Quick answers when something does not look restricted, looks too restricted, or a user cannot sign in.
Overview
Most support tickets fall into a few patterns: testing as an exempt admin, profile not assigned, archived profile, multiple profiles stacking, or a domain filter that is too strict.
Work through the checklist in How It Works before changing many settings at once.
How It Works
Quick diagnosis checklist
- Is the user an ACS Administrator? If yes, rules will not apply – use Test as User on a normal account.
- Is the profile Active and assigned via Users or Groups?
- In multi-company, does Companies on the profile include the company they are using?
- Do other profiles also apply and add more hides?
- Did the user refresh / start a new session after you saved?
Step-by-Step Guide
- Reproduce with Test as User on the affected person (or a twin test user).
- Open Access Profiles board and list every profile that includes that user or their groups.
- Confirm each profile is Active and has the rule type you expect (chips on the card).
- If lists are empty, temporarily relax Domain Access and retest.
- If export still appears, check Global Hide Export and Model Access Hide Export on that model.
- Fix one profile at a time, retest, then document what solved it in the profile chatter.
Fields Table
These are the settings you will see for this feature, explained in everyday language.
| Field Name | Description | Example |
|---|---|---|
Why don’t I see any restrictions? |
Usually testing as Administrator, or profile unassigned/archived. |
Use Test as User on staff account |
User sees an empty list |
Domain Access too strict, or date preset too narrow. |
Widen domain / clear date preset |
Menu hidden but user still opens records |
Bookmark or other path; add Model/Domain rules. |
Pair Menu + Model Access |
Export still available |
Export not hidden globally or on that model; another path exists. |
Hide Export global + model |
Button still visible |
Wrong button key/type; Discover again. |
Re-run Discover Buttons & Tabs |
Cannot log in |
Disable Login is on for their profile. |
Admin removes flag or unassigns profile |
Rules vanished after archive |
Archiving deactivates synced domain rules too. |
Restore/Activate the profile |
Import skipped some lines |
Missing menus/fields in target DB with Skip Missing References. |
Read Import Log; install missing apps |
New employee has no limits |
No Default for Internal Users profile set. |
Enable default on baseline profile |
Two profiles conflict |
Restrictions combine; required+invisible can clash. |
Simplify to fewer profiles |
Field Explanations
Each field from the table above is explained in more detail here.
Why don’t I see any restrictions?
Administrators are exempt by design. Also check assignment and Active.
User sees an empty list
Domain filters hide rows. Confirm with a manager account that data exists, then loosen the domain.
Menu hidden but user still opens records
Hiding navigation is not full security by itself – add model and domain rules for sensitive apps.
Export still available
Check both Global and Model Access. Also Hide Spreadsheet if they use spreadsheets to extract data.
Button still visible
Keys are technical; use Discover rather than guessing.
Cannot log in
Only an ACS Administrator (or someone not blocked) can fix Disable Login on that profile.
Rules vanished after archive
Expected. Restore the profile to bring rules back.
Import skipped some lines
Normal when databases differ. Install the same apps or recreate missing lines manually.
New employee has no limits
Defaults are optional – turn on Default for Internal Users on your baseline profile.
Two profiles conflict
Prefer one role profile plus one light baseline instead of many overlapping packs.
Tips
- Change one setting, then retest – easier to see what fixed it.
- Keep a test user per major role permanently.
- Export profiles before big changes so you can roll back.
Common mistakes
- Turning off many rules at once “to see what happens” without notes.
- Assuming Odoo group rights alone explain an ACS hide – check ACS profiles first.
- Giving Administrator rights to the stuck user instead of fixing the profile.