Org unit access scoping
How an administrator limits a user to certain Branches, Warehouses, Departments, Cost Centers, Locations and Business Segments, and which screens enforce the limit today.
In one minute
An org unit is a part of your business: a Branch, Warehouse, Department, Cost Center, Location or Business Segment. A grant says "this user may work with this org unit". Once a user has at least one grant, Winlium refuses what falls outside their grants on the screens listed below. A user with no grants is not limited at all.
Why Winlium has it
A cashier in Ikeja should not post stock out of the Kano warehouse. Roles say what a person may do. Grants say where they may do it.
How it works in Winlium
You set grants on the user's own page: User Management, then the Defaults tab. Two cards matter.
| Card | What it gives | Counts as "limited"? |
|---|---|---|
| Org Unit Access | Full operating access to the org unit. | Yes. The first grant switches limits on. |
| Request & Send-To Access | Only the right to name a Branch, Warehouse or Location as the other end of a transfer or stock request. No right to work there. | No. It never limits anyone. It only widens a user who is already limited. |
The six grant types
| Type | What the user may then use |
|---|---|
| Branch | Only the granted branches. |
| Warehouse | Only the granted warehouses. |
| Department | Only the granted departments. |
| Cost Center | Only the granted cost centers. |
| Location | Only the granted locations. A Location grant needs the grant for its Warehouse first. |
| Business Segment | Only the granted business segments. |
Each type is checked on its own. A Branch grant does not open that branch's warehouses.
Contexts
Each grant has a context: All, Sales, Purchase or Inventory. Today the context does not change what a grant allows. It only labels the grant and decides which default fills a form. Forms read defaults saved under All only.
Default grant
Mark one grant per type and context as the default. Entry forms such as Requisitions pre-fill it. A default never widens or narrows access. The default Location must sit inside the default Warehouse.
Limits switch on with the first grant
This surprises administrators, so read it twice.
- A user with no grants of any type is not limited anywhere.
- A user with grants, but none of one type, is not limited for that type. Grant only a Department and every warehouse stays open.
- SUPER_ADMIN and a TENANT_ADMIN working inside their own tenant are never limited.
- A grant limits only the screens in the next section. Everything else ignores grants.
Where grants are enforced today
Winlium refuses the save when any line names an org unit the user does not hold.
| Area | What is checked |
|---|---|
| Inventory | Warehouse on Goods Received Vouchers (and Location per line), journal batches, Delivery Orders, credit notes and returns to suppliers. Editing or deleting a warehouse. Item warehouse settings and availability. |
| Inventory transfers | Transfers, Stock Request Transfers, Stock Request Receipts, Production Request Transfers and Deliveries. The sending side needs a full grant. The other end also accepts Request & Send-To Access. |
| Sales | Warehouse on Quotations and Sales Orders. |
| Accounting | Warehouse on Customer Invoices, Supplier Bills, Credit Notes and Supplier Returns. General Journal lines check Warehouse, Department, Cost Center and Business Segment together. |
| Expense | Department on each line of a new claim. |
| Financial reports | A Branch filter on Trial Balance, Account Balances, Cash Flow, Balance Sheet, Profit and Loss and Combined COGS. |
| Reports and BID | Warehouse scope on Inventory, Sales and Purchase reports, Requisition History and the Inventory, Sales and Purchase BID (Business Intelligence Dashboard) pages. "All warehouses" means all of yours. |
Warehouse and Location pickers on many forms also hide units the user does not hold. This is a convenience. The server check is what enforces.
Grant versus dimension tag
A grant is permission to use an org unit. A dimension tag is the Branch, Department, Cost Center or Business Segment you pick on a transaction line so reports can group it. Tagging classifies. Grants decide who may tag. A limited user cannot tag a line with a unit they do not hold, on the screens above.
Screenshot pending
User Management, Defaults tab, showing the Org Unit Access card with an Add grant button and a table of grants
- 1Org Unit Access card
- 2Add grant
- 3Request & Send-To Access card
Example
Example only. Chinedu runs the Kano branch of a distributor. His administrator grants him the Branch "Kano" and the Warehouse "Kano Main Store". Chinedu raises a Transfer from Kano Main Store to the Lagos warehouse. Lagos is not his, so the administrator adds a Request & Send-To Access grant for it. The transfer saves. Chinedu still cannot receive stock in Lagos.
Grant access step by step
Open the user
Go to User Management. Open the user. A new user must be saved first, because grants are kept per user.Open the Defaults tab
Select Defaults. Find Org Unit Access.Add a grant
Select Add grant. Choose a type in the first box. Branch is best first, then Warehouse, then the rest.Pick the units
Open the second box and pick one or more. The list is narrowed to units inside what you already granted.Choose the context
Leave Context on All unless you have a reason.Optional: default
With exactly one unit picked, turn on Make default. For a Warehouse you can also pick its locations in Also grant locations (optional).Add
Select Add. A message shows how many grants were added. Grants save at once. You do not need Save.
To grant request access, repeat in Request & Send-To Access. Only Branch, Warehouse and Location are offered. To remove a grant, use the bin icon at the end of its row and confirm. Removing a Warehouse also removes the Locations inside it.
Messages you may see
| Message | Meaning and fix |
|---|---|
| No org-unit access grants yet — this user is not restricted to any specific branch/warehouse/department. | Shown when the user has no grants. Nothing is limited. |
| 1 grant(s) added, 1 already existed | Grants you repeated were skipped. |
| This grant already exists for this user. | Same type, unit and context is already there. |
| Cannot grant location "X" — the user has no access to its warehouse. Grant the warehouse first. | Grant the Warehouse, then the Location. |
| Set a default warehouse first — the default location must be one of its locations. | Make the Warehouse the default before its Location. |
| Forbidden resource | The save was refused because a line names an org unit the user does not hold. Grant it, or change the line. |
| You do not have access to the selected warehouse | A report asked for a warehouse the user does not hold. |
| You do not have access to one or more of the selected warehouses. | Same, for an Inventory report with several warehouses. |
Where it applies
- Setup: User Management, Defaults tab. See Roles and permissions for what a user may do.
- Expense claims check Department per line: see Expense.
- Approvals are not limited by grants: see Working with approvals.
Common mistakes
- Granting a Location alone. It needs its Warehouse grant, and a user with no Warehouse grant stays free on warehouses.
- Granting a Branch and expecting its warehouses to follow.
- Expecting Sales or Purchase context to limit a grant to that module. It does not today.
- Giving one Department grant to "start" and wondering why nothing else is limited.
- Forgetting that a user with no grants at all sees everything.