How to Restrict Vendor Bills to Their Creator in Odoo · Calibre Consulting

Show each user only their own vendor bills.

No standard Odoo access level limits users to the vendor bills they created. A global record rule does, while accountants keep full access.

This guide sets up Odoo so that staff who enter vendor bills see only the bills they created themselves, while accountants and approvers keep seeing every bill. No standard access level does this on its own: every accounting access level in Odoo can open all vendor bills in the company. The native way to get there, without custom code, is a global record rule, which is a filter Odoo applies to every user before showing them a type of record. The steps below were tested on Odoo 19.

It is written for owners, controllers and the person who administers Odoo in a company where several people enter bills.

Before you start

What the standard access levels let users see

Accounting access is set per user under Settings > Users & Companies > Users, on the Access Rights tab, in the Accounting line. In Community that line offers Invoicing and Administrator. With the Enterprise Accounting app it offers five levels:

The Purchase app adds one more route. A user whose Purchase access is User, with no accounting access, may open any vendor bill and create draft bills, but Odoo refuses to post (confirm) a bill for anyone without at least Invoicing access.

Why a rule on a group changes nothing

Each accounting level carries a built-in rule, named All Journal Entries for the Invoicing level, that opens every record. Rules attached to groups add access together: if any one of a user's groups allows a record, the user sees it. A new rule attached to the Invoicing group is outvoted by the existing one: on a test database, a clerk with such a rule still saw every bill. Global rules work the other way. Every user must pass every global rule, so the restriction has to be global, with the exemption for accountants written into the filter itself.

Copying the sales rule called Personal Invoices does not help either. It filters on the Salesperson field, and Odoo clears that field on vendor bills.

Add the rules step by step

The filters below exempt anyone whose accounting access is Administrator, Read-only or Bookkeeper. Everyone else, including Invoicing, Invoicing & Banks and Purchase-only users, sees only the vendor bills, vendor refunds and purchase receipts they created. Customer invoices, payments and other journal entries are not affected.

  1. With developer mode on, open the Settings app and go to Settings > Technical > Security > Record Rules. Click New.
  2. Enter a name such as Vendor bills: own only. In Model, choose Journal Entry, the record behind every bill and invoice.
  3. Leave Active switched on and the Read, Write, Create and Delete boxes ticked.
  4. In the box under Rule Definition (Domain Filter), paste the text below exactly, on one line.
  5. Leave the Groups (no group = global) section empty. The Global box shows as ticked. Save.

[(1, '=', 1)] if user.has_group('account.group_account_manager') or user.has_group('account.group_account_readonly') else ['|', ('move_type', 'not in', ('in_invoice', 'in_refund', 'in_receipt')), ('create_uid', '=', user.id)]

Repeat the same steps for a second rule, named Vendor bill lines: own only, with Model set to Journal Item, the individual lines of a bill. Without it, restricted users can still read the lines of other people's bills. Its filter is:

[(1, '=', 1)] if user.has_group('account.group_account_manager') or user.has_group('account.group_account_readonly') else ['|', ('move_id.move_type', 'not in', ('in_invoice', 'in_refund', 'in_receipt')), ('move_id.create_uid', '=', user.id)]

Then add a third rule with Model set to Invoices Statistics, the data behind Reporting > Management > Invoice Analysis. Without it, that report still shows every bill line, with vendor and amount, to Invoicing users. Its filter is:

[(1, '=', 1)] if user.has_group('account.group_account_manager') or user.has_group('account.group_account_readonly') else ['|', ('move_type', 'not in', ('in_invoice', 'in_refund', 'in_receipt')), ('move_id.create_uid', '=', user.id)]

Check that it worked

  1. Pick two users with Accounting set to Invoicing and one with Administrator, or create them on a copy of the database.
  2. Log in as the first Invoicing user, open the Accounting app, go to Vendors > Bills, create a bill and confirm it. Do the same as the second user.
  3. Each Invoicing user's Bills list now shows only their own bill. The administrator sees both, plus every older bill.
  4. Open Customers > Invoices as an Invoicing user. The list is the same as before the rules.

On the Odoo 19 test database, each clerk saw only their own bills, the administrator saw all of them, customer invoices were unchanged, and a clerk could still post a bill and register a payment on it.

Side effects to plan before switching it on

A note on Odoo 20

Odoo 20 replaces the Record Rules screen with a single list at Settings > Technical > Security > Access Rights. An entry with an empty Group is labelled a Restriction and applies to everyone, and restrictions still combine the same way. The Invoicing level still grants access to all journal entries there, so the same global approach applies, but the filters above were tested on Odoo 19 only. Test them on a copy of your database before using them on Odoo 20.

Steps verified on Odoo 19. Menus and labels can differ on other versions.

Common questions

Can Odoo show users only the vendor bills they created without custom code?

Yes, with global record rules added under Settings > Technical > Security > Record Rules in developer mode. No standard accounting access level does it, because each level can see every vendor bill.

Why does a record rule on the Invoicing group not restrict vendor bills in Odoo?

Rules attached to groups add access together, and the Invoicing level already has a rule named All Journal Entries that opens every record. A restriction only takes effect when the rule has no group, which makes it apply to every user.

Will accountants still see all vendor bills after the restriction?

With the filters in this guide, users whose accounting access is Administrator, Read-only or Bookkeeper still see every vendor bill. Invoicing, Invoicing & Banks and Purchase-only users see only the bills they created.

Who can see vendor bills that arrive by email once the rule is active?

Odoo records the creator as the user whose email address sent the message, or otherwise the account that processes incoming mail. Bills sent in by vendors are therefore usually visible only to exempt users, and the creator cannot be changed afterwards.

Does restricting vendor bills affect customer invoices in Odoo?

No. The filters only apply to vendor bills, vendor refunds and purchase receipts, so customer invoices, payments and other journal entries keep their usual visibility.

Talk to the team.

If you are setting this up, or Odoo is not behaving the way this guide describes, book a 30-minute call. We will look at your configuration and tell you what it needs. Calgary studio, in-house team, no offshore handoffs.

Book the call →