A systematic survey of NetSuite account TD3016323 to identify every asset, reference, and control dependency attributable to former employees: saved searches, script ownership, scheduled automation, role assignments, sales-representative relationships, and approval chains.
Twenty employee records are inactive in this account. The survey found that business data is in materially sound condition — no customer, case, task, or open approval depends on a departed employee — while automation ownership is significantly orphaned: 213 active saved searches, 81 scripts, and approximately 100 live script deployments remain owned by former staff, including four scheduled jobs that continue to execute.
An employee record was classified as departed where employee.isinactive = 'T' or releasedate was populated. In practice all 20 qualifying records carried the inactive flag and none carried a release date (see Section 11, Assumption A1).
Nine domains were examined: saved searches, script records, script deployments, workflows, role assignments, approval chains (four approver fields plus pending transaction approvals), customer sales-rep relationships, sales team memberships, and CRM activity records (cases, tasks, events, phone calls). File-cabinet ownership and CSV import maps were attempted but are not queryable in this account (Appendix B).
The census was performed in the primary session; three read-only research agents were then dispatched in parallel to survey automation assets, roles and approvals, and business-data references respectively. All agent findings bearing on the findings register were re-verified or cross-checked in the primary session. Every query executed appears verbatim in Appendix A. No record was created, modified, or deleted during this engagement.
Twenty inactive employee records. Seven own at least one asset; the remaining thirteen own nothing discoverable and require no action.
| ID | Name | Roles Held | Login | Searches | Scripts | Other |
|---|---|---|---|---|---|---|
| 1252 | Ryan Rote | Administrator | Revoked | 121 | 70 | — |
| 1358 | Marcy Meinert | Administrator | Revoked | 84 | — | — |
| 1221 | Ephraim Goyena | Administrator, Employee Center | Revoked | 5 | 2 | — |
| 5 | Ray Gravinese10 | — | Revoked | — | 8 | — |
| 10 | Eric Nelson03 | Administrator | Revoked | 2 | — | — |
| 1249 | Christopher Bermundo | — | Revoked | — | 1 | — |
| 1225 | Ron Villanueva | Administrator | Revoked | 1 | — | — |
| 6 | Jenny Lunsford03 | Administrator | Revoked | — | — | 48 calls |
| 1224 | Jef Sauco | Administrator, A/P Analyst, A/R Analyst | Revoked | — | — | 1 role† |
| 3872 | Alex Rymarquis | Administrator, CEO, CFO, Controller | Revoked | — | — | — |
| No assets held: Hazel Alcoy (1220), christian camacho (1223), Gin Amistoso (1248), Philip Cutler (1251), Pao Pao (1357), Kate Cabalar (1359), Paolo Abutal (2086), Trisha Cabral (2107), Steph Azoulay (3870), Marc Ordinanza (3873). | ||||||
† Sole remaining holder of role 1659 (SS RT PRM – A/P Analyst); see Finding F-04. "Login: Revoked" reflects giveaccess = 'F' on all twenty records.
| Ref | Severity | Finding | Owner(s) | Volume |
|---|---|---|---|---|
| F-01 | High | Scheduled script deployments continue to execute under a departed owner. Failures notify no one; error accountability is broken. | Ryan Rote (1252) | 4 deployments |
| F-02 | Medium | Live event-driven deployments (User Event, Client, Suitelet, RESTlet) owned by departed staff. Predominantly bundle-managed (SCM, Subsidiary Navigator), which mitigates but does not remove the accountability gap. | Rote, Gravinese10, Goyena, Bermundo | 81 scripts, ~100 deployments |
| F-03 | Medium | Active, public saved searches owned by departed employees, including hand-built searches that feed live scripts (Goyena's "Set Preferred Form" pair) and operational reconciliation searches (Nelson03's cash-sale mismatch check). | Rote, Meinert, Goyena, Nelson03, Villanueva | 213 searches |
| F-04 | Low | Role 1659 (SS RT PRM – A/P Analyst) is orphaned: its only holder is departed. Companion role 1660 (A/R Analyst) remains actively held. The role should be assigned to a successor or retired. | Jef Sauco (1224) | 1 role |
| F-05 | Low | Scheduled phone-call activity records (ids 14–61) owned by a departed employee remain in SCHEDULED status, polluting activity reporting. | Jenny Lunsford03 (6) | 48 records |
| Script ID | Script Name | Deployment | Status |
|---|---|---|---|
| 458 | SCM CPN Cleaner SS | customdeploy_scm_cpn_ss_cleaner | SCHEDULED |
| 459 | SCM Background Cleanup Process SS | customdeploy_scm_ss_bgcleanupprocess | SCHEDULED |
| 467 | ECO Details MR Delete Orphans | customdeploy_ecodetails_mr_delorp_sched | SCHEDULED |
| 468 | ECO MR Bulk Process | customdeploy_eco_mr_bulk_process_sched | SCHEDULED |
Four additional deployments owned by departed staff are deployed but not currently scheduled (customdeploy_snav_copysublogo, customdeploy_de_dept_hotfix_ss, and script ids 457, 460, 700, 701).
| Owner | Count | Character |
|---|---|---|
| Ryan Rote (1252) | 121 | SCM / Atlas / Merch Hierarchy bundle searches; two CUSTOMSEARCH_SDF_* artifacts (ids 1400–1401) |
| Marcy Meinert (1358) | 84 | Atlas / SuiteSuccess starter-edition searches |
| Ephraim Goyena (1221) | 5 | Hand-built: "***Set Preferred Form" pair (794, 795 — feed scripts 330/331), "B2B Customers" (800), "B2C Customers East/West" (801, 803) |
| Eric Nelson03 (10) | 2 | Hand-built: ".External ID List" (92), ".DE – Cash Sale SO Payment Mismatch" (96) — an operational reconciliation check |
| Ron Villanueva (1225) | 1 | "IF Check" (808) |
Every role held by a departed employee was tested for surviving active holders. One role is orphaned.
| ID | Role | Active Holders | Departed Holders | Verdict |
|---|---|---|---|---|
| 3 | Administrator | 7 | 14 | Shared |
| 15 | Employee Center | 1 | 1 | Shared |
| 1659 | SS RT PRM – A/P Analyst | 0 | 1 | Orphaned |
| 1660 | SS RT PRM – A/R Analyst | 1 | 1 | Shared |
| 1662 | SS RT PRM – Chief Executive Officer | 1 | 1 | Shared |
| 1663 | SS RT PRM – Chief Financial Officer | 1 | 1 | Shared |
| 1664 | SS RT PRM – Controller | 1 | 1 | Shared |
All twenty departed records carry giveaccess = 'F': no departed employee can log in. Fourteen of the twenty formerly held the Administrator role — an observation about historical provisioning breadth that management may wish to note for its joiner-mover-leaver policy, though it presents no current exposure.
Three tests were applied; all returned zero exceptions.
| Domain | Test | Hits | Verdict |
|---|---|---|---|
| Customers | customer.salesrep ∈ departed ids (273 customers in account) | 0 | Clean |
| Sales teams | customersalesteam.employee ∈ departed ids | 0 | Clean |
| Support cases | supportcase.assigned ∈ departed ids | 0 | Clean |
| Transactions | transaction.employee ∈ departed ids | 0 | Clean |
| Tasks | task.assigned or task.owner ∈ departed ids | 0 | Clean |
| Calendar events | calendarevent.owner/organizer ∈ departed ids | 0 | Clean |
| Phone calls | phonecall.owner/assigned ∈ departed ids | 48 | Finding F-05 |
The 48 phone-call records (internal ids 14–61) are all owned by Jenny Lunsford03 (id 6) and all remain in SCHEDULED status. They are demonstration-era CRM artifacts; the recommended disposition is bulk reassignment or completion/cancellation.
For completeness and auditability, the following were affirmatively verified as carrying zero departed-employee dependencies, each by direct query (Appendix A):
| # | Action | Addresses | Effort | Suggested Priority |
|---|---|---|---|---|
| 1 | Reassign the four SCHEDULED deployments (script ids 458, 459, 467, 468) to an active administrator; confirm error-notification recipients on each script record. | F-01 | < 1 hour | Immediate |
| 2 | Bulk-transfer script ownership (81 records) to a designated service account or active administrator. NetSuite permits owner reassignment by mass update or record edit; a service-account owner prevents recurrence at the next departure. | F-02 | Half day | Near term |
| 3 | Transfer the seven hand-built saved searches (92, 96, 794, 795, 800, 801, 803, 808) individually with review of what consumes them; bulk-transfer the 206 bundle-generated searches without review. | F-03 | Half day | Near term |
| 4 | Decide the disposition of role 1659 (A/P Analyst): assign to the incoming A/P owner or inactivate the role. Its A/R counterpart (1660) is actively held by Conner Avery, suggesting a successor assignment is the consistent choice. | F-04 | Minutes | Near term |
| 5 | Bulk-reassign or cancel the 48 scheduled phone calls (ids 14–61) owned by employee 6. | F-05 | Minutes | Discretionary |
| 6 | Preventive: add an ownership-transfer step to the employee-offboarding checklist (searches, scripts, roles, approval seats), and consider a quarterly re-run of this survey — the queries in Appendix A are re-executable as-is. | All | Policy | Ongoing |
All queries are SuiteQL, executed read-only under the reporting user's Administrator role. Ellipsized id lists denote the full set of twenty departed employee ids: 5, 6, 10, 1220, 1221, 1223, 1224, 1225, 1248, 1249, 1251, 1252, 1357, 1358, 1359, 2086, 2107, 3870, 3872, 3873.
SELECT id, entityid, firstname, lastname, title, email, isinactive, releasedate,
hiredate, issalesrep, issupportrep, giveaccess, rolesforsearch, supervisor,
approver, purchaseorderapprover, timeapprover, subsidiary, department, location
FROM employee
WHERE isinactive = 'T' OR releasedate IS NOT NULL
ORDER BY lastname
SELECT s.id, s.scriptid, s.name, s.scripttype, s.owner, s.isinactive FROM script s WHERE s.owner IN (5, 6, 10, ..., 3873)
SELECT ss.id, ss.scriptid, ss.name, ss.searchtype, ss.owner,
ss.isinactive, ss.ispublic, ss.isshared
FROM savedsearch ss
WHERE ss.owner IN (5, 6, 10, ..., 3873)
ORDER BY ss.owner, ss.id
SELECT s.owner, s.id AS script_id, s.name AS script_name, s.scripttype,
d.id AS deploy_id, d.scriptid AS deploy_scriptid, d.status, d.isdeployed
FROM scriptdeployment d
JOIN script s ON d.script = s.id
WHERE s.owner IN (5, 6, 10, ..., 3873)
AND d.isdeployed = 'T'
AND s.scripttype IN ('SCHEDULED', 'MAPREDUCE')
ORDER BY s.owner, s.id
SELECT s.owner, s.scripttype, COUNT(*) AS deployed_cnt FROM scriptdeployment d JOIN script s ON d.script = s.id WHERE s.owner IN (5, 6, 10, ..., 3873) AND d.isdeployed = 'T' GROUP BY s.owner, s.scripttype ORDER BY s.owner
SELECT w.internalid, w.scriptid, w.name, w.owner, w.isinactive, w.releasestatus FROM workflow w WHERE w.owner IN (5, 6, 10, ..., 3873)
SELECT id, name, scriptid, isinactive, centertype FROM role WHERE id IN (3, 15, 1659, 1660, 1662, 1663, 1664)
SELECT id, entityid, isinactive, rolesforsearch, giveaccess FROM employee WHERE isinactive = 'F' AND rolesforsearch IS NOT NULL
SELECT id, entityid, isinactive, supervisor, approver,
purchaseorderapprover, timeapprover
FROM employee
WHERE supervisor IN (5, 6, 10, ..., 3873)
OR approver IN (5, 6, 10, ..., 3873)
OR purchaseorderapprover IN (5, 6, 10, ..., 3873)
OR timeapprover IN (5, 6, 10, ..., 3873)
SELECT type, COUNT(*) AS cnt FROM transaction WHERE nextapprover IN (5, 6, 10, ..., 3873) GROUP BY type
SELECT id, entityid, companyname, salesrep FROM customer WHERE salesrep IN (5, 6, 10, ..., 3873)
SELECT cst.customer, c.entityid, c.companyname, cst.employee,
cst.salesrole, cst.isprimary, cst.contribution
FROM customersalesteam cst
JOIN customer c ON cst.customer = c.id
WHERE cst.employee IN (5, 6, 10, ..., 3873)
SELECT id, casenumber, title, assigned, status, BUILTIN.DF(status) AS status_name FROM supportcase WHERE assigned IN (5, 6, 10, ..., 3873)
SELECT type, COUNT(*) AS cnt FROM transaction WHERE employee IN (5, 6, 10, ..., 3873) GROUP BY type
SELECT id, title, assigned, status FROM task WHERE assigned IN (5, 6, 10, ..., 3873); SELECT id, title, owner, status FROM task WHERE owner IN (5, 6, 10, ..., 3873); SELECT id, title, status, owner, organizer, startdate FROM calendarevent WHERE owner IN (5, 6, 10, ..., 3873) OR organizer IN (5, 6, 10, ..., 3873); SELECT id, title, status, owner, assigned, startdate FROM phonecall WHERE owner IN (5, 6, 10, ..., 3873) OR assigned IN (5, 6, 10, ..., 3873)
Recorded so that future re-runs of this survey do not repeat the same discovery cost.