RBAC Overview
NetSuite uses a Role-Based Access Control (RBAC) model, where all user permissions are assigned through roles rather than granted directly. A role acts as...
NetSuite comes prepackaged with a collection of standard, or “seeded,” roles such as Administrator or Accounts Payable Manager. While these out-of-the-box roles are convenient to assign, they are rarely designed with a single organization’s risk tolerance, the principle of least privilege, segregation of duties rules in mind. Instead, one could argue, standard roles in NetSuite and other ERP they are intentionally over-provisioned so that ERP providers can cover the widest possible range of customer use cases right off the bat. Ultimately, access controls are each organization’s individual responsibility, and ERP providers want to give a functional product that can be leveraged from day one. The result is that organizations who don’t perform an independent analysis of roles and job requirements often grant users far more access than they need to perform their jobs via standard roles, which introduces unnecessary security and compliance risks.
ERP vendors often create standard roles to be universally functional, meaning they can handle every conceivable task in each area. However, this “one-size-fits-all” approach ignores the principle of least privilege. What works in a demo environment does not work in a real-world business where tight controls, regulatory requirements, and audit readiness are essential.
Organizations should begin by exporting their seeded roles into spreadsheets, through a custom saved search, or by leveraging a dedicated sensitive access (SA) and segregation of duties (SoD) assessment tool. These tools provide a structured way to analyze roles against a library of high-risk permissions and SoD conflicts, making it easier to pinpoint where overprovisioning exists. Once the data is extracted, roles and the permissions they contain can be reviewed line by line to determine which permissions are essential and which introduce risk. Pro tip: leverage pivot tables to make this work much easier. Particular attention should be paid to high-risk objects such as system configuration rights, permissions that provide access to view sensitive data, high-risk transactions, user and role administration rights, and access to master data records. Highlighting these areas within the report or assessment tool helps organizations quickly identify where role customization and de-scoping are needed.
Below are screenshots from NetSuite’s standard role documentation for the A/P Clerk and Buyer roles, with certain permissions highlighted that may pose risk. These permissions likely do not align with the principle of least privilege and, in most cases, should not be included in the role. We recognize that each organization has unique business requirements and mitigating controls, which may make some of these permissions acceptable in specific circumstances. However, as a general rule, the highlighted permissions warrant closer scrutiny and, in many cases, removal to ensure roles remain appropriately restricted.
| A/P Clerk Potential Role Design Issues |
| Edit – Bill of Materials |
| Edit – Item Receipt |
| Edit – Locations |
| Edit – Purchase Order |
| Edit – Receive Order |
| Edit – Vendor Return Authorization |
| Edit – Pay Bills |
| Edit – Vendors |
| Edit – Items |
| Edit – Classes |
| Edit – Requisition |
| Edit – Statistical Account |
| Edit – Units |
| Edit – Accounting Lists |
| Edit – Departments |
| Edit – Vendor Prepayment |
| Edit – Vendor Prepayment Application |
| Full – Vendor Bill Approval |
| Full – Vendor Payment Approval |
| Full – Vendor Prepayment Approval |
| Buyer Potential Role Design Issues |
| Edit – Vendors |
| Edit – Vendor Returns |
| Edit – Bill of Materials |
| Edit – Bills |
| Edit – Classes |
| Edit – Departments |
| Edit – Items |
| Edit – Locations |
| Edit – Receive Order |
| Edit – Inbound Shipment |
Hopefully you can see our point on why we recommend customizing all roles through the two examples provided above. Investing in customized roles clearly pays dividends. It reduces audit findings, strengthens compliance, and enforces least privilege across the enterprise. There are also little to no surprises because their purpose and structure can be well documented through the customization process. By systematically breaking down standard roles into custom roles, organizations can turn a risky convenience into a secure foundation for access management.
NetSuite uses a Role-Based Access Control (RBAC) model, where all user permissions are assigned through roles rather than granted directly. A role acts as...
ERP upgrades and patches are essential for keeping systems secure and up to date, but they can also introduce hidden...