Product Access, Finally Under Control
Give every user a personal allow-list of products, templates and categories — filtered at the source across sales, purchase and inventory, so restricted items never even appear.
Every internal user with product access can see, select and often edit the entire catalog. Sales reps quote items outside their line, purchasing agents transact outside their commodity categories, and cross-company items leak between subsidiaries — because Odoo's native access rights are not built for per-user product scoping.
Product Restriction On Users builds a per-user allow-list of products, templates and categories, enforced live everywhere a product appears — search, dropdowns, sales, purchase and inventory lines — so a restricted user never even sees what they cannot use.
Complete product scoping, not a partial filter
Every capability below is implemented in the module.
Granular Allow-Lists
Grant access down to individual product variants, whole product templates, or entire categories — mix and match per user for exactly the scope each role needs.
Category Inheritance
Grant a parent category and every subcategory is covered automatically, so new products added underneath become visible immediately without extra setup.
Filter at the Source
Restricted products never appear in search results or selection dropdowns across sales, purchase and inventory — users are never shown an item they cannot use.
Read-Only Mode
Let a user view their allowed products without creating, editing or deleting them, reserving full catalog rights for a dedicated manager group.
Time-Limited Access
Set a start and end date on a restriction profile so seasonal reps, contractors or short-term projects lose access automatically, no manual clean-up required.
Templates & Bulk Assignment
Save a restriction as a reusable template, such as "Sales Rep — EU Line", and apply it to many users at once instead of configuring every person one by one.
Self-Service Access Requests
Restricted users can request access to a specific product or category, and a manager approves or refuses it in one click — no more back-channel emails to unblock a sale.
Append-Only Audit Trail
Every grant, revoke, template application and approval is logged with who made the change and when, giving compliance teams a permanent record to review.
Clear, Actionable Errors
If a restricted user still attempts an unauthorized action, they see a specific message naming the product and pointing them to the access-request screen — never a vague permission error.
How it works
Create a Profile
An admin creates a restriction profile for a user and grants access to specific products, templates or categories.
Enforced Everywhere
Global record rules filter that user's product searches, dropdowns and order/stock lines automatically, with no per-screen setup.
Request & Approve
Need something new? The user submits an access request and a manager approves or refuses it in the same app.
Audit & Report
Every change is logged, and the profile list surfaces effective product counts, giving admins an instant access map.
See it in action
From profile setup to approval workflow and audit trail — every screen shown below.
Restriction profiles list: enable or disable each user's restriction, see read-only status, and check granted-item and effective-product counts at a glance.
Restriction profile form: assign allowed categories, product templates and variants across dedicated tabs, apply a template, and drill into effective products or the audit log.
Access-request list with status badges, so managers can see what is submitted, approved or refused at a glance.
Access-request workflow: a user requests a product or category and a manager submits, approves, refuses or cancels the request.
Restriction templates list, showing how many profiles use each reusable preset.
Restriction template form: define a reusable allow-list once, such as "Purchasing — Raw Materials", and apply it to many users.
Append-only audit log recording every grant, revoke, approval and template application, with who changed it and when.
Bulk-assign wizard: add, replace or remove allowed products and categories, and read-only status, across many users in a single action.
Frequently asked
What happens to a user with no restriction profile?
Nothing changes for them. A user with no profile, or a disabled one, sees the entire product catalog exactly as stock Odoo behaves. Restriction only applies once an admin creates and enables a profile for that user.
Does this only hide products, or does it actually block actions?
Both. Restricted products are filtered out of search results and selection dropdowns everywhere they appear, and a friendly, specific error is raised if a restricted product is ever referenced directly on a sales, purchase or inventory line.
Can I grant access to a whole category instead of listing every product?
Yes. Grant a category and every subcategory beneath it is covered automatically through live category inheritance, so newly added products in that category appear right away.
How do users get access to something new without emailing an admin?
They submit a self-service access request for the specific product or category from within the app, and any manager can approve or refuse it. The decision and reason are logged in the audit trail.
Get in Touch
Have questions or need customization? Every purchase includes 30 days of free support — we are here to help.
Visit Our Website
www.cerevantix.comExplore our apps, services, and portfolio.
Empowering growth through technology.
Product Restriction On Users gives every internal user a per-user allow-list of products, templates and categories — enforced live across sales, purchase and inventory, with templates, bulk assignment, self-service requests and a full audit trail.
| Availability |
Odoo Online
Odoo.sh
On Premise
|
| Odoo Apps Dependencies |
•
Discuss (mail)
• Inventory (stock) • Purchase (purchase) • Sales (sale_management) • Invoicing (account) |
| Lines of code | 1220 |
| Technical Name |
cerevantix_product_restriction_on_users |
| License | OPL-1 |
| Website | https://cerevantix.com |
Odoo Proprietary License v1.0 This software and associated files (the "Software") may only be used (executed, modified, executed after modifications) if you have purchased a valid license from the authors, typically via Odoo Apps, or if you have received a written agreement from the authors of the Software (see the COPYRIGHT file). You may develop Odoo modules that use the Software as a library (typically by depending on it, importing it and using its resources), but without copying any source code or material from the Software. You may distribute those modules under the license of your choice, provided that this license is compatible with the terms of the Odoo Proprietary License (For example: LGPL, MIT, or proprietary licenses similar to this one). It is forbidden to publish, distribute, sublicense, or sell copies of the Software or modified copies of the Software. The above copyright notice and this permission notice must be included in all copies or substantial portions of the Software. THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.
Please log in to comment on this module