Sample output from the Departed Employee Data Archaeology prompt in the Sonar AI Prompt Library, run against a NetSuite test account. Every name and number here is test data. Back to the post · The library
Internal Governance Review · Confidential

Departed Employee
Data Archaeology

A systematic survey of NetSuite account TD3016323 to identify every asset, reference, and control dependency attributable to former employees: saved searches, script ownership, scheduled automation, role assignments, sales-representative relationships, and approval chains.

AccountTD3016323 (Production, OneWorld)
Report DateAugust 24, 2026
Prepared BySonar AI, at the direction of T. Dietrich
Population Examined20 inactive employee records
MethodSuiteQL introspection; 3 parallel research agents
Scope of WritesNone — read-only engagement
Contents
Section 01

Executive Summary

Twenty employee records are inactive in this account. The survey found that business data is in materially sound condition — no customer, case, task, or open approval depends on a departed employee — while automation ownership is significantly orphaned: 213 active saved searches, 81 scripts, and approximately 100 live script deployments remain owned by former staff, including four scheduled jobs that continue to execute.

20Departed employees examined
294Orphaned automation assets (searches + scripts)
4Scheduled jobs still executing under departed owners
5 / 9Survey domains verified fully clean
Saved searches (active)
213
Scripts owned
81
Live deployments
~100
Scheduled & running
4
Phone-call records
48
Orphaned roles
1
Fig. 1 — Orphaned asset inventory by category. Emerald denotes the highest-priority remediation target.
Principal Conclusion The account's control posture is intact — no approvals are blocked and no login access persists — but its automation estate has lost its accountability chain. Ownership reassignment, not emergency intervention, is the required response.
Section 02

Scope & Methodology

Definition of "Departed"

An employee record was classified as departed where employee.isinactive = 'T' or releasedate was populated. In practice all 20 qualifying records carried the inactive flag and none carried a release date (see Section 11, Assumption A1).

Survey Domains

Nine domains were examined: saved searches, script records, script deployments, workflows, role assignments, approval chains (four approver fields plus pending transaction approvals), customer sales-rep relationships, sales team memberships, and CRM activity records (cases, tasks, events, phone calls). File-cabinet ownership and CSV import maps were attempted but are not queryable in this account (Appendix B).

Execution

The census was performed in the primary session; three read-only research agents were then dispatched in parallel to survey automation assets, roles and approvals, and business-data references respectively. All agent findings bearing on the findings register were re-verified or cross-checked in the primary session. Every query executed appears verbatim in Appendix A. No record was created, modified, or deleted during this engagement.

Section 03

Departed Employee Census

Twenty inactive employee records. Seven own at least one asset; the remaining thirteen own nothing discoverable and require no action.

IDNameRoles HeldLoginSearchesScriptsOther
1252Ryan RoteAdministratorRevoked12170
1358Marcy MeinertAdministratorRevoked84
1221Ephraim GoyenaAdministrator, Employee CenterRevoked52
5Ray Gravinese10Revoked8
10Eric Nelson03AdministratorRevoked2
1249Christopher BermundoRevoked1
1225Ron VillanuevaAdministratorRevoked1
6Jenny Lunsford03AdministratorRevoked48 calls
1224Jef SaucoAdministrator, A/P Analyst, A/R AnalystRevoked1 role†
3872Alex RymarquisAdministrator, CEO, CFO, ControllerRevoked
No assets held: Hazel Alcoy (1220), christian camacho (1223), Gin Amistoso (1248), Philip Cutler (1251), Pao Pao (1357), Kate Cabalar (1359), Paolo Abutal (2086), Trisha Cabral (2107), Steph Azoulay (3870), Marc Ordinanza (3873).

† Sole remaining holder of role 1659 (SS RT PRM – A/P Analyst); see Finding F-04. "Login: Revoked" reflects giveaccess = 'F' on all twenty records.

Section 04

Findings Register

RefSeverityFindingOwner(s)Volume
F-01HighScheduled script deployments continue to execute under a departed owner. Failures notify no one; error accountability is broken.Ryan Rote (1252)4 deployments
F-02MediumLive event-driven deployments (User Event, Client, Suitelet, RESTlet) owned by departed staff. Predominantly bundle-managed (SCM, Subsidiary Navigator), which mitigates but does not remove the accountability gap.Rote, Gravinese10, Goyena, Bermundo81 scripts, ~100 deployments
F-03MediumActive, public saved searches owned by departed employees, including hand-built searches that feed live scripts (Goyena's "Set Preferred Form" pair) and operational reconciliation searches (Nelson03's cash-sale mismatch check).Rote, Meinert, Goyena, Nelson03, Villanueva213 searches
F-04LowRole 1659 (SS RT PRM – A/P Analyst) is orphaned: its only holder is departed. Companion role 1660 (A/R Analyst) remains actively held. The role should be assigned to a successor or retired.Jef Sauco (1224)1 role
F-05LowScheduled phone-call activity records (ids 14–61) owned by a departed employee remain in SCHEDULED status, polluting activity reporting.Jenny Lunsford03 (6)48 records
High
1
Medium
2
Low
2
Fig. 2 — Findings by severity. The single high-severity finding (F-01) is scoped to four deployment records and is fully remediable by ownership transfer.
Section 05

Automation Assets

F-01 — Scheduled deployments still executing (owner: Ryan Rote, id 1252)

Script IDScript NameDeploymentStatus
458SCM CPN Cleaner SScustomdeploy_scm_cpn_ss_cleanerSCHEDULED
459SCM Background Cleanup Process SScustomdeploy_scm_ss_bgcleanupprocessSCHEDULED
467ECO Details MR Delete Orphanscustomdeploy_ecodetails_mr_delorp_schedSCHEDULED
468ECO MR Bulk Processcustomdeploy_eco_mr_bulk_process_schedSCHEDULED

Four additional deployments owned by departed staff are deployed but not currently scheduled (customdeploy_snav_copysublogo, customdeploy_de_dept_hotfix_ss, and script ids 457, 460, 700, 701).

Script and deployment footprint by departed owner

Ryan Rote (1252)
70
Ray Gravinese10 (5)
8
Ephraim Goyena (1221)
2
Christopher Bermundo (1249)
1
Fig. 3 — Script records by departed owner. Rote's 70 scripts break down as 15 Client, 48 User Event, 20 Suitelet, 6 RESTlet, 6 Scheduled, 4 Map/Reduce, 1 Bundle Install across ~100 live deployments; provenance is predominantly the SCM / ECO / Merchandise Hierarchy bundles.

Saved searches (213 total; all active, all public)

OwnerCountCharacter
Ryan Rote (1252)121SCM / Atlas / Merch Hierarchy bundle searches; two CUSTOMSEARCH_SDF_* artifacts (ids 1400–1401)
Marcy Meinert (1358)84Atlas / SuiteSuccess starter-edition searches
Ephraim Goyena (1221)5Hand-built: "***Set Preferred Form" pair (794, 795 — feed scripts 330/331), "B2B Customers" (800), "B2C Customers East/West" (801, 803)
Eric Nelson03 (10)2Hand-built: ".External ID List" (92), ".DE – Cash Sale SO Payment Mismatch" (96) — an operational reconciliation check
Ron Villanueva (1225)1"IF Check" (808)
Interpretive Note The bundle-owned majority (Rote, Meinert, Gravinese10) reflects a common NetSuite pattern: whoever installs a bundle becomes owner of its generated assets. The risk is concentrated in the hand-built minority — Goyena's preferred-form searches actively feed deployed scripts, and Nelson03's payment-mismatch search appears to be a live reconciliation control with no current owner.
Section 06

Roles & Access

Every role held by a departed employee was tested for surviving active holders. One role is orphaned.

IDRoleActive HoldersDeparted HoldersVerdict
3Administrator714Shared
15Employee Center11Shared
1659SS RT PRM – A/P Analyst01Orphaned
1660SS RT PRM – A/R Analyst11Shared
1662SS RT PRM – Chief Executive Officer11Shared
1663SS RT PRM – Chief Financial Officer11Shared
1664SS RT PRM – Controller11Shared

All twenty departed records carry giveaccess = 'F': no departed employee can log in. Fourteen of the twenty formerly held the Administrator role — an observation about historical provisioning breadth that management may wish to note for its joiner-mover-leaver policy, though it presents no current exposure.

Section 07

Approval Chains

Three tests were applied; all returned zero exceptions.

  1. Organizational references. No active employee names a departed employee as supervisor, approver, purchaseorderapprover, or timeapprover. (0 rows)
  2. Pending approvals. No transaction of any type carries a departed employee as nextapprover. Nothing is stuck. (0 rows)
  3. Workflow ownership. No workflow record is owned by a departed employee. (0 rows)
Verified Clean The approval architecture of this account has no dependency on any departed employee. This is the domain where departures most commonly cause silent operational damage; here it requires no remediation.
Section 08

Business-Data References

DomainTestHitsVerdict
Customerscustomer.salesrep ∈ departed ids (273 customers in account)0Clean
Sales teamscustomersalesteam.employee ∈ departed ids0Clean
Support casessupportcase.assigned ∈ departed ids0Clean
Transactionstransaction.employee ∈ departed ids0Clean
Taskstask.assigned or task.owner ∈ departed ids0Clean
Calendar eventscalendarevent.owner/organizer ∈ departed ids0Clean
Phone callsphonecall.owner/assigned ∈ departed ids48Finding F-05

The 48 phone-call records (internal ids 14–61) are all owned by Jenny Lunsford03 (id 6) and all remain in SCHEDULED status. They are demonstration-era CRM artifacts; the recommended disposition is bulk reassignment or completion/cancellation.

Section 09

Domains Verified Clean

For completeness and auditability, the following were affirmatively verified as carrying zero departed-employee dependencies, each by direct query (Appendix A):

Section 10

Remediation Plan

#ActionAddressesEffortSuggested Priority
1Reassign the four SCHEDULED deployments (script ids 458, 459, 467, 468) to an active administrator; confirm error-notification recipients on each script record.F-01< 1 hourImmediate
2Bulk-transfer script ownership (81 records) to a designated service account or active administrator. NetSuite permits owner reassignment by mass update or record edit; a service-account owner prevents recurrence at the next departure.F-02Half dayNear term
3Transfer the seven hand-built saved searches (92, 96, 794, 795, 800, 801, 803, 808) individually with review of what consumes them; bulk-transfer the 206 bundle-generated searches without review.F-03Half dayNear term
4Decide the disposition of role 1659 (A/P Analyst): assign to the incoming A/P owner or inactivate the role. Its A/R counterpart (1660) is actively held by Conner Avery, suggesting a successor assignment is the consistent choice.F-04MinutesNear term
5Bulk-reassign or cancel the 48 scheduled phone calls (ids 14–61) owned by employee 6.F-05MinutesDiscretionary
6Preventive: add an ownership-transfer step to the employee-offboarding checklist (searches, scripts, roles, approval seats), and consider a quarterly re-run of this survey — the queries in Appendix A are re-executable as-is.AllPolicyOngoing
Offer of Assistance Items 1, 2, 3, and 5 are executable by Sonar AI under the standard dry-run and approval workflow, on request.
Section 11

Assumptions & Limitations

  1. A1 — Departure definition. "Departed" was operationalized as isinactive = 'T'. No record carried a releasedate, and several carry hire dates postdating this report (a known artifact of demonstration data). If any of the twenty were inactivated for reasons other than departure, their findings transfer unchanged — the assets are orphaned either way.
  2. A2 — Bundle provenance is inferred. The script table does not expose bundle lineage in this account; SCM / Atlas / Subsidiary Navigator attribution rests on scriptid prefixes and naming conventions. Treat the bundle/hand-built split as high-confidence but not record-proven.
  3. A3 — File-cabinet ownership unauditable. file.owner is not exposed to SuiteQL here; files owned by departed employees could not be enumerated. A UI-based audit (Documents → File Cabinet, filter by owner) would close this gap.
  4. A4 — CSV import maps and search schedules undiscoverable. No SuiteQL table for import maps or saved-search email schedules exists in this account. Scheduled-search emails addressed to departed staff, if any, were not visible to this survey.
  5. A5 — Role assignments read from a derived column. employee.rolesforsearch is a derived multiselect; it was enumerated in full and matched in-session rather than filtered server-side (see Appendix B). Counts were spot-verified against known holders.
  6. A6 — Point-in-time. All figures reflect account state as of August 24, 2026. The queries in Appendix A are deterministic and re-executable for refresh.
Appendix A

Queries Executed

All queries are SuiteQL, executed read-only under the reporting user's Administrator role. Ellipsized id lists denote the full set of twenty departed employee ids: 5, 6, 10, 1220, 1221, 1223, 1224, 1225, 1248, 1249, 1251, 1252, 1357, 1358, 1359, 2086, 2107, 3870, 3872, 3873.

A.1 — Departed employee census
SELECT id, entityid, firstname, lastname, title, email, isinactive, releasedate,
       hiredate, issalesrep, issupportrep, giveaccess, rolesforsearch, supervisor,
       approver, purchaseorderapprover, timeapprover, subsidiary, department, location
FROM employee
WHERE isinactive = 'T' OR releasedate IS NOT NULL
ORDER BY lastname
A.2 — Scripts owned by departed employees
SELECT s.id, s.scriptid, s.name, s.scripttype, s.owner, s.isinactive
FROM script s
WHERE s.owner IN (5, 6, 10, ..., 3873)
A.3 — Saved searches owned by departed employees
SELECT ss.id, ss.scriptid, ss.name, ss.searchtype, ss.owner,
       ss.isinactive, ss.ispublic, ss.isshared
FROM savedsearch ss
WHERE ss.owner IN (5, 6, 10, ..., 3873)
ORDER BY ss.owner, ss.id
A.4 — Live deployments of departed-owned scripts (scheduled types)
SELECT s.owner, s.id AS script_id, s.name AS script_name, s.scripttype,
       d.id AS deploy_id, d.scriptid AS deploy_scriptid, d.status, d.isdeployed
FROM scriptdeployment d
JOIN script s ON d.script = s.id
WHERE s.owner IN (5, 6, 10, ..., 3873)
  AND d.isdeployed = 'T'
  AND s.scripttype IN ('SCHEDULED', 'MAPREDUCE')
ORDER BY s.owner, s.id
A.5 — Deployment counts by owner and script type
SELECT s.owner, s.scripttype, COUNT(*) AS deployed_cnt
FROM scriptdeployment d
JOIN script s ON d.script = s.id
WHERE s.owner IN (5, 6, 10, ..., 3873) AND d.isdeployed = 'T'
GROUP BY s.owner, s.scripttype
ORDER BY s.owner
A.6 — Workflow ownership (returned zero rows)
SELECT w.internalid, w.scriptid, w.name, w.owner, w.isinactive, w.releasestatus
FROM workflow w
WHERE w.owner IN (5, 6, 10, ..., 3873)
A.7 — Role identification
SELECT id, name, scriptid, isinactive, centertype
FROM role
WHERE id IN (3, 15, 1659, 1660, 1662, 1663, 1664)
A.8 — Active-employee role enumeration (matched in-session; see Appendix B.4)
SELECT id, entityid, isinactive, rolesforsearch, giveaccess
FROM employee
WHERE isinactive = 'F' AND rolesforsearch IS NOT NULL
A.9 — Approval-chain references (returned zero rows)
SELECT id, entityid, isinactive, supervisor, approver,
       purchaseorderapprover, timeapprover
FROM employee
WHERE supervisor IN (5, 6, 10, ..., 3873)
   OR approver IN (5, 6, 10, ..., 3873)
   OR purchaseorderapprover IN (5, 6, 10, ..., 3873)
   OR timeapprover IN (5, 6, 10, ..., 3873)
A.10 — Pending approvals held by departed staff (returned zero rows)
SELECT type, COUNT(*) AS cnt
FROM transaction
WHERE nextapprover IN (5, 6, 10, ..., 3873)
GROUP BY type
A.11 — Customer sales-rep assignments (returned zero rows)
SELECT id, entityid, companyname, salesrep
FROM customer
WHERE salesrep IN (5, 6, 10, ..., 3873)
A.12 — Sales team memberships (returned zero rows)
SELECT cst.customer, c.entityid, c.companyname, cst.employee,
       cst.salesrole, cst.isprimary, cst.contribution
FROM customersalesteam cst
JOIN customer c ON cst.customer = c.id
WHERE cst.employee IN (5, 6, 10, ..., 3873)
A.13 — Support cases (returned zero rows)
SELECT id, casenumber, title, assigned, status, BUILTIN.DF(status) AS status_name
FROM supportcase
WHERE assigned IN (5, 6, 10, ..., 3873)
A.14 — Transaction attributions (returned zero rows)
SELECT type, COUNT(*) AS cnt
FROM transaction
WHERE employee IN (5, 6, 10, ..., 3873)
GROUP BY type
A.15 — CRM activities (tasks/events zero rows; phone calls 48 rows)
SELECT id, title, assigned, status FROM task
WHERE assigned IN (5, 6, 10, ..., 3873);

SELECT id, title, owner, status FROM task
WHERE owner IN (5, 6, 10, ..., 3873);

SELECT id, title, status, owner, organizer, startdate FROM calendarevent
WHERE owner IN (5, 6, 10, ..., 3873) OR organizer IN (5, 6, 10, ..., 3873);

SELECT id, title, status, owner, assigned, startdate FROM phonecall
WHERE owner IN (5, 6, 10, ..., 3873) OR assigned IN (5, 6, 10, ..., 3873)
Appendix B

Schema Quirks Discovered

Recorded so that future re-runs of this survey do not repeat the same discovery cost.

  1. B.1 — file.owner is NOT_EXPOSED to SuiteQL in this account; file-cabinet ownership cannot be audited by query.
  2. B.2 — Nonexistent tables: usersavedsearch, csvimport, csvimportmap, importmap, scheduledsearch, and salesteam all return "Invalid search type." The sales-team mapping lives in customersalesteam.
  3. B.3 — scriptdeployment carries no owner column; ownership is resolved only through the join to script.owner.
  4. B.4 — employee.rolesforsearch is not reliably filterable server-side. A LIKE predicate against it returned zero rows despite known matches; the derived multiselect must be enumerated and matched client-side. This survey did so and spot-verified against known role holders.
  5. B.5 — transaction.salesrep and transactionline.salesrep are not exposed here; sales-rep exposure was assessed via customer.salesrep and customersalesteam instead.
  6. B.6 — supportcase.escalateto is unfilterable ("Invalid or unsupported search"); escalation chains could not be tested and are a residual blind spot alongside A3/A4.