Skip to main content
Document Management System (DMS) with Access Rights — Build-to-order Odoo DMS: hierarchical folders, version control, per-fol — 1/1Illustrative preview

Build-to-order Odoo DMS: hierarchical folders, version control,

per-folder access rights and full-text OCR search — built and installed by ECOSIRE.

What is Document Management System (DMS) with Access Rights?

Build-to-order Odoo DMS: hierarchical folders, version control, per-folder access rights and full-text OCR search — built and installed by ECOSIRE. Built to order by ECOSIRE for Odoo 17, 18, 19 — indicative price from $999.00 USD; request a quote for a scoped proposal.

Key Features

Hierarchical folder tree with unlimited nesting, modelled as a parent/child Odoo ORM model with a computed full-path field
Orthogonal many-to-many tag taxonomy so one document surfaces under multiple classifications independent of its folder
Granular per-folder access rights mapped to Odoo security groups, enforced via ir.model.access.csv plus record rules at the ORM domain layer
Read / write / create / delete permission tiers per folder and per group, with inheritance from parent folders and explicit overrides
Document version control: every upload creates an immutable version record with author, timestamp and change note
Check-out / check-in locking that prevents concurrent-edit overwrites and shows who currently holds a file
One-click rollback and side-by-side version history with preview and download of any prior revision
Full-text search across extracted content of PDFs, Office and text files, backed by Postgres indexing
Optional OCR pipeline that makes scanned images and image-only PDFs searchable by their recognised text
Bulk upload and OWL-based drag-and-drop multi-file uploader with per-file folder and tag assignment
Advanced filtering by folder, tag, owner, file type, size, date range and version state via standard Odoo search views
Per-document chatter (mail thread), followers and activity scheduling for review/approval reminders
QWeb PDF reports for folder manifests, access-rights matrices and full audit-trail summaries
Automated actions (server actions) for retention rules, expiry alerts and status-change notifications on a schedule
Complete audit logging of views, downloads, edits and permission changes for compliance evidence
XML-RPC / JSON-RPC endpoints so external systems can push, fetch and search documents programmatically

Built to order, done for you

No DIY setup — a working app, built, installed and supported by ECOSIRE.

  1. 1

    You order

    Start with a one-time build price. We scope it with you at kickoff.

  2. 2

    We build & install

    ECOSIRE builds, configures and installs it on your Odoo.

  3. 3

    Go live + support

    You go live in about one working week, with two weeks of go-live support. Defects in the code we deliver are fixed free of charge.

Technical Specifications

Odoo Compatibility
Odoo 17, Odoo 18, Odoo 19
Editions
Enterprise & Community
License
Licence confirmation required
Python Requirement
Python 3.10+
Database
PostgreSQL 12+

About this Product

Give your compliance-conscious team a controlled, auditable document repository living natively inside Odoo — no third-party portal, no data leaving your database. This is a build-to-order module: ECOSIRE designs, develops, installs and supports it for your instance on Odoo 17, 18 or 19 (Community or Enterprise). It is not an off-the-shelf apps.odoo.com download — expect a typical one working week lead time while we tailor the folder taxonomy, access-rights matrix and search behaviour to how your organisation actually works.

At its core the DMS ships as a proper Odoo module: a versioned __manifest__.py, ORM models (models.Model) for folders, documents and versions with computed fields (@api.depends) for storage size, current-version pointers and full paths. Access control is enforced the Odoo-native way — ir.model.access.csv for CRUD baselines plus record rules that scope every document to the folders a user's security groups are allowed to see, so a user in "HR Confidential" never even queries a "Finance" document. Nothing is hidden by UI trickery; the domain is applied at the ORM layer.

Documents are organised in a hierarchical folder tree with an orthogonal tag system, so a single contract can live in /Legal/Signed/2026 and still surface under the tags #nda and #vendor-acme. Every upload creates an immutable version record; check-out locks a file to one editor to prevent overwrite conflicts, and check-in stores the new revision while preserving the full history — you can preview, download or roll back to any prior version. Full-text search indexes the extracted text of PDFs, Office files and images; where you enable the optional OCR pipeline, scanned documents become searchable too, so "find every invoice mentioning purchase order 4471" returns hits inside the file content, not just the filename.

Because it is a first-class Odoo app, the DMS reuses the mail thread (chatter) for per-document discussion and follower notifications, exposes documents over XML-RPC / JSON-RPC for integration with your other systems, renders audit summaries and folder manifests as QWeb reports (PDF), and can drive retention or notification logic through automated actions (server actions on time/state triggers). Views are delivered in standard XML with OWL components for the drag-and-drop uploader and tree navigator, so the experience feels like part of Odoo rather than a bolted-on plugin. On Enterprise instances we can extend the standard Documents app patterns; on Community we deliver a complete, self-contained DMS with no Enterprise dependency.

ECOSIRE hands over clean, commented, upgrade-safe source code, a documented access-rights matrix, admin and end-user training, and a post-go-live support window. You own the code and the data, in your own database.

What you get

  • Complete, commented Odoo module source code (models, views, security, reports) targeting your chosen version 17, 18 or 19, delivered as a git repository you own
  • A documented access-rights matrix mapping your security groups to folder permissions, with the ir.model.access.csv and record rules that implement it
  • Installed and configured module on your Odoo instance (staging first, then production), including your initial folder taxonomy and tag set
  • Data migration or bulk import of an agreed initial document set, with folder placement and tagging
  • Optional OCR search pipeline configured and validated against a sample of your real scanned documents
  • Admin guide plus a live handover training session for administrators, and a short end-user walkthrough
  • QWeb report templates for the audit trail and access-rights matrix, ready to run from the DMS menus
  • A post-go-live support and bug-fix window (scope agreed in the SOW) covering defects and configuration questions

Who this is for

Compliance & Quality Manager

Needs a controlled, auditable repository where document access is provably restricted by role and every view, edit and version is logged as evidence for ISO, GDPR or internal audit. Values record-rule enforcement over UI-only hiding.

Operations / Document Controller

Manages large volumes of contracts, drawings, SOPs and certificates. Wants bulk drag-and-drop upload, version control with check-in/check-out to avoid overwrites, and fast full-text search to retrieve the right revision instantly.

IT / Odoo Administrator

Owns the Odoo instance and wants the DMS living inside the existing database — not a separate portal. Cares about upgrade-safe module code, native security groups, and XML-RPC/JSON-RPC endpoints to integrate with other internal systems.

Department Head (HR, Legal, Finance)

Requires that their team's confidential documents are visible only to their group, with clear per-folder permissions they can reason about, plus chatter-based discussion and review reminders on sensitive files.

How Document Management System (DMS) with Access Rights Compares

CriterionECOSIRECustom BuildCompetitorOdoo Native
Per-folder access rights enforced by record rules (not UI hiding)Purpose-built matrix mapped to your security groupsPossible but you design and test it yourselfOften coarse or global-group only; varies by moduleBasic model-level access; no folder-scoped record rules
Version control with check-in / check-out lockingFull immutable history, locking and one-click rollbackBuild and maintain the versioning model yourselfSometimes present, quality and rollback varyAttachments have no true versioning or locking
Full-text + OCR search across document contentContent indexing plus optional OCR pipeline, validated on your filesSignificant effort to build and tuneFull-text sometimes; OCR rarely includedSearches metadata/filenames, not file content
Tailored to your taxonomy and workflowsFolder tree, tags and rules built to your requirementsFully tailored, but at your team's cost and riskGeneric; you adapt your process to the moduleGeneric; minimal document-specific structure
Delivery modelBuild-to-order, one working week, installed on staging then prodWhatever your internal roadmap allowsInstant download, then self-configureAlready in Odoo, but not a real DMS
Code ownership and data locationYou own the git repo; data stays in your databaseYou own it; you also carry all maintenanceVendor-licensed code; upgrade at vendor's paceCore Odoo; no dedicated DMS to own
Audit trail and QWeb compliance reportsView/download/edit logging + PDF audit and access-matrix reportsMust be designed and built from scratchLogging varies; dedicated reports uncommonNo dedicated document audit trail or reports
Support and accountabilityNamed ECOSIRE support window with bug-fix SLA in SOWInternal team only; no external backstopMarketplace ticket queue; response variesCommunity/Enterprise support, not DMS-specific

Frequently Asked Questions about Document Management System (DMS) with Access Rights

Is this an instant download from the Odoo App Store?

No. This is a build-to-order module. ECOSIRE designs, develops, installs and supports it specifically for your Odoo instance and your document workflows. You are not buying an off-the-shelf apps.odoo.com download — you are commissioning a tailored DMS that we deliver as source code you own.

How long does delivery take, and what does the process look like?

Typical lead time is one working week depending on scope — for example the size of your folder taxonomy, whether OCR search is required, and any initial data migration. We start with a short requirements workshop to lock the access-rights matrix, build and demo on a staging instance, then install to production after your sign-off. Complex integrations may extend the timeline, which we confirm in the SOW before work begins.

How are updates, upgrades and support handled after go-live?

Every engagement includes a post-go-live support and bug-fix window (its length is agreed in your SOW). Within it we fix defects and answer configuration questions. Because we write upgrade-safe module code and hand you the git repository, the module can be moved forward to future Odoo versions; version upgrades and new feature work beyond the support window are quoted separately as a maintenance retainer or change request.

Does it work on Odoo Community, or do I need Enterprise?

Both. On Community we deliver a complete, self-contained DMS with no Enterprise dependency. On Enterprise we can additionally build on the standard Documents app patterns if you prefer. We support Odoo 17, 18 and 19 — tell us your version and edition and we target it exactly.

How is document security actually enforced — is it just hidden in the UI?

No. Access control is enforced at the ORM layer using Odoo's native ir.model.access.csv for CRUD baselines and record rules that apply a security-group domain to every document query. A user outside a folder's permitted groups cannot read, search or export those documents through the UI or the XML-RPC/JSON-RPC API — the records are filtered before they ever reach them.

Can the DMS integrate with our other systems and existing Odoo data?

Yes. Because it is a native Odoo module it exposes standard XML-RPC / JSON-RPC endpoints, so external systems can push, fetch and search documents. Inside Odoo it can link documents to partners, projects, sales orders or any record, reuse the chatter for discussion, and trigger automated actions for retention and notification logic.

Do we own the code and the data?

Yes. The module source is delivered as a git repository you own, and every document lives in your own Odoo database and filestore. Nothing is hosted on a third-party platform and no document content leaves your instance.

Request a quote

Document Management System (DMS) with Access Rights

Build-to-order Odoo DMS: hierarchical folders, version control, per-folder access rights and full-text OCR search — built and installed by ECOSIRE.

  • Hierarchical folder tree with unlimited nesting, modelled as a parent/child Odoo ORM model with a computed full-path field
  • Orthogonal many-to-many tag taxonomy so one document surfaces under multiple classifications independent of its folder
  • Granular per-folder access rights mapped to Odoo security groups, enforced via ir.model.access.csv plus record rules at the ORM domain layer
  • Read / write / create / delete permission tiers per folder and per group, with inheritance from parent folders and explicit overrides

Request a Quotation

Tell us about your Document Management System (DMS) with Access Rights requirements and we'll send pricing, licensing options and a tailored proposal — usually within one business day.

No payment now. This sends a quote request to our team — we'll follow up by email with pricing and next steps.