Restrict, watermark, and audit every POS invoice download
Stop unauthorized staff from exporting customer invoice PDFs at the point of sale. Role-based rules, business-hours windows, daily limits, and a full compliance audit trail — enforced at both the data and file level so it cannot be bypassed.
The problem
Any cashier with POS access can download a customer’s invoice PDF — a document packed with names, addresses, tax IDs, and transaction values. In regulated retail, hospitality, and gaming environments, that uncontrolled export creates audit-trail gaps and real privacy exposure, yet standard Odoo POS treats invoice download as an all-or-nothing, ungated action.
The solution
Cerevantix POS Invoice Restriction gates invoice downloads per store: only authorized groups can export, managers can override, and every attempt — allowed, watermarked, or denied — is logged with user, time, and reason. Enforcement runs at both the ORM and HTTP-controller level, so the rule holds even if someone pastes the raw download URL.
Everything a compliance-grade rollout needs
Every capability below is implemented in the module.
Role-Based Download Restriction
Limit POS invoice PDF downloads to specific user groups per store, so only authorized roles can export customer financial documents.
Manager Override
Users in the POS Manager or Administrator group always retain full download access, so the control never blocks a legitimate workflow.
Business-Hours Time Window
Disable downloads outside a configurable start and end hour per store, closing the off-hours data-extraction gap static role rules miss.
Daily Download Limits
Cap the number of invoices any one user can export per store per day, preventing mass exfiltration of customer data.
Watermarked Partial Access
Give limited-access staff a “Restricted Copy” watermarked PDF instead of a hard block, so they can still do their job without a full export.
Unbypassable Dual Enforcement
The restriction is checked both when the download action is triggered and again at the file-download controller, so pasting the raw PDF URL cannot circumvent it.
Full Audit Trail
Every attempt — allowed, watermarked, or denied — is recorded with user, invoice, store, amount, and reason, browsable as a list, pivot, or graph.
Proactive Email Alerts
Compliance managers get an email the moment a restricted user attempts a download, turning a passive log into active oversight.
Guided Setup Wizard
Configure rules through a wizard with a live role preview (who’s authorized, who’s blocked) and a test-before-save simulation for any user.
How it works
Enable Restriction
Turn on invoice download restriction for a store from POS Settings or the setup wizard.
Assign Rules
Choose authorized and watermark-only groups, set a business-hours window, and a daily download limit.
Preview & Test
Use the wizard’s role preview and test-before-save simulation to confirm the rule behaves as expected before applying it.
Monitor & Respond
Review every download attempt in the audit dashboard and get email alerts the moment a restricted user is denied.
Frequently asked
No sales fog. If your question isn't here, email us and we'll answer it the same way.
No. The restriction only applies to invoices that originated from a Point of Sale order. Accounting, Sales, and portal invoice downloads are never touched.
Buy it on the Odoo App Store
Purchase, download and install directly from the official Odoo Apps Store — you'll always get the latest supported build.
POS: Restrict Invoice Download
Role-based, dual-enforced limits on POS invoice downloads, with manager override, business-hours windows, daily caps, watermarked partial access, email alerts and a full audit trail.
Buy on Odoo App Store