AugForums.com

An Acumatica User Group

  • Free
    • Start Here
    • Rolodex
    • Podcast
    • Blog
    • Forums
  • Paid
    • AugSQL
    • GI Course
    • GI Library
    • Consulting
  • Register

Field Security

March 1, 2014 by Tim Rodman

This week I was reviewing the security options in Acumatica and I was pleased to discover that Acumatica offers field-level security on screens.

Sometimes it’s nice to be able to control which fields on a screen a user has access to. Maybe you want to allow the Sales department to control pricing and sales categories for a stock item in the Stock Items (IN202500) screen, but you want the Inventory department to control the warehouse details and the Shipping department to control the Packaging information. All of this information lives on the Stock Items (IN202500) screen so you wouldn’t want to grant permissions for everything on the screen to Sales, Inventory, and Shipping. This is where field-level security comes in handy. You can allow only specific fields to be edited by Sales, other fields to be edited by Inventory, and other fields to be edited by Shipping. You could still display all fields as read-only or maybe hide some fields if they contain sensitive information. And this can be done on any screen, not just the Stock Items (IN202500) screen.

My company’s current ERP system, Sage 500 ERP, only offers screen-level security. Because of this, I have had to create Microsoft Access applications in order to create more restricted screens for certain users. It gets the job done, but it’s very messy and it opens up some small security holes in the Sage 500 ERP application.

In this post I’d like to cover how to restrict the Vendors (AP303000) screen to only allow a user to modify the Vendor’s main address. This could be useful if you want to allow the Purchasing department to maintain the vendor’s main address without allowing them to change any other information on the vendor.

In order to setup security for a User, you first need to define a Role, assign the User to that Role, then define the security permissions for the Role. In order to create the Role, use the User Roles (SM201005) screen. Here I am going to created a Role called Vendor Main Address Edit and assign my trodman User to it.
2014-02-25_224732

 

Once you create the Role, you can define security for the Role using the Access Rights By Role (SM201025) screen. You could assign permissions of Not Set, Revoked, View Only, Edit, Insert, and Delete. Insert could come in very hand for a group of users who should be able to create new records, but not modify them. In this example though, I’m going to assign Edit permissions on the entire Vendors (AP303000) screen like this.
2014-02-25_225013

 

Now that I have given Edit permissions on the entire screen, I now want to lock down all the fields, except for the address fields. Notice that the Vendors (AP303000) screen is broken down into multiple categories and the fields are listed under each category. You have to double-click in the grid to begin selecting Access Rights for each category. You can choose from Inherited, Revoked, View Only, and Edit. I prefer to sort my grid by the Description field first, then assign permissions. By default, all the permissions are set to Inherited which means it will inherit its permissions from the next level up. In our example, I’m going to start by changing the permissions on all the categories from the default of Inherited to Revoked.
2014-02-25_231624

Once I have set permissions on all the categories to Revoked, I now want to set permissions on all the fields within each category to Revoked.
2014-02-25_230727

 

If anyone knows of an easy way to assign the permission of Revoked to all fields quickly, please let me know. The fastest way I know is to type the letter “r” on the keyboard, then press the “Enter” key twice in order to move to the next field down on the list. Then type “r” again, and continue the same pattern. It’s pretty fast since you don’t have to touch your mouse.

Once I’ve assigned Revoked to all the categories and all the fields in each category under the Vendors (AP303000) screen, I can now go back and assign Edit to the Address category and Edit to the fields within the Address category that I want the user to be able to edit.
2014-02-25_232136

 

 

2014-02-25_232246

 

Now for my favorite part. I can easily login as my trodman user by opening another tab in my Google Chrome web browser. I don’t need a separate computer or a separate browser in order to test, just simply another tab on my current browser. Somehow, Acumatica is able to have multiple users logged in simultaneously on multiple tabs of a web browser on the same computer. Another really nice feature is that the user picks up the new permissions simply by refreshing the webpage. You don’t need to logout and then back in like you do in Sage 500 ERP in order to pickup the new permissions. Now, when I login as my trodman user on a separate tab, this is what I see:
2014-02-25_232819

 

Hmmm, something doesn’t look right. Even though I have permissions to the Vendors (AP303000) screen, I can’t see the screen listed on the menu. But, since I’m able to be logged in as two different users on two different tabs of my web browser, I don’t have to logout and then back in as the admin user. I just click over to the tab that is logged in as admin and still has the Access Rights By Role (SM201025) screen open to make my security changes. I’m going to grant View Only permissions on the Finance module.
2014-02-25_233118

 

Then View Only to Accounts Payable:
2014-02-25_233230

 

Now I can click back over to the tab that is logged in as trodman and refresh my page by pressing Ctrl-r on my keyboard. Here is what the screen now looks like:
2014-02-25_233455

 

This is much better. I’m able to browse to the Vendors (AP303000) screen and I’m able to see the address fields. I still have a problem though because I don’t have any buttons available on the screen to select a vendor or save my changes. So, I need to set a few more permissions under the Vendor category and set the permissions on the Vendor category itself to Edit. In order to speed this example up, I’m going to set the permissions on the fields under the Vendor category, then filter the grid to only show which fields are no longer set to Revoked.
2014-02-25_234723

 

Now I can switch back to the trodman user and notice that this looks pretty good. I’m able to lookup based on the Vendor ID field and I can use the buttons on the top to browse through vendors or save my changes. And the trodman vendor can only make changes to the address fields which is exactly what I wanted.


2014-02-26_000913

 

So, as you can see, this is MUCH faster than having to use a program like Microsoft Access to develop a new screen. Also, this method has the BIG advantage of keeping all of our security setup inside of the ERP application. This becomes even more crucial as you use this method on more screens.

Filed Under: Acumatica Learning Tagged With: Acumatica, Acumatica Blog, Acumatica Field Security, Acumatica Field-Level Security, Acumatica Training, Acumatica User Security

By using this website, you agree to our Terms of Use (click here)
Building Generic Inquiries & Pivot Tables

Online Members

 No online members at the moment

Recent Blog Posts

  • EP 160: How long does it take an Automation Schedule to run in Acumatica (Podcast) November 7, 2025
  • EP 159: Mark Safran – Smartsheet Dashboards with Acumatica data (Podcast) October 29, 2025
  • EP 158: Garrett Rochell – Acumatica Upgades, especially with the Modern UI (Podcast) October 4, 2025
  • acuCONNECT 2025 – Visualizing Inventory Balance $ and Service Level % TOGETHER September 19, 2025
  • EP 157: acuCONNECT 2025 Preparation – Part 4 (Podcast) September 16, 2025

Recent Forum Posts

  • Tim Rodman

    RE: Generic inquiry with information from Audit history(CT301000)

    @graemelm Just pulled it in as a Custom DAC fed by the ...

    By Tim Rodman , 1 day ago

  • Tim Rodman

    RE: Importing Acumatica User Roles / User Security Permissions from Excel

    @astra-mathis thank you for the detailed instructions. ...

    By Tim Rodman , 1 day ago

  • Astra Mathis

    RE: Importing Acumatica User Roles / User Security Permissions from Excel

    @timrodman - using the files from this article and foll...

    By Astra Mathis , 2 days ago

  • GraemeLM

    RE: Generic inquiry with information from Audit history(CT301000)

    @timrodman Hi Tim, hope you're well! I'm interested t...

    By GraemeLM , 3 days ago

  • sangland

    RE: Customer Portal Setup - Access issues to create sales order

    Hi, was there an answer for this problem?

    By sangland , 2 weeks ago

  • Bronwyn Duprey

    RE: Attribute Input Mask

    Does anyone know where I can find instructions on the f...

    By Bronwyn Duprey , 3 weeks ago

  • Astra Mathis

    RE: Importing Acumatica User Roles / User Security Permissions from Excel

    @nangel SM651500 Access Rights by Role or SM651700 Acce...

    By Astra Mathis , 1 month ago

  • matthewjames

    RE: Generic Inquiry Screenid changes to ScreenId=00000000

    if anyone gets this error again (resetting screen ID to...

    By matthewjames , 2 months ago

  • Travis

    RE: Pick List report suddenly not splitting on Shipment

    I never found a solution initially - here I am 3 years ...

    By Travis , 3 months ago

Terms of Use & Disclaimers :: Privacy Policy

Copyright © 2025 · AUG Forums, LLC. All rights reserved. This website is not owned, affiliated with, or endorsed by Acumatica, Inc.