> For the complete documentation index, see [llms.txt](https://vezolve.gitbook.io/activebooks/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://vezolve.gitbook.io/activebooks/email/users-and-permissions/untitled-4.md).

# User Permissions

It  is a way of restricting user access to particular documents.

* Role based permissions allow setting complete access to a document type like Sales Invoice, Orders, Quotations etc. &#x20;

* If you assign a Sales User role to a user, they can access all the Sales Orders and Quotations.

* User Permissions can be used to restrict access to select documents based on the link fields in the document.

* For example, consider that you do business with multiple territories and you want to restrict access of certain Sales Users to Quotations/Sales Order belonging to a particular territory.

* This can be done via User Permissions.

* The restrictions can be set on Customer, Supplier, Customer Group, Supplier Group, etc.

**Setting User Permissions are particularly useful when you want to restrict based on:**                                                                   &#x20;

1. Allowing user to access data belonging to one Company
2. Allowing user to access data related to a specific Customer or Territory

**You can access User Permission via:**                                                &#x20;

Users > Permissions > User Permissions                                                Or                                                                                                                   Type 'New User Permission'                                                                       &#x20;

**How to create User Permissions?**

1. Go to the User Permissions list.
2. Select the user for which the rule has to be applied.
3. Select the type of document to be allowed (for example "Company").
4. Under For Value, select the specific item that you want to allow (the name of the "Company).
5. If you check 'Is Default', the value selected in 'For Value' will be used by default for any future transactions by this user. That is if company 'Celine' is selected as 'For Value', this Company will be set as default for all future transactions by this user.

![](https://429967333-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MgEi4gT9xOnYSAL1Pei%2F-Mi-gKzBzBaUXOpW9HbK%2F-Mi07bzOI1_4GX-pFGKc%2FUser%20Permission.png?alt=media\&token=1bd7bab5-238c-4431-b230-cc0d00684901)

### 2. More User Permission actions[ ](https://docs.erpnext.com/docs/v13/user/manual/en/setting-up/users-and-permissions/user-permissions#2-more-user-permission-actions) <a href="#id-2-more-user-permission-actions" id="id-2-more-user-permission-actions"></a>

#### 2.1 Advanced Control[ ](https://docs.erpnext.com/docs/v13/user/manual/en/setting-up/users-and-permissions/user-permissions#21-advanced-control) <a href="#id-21-advanced-control" id="id-21-advanced-control"></a>

In Advanced Control, you can have better command over where the User Permission is applied.

#### 2.1.1. Applicable For[ ](https://docs.erpnext.com/docs/v13/user/manual/en/setting-up/users-and-permissions/user-permissions#211-applicable-for) <a href="#id-211-applicable-for" id="id-211-applicable-for"></a>

You can optionally apply user permissions only for specific document type by setting the Document Type after unchecking the Apply To All Document Types checkbox. Setting **Applicable For** option will make the current user permission applicable only under the selected Document Type master.

![](https://429967333-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MgEi4gT9xOnYSAL1Pei%2F-Mi-gKzBzBaUXOpW9HbK%2F-Mi08xJHZ53CYVa-eI4C%2Fuser%20permission%201.png?alt=media\&token=50a7acd7-489f-4418-8ab3-9bc287aa6bcb)

In the above user permission, the user will be able to access only sales orders of selected company.

&#x20;**Note:** If **Applicable For** is not set, User Permission will apply across all related Document Types.

#### 2.1.2. Hide Descendants[ ](https://docs.erpnext.com/docs/v13/user/manual/en/setting-up/users-and-permissions/user-permissions#212-hide-descendants) <a href="#id-212-hide-descendants" id="id-212-hide-descendants"></a>

The value of **Allow** could be a DocType with a Tree View, which will have records with a parent-child or ancestor-descendant relationship.

Let's assume **For Value**, 'Celine', has a child company 'Fendy'. When a User Permission is created for 'Celine', permissions for its descendants are granted as well.

**Hide Descendants** is visible only on selecting a Tree View DocType. By enabling this checkbox, permissions for descendants of **For Value** will not be granted.

Example : A user that can view records of 'Celine' will not be able to view those of 'Fendy'.

#### 2.2 Ignoring User Permissions on Certain Fields <a href="#id-22-ignoring-user-permissions-on-certain-fields" id="id-22-ignoring-user-permissions-on-certain-fields"></a>

#### 2.3 Strict Permissions <a href="#id-23-strict-permissions" id="id-23-strict-permissions"></a>

#### 2.4 Checking How User Permissions are Applied <a href="#id-24-checking-how-user-permissions-are-applied" id="id-24-checking-how-user-permissions-are-applied"></a>
