Access Rights and Record Rules: Protecting Multi-Company Odoo Data

Access Rights and Record Rules: Protecting Multi-Company Odoo Data – Mediod Consulting Odoo Security guide cover

Odoo controls data access in layers. Access rights (ACLs) decide whether a group can read, write, create or delete records of a model at all. Record rules then filter which specific records that group can see, using domain expressions. Field groups hide individual sensitive fields.

In multi-company or multi-department databases, one wrong rule can show payroll, customer lists or ledgers to the wrong business unit. This article is part of our Odoo security series.

Key takeaways

  • Access rights work at model level; record rules work at record level; field groups work at field level.
  • Global rules apply to everyone and are combined with AND. Group rules are combined with OR among themselves.
  • In Odoo 20, record rules are removed and the domain sits directly on the access right.
  • Never run daily work as an administrator, and test every change as a restricted user.

How the layers fit together

  • Access rights (ACLs): per model and per group, with read, write, create and delete flags. If no group grants access, the user is refused.
  • Record rules (up to Odoo 19): domains that filter records. Global rules restrict everyone; group rules widen access for members of a group, within the limits of the global rules.
  • Field-level groups: the groups="..." attribute on fields and view elements hides values such as salaries or bank details from users outside those groups.

What changes in Odoo 20

The Odoo 20 release notes describe simplified access rights: record rules are removed, and a domain is added directly on the access right to decide which records it applies to. The principles stay the same — least privilege and company separation — but custom rules from older versions have to be reviewed and moved during the upgrade. Our Odoo migration team includes that review in every upgrade project.

Common mistakes

  • Working as Administrator. Admin accounts hide permission problems until a normal user hits them, or sees too much.
  • Global rules that are too strict or too loose. A global rule written for one department silently removes legitimate access for others, or a missing company rule exposes data across companies.
  • Sensitive fields on shared views. Salaries, bank accounts or internal notes visible on forms that many groups can open.
  • Too many custom groups. A permission matrix nobody understands is one nobody can audit.

Best practices

  1. Keep global rules minimal — mainly multi-company separation — and tie other restrictions to groups.
  2. Design groups around roles, documented in one place, and reuse Odoo’s standard groups where possible.
  3. Use field groups for sensitive fields instead of copying views.
  4. Test with personas. Keep a test user for each role and check every new feature with them.
  5. Remember licences. Granting a user access to a core app can change their licence type — see our Light User guide.

Running several companies in one database? Our guide to Odoo multi-company and multi-currency covers the setup side.

How Mediod can help

Mediod designs permission matrices, custom groups and company separation for multi-company Odoo databases, and reviews existing set-ups before an upgrade. Start with our Odoo implementation service or book a discovery call.

More from our Odoo security series

See all Odoo Security articles →

Want a second pair of eyes on your Odoo security?

Mediod Consulting is an Official Odoo Partner. We review custom modules, access rights, integrations and hosting set-ups, and give you a prioritised list of fixes. Book a free discovery call or request a quotation for a security review.

FAQs

Frequently Asked Questions

What is the difference between access rights and record rules in Odoo?

Access rights decide whether a group can read, write, create or delete records of a model at all. Record rules filter which individual records the group can access, using a domain.

How are global and group record rules combined?

Global rules apply to all users and are combined with AND. Group rules are combined with OR among themselves, and the result is then restricted by the global rules.

Are record rules removed in Odoo 20?

Yes. According to the Odoo 20 release notes, record rules are removed and a domain is added directly on the access right instead.

Ayesha Wajid avatar

Ayesha Wajid

Ayesha Wajid writes about Odoo ERP implementation, business process automation, and digital transformation at Mediod Consulting.

Leave a Comment

Your email address will not be published. Required fields are marked *