Loading

ERP Roles & Workspace

Give back-office staff ERP roles and company access, and use the ERP workspace on the Admin Home page, ERP search and the menu badges.

ERP Roles

An ERP role says what part of the ERP a security group's members may use: Finance, Purchasing, Projects and so on. Roles are how back-office staff who are not architects get into the ERP, and granting one also gives the group the Admin Panel menu entries for the screens that role uses.

Where to find it

Architect Panel → ERP - Setup:

  • ERP Setup — the ERP roles tab: security groups against roles and document permissions

Admin Panel → ERP - Setup:

  • ERP Setup — the same tab for holders of ERP: Administration

Two grants, both required

A role says what someone may do. Company access says where: read, write or post, company by company. Neither implies the other, so a Finance role with no company access opens nothing, and company access with no role opens no ERP screen. Members also need Admin Panel access through their security group. Architects hold every role and can use every company.

The twelve roles

On a standard installation each role opens these Admin Panel entries. Every role also opens the Approvals Inbox under Processes.

  • ERP: Finance: ledger, journals, periods, VAT, bank and reconciliation, statements. Opens Ledger & Finance, Bank Feeds & Reconciliation, ERP Analytics, Purchasing and Invoice Match Queue.
  • ERP: Receivables: customers, sales invoices, credit notes, receipts and credit control. Opens Receivables.
  • ERP: Payables: supplier invoices, payments and the match queue. Opens Purchasing and Invoice Match Queue.
  • ERP: Purchasing: requisitions, orders, goods receipts and PunchOut. Opens Purchasing.
  • ERP: Sales: quotes, orders, deliveries and pricing. Opens Sales and Pricing.
  • ERP: Inventory: items, stock, counts, inspections and structures. Opens Items, Stock, Structures, Production and Purchasing (for goods receipts).
  • ERP: Projects: projects, budgets, billing and approving time. Opens Projects & Time and My Time & Expenses.
  • ERP: Time & Expenses: logging your own time and expenses. Opens My Time & Expenses.
  • ERP: Fixed Assets: the asset register, maintenance and depreciation. Opens Fixed Assets.
  • ERP: Approvals: the shared pool of approval requests that name nobody. Opens Purchasing.
  • ERP: Reporting: read-only statements and analytics. Opens ERP Analytics and, read-only, Ledger & Finance, Projects & Time, Items, Stock, Structures, Production, Fixed Assets and Pricing.
  • ERP: Administration: ERP configuration. Opens every entry in the ERP - Setup section: ERP Setup, Record Numbering, Approval Matrices, ERP Documents, EDI and PunchOut.

The matrix also has columns for document permissions such as Approve purchase requisitions, Issue purchase orders and Approve supplier invoices. These allow a document move; they add no menu entries.

Granting a role

  1. Open ERP Setup and choose ERP roles.
  2. Find the security group's row and tick the role's column. The change is saved at once, and the message says how many menu entries were added for the group.
  3. Open What each role opens under the matrix to see the menu entries each role gives on your installation.
  4. Make sure the group also has company access on the Company access tab.

Removing a role takes away the menu entries that no other role of the group still needs. A menu entry is only ever added for a screen that admits the role, so nobody is offered a door that refuses them.

Add missing menu entries

Beside the button the tab says how many groups are missing menu entries. Add missing menu entries gives every group the entries its current roles open, and gives every admin group the Approvals Inbox. It never removes anything. Press it after creating a new security group, after installing a new ERP screen, or for groups that held roles before roles added menu entries.

What goes wrong

  • "Your account does not have the ERP role this needs": the screen names the role. Add the person's group to it here, and check its company access.
  • "You cannot change the roles of a security group you belong to": ask another ERP administrator. This stops an administrator promoting or locking out themselves.
  • The group is not listed: in an organisation's own tenant only its own security groups are listed. Platform groups such as All Users are managed from the platform.

Worked example

A finance team of three needs the ledger and the bank, and its manager also approves purchase invoices. The ERP administrator ticks Finance for the Finance group and Finance, Payables and Approve supplier invoices for the Finance Managers group. Both groups get Post access to the company. The next time the clerks open the Admin Panel, a Finance section shows Ledger & Finance and Bank Feeds & Reconciliation.

Recommendations

  • Grant roles to groups named for a job, such as Finance or Buyers, never to individuals.
  • Use Reporting for read-only users such as directors and auditors rather than giving them Finance.
  • Press Add missing menu entries whenever the tab reports a gap.
  • Review the matrix quarterly alongside your other security group reviews.

Company Access

Company access decides which companies a security group's members can work in, and how far: read, write or post. It is the second half of ERP access. A role says what a person may do; company access says in which companies they may do it, and every ERP screen, search, badge and figure is limited to those companies.

Where to find it

Architect Panel → ERP - Setup:

  • ERP Setup — the Company access tab: security groups against companies
  • Entity Permissions — the grants as a datastore, for inspection

Admin Panel → ERP - Setup:

  • ERP Setup — the same tab for holders of ERP: Administration

The three levels

Each level includes the ones before it.

  • Read: sees the company's records and reports. Enough for ERP Analytics, the trial balance and the statements.
  • Write: also raises and edits documents, codes and imports bank lines, edits the chart of accounts, tax codes and budgets.
  • Post: also posts to the company's ledger, closes its periods and files its VAT return.

Architects can use every company without a grant.

Granting access

  1. Open ERP Setup and choose Company access. There is one row per security group and one column per company.
  2. In the cell for a group and a company, choose None, Read, Write or Post. The change is saved as soon as you make it.
  3. Make sure the group also holds the ERP role it needs on the ERP roles tab.
  4. Return to the Checklist: Company access for security groups is green when every company has at least one group with access.

Rules for ERP administrators

A holder of ERP: Administration who is not an architect works under three limits, shown on the tab.

  • They see only the companies their own groups can read, and change access only on companies their groups can write to.
  • They cannot grant more than their own access: only someone who can post to a company can grant or change Post on it.
  • They cannot change the access of a group they belong to, including All Users. Those rows are marked (your group) and locked.

Where company access is applied

  • Company pickers on every ERP screen list only the companies you can read. They put the top of the group first and elimination companies last.
  • Actions check the level they need: Ledger & Finance needs Post to post a journal and Write to change the chart; Bank Feeds & Reconciliation needs Write to code or import and Post to post.
  • The ERP workspace, ERP search and menu badges count and find only what is in your companies.
  • ERP Analytics totals only your companies. Holders of ERP: Finance or ERP: Reporting read its source data through a system group called ERP analytics (implied by ERP roles), so no separate datastore grant is needed. That group never has members and is not offered on this tab.

What goes wrong

  • "You hold an ERP role but no company has been opened to you yet" on the ERP workspace: the group has a role and no company access.
  • "You do not have post access to that company": the group has Read or Write only. Raise it to Post if the person should post.
  • A new company appears on nobody's screens: grant at least one group access to it. The checklist names companies with no group.

Worked example

A group has a UK parent, a Dutch subsidiary and an eliminations company. The UK Finance group gets Post on the parent and Read on the subsidiary, so it can see the Dutch figures but not post to them. The NL Finance group gets Post on the subsidiary only. The Group Finance group gets Post on all three, which is what lets it run the consolidation and post the elimination journal. Directors get Read on all three with the ERP: Reporting role.

Recommendations

  • Grant by group, never by person, so access survives staff changes.
  • Give Post sparingly. Most people who raise documents need Write; only the finance team needs Post.
  • Keep the eliminations company to group finance. Its postings change every consolidated figure.
  • Review the matrix whenever a company is added: a new column starts empty for every group.

The ERP Workspace

The ERP workspace, sometimes called the role centre, is the first screen for anyone who works in the ERP. It shows what is waiting for them, the figures their role is measured by, one-click starts for what they do most and the documents they touched last, all limited to their roles and companies. There is nothing to build: it follows the roles and company access you grant.

Where to find it

The workspace has no menu entry of its own. It is the Admin Panel home page for anyone holding an ERP role, shown under the greeting, and the Admin Home button at the top of the admin menu brings it back from any screen. What it shows is decided by:

Admin Panel → ERP - Setup:

  • ERP Setup — the ERP roles and Company access tabs

What is on it

  • Company: one company, or All my companies. The choice is remembered on that browser.
  • Search the ERP: finds documents, customers, suppliers, items, projects, accounts and assets as you type.
  • Quick actions: for example Raise a requisition, Log time, New quote, Post a journal, Reconcile the bank, Record a receipt, Invoice match queue, Stock enquiry, Approve time, Asset register, ERP Analytics and ERP Setup, each shown only to the role that uses it.
  • Your figures: the role's ERP Analytics measures with a six-month trend. Finance sees Revenue, Operating profit, Cash and bank, Receivables outstanding and Payables outstanding; Payables sees Payables outstanding and Days payables outstanding, and so on. A balance shows today's value; a flow shows the financial year to date. The measures come from ERP Analytics.
  • Waiting for you: the work queues for your roles.
  • Your recent documents: documents you created or changed in the last 60 days.
  • Group overview: for architects and for Finance or Reporting holders who read two or more companies, a row per company with Revenue FYTD, Op. profit FYTD, Receivables, Payables, Periods open and Bank lines. Select a company code to switch to it.

The work queues

Each queue shows how many items are waiting, the oldest or largest few, and a link to the screen where you deal with them.

  • My approvals (everyone) and Requisitions to approve (Approvals).
  • Requisitions to order and Orders awaiting approval (Purchasing); Invoices on match hold (Payables).
  • Timesheets due (Time & Expenses) and Timesheets to approve (Projects).
  • Overdue customers (Receivables or Finance) and Open sales documents (Sales).
  • Items below reorder point (Inventory); Maintenance due (Fixed Assets).
  • Unreconciled bank lines and Periods to close (Finance).
  • Report schedules needing attention (Reporting); ERP setup (Administration), listing red and amber checklist rows.

Using it day to day

  1. Sign in. The workspace opens on the Admin Home page.
  2. Choose a company, or leave All my companies to see every queue across your companies.
  3. Work down Waiting for you, opening each queue's screen from its link.
  4. Use Your figures to see the month's position. With All my companies chosen and two or more companies, Finance and Reporting holders see group figures in the group currency, with a note on how intercompany trading was treated.

What goes wrong

  • No workspace on the home page: the person holds no ERP role, or the ERP module is switched off.
  • "You hold an ERP role but no company has been opened to you yet": grant the group company access.
  • A queue has a count but no link: the person's roles do not open that queue's screen. The count stays so the work is visible.
  • "Choose a company above to see its figures": the figures need one company, or a group whose companies can be translated into one currency.

Worked example

A finance manager holds Finance and Reporting with Post on two companies. On Monday morning their workspace shows Unreconciled bank lines 46 across two accounts and Periods to close 1 (last month for the subsidiary). Your figures shows group revenue for the year to date. They press Reconcile the bank, work the oldest account, then open Periods to close and land on the Periods tab of Ledger & Finance.

Recommendations

  • Start the day on the workspace, not on individual menu entries: it shows everything waiting across your roles.
  • Keep company access tight: the workspace is only as focused as the companies a person can read.
  • Use All my companies for queues and a single company for figures.
  • Point new users to the User Guide: its ERP section explains the workspace in the product itself.

ERP Search and Menu Badges

Anyone holding an ERP role can find a document, customer, supplier, item, project, account or asset from any admin screen with one search box, and the menu shows a number beside the screens where work is waiting. Both follow the person's roles and companies, so they never show more than that person may read.

Where to find it

The search box sits in the admin menu, labelled Search the ERP (Ctrl+K), for anyone holding an ERP role. The same search is on the ERP workspace on the Admin Home page. Badges appear on these entries:

Admin Panel → Finance:

  • Bank Feeds & Reconciliation — bank lines not yet reconciled

Admin Panel → Payables:

  • Invoice Match Queue — supplier invoices held by matching

Admin Panel → Purchasing:

  • Purchasing — requisitions submitted and orders waiting for approval

Admin Panel → Projects & Time:

  • Projects & Time — timesheets waiting for someone else's approval
  • My Time & Expenses — your own timesheets that were sent back

Admin Panel → Processes:

  • Approvals Inbox — approval requests waiting for you

Searching

  1. Press Ctrl+K (Cmd+K on a Mac) from any admin screen, or click the box.
  2. Type at least two characters: a document number or part of one, a name, a code or an account number.
  3. Move through the results with the arrow keys and press Enter to open one.
  4. Choose See all results to open the full ERP search page. There you can set Company and Look in (Everything, Documents, Customers, Suppliers, Items, Works orders, Projects, Accounts or Assets).

What you can find

Each kind is searched only for roles that read it, and only in the companies you can read (shared records that belong to no company are included).

  • Documents by number or reference, for every document type your roles read. Finance holders also find journals.
  • Customers, Suppliers and Items by code or name.
  • Works orders, Projects, ledger Accounts and fixed Assets.

A result whose screen your roles do not open is marked (no screen you can open) rather than offered as a link.

How badges count

  • The Purchasing, Invoice Match Queue, Bank Feeds & Reconciliation and Projects & Time badges count work in the companies you can open. Architects count every company. The Approvals Inbox badge counts requests that name you.
  • The Projects & Time badge leaves out your own submitted timesheets, because you cannot approve them.
  • The ERP workspace counts the same work company by company, so a badge and a queue can be compared.
  • Architect Panel tiles keep their own badges, for example Feed Queue (feed lines not yet posted, ignored or reconciled) and Accounting Outbox (failed outbound documents).

The User Guide inside the product

The User Guide button in the admin menu now has an ERP section for back-office users, with three topics: The role centre and ERP search, ERP roles, company access and your menu, and ERP Analytics: measures, reports and consolidation. Point new ERP users there on their first day.

What goes wrong

  • No search box in the menu: the person holds no ERP role, or the ERP module is switched off.
  • "Nothing in your companies matches.": the record may belong to a company you cannot read, or to a kind your roles do not search.
  • A badge higher than the workspace: a person signed in with a Windows or Active Directory identity counts every company, because their groups cannot be resolved for the count.

Worked example

A supplier rings about invoice 4471. The payables clerk presses Ctrl+K, types 4471, and sees the supplier invoice under Documents. They open it, see it is on match hold, and notice the Invoice Match Queue badge reads 3, so they clear the other two while they are there.

Recommendations

  • Teach Ctrl+K on day one. It replaces most menu navigation for finding a record.
  • Use the full search page when a short query matches too much; narrow it by company and kind.
  • Treat a badge as a prompt, and the ERP workspace as the detail behind it.
  • Keep company access accurate: search and badges are only as focused as the grants behind them.