Email-based Two-Factor Authentication with User-Level Control
Encrypted credential vault with folder organisation, sharing, and 2FA gate.
Enforce two-factor authentication and SAML/OIDC single sign-on against the customer's own IdP, with a VAIT/BAIT-style login policy. Community-friendly, BYOK.
Scheduled database backups to the customer's own storage plus automated restore-test verification reports for the German Notfallkonzept / BCP.
Visualize who-can-see-what, simulate access as any user and detect segregation-of-duties (Funktionstrennung / SoD) conflicts for the German IKS.
Access & login auditing for German IKS / Zugriffskontrolle: failed-login alerts, active session register, force-logout, and geo/anomaly detection.
Restrict user login to specific registered devices
Device Security Lock Module =========================== This module provides device-based login restrictions to enhance security: Features: --------- * Company-level device lock enable/disable * User-level login restrictions (Web, Mobile) * Device UUID tracking and validation * Admin reset functionality for device locks * Support team troubleshooting capabilities How it works: ------------- 1. Admin enables device lock at company level 2. Users are restricted based on their login restriction settings 3. On first login, device UUID is stored 4. Subsequent logins are validated against stored UUID 5. Admin can reset device locks when users change devices Perfect for organizations requiring strict device control!
All In One Access Security & Access Control application to define, control, and secure access rights for users and companies across all Odoo modules. This module provides a centralized solution to manage visibility and permissions for menus, fields, models, views, buttons, tabs, reports, actions, server actions, chatter, filters, group by options, imports, exports, and archive operations. Access rules can be configured user-wise or company-wise without using complex record rules, making security management easier, faster, and more flexible for administrators and functional users. This module allows hiding menus, sub-menus, and applications, hiding views such as Tree, Form, Kanban, Calendar, Pivot, Graph, Map, Activity, and Gantt, hiding object buttons, action buttons, smart buttons, state buttons, and navbar buttons, and hiding create, duplicate, delete, archive, import, and export options. It also supports hiding reports, actions, server actions, hiding chatter completely or partially, hiding filters and group by options, hiding tabs and notebook pages, and applying field-level control such as hide, readonly, required, and invisible. Administrators can make any user globally read-only across the system, apply model-wise read-only restrictions, restrict access to specific apps, views, reports, or actions, and control UI elements without modifying core code, all from a centralized access control and security management system. The module supports user-wise and company-wise access configuration, works in multi-company environments, and is fully compatible with standard Odoo security. The solution covers advanced access control, access management, user access rights, advanced access security, and Odoo security requirements including hide menu, hide buttons, hide views, hide full chatter and chatter features, readonly users, global readonly users, model-wise readonly a ccess, field hide, field required, field readonly, hide create, hide archive, hide unarchive, hide delete, hide export, hide import, navbar button hide, state button hide, server action security, window action security, hide filter, hide group, hide custom filter and group, global restriction, hide global chatter and all chatter features such as send message, log note, activity, followers, attachment, hide global print action, hide global import export, hide global create and delete buttons, disable login for users or companies, disable developer mode, hide tree, list, kanban, graph, activity, calendar, pivot, gantt, and hierarchy views, report button security, company-wise access control, user-wise restriction, role-based access control, permissions management, advanced user permissions, all-in-one access rights management, UI access control, access rules with active and deactive rules.
Schedule database backups to the customer's EU-region storage (BYOK) and run an automated restore-test report so backups are actually proven (FR/BE/NL BCP)
Fuzzy de-duplicate partners keyed on French SIREN/SIRET, Belgian KBO/BCE and Dutch KvK/RSIN numbers, then merge safely with full relink (FR/BE/NL)
Restrict login by country / IP range and log every access attempt for EU data-residency policies (FR/BE/NL), with EEA allow-listing and CIDR rules
Second-approval (maker-checker) gate before posting VAT returns, payment runs or e-invoices, with a segregation-of-duties report (FR/BE/NL internal control)
Detect over-retained personal data per FR/BE/NL rule and run a GDPR-safe purge with an evidence log
Extension de las reglas de permisos para Contabilidad
Checksum-validate FR NIR, BE NISS/INSZ and NL BSN on partner & employee records (local algorithm, no registry)
Mask & pseudonymise national IDs (NIR, NISS/INSZ, BSN) with role-based reveal and an access log
Immutable field-level change history on fiscal-relevant records to support the French piste d'audit fiable (PAF / CGI art. 289, BOI-TVA-DECLA)