Tracking permissions — the trap of two separate grants
The “Deliveries” permission opens the menu, while “Shipments and labels” grants the data. A role with one but not the other shows the screen and an empty table — without any message.
Tracking screens can require up to three different permissions at once. This is the most common reason people report “I have access, but I cannot see anything”.
Step by step — grant the missing permission
A company administrator does this. It takes a minute but requires 2FA confirmation — have your phone ready.
- Expand Configuration → Team and access in the menu and click Roles and permissions.
- In the Company roles list, find the role of the user reporting the problem. The Permissions column summarises how many modules the role has.
- At the end of the row, click the pencil icon — tooltip Edit role.
- Stay on the Module permissions tab. The Module access grid opens, with a Module column and three checkbox columns: Read, Write, and Create.
- Find the missing module and select Read next to it:
- Shipments and labels — without it, the tracking table is always empty;
- Deliveries — without it, Tracking is absent from the menu;
- Integrations — without it, the Integration filter is an empty list;
- Audit Log — without it, the document history window will not load. This module is listed in English; do not search for “Change log”.
- Click Update role at the bottom of the window.
- The 2FA verification required window appears (This action is sensitive — confirm your identity with a code from your authenticator app.). Enter the Verification code and click Confirm. You will not be asked again for the next 15 minutes.
- Ask the user to refresh the page. The menu is built from permissions, so a missing item appears only after reloading.
If you see Two-factor verification required instead of a code field in the 2FA window, you have not enabled 2FA on your own account yet. Go to 2FA settings takes you to the place where you can enable it; then return and repeat the operation.
| What | Permission | Without it |
|---|---|---|
| Menu item and access to the screen | Deliveries | Menu item is hidden |
| Rows in the table | Shipments and labels | Screen opens, table is always empty |
| Integration filter | Integrations | Dropdown list is empty |
| History icon (documents) | Audit Log | History window does not load |
The main trap
The permission that opens the menu is Deliveries. The permission that grants the data is Shipments and labels. These are two separate entries in roles.
A role with only Deliveries behaves like this:
- the user sees Tracking in the menu;
- they open it and the screen loads correctly;
- the table says “No data”;
- no permission-denied message appears.
It looks like an empty warehouse, but it is an access denial. This applies to both the shipment list and the document list.
Diagnosis: if the table is empty regardless of filters and you know parcels exist, check the role for Shipments and labels before looking for a data issue (see missing shipment status update).
The other two gaps
- An empty Integration filter means missing Integrations permission, not missing connections. The rest of the screen works normally, so it is easy to miss.
- Document history that does not load means missing Audit Log permission — granted separately and not automatically assigned to roles created earlier.
Who has it by default
When introduced, Shipments and labels was granted to roles named BOK and Warehouse. Roles created later and roles with other names do not have it — assign it manually.
The superadministrator and company administrator bypass all these checks and can see everything.
The Carrier filter is an exception
The Carrier dropdown requires no additional permission and is not limited to your company — it shows all carriers defined on the platform. Seeing a carrier you have never used is normal and does not mean data has leaked: this is only a dictionary of names, with no shipments.
Want to see this with your orders? We’ll show you NOXTI with your sales channels and warehouse.
Book a demo