A colleague needs to approve an invoice, confirm an order or block a card, but the button is missing or they get the message that they have no access. So what do you switch on? In this article we approach it from the other side: not which fields a role contains, but what you need to set up to let someone perform a specific action.
This article is intended for application administrators. Are you not an application administrator and is there something you cannot do? Then forward this article to your application administrator, together with the action you want to perform and the amount involved.
Access consists of four layers
Almost every question along the lines of 'why can a user not do this?' is caused by one of these four layers being overlooked. They work together: if one is missing, the action is not available.
- The role determines which components and actions someone has in principle. You set up roles via Application management / Organization / Roles. If you work with function profiles, those are collections of roles. An employee has one or more roles, per organizational unit.
- The right is the concrete authorization for a component or an individual action, for example unblocking a card or requesting a PIN. You manage rights via Application management / Organization / Rights. Without the right the button is not there, even if the page itself is visible.
- The procuration determines up to which amount someone may approve, and in which organizational unit. You set this up per module via Application management / Invoice processing / Procuration, Application management / Procurement / Procuration and Application management / Expense claims / Procuration. Rights alone are not enough: without an procuration amount someone will not appear in the approval flow.
- The status of the employee: active, not deleted, and with an active role. This is the layer that is forgotten most often, because there is no message about it. If you set an employee to inactive, they silently disappear from flows they were previously part of.
So always check in this order: role → right → procuration limit (amount and unit) → status of the employee → substitution. The question 'does he have the right?' is almost never enough.
I want someone to be able to do this: where do you set it up?
Cash & Card
- Temporarily blocking a card, unblocking it, changing the PIN or requesting the PIN: these are four separate rights. So someone can, for example, block but not unblock. In addition, the card book must be part of the employee's role. See Roles, rights and function profiles for Cash & Card and Standaard rechtenset Kas & Pas (Dutch).
- Reviewing bookings: the right to review, plus authorization for the relevant book.
- Closing a period: this is a separate setting on the role, independent of reviewing. Someone who may review is therefore not automatically allowed to close.
- Exporting bookings: right for Cash & Card / Export, and the export mapping must be set up.
Invoice processing
- Coding or approving invoices: right for the relevant component, plus an procuration limit for the amount of the invoice. See Setting up procuration limits for Invoice processing and Standaard rechtenset Factuurverwerking (Dutch).
- Exporting invoices: right for Invoice processing / Export. In addition, the invoice must have the status approved, ready for export and must not already be part of an export in progress.
- Marking an invoice as exported: this is a separate right for the manual export action. Grant it very selectively: with this action someone can set an invoice to exported without the booking being present in your financial package.
- Managing the export mapping or the export schedule: separate administrator rights, to be set up via Application management / Invoice processing / Export mapping and Application management / General / Export schedule.
Procurement
Would you rather start from an existing set? Then have a look at the
default rights sets and adjust those, instead of building a role from scratch. With
function profiles you keep that manageable afterwards.
Procuration: amount and organizational unit
An approver only appears in the approval flow if all of these conditions are met:
- their procuration amount is equal to or higher than the amount that needs to be reviewed;
- the employee is active and not deleted;
- the employee's role is active and not deleted;
- the employee is in the same organizational unit or in a higher-level unit;
- for orders, the requester themselves cannot be selected as the reviewer.
That explains the four situations we see most often when someone is 'not in the list':
- The amount is too low. Procuration is a limit, not a permission: below that amount someone may approve, above it they may not.
- The wrong organizational unit. Procuration work upwards in your structure, not sideways. Someone from a sister department will never appear in the flow, regardless of their amount. Check the unit via Application management / Organization / Structure.
- The employee or their role is inactive. The approver then disappears from the flow, without any message.
- The requester is the intended reviewer. For orders they are deliberately excluded, so there must always be someone else in the flow.
Substitution: what it does and does not do
A substitute takes over tasks from an absent colleague, and for invoices you can see in the history that an action was performed by a substitute. Important to know: a substitute does not automatically take over everything the absent colleague can do. Substitution works per component, and it is exactly that misunderstanding that leaves an order pending while the substitution has 'already been set up'.
If a substitution does not seem to work, check the following:
- has the absence been recorded with the correct period, and has the end date not yet passed? After the end date the substitution expires;
- is the substitute themselves active and do they have the role and the right for the action;
- for approvals, does the substitute have a sufficient procuration limit of their own? A substitution does not replace an procuration amount.
The message 'No access to this component'
This message does not say which right is missing. So work through the four layers in the order above: role, right, procuration, status of the employee, and after that substitution. In practice, nine times out of ten it is the right for the component or the organizational unit.
Please note! When completing or cancelling orders this message can also appear while the rights are set up correctly. If the four layers are in order and the message keeps appearing, do not keep searching in the configuration, but contact support.
Useful to know: in Application management / Organization / Audit log you can see changes to roles and rights. If something 'still worked yesterday', start there.
Further reading
Still stuck? Then contact support via
support@spend.cloud. Mention the name of the employee, the action they want to perform and the amount: then we can look into the configuration with you straight away.