Skip to content
TaktSignal

Docs / Connect ERPNext · Community Alpha

Create a TaktSignal Reader in ERPNext

TaktSignal only needs to read ERPNext. You give it its own ERPNext user — the TaktSignal Reader — that can look at documents but cannot create, change or delete anything. This takes about 10 minutes and is done once, in ERPNext, by someone who may manage users and roles (usually your ERPNext administrator).

The same guide is available inside TaktSignal: Connect ERPNext → How to create a read-only ERPNext account.

Why a dedicated reader?

  • Never use the Administrator account. It can do everything; TaktSignal refuses it.
  • Never use your own login or a user with System Manager or any role that can create, submit, cancel or delete documents. TaktSignal never writes to ERPNext — but an API key that could write is a risk if it is ever lost.
  • Never give TaktSignal database passwords or server (SSH) access. It uses ERPNext's normal REST API only.

A dedicated reader also shows up clearly in ERPNext's logs, and you can switch it off at any time without affecting anyone else.

Step 1 — Create the role “TaktSignal Reader”

  1. In ERPNext, type Role in the search bar at the top and open Role List.
  2. Click + Add Role. Name it TaktSignal Reader. Leave Desk Access off. Save.

Step 2 — Allow the role to read, and only read

  1. Search for Role Permissions Manager and open it.
  2. For each document type in the tables below: choose the document type, click Add a new rule, pick the role TaktSignal Reader, level 0, and tick Read only.
  3. Leave Write, Create, Submit, Cancel, Amend, Delete — and Import, Export, Print, Email, Share — unticked.

Required — TaktSignal cannot work without these

Document type Used for
Item items, units of measure, costs
Workstation work centers
BOM expected material per unit
Sales Order customer orders and promise dates
Work Order production orders and required materials
Bin stock levels
Purchase Order incoming supply
Document type Used for If TaktSignal cannot read it
Warehouse which warehouses hold usable stock (strongly recommended) Warehouse roles are guessed from work orders and names; stock in unrecognised warehouses is not counted
Company listing your companies during setup Needed if Warehouse is not readable; with neither, setup cannot verify the company
Job Card shop-floor progress of operations Progress comes from work orders only and may lag the floor; timing confidence is lower
Item Group classifying raw material / semi-finished / finished goods Items in nested groups may stay unclassified
Customer customer names Names are taken from the sales orders
Stock Entry comparing material issued with material used Material reconciliation per work order is unavailable
Purchase Receipt checking supplier deliveries Supplier receipt checks are unavailable
Purchase Invoice invoiced quantities Invoiced quantities are unknown
Stock Reconciliation stock counts done in ERPNext ERPNext counts are not used to judge inventory trust

The lines inside documents (order items, BOM items, work-order operations and so on) come with their document; no separate permission is needed.

Step 3 — Create the user

  1. Search for User, open User List, click + Add User.
  2. E-mail: for example taktsignal@your-company.com (it does not need a real mailbox). User type: System User. Save.
  3. In the Roles section of the user, tick only TaktSignal Reader. Untick every other role. Save.
  4. Optional: under User Permissions, allow only your company (Company = <your company>) so the Reader never sees other companies. A warehouse the Reader cannot see is treated as unknown: its stock is shown but never counted as usable supply.

Step 4 — Create the API key and secret

  1. Open the new user. Go to the Settings tab and scroll to API Access. Click Generate Keys. In some ERPNext versions the button is in the ⋯ / Actions menu at the top of the user form.
  2. ERPNext shows the API secret once. Copy it now. The API key is shown in the same section.
  3. Paste both into TaktSignal's Connect ERPNext screen (Connect ERPNext). TaktSignal stores them in your computer's password store — never in a file, never in its database.

Lost the secret? Click Generate Keys again (the old secret stops working) and enter the new one in TaktSignal (Control Center → Connection).

ERPNext menus move between versions. The steps above follow ERPNext 15 and 16; if a button is not where this guide says, use the search bar with the same name (Role List, Role Permissions Manager, User List). TaktSignal has been exercised with ERPNext 15 (v15.121.4) and 16 (v16.36.0); other versions may work but are not validated.

What TaktSignal checks

After you enter the address, key and secret, TaktSignal:

  1. connects and identifies the user — Administrator is refused;
  2. lists which document types the Reader can read (required and recommended);
  3. read-only verification: asks ERPNext itself what this user may do with a real Sales Order, Work Order, Purchase Order, Bin and Item. If ERPNext reports any write, create, submit, cancel, amend or delete permission, setup stops, shows which permission on which document type, and cannot be skipped;
  4. shows the resulting capabilities: Ready, Limited (with what is reduced) or Unavailable.

This check samples the document types TaktSignal reads; it cannot see every permission in ERPNext. That is why the Reader should have only the TaktSignal Reader role.

If write permission is detected

Setup shows “This ERPNext account has write permissions.” Nothing was changed in ERPNext. To fix it:

  1. Open the user in ERPNext and untick every role except TaktSignal Reader.
  2. In Role Permissions Manager, check that the TaktSignal Reader rules have only Read ticked.
  3. Back in TaktSignal, click Test again.

TaktSignal repeats this check in Help & diagnostics → Run system check, so a role added later is noticed.

Switching TaktSignal off in ERPNext

Disable the user (untick Enabled) or regenerate its keys. TaktSignal's background reads then fail with “ERPNext rejected the API credentials” and nothing else happens; your ERPNext data is unaffected.