Back to blog

NetSuite: Breakdowns of Standard Roles in NetSuite That Pose Risk

The Common Issue with Standard / Seeded Roles

NetSuite comes prepackaged with a collection of standard, or “seeded,” roles such as Administrator or Accounts Payable Manager. While these out-of-the-box roles are convenient to assign, they are rarely designed with a single organization’s risk tolerance, the principle of least privilege, segregation of duties rules in mind. Instead, one could argue, standard roles in NetSuite and other ERP they are intentionally over-provisioned so that ERP providers can cover the widest possible range of customer use cases right off the bat. Ultimately, access controls are each organization’s individual responsibility, and ERP providers want to give a functional product that can be leveraged from day one. The result is that organizations who don’t perform an independent analysis of roles and job requirements often grant users far more access than they need to perform their jobs via standard roles, which introduces unnecessary security and compliance risks.

Why Over-Provisioning Happens

ERP vendors often create standard roles to be universally functional, meaning they can handle every conceivable task in each area. However, this “one-size-fits-all” approach ignores the principle of least privilege. What works in a demo environment does not work in a real-world business where tight controls, regulatory requirements, and audit readiness are essential.

A Structured Role-Review Method

Organizations should begin by exporting their seeded roles into spreadsheets, through a custom saved search, or by leveraging a dedicated sensitive access (SA) and segregation of duties (SoD) assessment tool. These tools provide a structured way to analyze roles against a library of high-risk permissions and SoD conflicts, making it easier to pinpoint where overprovisioning exists. Once the data is extracted, roles and the permissions they contain can be reviewed line by line to determine which permissions are essential and which introduce risk. Pro tip: leverage pivot tables to make this work much easier. Particular attention should be paid to high-risk objects such as system configuration rights, permissions that provide access to view sensitive data, high-risk transactions, user and role administration rights, and access to master data records. Highlighting these areas within the report or assessment tool helps organizations quickly identify where role customization and de-scoping are needed.

Examples of Risky Standard Roles in NetSuite

Below are screenshots from NetSuite’s standard role documentation for the A/P Clerk and Buyer roles, with certain permissions highlighted that may pose risk. These permissions likely do not align with the principle of least privilege and, in most cases, should not be included in the role. We recognize that each organization has unique business requirements and mitigating controls, which may make some of these permissions acceptable in specific circumstances. However, as a general rule, the highlighted permissions warrant closer scrutiny and, in many cases, removal to ensure roles remain appropriately restricted.

A/P Clerk Potential Role Design Issues
Edit – Bill of Materials
Edit – Item Receipt
Edit – Locations
Edit – Purchase Order
Edit – Receive Order
Edit – Vendor Return Authorization
Edit – Pay Bills
Edit – Vendors
Edit – Items
Edit – Classes
Edit – Requisition
Edit – Statistical Account
Edit – Units
Edit – Accounting Lists
Edit – Departments
Edit – Vendor Prepayment
Edit – Vendor Prepayment Application
Full – Vendor Bill Approval
Full – Vendor Payment Approval
Full – Vendor Prepayment Approval

 

Buyer Potential Role Design Issues
Edit – Vendors
Edit – Vendor Returns
Edit – Bill of Materials
Edit – Bills
Edit – Classes
Edit – Departments
Edit – Items
Edit – Locations
Edit – Receive Order
Edit – Inbound Shipment

The Benefits of Customization

Hopefully you can see our point on why we recommend customizing all roles through the two examples provided above. Investing in customized roles clearly pays dividends. It reduces audit findings, strengthens compliance, and enforces least privilege across the enterprise. There are also little to no surprises because their purpose and structure can be well documented through the customization process. By systematically breaking down standard roles into custom roles, organizations can turn a risky convenience into a secure foundation for access management.