Purchasing permissions
Access to purchasing is controlled by permissions, set per role in an organisation's Roles & permissions settings. Most of purchasing runs on one set of permissions attached to suppliers; posting a goods receipt also needs a separate one.
Supplier permissions
| Permission | Roles-screen label | What it allows |
|---|---|---|
| Create | Create suppliers & purchase orders | Creating a new supplier, purchase order, goods receipt, supplier invoice, supplier return, prepayment, or an OCR invoice upload. |
| View | View purchasing | Viewing every purchasing list and record. Without it, the Purchasing section doesn't appear in the sidebar at all. |
| Edit | Edit suppliers & purchase orders | Editing a supplier and its supplier price list; submitting and sending a purchase order; submitting a goods receipt for review, and — together with Accept receiving discrepancies below — posting one; matching and posting a supplier invoice; editing draft supplier returns and prepayments. |
| Delete | Delete purchasing records | Exists as a permission, but nothing currently reachable in purchasing uses it. Suppliers, for example, cannot be deleted from the interface at all. |
| Approve | Approve purchase orders | Approving a purchase order, and releasing a held supplier invoice — the same permission covers both. |
| Quick-receive | Quick-receive a whole PO (skip scan check) | The one-click shortcut that receives an entire purchase order without scanning each line individually. |
Accepting receiving discrepancies
Posting a goods receipt is gated by a separate permission, on its own resource rather than the supplier one above: Accept receiving discrepancies.
Posting a receipt needs both Edit suppliers & purchase orders and Accept receiving discrepancies. A user who holds only the edit permission gets Submit for review instead of Post — their receipt then waits for someone who holds both to post it.
Reordering needs an inventory permission too
Reordering sits in the Purchasing section of the sidebar, but its figures are inventory data. Opening it needs both View purchasing and View inventory — the second from the Inventory group on the roles screen. Holding only one of the two hides the item, rather than showing a page that could never load a worklist.
No default role is affected: all five hold both permissions. It only bites on a custom role built by removing View inventory while leaving View purchasing in place.
Default roles
| Role | Supplier permissions | Accept receiving discrepancies |
|---|---|---|
| Owner, Administrator | All six | Yes |
| Member, Warehouse, Read only | View purchasing only | No |
On the default roles, warehouse and member users can view purchasing but cannot post a goods receipt themselves. They can build a receipt and submit it for review; an owner or administrator then posts it. This is the most common surprise for a team new to purchasing — worth checking before anyone asks why they only see Submit for review.
Where roles are changed
Permissions are set per role on the organisation's Roles & permissions settings page, which itself needs permission to view roles.
Sidebar visibility
Purchasing's sidebar items are hidden, not greyed out, for a user who lacks the permission behind them. A user without View purchasing sees no Purchasing section in the sidebar at all — not a disabled one.