User Roles - VPD and Access Control Lists

In OTM, access control for a user is defined through a User Role — a container that groups two distinct types of restrictions that must be configured together:

VPD (Virtual Private Database) controls data-level visibility. It operates at the database row level, silently filtering query results so that a user only ever sees records they are permitted to access — for example, a planner restricted to their own region’s shipments, or an approver who can only see invoices within their approval threshold. VPD rules are invisible to the user: the application does not show a filtered view, it simply never returns rows they are not permitted to see.