# Setting proper user permissions

**URL:** https://discuss.tryton.org/t/setting-proper-user-permissions/2995
**Category:** User
**Created:** [July 8, 2020, 3:05pm UTC](https://discuss.tryton.org/t/setting-proper-user-permissions/2995 "2020-07-08T15:05:46Z")
**Posts on this page:** 3
**Page:** 1

<div class="post-metadata">

### Author: ![TelematicMan](https://discuss-cdn.tryton.org/letter_avatar_proxy/v4/letter/t/58956e/32.png) [@TelematicMan](https://discuss.tryton.org/u/TelematicMan)
#### Post date: [July 8, 2020, 3:05pm UTC](https://discuss.tryton.org/t/setting-proper-user-permissions/2995/1 "2020-07-08T15:05:46Z")

</div>

I cant get the permissions set for the other users not to see all the modules. I must be missing something somewhere. I have other employees that will need Tryton access but I do not want them in say the account module or pay roll for example. Thanks TelematicMan

---

<div class="post-metadata">

### Author: ![ced](https://discuss-cdn.tryton.org/user_avatar/discuss.tryton.org/ced/32/1237_2.png) [@ced](https://discuss.tryton.org/u/ced)
#### Post date: [July 8, 2020, 4:19pm UTC](https://discuss.tryton.org/t/setting-proper-user-permissions/2995/2 "2020-07-08T16:19:43Z")

</div>

Access rights are base on the user groups, see [Access Rights — Tryton server](https://docs.tryton.org/projects/server/en/latest/topics/access_rights.html#topics-access-rights)

---

<div class="post-metadata">

### Author: ![TelematicMan](https://discuss-cdn.tryton.org/letter_avatar_proxy/v4/letter/t/58956e/32.png) [@TelematicMan](https://discuss.tryton.org/u/TelematicMan)
#### Post date: [July 8, 2020, 4:49pm UTC](https://discuss.tryton.org/t/setting-proper-user-permissions/2995/3 "2020-07-08T16:49:37Z")

</div>

ced thanks I think this maybe my issue ill give it another go.

* * *

A rule group matches a record if the record is validated by at least one of the domains. The access is granted to a record:

```
    if the user belongs to a group which has at least one matching rule group that has the permission,
    or if there is a default matching rule group with the permission,
    or if there is a global matching rule group with the permission.

```

Otherwise the access is denied if there is any matching rule group.
