Roles, Permissions & Data Access Design
HRDC Claimable
About this course
Who can see what — and why it matters.
Design the NetSuite role and permission structure that provides appropriate access, protects sensitive data, and satisfies audit requirements for an African organisation. 6 hrs · 2 sessions · Intermediate.
Overview
Access misconfiguration is the most common audit finding on NetSuite instances. Users have access to data they should not see, segregation of duties controls are bypassed because it was easier to give everyone the same role, and the user access review cannot be completed because no one knows who has access to what.
This course teaches how to design a role and permission structure that is secure, auditable, and maintainable — not just on day one but as the organisation grows and people change roles. Drawn from Awatay and MIWA implementation experience, including the access design decisions that were revised after an internal audit and what the revision cost.
Learning outcomes
• Design a role structure that provides appropriate access without over-permissioning any user
• Build custom roles from standard templates for specific job functions in an African organisation
• Apply subsidiary, department, and class restrictions to control data visibility below the role level
• Manage user onboarding, offboarding, and role changes with a complete access governance process
• Produce the user access report that satisfies an internal or external audit access review request
Prerequisites
• NetSuite Navigation & Personalisation course or comfortable with the interface
• Basic understanding of IT security concepts (access control, least privilege) is helpful
• No prior NetSuite configuration experience required
Modules
1. Roles, permissions & the NetSuite security model (3 hours)
NetSuite's security model: the role as the fundamental access unit, how roles control what a user can see, create, edit, and delete across every record type. The permission matrix: record type, permission level (none, view, create, edit, full), and the interaction between role permissions and subsidiary restrictions. Permission levels in practice: why giving a user "full" access to vendor bills when they only need "create" is a segregation of duties violation — and why most implementations get this wrong. Standard roles: the roles NetSuite provides out of the box, which ones are usable as-is, and which ones grant far more access than any real job function requires. Custom roles: how to copy a standard role and modify it, how to build a role from scratch, and why building from a copy is almost always the right approach. Role design patterns for African organisations: the AP clerk role, the AR officer role, the finance manager role (approve but not post), the read-only CFO role, the HR administrator role restricted to HR records, and the subsidiary-restricted regional accountant role. Restricting by subsidiary: how to give a user access to only one or two subsidiaries without being able to see data from others. Restricting by department or class: the additional filtering that limits what transactions a user can see even within their permitted record types.
Topics: Role as access unit; Permission matrix; Permission levels; Segregation of duties; Standard roles; Custom role design; Copy vs build from scratch; AP clerk role pattern; Finance manager role pattern; Read-only executive role; Subsidiary restriction; Department restriction; Class restriction
2. User setup, access governance & the audit review (3 hours)
The employee record and the user record: how they link, why the employee record must exist before the user record is created, and what each one controls. Creating a user: the required fields, the role assignment, the two-factor authentication enforcement, and the password policy. Multiple roles per user: when it is appropriate to give one person two or three roles (e.g., project manager who also does timesheet approvals), the risk of role combinations that create unintended access, and how to test for it. Access governance in practice: the quarterly access review — running the user access report, identifying users who have left or changed roles, and removing access promptly. The onboarding checklist: the sequence that ensures a new employee has the correct access from day one. The offboarding checklist: the complete access termination sequence that ensures a departing employee cannot access NetSuite after their last day. Role change management: how to handle a promotion or a function change without leaving orphaned access from the old role. Responding to an audit access review request: the report to run, the format to provide, and how to explain access decisions that look like segregation of duties violations but are deliberate and controlled.
Topics: Employee vs user record; User creation sequence; Role assignment; Two-factor enforcement; Password policy; Multiple role risk; Access review process; User access report; Inactive user identification; Onboarding checklist; Offboarding sequence; Role change management; Audit access review response; SoD violation explanation
Delivery
Best attended by the system administrator and the IT security or compliance lead together. Groups of 4–10. Two sessions in one day work well for an experienced IT team; two days with time to review the existing access structure between sessions is better for an audit-remediation context.
Certification
Certificate of completion
Price
USD 700 · per participant
per person · indicative · group pricing available
HRDC eligibility
Up to 75% refundable
Mauritius-registered employers may claim this training via the HRDC levy. We provide full documentation to support your claim.
Languages
English
Provider reference
SIMPLIT-056-NS_ROLES_PERMISSIONS
Who is this for?
• NetSuite administrators responsible for user management and system security
• Implementation consultants configuring access control on a new NetSuite instance
• IT security leads assessing NetSuite access risk for audit or compliance purposes
• Finance directors concerned about segregation of duties in the AP and AR processes
• HR directors responsible for ensuring employee data is appropriately restricted
• Internal auditors reviewing access governance on an existing NetSuite instance
Course Details
- Date
- To be announced
- Duration
- 6 hours (2 × 3 hrs)
- Price
- Rs 700
- Location
- Virtual (live, online) / On-site at client / Individual coaching
- Status
- Active
- Presenter
- Simpl'IT Cloud
CategoriesTechnology, Business & Management
Tags
Oracle NetSuiteIntermediateOnline AvailableCorporate TrainingIndividual CoachingData Analytics