Skip to main content
Maps roles and permissions against a segregation-of-duties conflict matrix — conflicts are reported with least-privilege fixes for your review, and no role is ever changed.
Every toxic permission combination, named — with the least-privilege fix. The riskiest access in NetSuite is the combination nobody meant to grant: one role that can both create a vendor and pay that vendor, or both post and approve a journal. This agent reviews your roles, permissions, and who actually holds them with read-only SuiteQL, maps permissions against a segregation-of-duties conflict matrix, and reports every toxic combination with the roles and users involved plus a least-privilege remediation recommendation. It reads and reports only — it never edits a role or permission. Team: Audit & Controls · Type: Agent

What’s included

Pinned tools

  • er_suiteql_example_find
  • er_suiteql_query_validate
  • ns_getSuiteQLMetadata
  • ns_runCustomSuiteQL
  • NetSuite Intelligence Library

Starter prompts

  • Run a full SoD review
  • Vendor create + pay
  • Audit one role
  • Integration role hygiene
  • Review exported roles

Trust and governance

This agent is read-only in NetSuite: it queries and analyses your data but pins no NetSuite write tools, so it cannot create, change, or send anything on your behalf. All activity is captured in a full audit trail, agents use your existing NetSuite roles and permissions, and your data is never used to train models. Works with: NetSuite