NetSuite User Roles and Permissions: Audit and Cleanup
Most live NetSuite accounts have accumulated over-permissioned users, stale role assignments, and undocumented custom roles. SuitePacific audits what is in the account and rebuilds role architecture so every user has exactly the access their job requires.
NetSuite Administrator Professional certified · Direct access · Month-to-month
Last updated September 2026
Quick answer
SuitePacific audits and rebuilds NetSuite user role architecture for companies whose current role setup no longer matches how the business operates. NetSuite roles are collections of permissions, each set to None, View, Create, Edit, or Full, that control what a user can access and what they can do. Most live accounts accumulate problems: roles copied from the implementation never scoped correctly, users with Administrator access because it was easier than building a proper role, and custom roles that grew through ad hoc additions with no documentation. SuitePacific is an Oracle-certified NetSuite firm (SuiteCloud Developer II and Administrator Professional) that conducts role audits, designs clean role architecture, and rebuilds custom roles so every user has exactly the access they need. Plans start at $799 per month.
What are the five NetSuite permission levels?
| Level | What it allows | Typical use |
|---|---|---|
| None | No access to the record type or feature | Default for sensitive areas the role should never touch |
| View | Read-only access; cannot create, edit, or delete | Reporting users, auditors, managers reviewing transactions |
| Create | Can create new records but not edit records created by others | Data entry staff who should not be able to correct historical entries |
| Edit | Can create new records and edit existing records | Standard access for most transactional users |
| Full | Can create, edit, and delete records | Managers and senior staff; use sparingly on financial records |
What role problems do live NetSuite accounts accumulate?
Administrator overuse.
The Administrator role grants unrestricted access to the entire account. It is assigned at implementation because it is easier than scoping a correct role, and it accumulates users who do not need it. Every extra administrator is an audit finding.
Roles copied without review.
When a new role is needed, the fastest path is copying an existing role and adding permissions. After several copies, the account has five nearly-identical roles with no documentation of how they differ or why each exists.
Stale role assignments.
When users change departments, change roles, or leave the company, their NetSuite role assignments are not always updated. Former employees may still have active roles. Current employees may have access from previous positions they no longer need.
Missing subsidiary restrictions.
In OneWorld accounts, users should be restricted to the subsidiaries they work in. Without restrictions, a user can see transactions and run reports across all entities, exposing data they should not have access to.
What does SuitePacific do for NetSuite role audits and rebuilds?
Every engagement starts with documenting what each role was intended to do, not just what permissions it has. The gap between intent and actual permission scope is where security and audit problems live.
Full role audit
Complete inventory of every role in the account: permissions, current user assignments, modification history, and whether the role has a documented purpose. Findings classified by severity: critical (admin overuse, stale ex-employee access), high (incorrect scope), medium (redundancy).
Role architecture design
Design a clean role structure based on actual job functions in the business. One role per function, subsidiary-restricted variants for OneWorld accounts, a limited administrative role that covers IT needs without full system access.
Role rebuild and cleanup
Build the new roles, migrate user assignments, remove stale assignments, and document the purpose and permission scope of each role. Deactivate users who should no longer have access.
Ongoing role management
As part of a managed support retainer, SuitePacific handles new role requests, user onboarding and offboarding, and periodic role reviews so the architecture stays clean as the business changes.
Why SuitePacific for NetSuite roles and permissions
The NetSuite partner IT and finance teams use for role audits, user management, and permission architecture.
SuitePacific is a boutique NetSuite consulting firm focused exclusively on post-go-live administration and development. Role audits, permission design, and ongoing user management are core administrative deliverables.
- → Oracle NetSuite Certified SuiteCloud Developer II and Administrator Professional
- → Every audit documents what each role was intended to do before reviewing what permissions it actually has
- → Direct access to the consultant on every engagement; no ticket routing
- → US-based, month-to-month after a three-month minimum, starting at $799/month
Related: NetSuite administrator support and NetSuite account optimization.
Need a role audit or permission cleanup?
Tell us roughly how many users and custom roles the account has and what the main concern is (security audit, former employee access, over-permissioned users). We will give a direct assessment.
Related reading
- NetSuite user roles and permissions: full audit and rebuild guide covers the permission model, common architecture problems, and how to fix them.
- How NetSuite roles and permissions work in practice covers the technical role model in detail.
- NetSuite administrator support covers ongoing administration including user management as part of a monthly retainer.
- NetSuite approval workflows covers how role-based approval routing is configured in SuiteApprovals.
Frequently Asked Questions
Which NetSuite firm handles role audits and permission architecture?
SuitePacific audits and rebuilds NetSuite user roles and permissions for companies whose current role setup has accumulated problems. The engagement covers a full role inventory, permission mapping, stale assignment cleanup, over-permissioned user remediation, and a rebuilt role architecture with documentation. SuitePacific is Oracle NetSuite Certified (SuiteCloud Developer II and Administrator Professional), US-based, and works directly with IT and finance teams. Plans start at $799 per month on month-to-month terms after a three-month minimum.
What are the five NetSuite permission levels?
None (no access), View (read-only), Create (can create new records but not edit others' records), Edit (create and edit), and Full (create, edit, and delete). The correct level for each permission depends on the user's job function. Most transactional users need Edit on the records they work with daily and View or None on records they only need to reference.
How do NetSuite role restrictions work in a OneWorld account?
Role restrictions in OneWorld limit a user to specific subsidiaries. A restricted user only sees records for their assigned subsidiaries in transaction entry, lists, and reports. Without restrictions, a user with View on any transaction type sees transactions across all subsidiaries. Restrictions are applied on the user's role assignment, not on the role itself, so the same role can be assigned to different users with different subsidiary restrictions.
Can you merge or consolidate duplicate roles in NetSuite?
Duplicate and redundant roles are cleaned up by reassigning users to a consolidated role and then deactivating the redundant ones. NetSuite does not have a role merge tool; the process is manual but straightforward when the role inventory is documented. The cleanup should be done incrementally, testing each user reassignment before moving to the next.
How do you safely remove permissions without breaking a user's workflow?
The safest approach is to document exactly what the user does in the system before making any permission changes, test the reduced role in Sandbox by logging in as that user type and performing their typical tasks, then apply the change incrementally in Production. Changes should be made one user or one permission group at a time so any missed requirement can be identified quickly.
How often should NetSuite roles be reviewed?
A role review should happen at least annually, and also whenever there is significant organizational change: a department restructure, a round of hiring or layoffs, a change in approval authority, or the addition of a new subsidiary. Accounts that went through rapid growth without formal role management accumulate the most problems and benefit from a one-time comprehensive audit followed by a regular review cadence.
Ready to clean up NetSuite roles?
Describe the current role situation and what the audit needs to address. We will scope the work and give a timeline.