🛡️ Access Control
User accounts, system roles and everything they are allowed to do — on one screen.
🪪 Account
Who this login is, and which role it belongs to.📄 Page Access
Which menu pages this role may open.🗂️ Report Access
Reports Center visibility & export, by category.🌐 Data Scope
How much this role can see. Two separate questions — which locations, and whose records.“Only their own” is for field sales. Accounts, management and office roles need All records, or their screens come up empty — the data is filtered out, not missing. A user on an “only their own” role must be linked to an employee on the Account tab, otherwise there is no way to tell which records are theirs and they will see none. Sales managers who should see a team belong on this setting too; their team comes from Setup → Sales Teams.
Without this, the role can still add and edit a customer or supplier — name, address, contact, region, location. It just cannot decide who owns the account or what credit it carries; that half of the form is hidden and the server ignores it if sent anyway. Off by default for a new role. Field sales normally stays off: a rep on “only their own records” cannot see the outstanding or the payment history of the account whose limit they would be setting. Administrators always hold this and it cannot be taken from them, or there would be nobody left to grant it back.
This role can view stock & reports across all locations, but writes are still limited to the locations assigned to each user. This does not affect record visibility above.