NetSuite's best practices for roles and permission...
# administration
a
NetSuite's best practices for roles and permissions are outlined as follows, but I often find myself unable to follow two of them in particular: Planning it out thoroughly instead of trial-and-error, and having a solid testing procedure: Best Practices • Always grant the lowest level of access required to perform duties. • Plan carefully when customizing roles rather than using a trial-and-error approach with the hopes of getting it right eventually. • Global permissions assigned to users override their role-based permissions, so use them judiciously. • Define and document organizational policies for role management: ∘ How are changes to roles/ permissions requested? ∘ Is internal approval required before changes can be made? ∘ Who manages changes to roles/permissions? ∘ What testing strategy is followed to validate changes? The Plan Carefully part is difficult because I haven't been able to find good documentation that gives a clear and thorough picture of what exactly each permission is going to enable. The testing strategy is more doable in general, but still difficult for the same reason. What do you all do to gain clarity into what exactly the permissions are going to do and not do?
j
Trial and error, but in sandbox first 😂
If you have the permission excel doc from this SA article, that's about as good as it gets, IME: suiteanswers.custhelp.com/app/answers/…/9911 and you'll inevitably have to do some testing to uncover the more nuanced intricacies of what each permission does
a
• A trusted finance colleague who's nosey can be a good testing buddy in SB. If they can already see most (if not all data) for the sub/s the role can see, they can just click around, try and do things. But this will be limited to what they do know about the system, but if viewing/finding financially restricted data is a problem, then I find it's a good one to start with. • Ultimately trail and error with some specific role testing (can they raise this transaction as needed etc). • If it's particular for colleagues, get a testing buddy to try and do all their normal day to day in SB - then you can try and view the blocked/restricted things. • If the role/s have anything they really aren't allowed to do/see, then I would start trying to view/navigate to those things first. Just to make sure they can/cannot. Hope this helps
a
Thanks 🙂