16.1 What a Custom Role Can See and Do
Key Takeaways
View, Create, Edit, and Full are the permission levels: Create can add and view records but cannot edit them, and Edit can create and change records but cannot delete them.
A global Edit permission on one employee's record adds Edit for that employee. The shared role's Create permission still lets that employee create records.
Subsidiary restrictions default to User Subsidiary. Department, class, and location restrictions use none - no default, none - default to own, own, subordinate, and unassigned, or own and subordinates only.
Accounts on the chart of accounts with no department or class stay visible under those segment restrictions, so account access is wider than the restriction line suggests.
Import CSV File and Export Lists are separate permissions. Full CSV Export remains available only to the Administrator role.
Data access by role
A custom role controls data access by role in two layers. A permission decides what the user can do with a record type, a task, or a page. A restriction decides which records of that type the user can reach. Oracle NetSuite Help documents the working levels as View, Create, Edit, and Full. None, where the list offers it, grants no access. CSV import and CSV export are separate permissions, not a side effect of Edit or Full.
Open the role from Setup > Users/Roles > Manage Roles. Click Edit on a custom role, or Customize when you start from a standard role. Permissions are grouped on Transactions, Reports, Lists, Setup, and Custom Records. Each line has its own level.
What each permission level allows
Help defines the levels as a ladder. A higher level adds actions. It keeps the actions of the levels below it.
View lets the user see existing records only. The user cannot create, change, or delete a record.
Create lets the user create new records and view existing records. The user cannot edit an existing record and cannot delete one. Create does not include Edit. A role with Opportunities set to Create can enter a new opportunity and can open one that already exists. Saving a change to that existing opportunity requires Edit or Full.
Edit lets the user create new records, view existing records, and edit existing records. The user cannot delete them. Edit includes creating new records, so a user at Edit can still create. Raising a permission from Create to Edit adds the ability to change existing records and leaves creation in place.
Full lets the user create new records and view, edit, and delete existing records. A few permissions do not follow this ladder. Export Lists, for example, has only the Create level.
| Level | What the user can do to a record |
|---|---|
| View | View existing records only. Cannot create, edit, or delete. Printing is generally available at View. |
| Create | Create new records and view existing records. Cannot edit or delete. Create does not include Edit. |
| Edit | Create new records, view existing records, and edit existing records. Cannot delete. |
| Full | Create new records and view, edit, and delete existing records. |
| Global permission | Adds the level stored on that employee's record. It does not replace the role with a lower level, and it is ignored for the Administrator role. |
Global permissions add access for one employee
Global Permissions is optional, and Help describes it as not the preferred way to grant access. Enable it at Setup > Company > Setup Tasks > Enable Features, on the Employees tab. The employee record then has a Global Permissions subtab under Access. Select a permission and a level of View, Create, Edit, Full, or None.
The employee still needs a role on the Roles subtab. At login, the permission set is a combination of the global permissions and the role in use. Global permissions are ignored for the Administrator role, and they cannot reduce Administrator access.
Two users can share a role whose Opportunities permission is Create. The first user has no global permission for Opportunities. That user can create opportunities and view them, and cannot edit an existing opportunity, because Create does not include Edit. The second user has the same role and a global permission of Edit for Opportunities on the employee record. That user can edit existing opportunities and can still create them. Edit includes creating new records, and the global permission adds Edit for that user only. It does not replace the shared role with a lower level, and it does not remove Create. The first user is unchanged, because the global line sits on the employee, not on the role. Edit includes create. It adds the ability to change existing records.
Restrictions on which records appear
A permission grants the record type. A restriction decides which instances the user can access. In OneWorld, set subsidiary limits under Subsidiary Restrictions. Set department, class, and location limits on the Restrictions subtab, and employee limits in Employee Restrictions. The same limits can apply to a custom record when Apply Role Restrictions is checked on a list or record custom field. Users already logged in must log out and back in before new permissions or subsidiary restrictions apply.
Subsidiaries
In NetSuite OneWorld the default is User Subsidiary. The user sees the subsidiary on the employee record, so two people who share a role can still see different subsidiaries. Active grants active subsidiaries only. All includes inactive subsidiaries. Selected grants the subsidiaries you pick on the role.
Allow Cross-Subsidiary Record Viewing lets the role see, but not edit, records in subsidiaries it is not granted. That box cannot show employee payroll or commissions.
A subsidiary restriction also narrows departments and classes. When a department belongs only to one subsidiary and the role is limited to that subsidiary, the user can use the department even with no separate department restriction. A role can edit a department only when it can reach every subsidiary assigned to that department.
Departments, classes, and locations
With Departments, Classes, or Locations enabled, these limits cover transaction, employee, and partner records, and item records if you apply them to items. They also limit which segment values the user may assign. Choose the segment, then a level:
- none - no default leaves the segment unrestricted and fills no default.
- none - default to own leaves the segment unrestricted and defaults new records to the user's own department, class, or location.
- own, subordinate, and unassigned limits the user to that segment, its children, and records where the segment is blank.
- own and subordinates only limits the user to that segment and its children, and hides records where the segment is blank.
Allow Viewing lets the user see, but not edit, values outside the restriction. It does not reveal payroll or commissions. At own and subordinates only, the user still cannot view non-subordinate records other than the user's own.
An account with no department, or no class, sits outside own, subordinate, and unassigned and outside own and subordinates only. The segment restriction does not hide it. Limit accounts by restricting the account records and the role together.
Employee restrictions
Employee Restrictions use the same four values. They limit transaction, customer, and employee records by the employee, sales rep, and supervisor fields, and they do not limit contacts. The two tighter values let the user select only self or subordinates. Own, subordinate, and unassigned still shows records with nobody in that hierarchy. Own and subordinates only hides them. Allow Viewing shows other employees without edit rights and still blocks payroll and commissions.
When Advanced Employee Permissions is on, Employee Self, Employee Public, Employee Confidential, and Employee Compensation ignore these role-page limits. The Lists permission Employees overrides them with full employee-record access. Remove Employees when the role should see only part of the record.
Restricting CSV import and export permissions
Import CSV File and Export Lists are different permissions. Granting one does not grant the other, and neither belongs on every role.
Import CSV File is a Setup permission. Most Import Assistant record types require it. The role still needs the record permission for the file. A journal-entry import needs Make Journal Entry at Edit or Full together with Import CSV File.
Export Lists is a Lists permission with only the Create level. It adds Export and Email on search and saved-search results for record types the role can already open, and it requires Perform Search at least at View.
Full CSV Export, at Setup > Import/Export > Export Tasks > Full CSV Export, is limited to the Administrator role. Export Lists does not turn that task on.
Leave both off roles that only enter or review transactions. An import writes many records in one job, and a downloaded export is no longer filtered by subsidiary, department, class, location, or employee. When you customize a standard role, remove these lines unless that job loads or extracts files.
A custom role sets the Opportunities permission to Create. Which action can a user of that role take on an opportunity that already exists?
Open the opportunity and view it, without changing its fields or deleting it
Change fields on the opportunity, because Create includes Edit
Delete the opportunity, because each higher level includes every action below it and delete is included at Create
Create a second opportunity only after an administrator raises the permission to Edit
Two employees use the same custom role. The role's Opportunities permission is Create. Only the second employee has a global permission of Edit for Opportunities. What can each employee do?
Both employees can edit existing opportunities, because a global permission rewrites the shared role
The second employee can edit opportunities but can no longer create them, because the global permission replaces Create
The first employee can create opportunities, and the second employee can edit opportunities and can still create them
Neither employee can create an opportunity until the role itself is raised from Create to Edit
A OneWorld company wants each person who shares a custom role to see only the subsidiary on that person's employee record, and the role should not import or export CSV files. Which setup matches that requirement?
Set subsidiary restrictions to All, and add both Import CSV File and Export Lists
Set subsidiary restrictions to Selected for every subsidiary, and add Import CSV File only
Set subsidiary restrictions to Active, and add Export Lists so each user can download the subsidiary they can already see
Leave subsidiary restrictions at the default User Subsidiary, and do not assign Import CSV File or Export Lists
Sections you finish are checked off in the contents.