TotalApp Docs

Troubleshooting & Access Requests

What the "Access Denied" (403) and "Upgrade Required" screens mean, how to tell them apart, and how to request the access you need.

Two Different Blocked Screens

When a screen won't open, the panel you see tells you why — and who can fix it:

You seeMeaningWho resolves it
Upgrade Required (padlock)Your company hasn't activated this add-on package (Level 1).A Tenant/System Admin activates the package, or you upgrade the plan.
Access Denied — 403 (shield)The module is active, but you don't have permission to open this screen (Level 2).An administrator grants you a role in that module.

"You don't have access to this screen" (403)

This appears when the add-on is active for your company, but your account doesn't hold the right role. Two common cases:

Operational screen

You don't yet hold any role in that module's domain. Ask an admin to assign you a module role (see below).

Governance screen (Roles / Staff)

These are administrator-only. A normal domain role does not grant access — and these cards are hidden from your menus entirely. Only a Tenant/System Admin can open them.

Back to Workspace

The 403 panel includes a "Back to Workspace" action so you're never stuck — you're returned to a screen you can use.

"Module is not in your plan" (Upgrade Required)

This is a company-level block: the add-on package isn't active for your tenant. Nothing about your personal role will change it — the tenant needs the package activated. Contact your administrator or use the Upgrade action to request it.

Requesting Access

  1. Identify which block it is — Upgrade Required (package) vs. Access Denied (role). The panel's title and icon tell you.
  2. For Upgrade Required: ask a Tenant/System Admin to activate the add-on package for your company (Admin → Add-Ons), or request a plan upgrade.
  3. For Access Denied: ask an administrator to grant you a role in that module. In Admin → Add-Ons → Screen Access, they select the module, find your name, and assign you a domain role — which grants the module's capabilities and unlocks its operational screens.

What the admin does

Granting you a domain role writes it onto your employee profile and immediately drives your access. Governance screens (Roles / Staff Master) remain restricted to administrators even after you're granted an operational role.

Common Situations

I can open other screens in this module but the Roles screen shows Access Denied.
Expected. Roles (and Staff Master) are governance screens — administrator-only. Operational screens in the same module stay open to anyone holding a domain role.
Everything in a module is blocked with "Upgrade Required".
The package isn't active for your company. That's a Level-1 block — an admin must activate the add-on, or the plan must be upgraded.
I don't even see the Roles / Staff cards in my menu.
That's by design — governance cards are hidden from non-administrators. You only see the operational setup relevant to your job.
Locally I can open everything, but a colleague on the tenant can't.
Local/standalone sessions are treated as admin so the app is usable while evaluating. Real tenant users go through the normal two-level checks — assign them a role.