Skip to main content

Overview

Inventario implements a role-based access control (RBAC) system with two primary roles: Admin and Vendedor (Salesperson). Each role has distinct permissions and access levels throughout the system.

User Model

Roles are defined directly in the Usuario model:
The creado_por field creates a hierarchical relationship where admins can create and manage their vendedor accounts.

Admin Role

Capabilities

Administrators have full access to the system:

User Management

Create, edit, and delete vendedor accounts

Dashboard Access

View comprehensive analytics and insights

Inventory Control

Manage products, suppliers, and stock levels

Financial Reports

Access sales reports, expenses, and profit analysis

Configuration

Configure invoice settings and system preferences

Purchase Management

Record purchases and manage expenses

Client Management

Manage client database and relationships

AI Features

Access AI-powered insights and recommendations

Admin-Only Views

Certain views are restricted to admins using the @admin_required decorator:
applications/cuentas/decorators.py
applications/cuentas/views.py
The dashboard uses get_subordinate_ids() to show data only for the admin and their vendedores.

Vendedor Role

Capabilities

Vendedores (Salespeople) have focused access to sales operations:

Sales Management

Create and view their own sales transactions

Product Catalog

View available products and inventory

Client Information

Access client information for sales

Invoice Generation

Generate invoices for their sales

Vendedor Restrictions

Vendedores cannot:
  • Access the admin dashboard
  • Create or manage other users
  • Modify product inventory or prices
  • View financial reports or analytics
  • Access purchase management
  • Change system configuration
  • View sales from other vendedores

Vendedor-Only Decorator

applications/cuentas/decorators.py

Role Assignment

Creating Vendedor Accounts

Only admins can create vendedor accounts through the user management interface:
1

Admin Accesses User List

Navigate to the user management section (restricted to admins).
2

Create New User

Fill out the user creation form:
3

Automatic Assignment

The system automatically assigns the creating admin as the vendedor’s supervisor:
4

Password Setup

New vendedores receive a temporary password and are required to change it on first login:
Security Note: The user creation form only allows admins to create vendedor accounts. Admins cannot create other admin accounts through the UI.

User Form Configuration

Hierarchical Data Access

Subordinate Filtering

Admins only see data for themselves and their vendedores:
applications/cuentas/utils.py

Application in Views

This hierarchical model ensures data isolation between different admin accounts and their vendedor teams.

Multi-User Workflows

Sales Attribution

Each sale is automatically attributed to the logged-in user:

Reporting & Analytics

Admins can:
  • View aggregated sales across their team
  • Compare performance between vendedores
  • Filter reports by vendedor
  • Track individual contributions
The dashboard automatically aggregates data from all subordinate vendedores, providing a complete view of team performance.

Login Redirects

Users are automatically redirected based on their role after login:
applications/cuentas/views.py

Superuser

→ /admin/ (Django admin panel)

Admin

→ /dashboard/ (Analytics dashboard)

Vendedor

→ Sales list (Operational view)

Permission Management

User List Access Control

applications/usuarios/views.py

Edit/Delete Restrictions

Admins can only edit/delete vendedores they created:
applications/usuarios/views.py
Cascade Deletion: When an admin account is deleted, all vendedor accounts created by that admin are also deleted due to the on_delete=models.CASCADE relationship.

Best Practices

  • Always assign vendedores to the correct admin supervisor
  • Require password changes for new vendedor accounts
  • Use strong password validation rules
  • Regularly audit user accounts and permissions
  • Always filter queries using get_subordinate_ids()
  • Verify ownership before allowing edits/deletes
  • Use get_object_or_404 with ownership filters
  • Test multi-admin scenarios thoroughly
  • Apply @admin_required to sensitive views
  • Use @vendedor_required for role-specific features
  • Combine with @login_required for authentication
  • Implement proper error messages for unauthorized access

Authentication

Learn about login methods and security

Profile Management

Manage user profiles and settings

Security Configuration

Advanced security and access control

Authentication API

Programmatic authentication and user management