> ## Documentation Index
> Fetch the complete documentation index at: https://docs.erstan.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Segregation of Duties Check

> Maps roles and permissions against a segregation-of-duties conflict matrix — conflicts are reported with least-privilege fixes for your review, and no role is ever changed.

> Maps roles and permissions against a segregation-of-duties conflict matrix — conflicts are reported with least-privilege fixes for your review, and no role is ever changed.

**Every toxic permission combination, named — with the least-privilege fix.**

The riskiest access in NetSuite is the combination nobody meant to grant: one role that can both create a vendor and pay that vendor, or both post and approve a journal. This agent reviews your roles, permissions, and who actually holds them with read-only SuiteQL, maps permissions against a segregation-of-duties conflict matrix, and reports every toxic combination with the roles and users involved plus a least-privilege remediation recommendation. It reads and reports only — it never edits a role or permission.

**Team:** Audit & Controls · **Type:** Agent

## What's included

### Pinned tools

* `er_suiteql_example_find`
* `er_suiteql_query_validate`
* `ns_getSuiteQLMetadata`
* `ns_runCustomSuiteQL`

### Recommended skills

* NetSuite Intelligence Library

### Starter prompts

* Run a full SoD review
* Vendor create + pay
* Audit one role
* Integration role hygiene
* Review exported roles

## Trust and governance

This agent is **read-only in NetSuite**: it queries and analyses your data but pins no NetSuite write tools, so it cannot create, change, or send anything on your behalf.

All activity is captured in a full audit trail, agents use your existing NetSuite roles and permissions, and your data is never used to train models.

**Works with:** NetSuite
