20+ years of combined team expertise in Salesforce & NetSuite. Talk to an Expert →
← GuidesNetSuite · Security

NetSuite Roles and Permissions: Least Privilege Without Slowing People Down

Security in an ERP is a balance. Give people too little access and they cannot work; give them too much and a mistake or a misuse becomes expensive. Most security problems in NetSuite are not exotic attacks but ordinary over-permissioning: too many administrators, copied roles that nobody reviewed, and shared integration logins. This guide describes a practical way to design roles and keep them healthy.

Talk to an Expert →

Design roles around jobs, not people

Start with the work: which tasks does an accounts payable clerk, a sales rep, or a warehouse picker perform? Create roles that grant exactly those permissions. Individual exceptions are tempting but multiply quickly and become unmanageable. If a person needs something unusual, consider whether it is a legitimate part of a job or a workaround that should be a process change.

  • Base custom roles on a standard role and trim what is not needed.
  • Name roles by function and scope, such as Accounts Payable Clerk, Canada.
  • Document the purpose and owner of each role.

Segregation of duties

Some combinations of access create risk, such as creating a vendor and approving payments to it, or entering and approving the same journal. Identify the conflicts that matter in your business, design roles that avoid them, and review users who hold several roles. Where small teams make strict separation impractical, add compensating controls such as an independent review of reports.

Our NetSuite ERP practice →

Restricting by subsidiary, department and location

In multi-entity accounts, roles can be limited to particular subsidiaries, and in many cases to departments or locations. Use these restrictions so people see and edit only what concerns them. Test each role by logging in as a user with that role, since the effect of restrictions on lists, reports, and searches is sometimes surprising.

Authentication, access to the account and integrations

Strengthen how people sign in. Multi-factor authentication is expected for sensitive roles, and single sign-on can simplify access while allowing centralized control of who is active. Integrations should use their own dedicated credentials with narrowly scoped roles, not a person's login or an administrator role. When an employee leaves, a clear offboarding step must remove access to NetSuite along with other systems.

NetSuite integration services →

Protecting sensitive fields and exports

Some data deserves extra care: bank details, tax identifiers, salaries, and personal information. Restrict the fields to the roles that genuinely need them, and consider whether anyone outside finance or human resources should see them at all. Exports are another leak path, since a downloaded spreadsheet leaves the system's controls behind. Limit who may export bulk data, and treat exported files as sensitive documents with their own handling rules.

Audit trails and periodic access reviews

NetSuite records changes and logins, which supports investigation and audit. Make use of those records through regular review of who holds administrator access, who has accessed sensitive areas, and whether roles still match current duties. Schedule an access review at least annually, and after reorganizations or acquisitions, with managers confirming that their staff's access is still appropriate.

Managed and advisory services →

Decisions to settle before you build roles

  • Role catalogue. List the jobs in each department and agree the roles that cover them.
  • Conflicting duties. Identify combinations that must not coexist and how exceptions are approved.
  • Administrator policy. Limit administrators to a small named group and require a business reason.
  • Joiner, mover, leaver process. Define who requests, approves, and removes access when people change roles or leave.

A realistic first 90 days of security hardening

  • Days 1 to 30. Export users and roles, identify administrators and unusual permissions, and remove obvious excess access.
  • Days 31 to 60. Redesign roles around jobs, move integrations to dedicated credentials, and enable stronger sign-in.
  • Days 61 to 90. Run the first manager access review, document the process, and schedule the next review.

Pitfalls to avoid

  • Everyone is an administrator. Broad access is easy to grant and hard to take back. Keep the group small.
  • Shared logins. Shared credentials erase accountability. Give each person and integration their own.
  • Roles copied and forgotten. Copies drift. Review and consolidate periodically.
  • Skipping offboarding. Former employees with active accounts are a classic audit finding. Automate or checklist the removal.

Talk to a NetSuite Expert About NetSuite Security

Share where you are today and a Cold Sun consultant will recommend a practical next step.

Talk to a NetSuite Expert →
Erik Wiltjer
FAQ

Frequently Asked Questions

Keep Reading

Related Guides

Rescuing a Struggling NetSuite Implementation
Signs a NetSuite project is in trouble, how to assess it honestly, what to keep, and how to decide between repairing, relaunching and re-implementing.
Read Guide →
Implementing NetSuite Yourself: When It Works and When Not
When a self-implemented NetSuite project is realistic, the risks teams underestimate, and how a partner-guided hybrid can protect time and budget.
Read Guide →
NetSuite Optimization After Go-Live: A 12-Month Plan
How to get more from NetSuite after go-live: stabilize, measure adoption, simplify processes, improve reporting, add automation and plan the next phase.
Read Guide →