Reporting Permissions
Who can open which report, how centers bound the data, and why Staff never sees Reporting.
Reporting has no permissions of its own. A report is visible because the features it reads are granted to you, and the data inside it is bounded by the same center allow-list that bounds every other screen. The catalog, the hub and every report endpoint apply the same rules, so a report you cannot open is one you never see listed.
A user whose role authority is Staff is refused every report, on every route, before any feature is consulted. There is no Reporting sidebar entry, the catalog is empty, custom reports, packs, schedules, workbooks, reconciliation and the dashboard analytics all return 403, and a schedule created by someone else is never listed to them. The Portal role is refused the same way. Nothing in role configuration can open this.
How a Report Is Gated
Each report path maps to a policy. A policy names one or more features and whether you need any of them or all of them.
| Policy | Example | What it takes |
|---|---|---|
| One feature | Inventory Summary → Inventories | Read permission on that feature, and the feature must be active on your subscription. |
| Any of several | Sales Summary → Invoices or Sales Receipts | Read permission on at least one. The report then covers only the document families you hold — an Invoices-only user sees invoices, not sales receipts. |
| All of several | Gross Profit by Item, Sales Price Exceptions → Invoices and Sales Receipts | Read permission on every feature named. The center scope is the intersection of their allow-lists. |
| Role only | User Activity → Super Administrator or Administrator | Independent of any module. A missing module never hides it; a feature grant never opens it. |
An unknown report path fails closed — it is treated as no access, never as inherited module access.
Which feature opens which category
| Category | Features consulted |
|---|---|
| Financial & General | Journals (P&L, General Ledger, Journal Entries, comparisons, bridges, income/expense by account, tax summary, cash flow, changes in equity, revenue & expense trend, Group Management Report) and Chart of Accounts (Balance Sheet, Trial Balance, Working Capital, Financial Ratios, Bank Account Summary). The catalog additionally lists this category only to Super Administrators and Administrators. |
| Sales | Invoices, Sales Receipts (cash sales), Sales Orders, Payment receipts, Customers |
| Purchases | Bills, Expenses, Purchase Orders, Payment vouchers, Vendors |
| Operations | Inventories, Productions, Fixed Assets, Projects |
| People | Personnel, Payroll, Requisitions |
| Administration | Super Administrator or Administrator role |
The exact feature behind every report is listed on Report catalog.
How the Data Is Bounded
Once a report is open, the rows it returns are scoped in two steps. Centers come first; the feature's data scope only refines within them.
| Who | Scope |
|---|---|
| Super Administrator, Administrator | The whole business, every center. |
| Every other role — Supervisor, Manager, Team Lead, custom roles | Only the centers on your allow-list. A feature with data scope "own" narrows further to documents you created, still inside your centers. |
| A user with an empty center allow-list | No data. An empty list means no centers, never everywhere. |
A report that needs two features (all-of) uses the centers common to both. If the two allow-lists share no center, the report is refused rather than widened.
Some business-level analyses cannot honour an "own" scope because they have no per-creator dimension — Collections by Bank refuses such a user with This report covers collections across the business. Your access is limited to your own records.
Schedules, Custom Reports, Packs and Workbooks
| Surface | Who sees it |
|---|---|
| Custom reports (table and composed) | Only the user who saved them, within their business. Building a table report from a module requires access to that module's gate report (for example Sales documents for the Sales module). |
| Scheduled deliveries | The creator, plus anyone else in the business who can open the underlying report. A schedule runs with the creator's permissions at the time it fires. |
| Daily packs | Any non-Staff user, for the centers on their allow-list. Submitting, listing and opening a pack for a center outside your list is refused. |
| Ledger workbooks | Customer ledgers need the Customer Balances report; vendor ledgers the Vendor Balances report; inventory ledgers the Inventory Summary report. |
| AR / AP reconciliation and dashboard analytics | Anyone who can open at least one report. |
| Group reporting | Only companies where you hold an active role are disclosed; the rest are counted, never named. |
What Is Logged
Every refused report request is written to the security log as an authorization denial. Every PDF, Excel and CSV download and every workbook is logged as a data export. Creating, updating and deleting a custom report is written to the tenant activity log. See Settings → Activity Logs.
Related
- What a filter can and cannot reach: Filtering a report.
- Which reports each grant opens: Report catalog.
- Whose permissions a scheduled send runs with: Managing schedules.