How Rules Combine

Updated 15 July 2026

Understand what happens when someone matches several profiles, and who is never restricted by Access Control Studio.

Overview

Real companies stack rules: a company-wide default profile, a department profile, and maybe an exception on one user. ACS combines matching profiles so restrictions accumulate.

People in Access Control Studio / Administrator (and similar full admin cases) are exempt – profiles do not limit them. That keeps the system manageable and safe.

How It Works

If Profile A hides the Accounting menu and Profile B hides Export on Contacts, a user in both gets both restrictions.

Hides and blocks generally unite (more restriction wins). That is why testing the combined user is essential.

Archived profiles do not participate. Unassigned profiles do nothing. Company-limited profiles apply only in those companies.

Step-by-Step Guide

Fields Table

These are the settings you will see for this feature, explained in everyday language.

Field Explanations

Each field from the table above is explained in more detail here.

Users on profile

Most specific way to attach rules to one person.

Groups on profile

Scales with your existing Odoo team groups.

Companies on profile

Use in multi-company databases when access differs by company.

Active

Archive to disable without losing configuration.

Administrator group

Exemption is intentional. Use Test as User to see real staff experience.

Multiple profiles

Plan for stacking. Prefer fewer clearer profiles over many overlapping ones.

Tips

Common mistakes

Image

How Rules Combine