Read access for everyone. Edit rights for only who you choose.

Grant any user or group full read visibility into sensitive records while blocking create, edit and delete — enforced server-side, with a guided wizard, presets and an audit trail built for compliance.

The problem

Odoo's access rights are all-or-nothing: a user can either edit a model or cannot see it at all. There is no native way to let an auditor, finance reviewer or seasonal hire view a record without risking an accidental change — so admins resort to fragile record-rule workarounds or simply grant full edit access.

The solution

Read-Only Access by User/Group lets you freeze create, edit and delete for chosen users, groups or record domains while read access stays fully intact. A guided wizard with ready-made presets gets a policy live in minutes, and every blocked attempt is logged for audit evidence.

Capabilities

Everything a compliance-minded admin needs

Every capability below is implemented in the module.

01

Block edits, keep read access

Create, write and unlink are blocked server-side for the users you target while read access is always preserved — enforced through import, RPC and mass actions, not just the UI.

02

Per-user and per-group targeting

Freeze a model for one individual or an entire role at once, so policies scale from a single reviewer to a full department.

03

Domain-based conditions

Restrict only matching records — for example confirmed sales orders — with a standard Odoo domain editor, so a rule applies exactly where it should.

04

Guided setup wizard

A step-by-step wizard walks admins through choosing models, users, groups and blocked operations without ever opening the Technical menu.

05

Preset templates

One-click presets for Sales Orders, Purchase Orders, Invoices and Contacts get a working restriction live in seconds.

06

Model search and multi-select

Search and multi-select models, users and groups directly in the wizard instead of scrolling long unfiltered lists.

07

Visual restriction status

List and kanban views show which restrictions are active, archived, or user/group-targeted at a glance, so nothing is configured blind.

08

Audit log of blocked attempts

Every blocked create, write or delete is logged with the user, model and timestamp — ready evidence for a compliance review.

09

One-click test kill-switch

A single settings toggle suspends every restriction temporarily so admins can validate configuration changes without deleting rules.

Workflow

How it works

1

Open the wizard

Launch the guided setup wizard from the app menu — no Technical settings required.

2

Pick a preset or build a rule

Choose a ready-made template like Invoices or Contacts, or select any model, domain, users and groups yourself.

3

Choose what to block

Select which operations — create, edit, delete — are blocked while read access stays on for everyone in scope.

4

Monitor and adjust

Review restriction status at a glance, check the audit log for blocked attempts, and flip the kill-switch to test changes safely.

Questions

Frequently asked

No sales fog. If your question isn't here, email us and we'll answer it the same way.

Both. A restriction blocks create, write and unlink for its targeted users, groups or domain while read access is always preserved — enforcement is server-side, so it also applies to imports, RPC calls and mass actions, not only the web UI.

Get the app

Buy it on the Odoo App Store

Purchase, download and install directly from the official Odoo Apps Store — you'll always get the latest supported build.

Read-Only Access by User/Group

Read-only access by user or group with domain-based conditions, a guided setup wizard and preset templates — create, edit and delete blocked, every attempt logged.

Buy on Odoo App Store