> ## Knowledge Base Index
> Fetch the complete knowledge base index at: https://support.robaws.com/sitemap.xml
> Use this file to discover available pages before exploring further.
> Pure-Markdown content can be obtained by appending a '.md' suffix to the content URLs listed in the sitemap (without the trailing slash).

# What is a confidential incoming invoice?

In Robaws you can mark certain **incoming invoices as confidential**. Only users with the right permissions still see those invoices. That is particularly useful if all incoming invoices of your organisation [come into Robaws via Peppol](https://support.robaws.com/en/article/connecting-peppol-to-robaws-or-to-your-accounting-software-1kgzkx1/): everything then passes through Robaws, including what is not intended for everyone.

*Example: you do not want the invoices for corporate gifts or from the payroll agency to be handled by the administrative assistant. You handle those yourself.*

## Shielding via the user role

Via the [user roles](https://support.robaws.com/en/article/setting-up-the-permissions-of-your-users-7wabst/) you determine who has access to which module. For the **incoming invoices** module you choose between 'All', 'All except confidential', 'Team', 'Own' and 'Nothing'. Only **'All'** gives access to the confidential incoming invoices. With every other choice they remain hidden.

|| This shielding is in the database itself, not only in the screen. A user without the 'All' permission therefore does not see the invoice in an export or via the API either.

||| One exception: if a user is an approver in an [acceptance flow](https://support.robaws.com/en/article/acceptance-flow-c1qga3/) on a confidential invoice, that user does see the invoice. So do not put confidential invoices in an acceptance flow with people who are not allowed to see them.

## Marking invoices as confidential

### Per supplier

You can treat all invoices from a particular supplier as confidential. To do so, tick the **'confidential'** option on the **supplier record**. All invoices that come in from that supplier afterwards are marked as confidential automatically. You can still untick the option per invoice afterwards.

*Example: all invoices from the payroll agency.*

||| The tick is copied at the moment the invoice is created. If you only set a supplier to confidential later on, the invoices that are already in Robaws simply remain visible. You still have to tick those yourself.

|| The permission on the incoming invoices says nothing about the supplier record itself: someone who is not allowed to see the confidential invoices still sees the record of that supplier. That is a separate setting — see [shielding the supplier record](#2-shielding-the-supplier-record-itself).

### Per invoice

You can also mark an incoming invoice as confidential ad hoc. To do so, tick the **'confidential'** option on the incoming invoice.

| Tip: create your [own overview](https://support.robaws.com/en/article/using-overview-screens-10zscoo/) of the confidential incoming invoices, so that you do not forget to handle them.

## Shielding the supplier record itself

If you also want a user not to see the **record** of a confidential supplier, you set that separately on the user role. Go to **your name (top right) > users > user roles action button**, open the role and look for the row of the **suppliers** module under **permissions**.

Every module has three permissions there — **read**, **change** and **delete** — each with its own drop-down list. For suppliers you have only three choices:

| Choice | What the user sees |
| ---- |
| All | All suppliers, including the confidential ones. |
| All except confidential | All suppliers except those with the 'confidential' tick. |
| Nothing | No supplier at all. |

Set **read** to **'All except confidential'** to hide the records of confidential suppliers. As with the incoming invoices, that shielding is in the database, so the supplier also disappears from search fields, exports and the API.

||| The drop-down lists next to the permissions can only be adjusted if **advanced permissions** are active on your environment. If they are read-only, please contact support@robaws.com.

|| This is a separate permission, independent of the incoming invoices. Giving someone the 'All except confidential' permission on suppliers therefore does not automatically hide the confidential incoming invoices, and vice versa. If you want to shield both, set both.

## New suppliers confidential by default

Do you want every new supplier to be set to confidential by default? Then set up an [automation](https://support.robaws.com/en/article/robaws-automation-1n5kuwm/) on the supplier that switches on the 'confidential' field on creation. From then on, the invoices from those suppliers are also marked as confidential automatically.