Security in an ERP is a balance. Give people too little access and they cannot work; give them too much and a mistake or a misuse becomes expensive. Most security problems in NetSuite are not exotic attacks but ordinary over-permissioning: too many administrators, copied roles that nobody reviewed, and shared integration logins. This guide describes a practical way to design roles and keep them healthy.
Talk to an Expert →Start with the work: which tasks does an accounts payable clerk, a sales rep, or a warehouse picker perform? Create roles that grant exactly those permissions. Individual exceptions are tempting but multiply quickly and become unmanageable. If a person needs something unusual, consider whether it is a legitimate part of a job or a workaround that should be a process change.
Some combinations of access create risk, such as creating a vendor and approving payments to it, or entering and approving the same journal. Identify the conflicts that matter in your business, design roles that avoid them, and review users who hold several roles. Where small teams make strict separation impractical, add compensating controls such as an independent review of reports.
Our NetSuite ERP practice →In multi-entity accounts, roles can be limited to particular subsidiaries, and in many cases to departments or locations. Use these restrictions so people see and edit only what concerns them. Test each role by logging in as a user with that role, since the effect of restrictions on lists, reports, and searches is sometimes surprising.
Strengthen how people sign in. Multi-factor authentication is expected for sensitive roles, and single sign-on can simplify access while allowing centralized control of who is active. Integrations should use their own dedicated credentials with narrowly scoped roles, not a person's login or an administrator role. When an employee leaves, a clear offboarding step must remove access to NetSuite along with other systems.
NetSuite integration services →Some data deserves extra care: bank details, tax identifiers, salaries, and personal information. Restrict the fields to the roles that genuinely need them, and consider whether anyone outside finance or human resources should see them at all. Exports are another leak path, since a downloaded spreadsheet leaves the system's controls behind. Limit who may export bulk data, and treat exported files as sensitive documents with their own handling rules.
NetSuite records changes and logins, which supports investigation and audit. Make use of those records through regular review of who holds administrator access, who has accessed sensitive areas, and whether roles still match current duties. Schedule an access review at least annually, and after reorganizations or acquisitions, with managers confirming that their staff's access is still appropriate.
Managed and advisory services →Share where you are today and a Cold Sun consultant will recommend a practical next step.
Talk to a NetSuite Expert →
As few as the business can reasonably function with, each named and justified, with administrator use reviewed periodically.
Yes. Roles can be limited by subsidiary and often by department and location, which should be tested as the affected user.
With dedicated credentials and roles that have only the permissions the integration needs, never a person's login or an administrator role.
Separating tasks so one person cannot both create and approve a risky transaction, supported by compensating controls where separation is impractical.
At least annually, and after reorganizations, acquisitions, or changes in responsibilities.
Yes. We analyze roles and users, highlight excess access and conflicts, and recommend a cleaner design.