One group edits the catalog. Everyone else just uses it.
Give sales, warehouse, and purchasing teams full use of the product catalog while a designated Full Rights group keeps sole control over creates, edits, and deletes — with category-level grants, storefront visibility rules, and a complete audit trail.
The problem
Anyone with access to Sales, Inventory, or Purchase can rename products, delete variants, or edit attributes in stock Odoo. A rep renames a product mid-quarter, a warehouse user deletes a variant, or an attribute value gets edited and silently corrupts existing variants — data-integrity incidents that are hard to trace and expensive to unwind.
The solution
A designated Full Rights group maintains the catalog; everyone else gets safe read-only access by default. Delegate edit rights by category, hide cost data, hide products from specific customers on the storefront, and keep a full audit trail — all configurable from a guided wizard, no developer mode required.
Everything you need to lock down the catalog
Every capability below is implemented in the module.
Full Rights vs. Read-Only by Default
A dedicated Full Rights for Products group can create, edit, and delete product templates, variants, and attributes. Everyone else gets safe, read-only access to the catalog out of the box.
Category-Scoped Edit Grants
Delegate edit rights to specific staff for specific product categories — including child categories — without handing them the whole catalog. No grant means read-only.
Attribute & Attribute-Value Protection
Product attributes and attribute values are global and easy to corrupt existing variants. Only Full Rights users can create, edit, or delete them.
Coherent Menu Navigation
Native product configuration menus — Attributes, Categories — disappear for restricted users instead of leading to dead-end Access Denied clicks.
Customer-Facing Storefront Visibility
Hide selected products from customers on the eCommerce shop by partner tag or customer group, so pricing or catalog segments stay private to the right buyers.
Hide Cost & Margin
Gate the product cost and margin fields behind a dedicated group, keeping sensitive commercial data out of view for users who do not need it.
Per-User Audit Trail
Every create, edit, delete, and denied attempt is logged with the user, product, and timestamp, giving catalog owners a clear trail when something changes unexpectedly.
Bulk Access Assignment
Apply Full Rights, category-scoped access, or read-only to any number of users in a single action instead of configuring each user one at a time.
Guided Setup Wizard
Walk through common scenarios — lock the whole catalog except a group, or hide products from a customer tag — and apply the right configuration in a couple of clicks.
How it works
Assign Full Rights
Add your catalog owners to the Full Rights for Products group, or run the guided wizard to lock the catalog except for a chosen group.
Delegate by category
Grant specific staff edit access to selected product categories using Access Grants or the bulk assignment wizard.
Set visibility rules
Hide sensitive cost data behind a group, and hide selected products from customers by partner tag or customer group on the storefront.
Review the audit log
Check the Audit Log any time to see who created, modified, deleted, or was denied access to a product.
Frequently asked
No sales fog. If your question isn't here, email us and we'll answer it the same way.
No. It layers a turnkey Full Rights group, category-scoped grants, menu hiding, and storefront visibility on top of Odoo’s own security — it only ever narrows access, it never removes your existing configuration.
Buy it on the Odoo App Store
Purchase, download and install directly from the official Odoo Apps Store — you'll always get the latest supported build.
Limited Access For Products
A Full Rights vs. read-only default with category-scoped edit grants and attribute protection — locking down who can rename, delete, or edit the catalog.
Buy on Odoo App Store