Managing user access is one of the most important responsibilities for NetSuite administrators. Over time, roles can accumulate unnecessary permissions, creating security risks, segregation-of-duties concerns, and reporting inconsistencies.
This article reviews practical ways administrators can audit roles and permissions more effectively using standard NetSuite tools and best practices.
Key Tools for Auditing Roles and Permissions
1. Use Show Role Permission Differences
This feature allows administrators to compare:
- Standard roles vs custom roles
- Two custom roles
- Permission level differences
2. Review Permissions by Access Level
NetSuite permissions use four primary access levels:
Administrators should pay close attention to:
- Full access permissions
- Financial transaction permissions
- Employee record access
- Web services permissions
- SuiteScript and customization permissions
3. Audit Roles with Saved Searches
NetSuite documentation recommends using searches to audit:
- Roles
- Permissions
- Employee access assignments
Useful searches include:
- Employees by assigned role
- Roles containing Full permissions
- Users with Administrator access
- Inactive employees with active access
- Roles with Web Services permissions
Additional Areas to Review
Administrators should also periodically audit:
- SuiteAnalytics Workbook permissions
- File Cabinet access
- REST and SOAP Web Services permissions
- Token-based authentication roles
- Employee record permissions
- Custom record permissions
Have any tips to share with the community? Share them in the NetSuite Admin Corner.