Restrict, watermark, and audit every POS invoice download

Stop unauthorized staff from exporting customer invoice PDFs at the point of sale. Role-based rules, business-hours windows, daily limits, and a full compliance audit trail — enforced at both the data and file level so it cannot be bypassed.

The problem

Any cashier with POS access can download a customer’s invoice PDF — a document packed with names, addresses, tax IDs, and transaction values. In regulated retail, hospitality, and gaming environments, that uncontrolled export creates audit-trail gaps and real privacy exposure, yet standard Odoo POS treats invoice download as an all-or-nothing, ungated action.

The solution

Cerevantix POS Invoice Restriction gates invoice downloads per store: only authorized groups can export, managers can override, and every attempt — allowed, watermarked, or denied — is logged with user, time, and reason. Enforcement runs at both the ORM and HTTP-controller level, so the rule holds even if someone pastes the raw download URL.

Capabilities

Everything a compliance-grade rollout needs

Every capability below is implemented in the module.

01

Role-Based Download Restriction

Limit POS invoice PDF downloads to specific user groups per store, so only authorized roles can export customer financial documents.

02

Manager Override

Users in the POS Manager or Administrator group always retain full download access, so the control never blocks a legitimate workflow.

03

Business-Hours Time Window

Disable downloads outside a configurable start and end hour per store, closing the off-hours data-extraction gap static role rules miss.

04

Daily Download Limits

Cap the number of invoices any one user can export per store per day, preventing mass exfiltration of customer data.

05

Watermarked Partial Access

Give limited-access staff a “Restricted Copy” watermarked PDF instead of a hard block, so they can still do their job without a full export.

06

Unbypassable Dual Enforcement

The restriction is checked both when the download action is triggered and again at the file-download controller, so pasting the raw PDF URL cannot circumvent it.

07

Full Audit Trail

Every attempt — allowed, watermarked, or denied — is recorded with user, invoice, store, amount, and reason, browsable as a list, pivot, or graph.

08

Proactive Email Alerts

Compliance managers get an email the moment a restricted user attempts a download, turning a passive log into active oversight.

09

Guided Setup Wizard

Configure rules through a wizard with a live role preview (who’s authorized, who’s blocked) and a test-before-save simulation for any user.

Workflow

How it works

1

Enable Restriction

Turn on invoice download restriction for a store from POS Settings or the setup wizard.

2

Assign Rules

Choose authorized and watermark-only groups, set a business-hours window, and a daily download limit.

3

Preview & Test

Use the wizard’s role preview and test-before-save simulation to confirm the rule behaves as expected before applying it.

4

Monitor & Respond

Review every download attempt in the audit dashboard and get email alerts the moment a restricted user is denied.

Questions

Frequently asked

No sales fog. If your question isn't here, email us and we'll answer it the same way.

No. The restriction only applies to invoices that originated from a Point of Sale order. Accounting, Sales, and portal invoice downloads are never touched.

Get the app

Buy it on the Odoo App Store

Purchase, download and install directly from the official Odoo Apps Store — you'll always get the latest supported build.

POS: Restrict Invoice Download

Role-based, dual-enforced limits on POS invoice downloads, with manager override, business-hours windows, daily caps, watermarked partial access, email alerts and a full audit trail.

Buy on Odoo App Store