Settings access — permission pitfalls
You need the “Settings” permission to open any settings section, regardless of what it covers. This is the first of several surprises.
1. Without “Settings” permission, you cannot open anything
One permission protects the entire settings area: Settings. It is checked before the system looks at which section you are trying to open.
As a result, a role with full Warehouse access but no Settings permission cannot open warehouse settings. Access is denied at the entrance.
This is the first thing to check when someone reports “I can’t see settings”.
2. The tab is visible, but the data is empty
Some tabs read data using a different permission from the one that makes the tab visible:
- Email and SMS accounts read from integrations, so they require Integrations permission.
- Change audit reads from the assistant log, so it requires AI Assistant permission.
The symptom is always the same: the tab opens, the table is empty, and there is no access-denied message.
3. Saving is denied even though the form is visible
Two tabs look editable but deny saving to everyone outside a narrow group:
- Currency rates — only a superadministrator or company administrator can save. The rates are shared across the entire platform.
- Session security — everyone can read it, but only a company administrator can save.
4. Permissions for individual tabs do nothing
The field-permission catalog contains more than twenty entries named “Settings > …”, one for each tab. They look like precise access controls.
These entries do not work. Nothing checks them. Selecting or clearing them changes nothing.
Access is controlled only by module permissions (Settings — map of ten sections). Do not build an access policy around those entries; they are the most misleading part of the entire catalog (Permission traps — why granting access sometimes changes nothing).
5. Saving requires 2FA confirmation
Most settings changes are elevated-risk operations and will ask for a code (2FA confirmation when changing permissions).
An API token can never save these settings. Neither a script nor a scanner can change company configuration, regardless of the token owner’s permissions (API keys — your personal tokens).
Diagnosis
- Do you have Settings permission? Without it, nothing else matters.
- Do you have permission for the section?
- Does the tab require a different permission (see section 2)?
- Is the tab reserved for a superadministrator (Settings shared across the platform)?
- Is the denial for saving, rather than reading?
Want to see this with your orders? We’ll show you NOXTI with your sales channels and warehouse.
Book a demo