Loading

Company Access

Company access decides which companies a security group's members can work in, and how far: read, write or post. It is the second half of ERP access. A role says what a person may do; company access says in which companies they may do it, and every ERP screen, search, badge and figure is limited to those companies.

Where to find it

Architect Panel → ERP - Setup:

  • ERP Setup — the Company access tab: security groups against companies
  • Entity Permissions — the grants as a datastore, for inspection

Admin Panel → ERP - Setup:

  • ERP Setup — the same tab for holders of ERP: Administration

The three levels

Each level includes the ones before it.

  • Read: sees the company's records and reports. Enough for ERP Analytics, the trial balance and the statements.
  • Write: also raises and edits documents, codes and imports bank lines, edits the chart of accounts, tax codes and budgets.
  • Post: also posts to the company's ledger, closes its periods and files its VAT return.

Architects can use every company without a grant.

Granting access

  1. Open ERP Setup and choose Company access. There is one row per security group and one column per company.
  2. In the cell for a group and a company, choose None, Read, Write or Post. The change is saved as soon as you make it.
  3. Make sure the group also holds the ERP role it needs on the ERP roles tab.
  4. Return to the Checklist: Company access for security groups is green when every company has at least one group with access.

Rules for ERP administrators

A holder of ERP: Administration who is not an architect works under three limits, shown on the tab.

  • They see only the companies their own groups can read, and change access only on companies their groups can write to.
  • They cannot grant more than their own access: only someone who can post to a company can grant or change Post on it.
  • They cannot change the access of a group they belong to, including All Users. Those rows are marked (your group) and locked.

Where company access is applied

  • Company pickers on every ERP screen list only the companies you can read. They put the top of the group first and elimination companies last.
  • Actions check the level they need: Ledger & Finance needs Post to post a journal and Write to change the chart; Bank Feeds & Reconciliation needs Write to code or import and Post to post.
  • The ERP workspace, ERP search and menu badges count and find only what is in your companies.
  • ERP Analytics totals only your companies. Holders of ERP: Finance or ERP: Reporting read its source data through a system group called ERP analytics (implied by ERP roles), so no separate datastore grant is needed. That group never has members and is not offered on this tab.

What goes wrong

  • "You hold an ERP role but no company has been opened to you yet" on the ERP workspace: the group has a role and no company access.
  • "You do not have post access to that company": the group has Read or Write only. Raise it to Post if the person should post.
  • A new company appears on nobody's screens: grant at least one group access to it. The checklist names companies with no group.

Worked example

A group has a UK parent, a Dutch subsidiary and an eliminations company. The UK Finance group gets Post on the parent and Read on the subsidiary, so it can see the Dutch figures but not post to them. The NL Finance group gets Post on the subsidiary only. The Group Finance group gets Post on all three, which is what lets it run the consolidation and post the elimination journal. Directors get Read on all three with the ERP: Reporting role.

Recommendations

  • Grant by group, never by person, so access survives staff changes.
  • Give Post sparingly. Most people who raise documents need Write; only the finance team needs Post.
  • Keep the eliminations company to group finance. Its postings change every consolidated figure.
  • Review the matrix whenever a company is added: a new column starts empty for every group.