Rule Restriction

Decide per user what each person can create, edit, delete, see and click in Odoo

Rule Restriction is an Odoo 19 Enterprise app for per-user access control without cloning or editing standard groups. Block create, edit and delete on any model, hide buttons, menus and fields, and limit which warehouses, journals, companies, pricelists and products each user sees.

Odoo 19.0 · Enterprise · Odoo.sh, On-premise · 139,30 € · Buy on Odoo Apps

Available for: Odoo 19.0

The problem

Standard Odoo access groups work at the level of a whole app. To stop one person from deleting invoices or seeing one warehouse, administrators clone groups or edit master data. Every cloned group is one more thing to maintain, and one mistake can expose data or block a colleague. Over time nobody is sure who can do what.

What it does

Block actions per user

Hide parts of the interface

Limit which records users see

One rule, many users

Safe by design

Rule Restriction access rule card in Odoo with Create, Edit and Delete blocked and read access allowed for selected users
One access rule decides which operations the selected users can perform. Illustration from the store listing.
Record visibility table in Odoo listing warehouses, journals and a pricelist, each shown or hidden for the selected users
Show or hide individual warehouses, journals and pricelists per user. Illustration from the store listing.

Who it is for

Not a fit when:

Install

Requires: Inventory (stock), Invoicing (account), Discuss (mail)

  1. Buy Rule Restriction on the Odoo Apps Store with the Odoo account linked to your database.
  2. Add the module to your Odoo.sh repository or your on-premise addons path.
  3. Update the apps list and install Rule Restriction. Odoo installs Inventory, Invoicing and Discuss with it if they are missing.

Built and tested for Odoo 19 Enterprise on-premise and on Odoo.sh. Odoo Online does not allow third-party apps, so it cannot be installed there.

Configure

  1. Open the Restrictions app and create a new rule.
  2. Pick the users the rule applies to and the model it controls.
  3. Combine the layers you need in the same rule card: blocked operations, hidden interface elements and record visibility.
  4. Add the people who maintain rules to the Exempt (Admin) group so they are never restricted.
  5. If restricted users could reach Odoo through the API, turn on the optional server-side enforcement.
SettingWhat it does
Target usersThe users the rule applies to. One rule can cover many users.
ModelThe Odoo model whose create, edit and delete actions the rule controls.
Blocked operationsCreate, edit and delete can each be blocked for the selected users.
Hidden interface elementsButtons, menus, fields, tabs, groups, statusbar values and actions to hide from the selected users.
Record visibilityWarehouses, journals, companies, locations, pricelists and products to hide or allow-list. An empty allow-list means available to everyone.
Server-side enforcementOptional. Also blocks create, write and unlink over RPC, in addition to the interface.
Exempt (Admin) groupMembers skip every restriction, which keeps administrators from locking themselves out.

How to use it

Stop a user from deleting records on one model

  1. Create a rule and select the user or users.
  2. Choose the model whose records they must not delete.
  3. Block Delete and save. Those users no longer see the delete option in the interface.
  4. Turn on server-side enforcement if they could also reach the data through the API.

Limit a user to their own warehouse and journals

  1. Create a rule for the user.
  2. In the record visibility layer, allow-list the warehouses, journals or pricelists they should see.
  3. Save. Other warehouses, journals and pricelists disappear from that user's dropdowns and dashboards, and existing records that reference them still open.

Restrict temporary or external staff

  1. Create one rule and add all temporary or external users to it.
  2. Block the operations they should not perform and hide the menus, buttons and actions they do not need.
  3. When someone leaves, remove them from the rule. No groups need rebuilding.

Limits

Frequently asked questions

Can I restrict delete rights for one user in Odoo without new groups?

Yes. With Rule Restriction you create a rule, select the user and the model, and block Delete. The user loses the delete option on that model while the standard groups stay as they are. One rule can also cover many users.

How do I hide a warehouse or journal from a specific Odoo user?

Create a Rule Restriction rule for that user and allow-list only the warehouses, journals or pricelists they should see. The others disappear from their dropdowns and dashboards. Old records that reference hidden data still open.

Can I hide buttons and menus per user in Odoo?

Yes. Rule Restriction hides buttons, menus, fields, tabs, groups, statusbar values and actions for the users you select. The hiding happens in the interface and needs no changes to Odoo core.

Can an administrator lock themselves out with Rule Restriction?

No. Members of the Exempt (Admin) group skip every restriction, managers and system administrators are exempt automatically, and superuser, sudo and scheduled code paths are always bypassed.

Can a restricted user get around the rules through the API?

Interface restrictions apply by default. Turn on the optional server-side enforcement in Rule Restriction to also block create, write and unlink over RPC.

Which Odoo versions does Rule Restriction support?

Odoo 19 Enterprise, on-premise and on Odoo.sh. Odoo Online does not allow third-party apps, so it cannot be installed there. The price is one-time per Odoo major version, and each new version is sold separately.