions — read, write, and create).
7. “Advanced” neither opens nor closes anything
It is only a visibility switch for the menu section. Granting it provides no access; removing it revokes none — the pages underneath have their own gates and remain accessible by URL.
8. The “admin only” marker does not enforce anything
Some modules have an “admin only” marker in the database. Nothing checks it. Modules such as Users or Roles can be granted to an ordinary role like any other. Do not rely on this marker for security.
How to check the facts instead of guessing
Do not infer from names. Open Effective permissions for the specific person and inspect the calculated result (“Why can’t they see it?” — diagnosing permissions).
Want to see this with your orders? We’ll show you NOXTI with your sales channels and warehouse.
Book a demo