Access Pro | Role Based Permissions | User Roles | Security Groups Manager | Access Rights | Field Level Security
by Tedred Technologies https://tedred.com$ 149.00
TedRed for Odoo 18
Access Pro
Give every user one Role instead of dozens of checkboxes — composed from capabilities a manager can actually read.
Odoo 18 · Community & Enterprise · by TedRed

Access Pro replaces the security checkbox grid with roles. Odoo access rights are a long list of technical groups, and getting a new joiner right means copying someone else and hoping. Access Pro lets you define a role once — Sales Representative, Accountant, Warehouse Operator — build it from business-readable capabilities, set how much data it can see, and assign it in one field.
1 role per user, not 40 checkboxes |
5 data scope levels |
3 risk ratings per capability |
2 dependencies: base and mail |
0 external services called |
Roles
One role, assigned in one field
Roles are versioned records with a draft and an active state, so a change is prepared, reviewed and applied deliberately rather than by ticking a box in a user form.

A role catalogue that reads like your org chart, not like a permissions table.
Capabilities
Permissions in business language
A capability is a named thing a person can do — "Confirm sales orders", "Post journal entries" — that maps to the underlying Odoo groups. Each one carries a risk rating, so the sensitive ones are visible at a glance.

Capabilities are grouped by category and rated normal, sensitive or critical.
Data scope
How much of the data a role can see
Beyond what a user may do, a scope domain controls how much they may see on a given model: only their own records, their team, their branch, their company, or everything.

Point a scope at a model and its owner field; each role then picks its level.
• Five levels: own, team, branch, company, all.
• Backed by ordinary Odoo record rules, nothing exotic.
• A role can hold a different scope level per model.
Assignment and audit
Who has what, and since when
Role assignments are dated records with an optional reason, so the question "why does this person have access to that?" has an answer in the system rather than in someone's memory.

Assignments carry dates and companies, and expire on their own.
Complete feature list
Everything the module does
A full role and permission layer, built on Odoo's own security primitives.
Roles instead of groups
Define a role once and assign it in a single field. The underlying Odoo groups are applied for you.
Business-readable capabilities
Name what a person can do rather than which technical group they belong to, and map it to the real groups behind the scenes.
Risk ratings
Every capability is rated normal, sensitive or critical, so the dangerous ones stand out during review.
Role inheritance
A role can inherit another, so Sales Manager starts from Sales Representative instead of repeating it.
Data scope per model
Own, team, branch, company or all — enforced through standard Odoo record rules.
Field level guards
Hide or protect sensitive fields for roles that should not see them.
Draft and apply
Roles are versioned with a draft state, so changes are prepared and applied deliberately, not by accident.
Dated assignments
Give a role a start and end date, restrict it per company, and record why it was granted.
Segregation of duties
Define rules for combinations that must never sit with the same person.
Access requests
Users can request access; the request carries an approval trail.
Assignment history
Every grant and revoke is logged, so an audit has a record to read.
Export logging
Track who exported data, and block bulk export for roles that should not have it.
Questions answered
Frequently asked questions
Does it replace Odoo security or sit on top of it?
On top. Capabilities map to ordinary res.groups and scopes are enforced by ordinary record rules, so nothing behaves in a way Odoo cannot explain.
What happens to my existing groups?
Nothing. Users keep whatever they have; a role adds its groups when applied. You can adopt it one team at a time.
Does it ship with ready-made roles?
It ships the capability categories and the framework. Roles and capabilities are yours to define, because they depend on which apps you run and how your business is organised.
Does it work on Odoo Community?
Yes. It depends on base and mail only, so it runs on both Community and Enterprise.
Can a role expire automatically?
Yes. Assignments carry a start and end date, so temporary access ends on its own instead of being forgotten.
Is anything sent outside my server?
No. There are no outbound calls, no external service and no telemetry.
Built for your next step
Want your role catalogue built with you?
Mapping an existing permission mess onto roles is the hard part, and it is work we do regularly. TedRed combines technology, design, media and marketing under one roof, and responds within one business day.
tedred.com · support@tedred.com
| Availability |
Odoo Online
Odoo.sh
On Premise
|
| Odoo Apps Dependencies |
Discuss (mail)
|
| Lines of code | 4676 |
| Technical Name |
tedred_access |
| License | OPL-1 |
| Website | https://tedred.com |
Odoo Proprietary License v1.0 This software and associated files (the "Software") may only be used (executed, modified, executed after modifications) if you have purchased a valid license from the authors, typically via Odoo Apps, or if you have received a written agreement from the authors of the Software (see the COPYRIGHT file). You may develop Odoo modules that use the Software as a library (typically by depending on it, importing it and using its resources), but without copying any source code or material from the Software. You may distribute those modules under the license of your choice, provided that this license is compatible with the terms of the Odoo Proprietary License (For example: LGPL, MIT, or proprietary licenses similar to this one). It is forbidden to publish, distribute, sublicense, or sell copies of the Software or modified copies of the Software. The above copyright notice and this permission notice must be included in all copies or substantial portions of the Software. THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.
Please log in to comment on this module