Overview
Inventario implements a role-based access control (RBAC) system with two primary roles: Admin and Vendedor (Salesperson). Each role has distinct permissions and access levels throughout the system.User Model
Roles are defined directly in theUsuario model:
The
creado_por field creates a hierarchical relationship where admins can create and manage their vendedor accounts.Admin Role
Capabilities
Administrators have full access to the system:User Management
Create, edit, and delete vendedor accounts
Dashboard Access
View comprehensive analytics and insights
Inventory Control
Manage products, suppliers, and stock levels
Financial Reports
Access sales reports, expenses, and profit analysis
Configuration
Configure invoice settings and system preferences
Purchase Management
Record purchases and manage expenses
Client Management
Manage client database and relationships
AI Features
Access AI-powered insights and recommendations
Admin-Only Views
Certain views are restricted to admins using the@admin_required decorator:
applications/cuentas/decorators.py
Example: Dashboard View
Example: Dashboard View
applications/cuentas/views.py
get_subordinate_ids() to show data only for the admin and their vendedores.Vendedor Role
Capabilities
Vendedores (Salespeople) have focused access to sales operations:Sales Management
Create and view their own sales transactions
Product Catalog
View available products and inventory
Client Information
Access client information for sales
Invoice Generation
Generate invoices for their sales
Vendedor Restrictions
Vendedor-Only Decorator
applications/cuentas/decorators.py
Role Assignment
Creating Vendedor Accounts
Only admins can create vendedor accounts through the user management interface:1
Admin Accesses User List
Navigate to the user management section (restricted to admins).
2
Create New User
Fill out the user creation form:
3
Automatic Assignment
The system automatically assigns the creating admin as the vendedor’s supervisor:
4
Password Setup
New vendedores receive a temporary password and are required to change it on first login:
Security Note: The user creation form only allows admins to create vendedor accounts. Admins cannot create other admin accounts through the UI.
User Form Configuration
Hierarchical Data Access
Subordinate Filtering
Admins only see data for themselves and their vendedores:applications/cuentas/utils.py
Application in Views
This hierarchical model ensures data isolation between different admin accounts and their vendedor teams.
Multi-User Workflows
Sales Attribution
Each sale is automatically attributed to the logged-in user:Reporting & Analytics
Admins can:- View aggregated sales across their team
- Compare performance between vendedores
- Filter reports by vendedor
- Track individual contributions
Login Redirects
Users are automatically redirected based on their role after login:applications/cuentas/views.py
Superuser
→
/admin/ (Django admin panel)Admin
→
/dashboard/ (Analytics dashboard)Vendedor
→ Sales list (Operational view)
Permission Management
User List Access Control
applications/usuarios/views.py
Edit/Delete Restrictions
Admins can only edit/delete vendedores they created:applications/usuarios/views.py
Best Practices
Role Assignment
Role Assignment
- Always assign vendedores to the correct admin supervisor
- Require password changes for new vendedor accounts
- Use strong password validation rules
- Regularly audit user accounts and permissions
Data Isolation
Data Isolation
- Always filter queries using
get_subordinate_ids() - Verify ownership before allowing edits/deletes
- Use
get_object_or_404with ownership filters - Test multi-admin scenarios thoroughly
Security
Security
- Apply
@admin_requiredto sensitive views - Use
@vendedor_requiredfor role-specific features - Combine with
@login_requiredfor authentication - Implement proper error messages for unauthorized access
Related Resources
Authentication
Learn about login methods and security
Profile Management
Manage user profiles and settings
Security Configuration
Advanced security and access control
Authentication API
Programmatic authentication and user management