NetSuite ERP Implementation: The Complete Step-by-Step Guide
On this page A NetSuite ERP implementation is one of the highest-stakes technology projects a…
NetSuite’s role-based access system gives each user access to exactly what they need. Sales reps see their deals and customer records. Warehouse staff see inventory and fulfilment. The CFO sees everything. For Indian mid-market companies with 20 to 200 users across departments, getting roles and permissions right is critical for data security and operational efficiency.

Every NetSuite user is assigned one or more roles. A role defines which modules, records, reports, and actions the user can access. NetSuite ships with 20+ standard roles (Administrator, Sales Manager, Accountant, Warehouse Manager, etc.) that cover most common configurations.
For Indian businesses going live on NetSuite, the roles most frequently assigned are Administrator (full system access, typically limited to one or two IT or ERP admins), Accountant (access to all accounting transactions and reports, but no ability to change system configuration), Sales Rep (access to CRM, quotes, and orders, but not financial data), Purchasing Agent (access to requisitions, POs, and vendor bills), and Warehouse Manager (access to inventory, item receipts, and fulfilment).
| Role | Access |
|---|---|
| Sales Rep | Own leads, contacts, opportunities, quotes |
| Sales Manager | All sales data, team pipeline, forecasts |
| Accountant | GL, AP, AR, bank reconciliation, reports |
| A/P Clerk | Vendor bills, payments, PO matching |
| Warehouse | Inventory, fulfilment, receiving, transfers |
| Executive | Dashboards, KPIs, all reports (read-only) |
| Administrator | Full access including configuration |
Standard roles are a good starting point, but most Indian businesses need adjustments. The standard Accountant role, for example, gives access to all subsidiaries by default, which is inappropriate if your company has subsidiaries in different states and you want each accounts team to see only their own entity’s data. This is where role customisation becomes necessary.
Go to Setup > Users/Roles > Manage Roles > New. A custom role is a permission set you build from scratch. For each transaction type, set permission to None, View, Create, Edit, or Full. For example, a “Purchase Coordinator” role might have Create and Edit on Purchase Orders but View-only on Vendor Bills.
Rather than building a role from a blank slate, start by copying the standard role that is closest to what you need, then adjust permissions from there. NetSuite permissions work at two levels: record-level access, which determines whether a user can see a given record type at all, and field-level security, which controls visibility of specific fields within a record the user can otherwise access. For sensitive data such as salary information or bank account details, apply field-level security even within a role that otherwise has broad access.

Beyond role permissions, restrict record access by department, subsidiary, or location. A salesperson in the West India team sees only customers and deals in the West India subsidiary. A warehouse manager in the Mumbai location sees only Mumbai inventory. Configure these restrictions in the role settings under Audience.
Subsidiary access is controlled separately from module permissions: a role can have full functional access across NetSuite but still be restricted to a single subsidiary. This matters for Indian companies with subsidiaries registered in different states, for example a Maharashtra entity and a Karnataka entity with separate GSTINs, where each state’s accounts team should see only its own subsidiary’s transactions.
For audit NetSuite India GST setup, ensure no single user can both create a vendor bill and approve its payment. NetSuite supports segregation of duties by assigning different roles for creation and approval. The person who enters a vendor bill should not be the same person who releases the payment.
This follows the least privilege principle: users should have only the access they need to do their job, nothing more. This matters in Indian businesses where ERP fraud in the form of duplicate vendor payments, fictitious vendors, or unauthorised PO approvals is a real risk. Common over-permission situations to check for:
NetSuite’s User Access Audit report (under Reports > Audit Trail) shows a log of who accessed which records and when. Run this quarterly and investigate any unusual access patterns.
Tell us what you are working through and a senior architect from our team will get back to you with a straight answer, usually within a couple of working days. No bot, no hard sell.
A senior architect will get back to you at , usually within a couple of working days. Worth checking your spam folder, just in case.
Tell us what you are actually trying to do. You will get a straight answer from a senior architect who has done this before, not a sales rep.
A senior architect will get back to you at , usually within a couple of working days. Worth checking your spam folder, just in case.
Ask it now and a senior architect will get back to you, usually within a couple of working days. It goes to our team, not a mailing list.
A senior architect will get back to you at , usually within a couple of working days. Worth checking your spam folder, just in case.