Skip to content
WinliumDocs

Org unit access scoping

How an administrator limits a user to certain Branches, Warehouses, Departments, Cost Centers, Locations and Business Segments, and which screens enforce the limit today.

LimitedChecked against the product 06 Oct 2026

In one minute

An org unit is a part of your business: a Branch, Warehouse, Department, Cost Center, Location or Business Segment. A grant says "this user may work with this org unit". Once a user has at least one grant, Winlium refuses what falls outside their grants on the screens listed below. A user with no grants is not limited at all.

Why Winlium has it

A cashier in Ikeja should not post stock out of the Kano warehouse. Roles say what a person may do. Grants say where they may do it.

How it works in Winlium

You set grants on the user's own page: User Management, then the Defaults tab. Two cards matter.

CardWhat it givesCounts as "limited"?
Org Unit AccessFull operating access to the org unit.Yes. The first grant switches limits on.
Request & Send-To AccessOnly the right to name a Branch, Warehouse or Location as the other end of a transfer or stock request. No right to work there.No. It never limits anyone. It only widens a user who is already limited.

The six grant types

TypeWhat the user may then use
BranchOnly the granted branches.
WarehouseOnly the granted warehouses.
DepartmentOnly the granted departments.
Cost CenterOnly the granted cost centers.
LocationOnly the granted locations. A Location grant needs the grant for its Warehouse first.
Business SegmentOnly the granted business segments.

Each type is checked on its own. A Branch grant does not open that branch's warehouses.

Contexts

Each grant has a context: All, Sales, Purchase or Inventory. Today the context does not change what a grant allows. It only labels the grant and decides which default fills a form. Forms read defaults saved under All only.

Default grant

Mark one grant per type and context as the default. Entry forms such as Requisitions pre-fill it. A default never widens or narrows access. The default Location must sit inside the default Warehouse.

Limits switch on with the first grant

This surprises administrators, so read it twice.

  1. A user with no grants of any type is not limited anywhere.
  2. A user with grants, but none of one type, is not limited for that type. Grant only a Department and every warehouse stays open.
  3. SUPER_ADMIN and a TENANT_ADMIN working inside their own tenant are never limited.
  4. A grant limits only the screens in the next section. Everything else ignores grants.

Where grants are enforced today

Winlium refuses the save when any line names an org unit the user does not hold.

AreaWhat is checked
InventoryWarehouse on Goods Received Vouchers (and Location per line), journal batches, Delivery Orders, credit notes and returns to suppliers. Editing or deleting a warehouse. Item warehouse settings and availability.
Inventory transfersTransfers, Stock Request Transfers, Stock Request Receipts, Production Request Transfers and Deliveries. The sending side needs a full grant. The other end also accepts Request & Send-To Access.
SalesWarehouse on Quotations and Sales Orders.
AccountingWarehouse on Customer Invoices, Supplier Bills, Credit Notes and Supplier Returns. General Journal lines check Warehouse, Department, Cost Center and Business Segment together.
ExpenseDepartment on each line of a new claim.
Financial reportsA Branch filter on Trial Balance, Account Balances, Cash Flow, Balance Sheet, Profit and Loss and Combined COGS.
Reports and BIDWarehouse scope on Inventory, Sales and Purchase reports, Requisition History and the Inventory, Sales and Purchase BID (Business Intelligence Dashboard) pages. "All warehouses" means all of yours.

Warehouse and Location pickers on many forms also hide units the user does not hold. This is a convenience. The server check is what enforces.

Grant versus dimension tag

A grant is permission to use an org unit. A dimension tag is the Branch, Department, Cost Center or Business Segment you pick on a transaction line so reports can group it. Tagging classifies. Grants decide who may tag. A limited user cannot tag a line with a unit they do not hold, on the screens above.

Screenshot pending

User Management, Defaults tab, showing the Org Unit Access card with an Add grant button and a table of grants

  1. 1Org Unit Access card
  2. 2Add grant
  3. 3Request & Send-To Access card

Example

Example only. Chinedu runs the Kano branch of a distributor. His administrator grants him the Branch "Kano" and the Warehouse "Kano Main Store". Chinedu raises a Transfer from Kano Main Store to the Lagos warehouse. Lagos is not his, so the administrator adds a Request & Send-To Access grant for it. The transfer saves. Chinedu still cannot receive stock in Lagos.

Grant access step by step

  1. Open the user

    Go to User Management. Open the user. A new user must be saved first, because grants are kept per user.
  2. Open the Defaults tab

    Select Defaults. Find Org Unit Access.
  3. Add a grant

    Select Add grant. Choose a type in the first box. Branch is best first, then Warehouse, then the rest.
  4. Pick the units

    Open the second box and pick one or more. The list is narrowed to units inside what you already granted.
  5. Choose the context

    Leave Context on All unless you have a reason.
  6. Optional: default

    With exactly one unit picked, turn on Make default. For a Warehouse you can also pick its locations in Also grant locations (optional).
  7. Add

    Select Add. A message shows how many grants were added. Grants save at once. You do not need Save.

To grant request access, repeat in Request & Send-To Access. Only Branch, Warehouse and Location are offered. To remove a grant, use the bin icon at the end of its row and confirm. Removing a Warehouse also removes the Locations inside it.

Messages you may see

MessageMeaning and fix
No org-unit access grants yet — this user is not restricted to any specific branch/warehouse/department.Shown when the user has no grants. Nothing is limited.
1 grant(s) added, 1 already existedGrants you repeated were skipped.
This grant already exists for this user.Same type, unit and context is already there.
Cannot grant location "X" — the user has no access to its warehouse. Grant the warehouse first.Grant the Warehouse, then the Location.
Set a default warehouse first — the default location must be one of its locations.Make the Warehouse the default before its Location.
Forbidden resourceThe save was refused because a line names an org unit the user does not hold. Grant it, or change the line.
You do not have access to the selected warehouseA report asked for a warehouse the user does not hold.
You do not have access to one or more of the selected warehouses.Same, for an Inventory report with several warehouses.

Where it applies

Common mistakes

  • Granting a Location alone. It needs its Warehouse grant, and a user with no Warehouse grant stays free on warehouses.
  • Granting a Branch and expecting its warehouses to follow.
  • Expecting Sales or Purchase context to limit a grant to that module. It does not today.
  • Giving one Department grant to "start" and wondering why nothing else is limited.
  • Forgetting that a user with no grants at all sees everything.