Security
What each group may do with each model, as the modules define it. Odoo applies access rights and record rules the same way to the user interface, imports and RPC calls. Which role needs which group is explained in Roles and permissions.
Groups
| Group | XML id | Implies | Description |
|---|---|---|---|
| Rx Tracking / Manager | aglow_rx_tracking.group_dscsa_manager | aglow_rx_tracking.group_dscsa_user | Manage licenses, quarantine and release lots, verify returns, answer trace requests, set legal holds. |
| Rx Tracking / User | aglow_rx_tracking.group_dscsa_user | quality.group_quality_user, stock.group_stock_user | Scan serials, view packages, licenses and DSCSA documents. |
| DSCSA Owner Portal | aglow_rx_tracking_3pl.group_dscsa_owner_portal | base.group_portal | Portal access of a 3PL owner's users to the owner's DSCSA documents, stock and holds. |
Access rights
One row per access rule the modules define (read, write, create, delete).
| Model | Group | Read | Write | Create | Delete | Module |
|---|---|---|---|---|---|---|
dscsa.archive.job | Rx Tracking / Manager | ✓ | ✓ | – | – | aglow_rx_tracking |
dscsa.archive.job | Rx Tracking / User | ✓ | – | – | – | aglow_rx_tracking |
dscsa.client.list.wizard | Rx Tracking / User | ✓ | ✓ | ✓ | ✓ | aglow_rx_tracking_3pl |
dscsa.discrepancy | Rx Tracking / Manager | ✓ | ✓ | ✓ | – | aglow_rx_tracking |
dscsa.discrepancy | Rx Tracking / User | ✓ | ✓ | – | – | aglow_rx_tracking |
dscsa.document | Rx Tracking / Manager | ✓ | ✓ | – | – | aglow_rx_tracking |
dscsa.document | Rx Tracking / User | ✓ | – | – | – | aglow_rx_tracking |
dscsa.document | User types / Portal | ✓ | – | – | – | aglow_rx_tracking |
dscsa.document.history | Rx Tracking / Manager | ✓ | ✓ | ✓ | ✓ | aglow_rx_tracking |
dscsa.document.history | Rx Tracking / User | ✓ | – | – | – | aglow_rx_tracking |
dscsa.document.line | Rx Tracking / Manager | ✓ | – | – | – | aglow_rx_tracking |
dscsa.document.line | Rx Tracking / User | ✓ | – | – | – | aglow_rx_tracking |
dscsa.document.publish.wizard | Rx Tracking / Manager | ✓ | ✓ | ✓ | ✓ | aglow_rx_tracking_3pl |
dscsa.epcis.import | Rx Tracking / User | ✓ | – | – | – | aglow_rx_tracking |
dscsa.epcis.import.wizard | Rx Tracking / User | ✓ | ✓ | ✓ | ✓ | aglow_rx_tracking |
dscsa.facility.event | Rx Tracking / Manager | ✓ | ✓ | ✓ | – | aglow_rx_tracking_3pl |
dscsa.facility.event | Rx Tracking / User | ✓ | – | – | – | aglow_rx_tracking_3pl |
dscsa.fda.report | Rx Tracking / Manager | ✓ | ✓ | ✓ | – | aglow_rx_tracking_3pl |
dscsa.fda.report | Rx Tracking / User | ✓ | – | – | – | aglow_rx_tracking_3pl |
dscsa.gate.log | Rx Tracking / Manager | ✓ | – | – | – | aglow_rx_tracking_3pl |
dscsa.gate.log | Rx Tracking / User | ✓ | – | – | – | aglow_rx_tracking_3pl |
dscsa.inventory.serials.line | Rx Tracking / User | ✓ | ✓ | ✓ | ✓ | aglow_rx_tracking |
dscsa.inventory.serials.wizard | Rx Tracking / User | ✓ | ✓ | ✓ | ✓ | aglow_rx_tracking |
dscsa.jurisdiction | Rx Tracking / Manager | ✓ | ✓ | ✓ | – | aglow_rx_tracking_3pl |
dscsa.jurisdiction | Rx Tracking / User | ✓ | – | – | – | aglow_rx_tracking_3pl |
dscsa.ledger.check | Rx Tracking / Manager | ✓ | – | – | – | aglow_rx_tracking |
dscsa.ledger.owner.check | Rx Tracking / Manager | ✓ | – | – | – | aglow_rx_tracking_3pl |
dscsa.ledger.owner.check | Rx Tracking / User | ✓ | – | – | – | aglow_rx_tracking_3pl |
dscsa.legal.hold.wizard | Rx Tracking / Manager | ✓ | ✓ | ✓ | – | aglow_rx_tracking |
dscsa.license | Rx Tracking / Manager | ✓ | ✓ | ✓ | ✓ | aglow_rx_tracking |
dscsa.license | Rx Tracking / User | ✓ | – | – | – | aglow_rx_tracking |
dscsa.lot.quarantine.owner.line | Rx Tracking / Manager | ✓ | ✓ | ✓ | ✓ | aglow_rx_tracking_3pl |
dscsa.lot.quarantine.wizard | Rx Tracking / Manager | ✓ | ✓ | ✓ | ✓ | aglow_rx_tracking |
dscsa.opening.balance.wizard | Rx Tracking / Manager | ✓ | ✓ | ✓ | ✓ | aglow_rx_tracking |
dscsa.owner.data.wizard | Rx Tracking / Manager | ✓ | ✓ | ✓ | ✓ | aglow_rx_tracking_3pl |
dscsa.owner.data.wizard | Rx Tracking / User | ✓ | ✓ | ✓ | ✓ | aglow_rx_tracking_3pl |
dscsa.owner.export | Rx Tracking / Manager | ✓ | ✓ | ✓ | – | aglow_rx_tracking_3pl |
dscsa.owner.export | Rx Tracking / User | ✓ | – | – | – | aglow_rx_tracking_3pl |
dscsa.owner.hold | Rx Tracking / Manager | ✓ | – | – | – | aglow_rx_tracking_3pl |
dscsa.owner.hold | Rx Tracking / User | ✓ | – | – | – | aglow_rx_tracking_3pl |
dscsa.owner.hold.release | Rx Tracking / Manager | ✓ | ✓ | ✓ | ✓ | aglow_rx_tracking_3pl |
dscsa.owner.hold.release | Rx Tracking / User | ✓ | – | – | – | aglow_rx_tracking_3pl |
dscsa.owner.instruction | Rx Tracking / Manager | ✓ | – | ✓ | – | aglow_rx_tracking_3pl |
dscsa.owner.instruction | Rx Tracking / User | ✓ | – | ✓ | – | aglow_rx_tracking_3pl |
dscsa.owner.notice | Rx Tracking / Manager | ✓ | – | – | – | aglow_rx_tracking_3pl |
dscsa.owner.notice | Rx Tracking / User | ✓ | – | – | – | aglow_rx_tracking_3pl |
dscsa.owner.order | Rx Tracking / Manager | ✓ | ✓ | ✓ | ✓ | aglow_rx_tracking_3pl |
dscsa.owner.order | Rx Tracking / User | ✓ | ✓ | ✓ | – | aglow_rx_tracking_3pl |
dscsa.owner.order.line | Rx Tracking / Manager | ✓ | ✓ | ✓ | ✓ | aglow_rx_tracking_3pl |
dscsa.owner.order.line | Rx Tracking / User | ✓ | ✓ | ✓ | ✓ | aglow_rx_tracking_3pl |
dscsa.owner.portal.access | Rx Tracking / Manager | ✓ | ✓ | ✓ | ✓ | aglow_rx_tracking_3pl |
dscsa.owner.portal.access.line | Rx Tracking / Manager | ✓ | ✓ | ✓ | ✓ | aglow_rx_tracking_3pl |
dscsa.owner.profile | Rx Tracking / Manager | ✓ | ✓ | ✓ | – | aglow_rx_tracking_3pl |
dscsa.owner.profile | Rx Tracking / User | ✓ | – | – | – | aglow_rx_tracking_3pl |
dscsa.owner.report.csv | Rx Tracking / User | ✓ | ✓ | ✓ | ✓ | aglow_rx_tracking_3pl |
dscsa.package | Rx Tracking / Manager | ✓ | – | – | – | aglow_rx_tracking |
dscsa.package | Rx Tracking / User | ✓ | – | – | – | aglow_rx_tracking |
dscsa.package | Inventory / User | ✓ | – | – | – | aglow_rx_tracking |
dscsa.recall.consignees | Rx Tracking / Manager | ✓ | ✓ | ✓ | ✓ | aglow_rx_tracking_3pl |
dscsa.recall.consignees | Rx Tracking / User | ✓ | ✓ | ✓ | ✓ | aglow_rx_tracking_3pl |
dscsa.recall.consignees.line | Rx Tracking / Manager | ✓ | ✓ | ✓ | ✓ | aglow_rx_tracking_3pl |
dscsa.recall.consignees.line | Rx Tracking / User | ✓ | ✓ | ✓ | ✓ | aglow_rx_tracking_3pl |
dscsa.record.ts.wizard | Rx Tracking / User | ✓ | ✓ | ✓ | ✓ | aglow_rx_tracking |
dscsa.retention.export | Rx Tracking / Manager | ✓ | – | – | – | aglow_rx_tracking |
dscsa.scan.wizard | Rx Tracking / User | ✓ | ✓ | ✓ | ✓ | aglow_rx_tracking |
dscsa.send.owner.documents | Rx Tracking / User | ✓ | ✓ | ✓ | ✓ | aglow_rx_tracking_3pl |
dscsa.title.import.wizard | Rx Tracking / Manager | ✓ | ✓ | ✓ | ✓ | aglow_rx_tracking_3pl |
dscsa.title.import.wizard | Rx Tracking / User | ✓ | ✓ | ✓ | ✓ | aglow_rx_tracking_3pl |
dscsa.title.select.serials | Rx Tracking / Manager | ✓ | ✓ | ✓ | ✓ | aglow_rx_tracking_3pl |
dscsa.title.select.serials | Rx Tracking / User | ✓ | ✓ | ✓ | ✓ | aglow_rx_tracking_3pl |
dscsa.title.transfer | Rx Tracking / Manager | ✓ | ✓ | ✓ | – | aglow_rx_tracking_3pl |
dscsa.title.transfer | Rx Tracking / User | ✓ | ✓ | ✓ | – | aglow_rx_tracking_3pl |
dscsa.title.transfer.line | Rx Tracking / Manager | ✓ | ✓ | ✓ | ✓ | aglow_rx_tracking_3pl |
dscsa.title.transfer.line | Rx Tracking / User | ✓ | ✓ | ✓ | ✓ | aglow_rx_tracking_3pl |
dscsa.trace.request | Rx Tracking / Manager | ✓ | ✓ | ✓ | – | aglow_rx_tracking |
dscsa.trace.request | Rx Tracking / User | ✓ | ✓ | ✓ | – | aglow_rx_tracking |
quality.alert | Rx Tracking / Manager | ✓ | ✓ | ✓ | ✓ | aglow_rx_tracking_quality |
quality.alert | Rx Tracking / User | ✓ | ✓ | ✓ | – | aglow_rx_tracking_quality |
Record rules
Rules without a group are global: they apply to every user, on top of the group rules.
| Model | Rule | Groups | Domain | Applies to | Module |
|---|---|---|---|---|---|
dscsa.archive.job | DSCSA S3 archive job: multi-company | all users (global) | [('company_id', 'in', company_ids)] | read/write/create/delete | aglow_rx_tracking |
dscsa.discrepancy | DSCSA receiving discrepancy: multi-company | all users (global) | [('company_id', 'in', company_ids)] | read/write/create/delete | aglow_rx_tracking |
dscsa.document | DSCSA document: multi-company | all users (global) | [('company_id', 'in', company_ids)] | read/write/create/delete | aglow_rx_tracking |
dscsa.document | DSCSA document: portal buyer | User types / Portal | [('direction', '=', 'outbound'), ('state', '=', 'posted'), ('partner_id', 'child_of', [user.commercial_partner_id.id])] | read | aglow_rx_tracking |
dscsa.document | DSCSA document: owner portal (documents in the owner's name) | DSCSA Owner Portal | [('state', '=', 'posted'), ('dscsa_owner_id', '=', user.commercial_partner_id.id)] | read | aglow_rx_tracking_3pl |
dscsa.document | DSCSA document: share users see owner documents only when visible to them | all users (global) | ['|', ('dscsa_owner_id', '=', False), '|', ('dscsa_buyer_visible', '=', True), ('dscsa_owner_id', '=', user.commercial_partner_id.id)] if user.share else [(1, '=', 1)] | read/write/create/delete | aglow_rx_tracking_3pl |
dscsa.document.history | DSCSA transaction history: multi-company | all users (global) | [('company_id', 'in', company_ids)] | read/write/create/delete | aglow_rx_tracking |
dscsa.document.line | DSCSA document line: multi-company | all users (global) | [('company_id', 'in', company_ids)] | read/write/create/delete | aglow_rx_tracking |
dscsa.epcis.import | Supplier EPCIS file: multi-company | all users (global) | [('company_id', 'in', company_ids)] | read/write/create/delete | aglow_rx_tracking |
dscsa.facility.event | DSCSA facility event: multi-company | all users (global) | [('company_id', 'in', company_ids)] | read/write/create/delete | aglow_rx_tracking_3pl |
dscsa.fda.report | DSCSA FDA annual report: multi-company | all users (global) | [('company_id', 'in', company_ids)] | read/write/create/delete | aglow_rx_tracking_3pl |
dscsa.gate.log | DSCSA gate log: multi-company | all users (global) | [('company_id', 'in', company_ids)] | read/write/create/delete | aglow_rx_tracking_3pl |
dscsa.jurisdiction | DSCSA jurisdiction: multi-company | all users (global) | [('company_id', 'in', company_ids)] | read/write/create/delete | aglow_rx_tracking_3pl |
dscsa.ledger.check | DSCSA ledger check: multi-company | all users (global) | [('company_id', 'in', company_ids)] | read/write/create/delete | aglow_rx_tracking |
dscsa.ledger.owner.check | DSCSA ledger vs stock per owner: multi-company | all users (global) | [('company_id', 'in', company_ids)] | read/write/create/delete | aglow_rx_tracking_3pl |
dscsa.license | DSCSA license: multi-company | all users (global) | ['|', ('company_id', '=', False), ('company_id', 'in', company_ids)] | read/write/create/delete | aglow_rx_tracking |
dscsa.owner.export | DSCSA owner export: multi-company | all users (global) | [('company_id', 'in', company_ids)] | read/write/create/delete | aglow_rx_tracking_3pl |
dscsa.owner.hold | DSCSA owner hold: multi-company | all users (global) | [('company_id', 'in', company_ids)] | read/write/create/delete | aglow_rx_tracking_3pl |
dscsa.owner.instruction | DSCSA owner instruction: multi-company | all users (global) | [('company_id', 'in', company_ids)] | read/write/create/delete | aglow_rx_tracking_3pl |
dscsa.owner.notice | DSCSA owner notice: multi-company | all users (global) | [('company_id', 'in', company_ids)] | read/write/create/delete | aglow_rx_tracking_3pl |
dscsa.owner.order | DSCSA owner order: multi-company | all users (global) | [('company_id', 'in', company_ids)] | read/write/create/delete | aglow_rx_tracking_3pl |
dscsa.owner.order.line | DSCSA owner order line: multi-company | all users (global) | [('company_id', 'in', company_ids)] | read/write/create/delete | aglow_rx_tracking_3pl |
dscsa.owner.profile | DSCSA owner profile: multi-company | all users (global) | [('company_id', 'in', company_ids)] | read/write/create/delete | aglow_rx_tracking_3pl |
dscsa.package | DSCSA package: multi-company | all users (global) | [('company_id', 'in', company_ids)] | read/write/create/delete | aglow_rx_tracking |
dscsa.retention.export | DSCSA retention export: multi-company | all users (global) | [('company_id', 'in', company_ids)] | read/write/create/delete | aglow_rx_tracking |
dscsa.title.transfer | DSCSA title transfer: multi-company | all users (global) | [('company_id', 'in', company_ids)] | read/write/create/delete | aglow_rx_tracking_3pl |
dscsa.title.transfer.line | DSCSA title transfer line: multi-company | all users (global) | [('company_id', 'in', company_ids)] | read/write/create/delete | aglow_rx_tracking_3pl |
dscsa.trace.request | DSCSA trace request: multi-company | all users (global) | [('company_id', 'in', company_ids)] | read/write/create/delete | aglow_rx_tracking |
stock.picking | Transfers: portal users limited to their commercial partner (DSCSA) | all users (global) | ['|', ('partner_id', 'child_of', [user.commercial_partner_id.id]), ('sale_id.partner_id', 'child_of', [user.commercial_partner_id.id])] if user.share else [(1, '=', 1)] | read/write/create/delete | aglow_rx_tracking |