Users
Users on the left, one user's rights on the right. A user inherits the access levels of every group they belong to, and an override on the user wins over that inheritance.
Group memberships
Which groups the user belongs to. They are managed in SAP Business One — the screen says so — and a user in no group says This user does not belong to any group.
Permission overrides
Grant or deny individual permissions on top of what the user inherits from their groups. Each permission is set to:
| Field | Description |
|---|---|
| Grant | Give this user the permission, whatever their groups say. |
| Inherit | Take whatever the groups give — the default. |
| Deny | Refuse it to this user, whatever their groups say. |
The permissions the user already has through a group are marked as inherited, so an override is always visible as a deliberate departure.
A SAP superuser bypasses every permission check. The screen shows a banner saying so on such a user, and nothing configured here changes it.
Examples
Somebody sees a screen you thought you had closed. Check the three levels in order: the user's own override, then every group they belong to, then whether they are a superuser. A single group granting Read is enough — inheritance is a union, not an intersection.
Group memberships that will not change. Membership comes from SAP Business One. To move somebody between groups, do it there; this screen will follow.