customscript_print_list_sync_sheduler (id 1620) throws AUTH_ERROR β "The configured password API key is invalid." Biggest quick win: fix the key or disable it. ~15 minutes.
Role 3 includes accounts on anchorgroup.tech, netsuite.com and oracle.com. If those engagements ended, this is the account's top security exposure.
Every monthly period from Sep 2025 through Aug 2026 is open and unlocked β prior-period numbers can silently change at any time.
TESTING workflows execute only for their owner β for everyone else the process (incl. NCR β Create Rework WO) silently does nothing.
Plus 91 scripts with zero deployments and 326 with only disabled deployments β a large dead-code surface that slows every audit and upgrade.
Script 1620 alone is ~83% of all error log volume β roughly 40 failures per day, every day.
SS1.0 concentration: 308 Suitelets, 99 client scripts, 89 user events, 62 scheduled, 37 RESTlets.
| Severity | Finding | Evidence | Recommended action | Effort |
|---|---|---|---|---|
| Critical | Print List Sync Scheduler failing continuously with AUTH_ERROR | customscript_print_list_sync_sheduler id 1620 Β· 1,254 errors/30d Β· "configured password API key is invalid" | Rotate/fix the print-service API key, or disable the deployment if retired | S |
| High | WMS bin-lock delete scheduler erroring repeatedly | customscript_wmsse_binlocks_del_sch id 1109 Β· 157 errors/30d | Review bin-lock cleanup config; escalate to SuiteApp vendor if bundle-owned | M |
| High | 638 active SuiteScript 1.0 scripts (28%) | API-version rollup from script table | Inventory custom (non-bundle) SS1.0 scripts; plan 2.1 migration | L |
| Medium | Dead code: 91 scripts with zero deployments; 326 with only disabled deployments | script β scriptdeployment, isinactive=F | Mark inactive / archive to shrink audit surface | M |
| Medium | 6 additional recurring error sources (9β23 errors each) | ids 7364, 6865, 6864, 1340, 5784, 5524 | Triage each via execution-log detail; fix or silence expected errors | M |
655 custom record types exist; only 5 are inactive. The vast majority are bundle-installed (Quality Management, Advanced Manufacturing/iQity, Fixed Assets, Electronic Payments, WMS). Visible generational duplication: legacy "QMS" workflows/records coexist with the "QM" Enhanced SuiteApp β one generation is probably retired but still installed and executing.
| Severity | Finding | Workflows | Action |
|---|---|---|---|
| High | Stuck in TESTING β executes only for the owner; a silent no-op for all other users | id 32 NCR β Create Rework WO Β· id 38 PO Form Default for Outsourced Mfg Β· ids 52, 152 SuiteSuccess translations | Release to production if the business depends on them; delete if abandoned |
| Medium | Not Initiating (dormant approval routing) | id 4 Vendor Bill Approval Routing Β· id 5 Invoice Approval Workflow (12) | Confirm intentional; delete if the approval process moved elsewhere |
| Medium | 14 of 29 active workflows run as Admin | Custom (non-bundle): ids 20, 32, 37, 38 | Review custom workflows for least-privilege execution |
Oldest open sales order dates to 2025-12-01. Review pending-fulfillment backlog; close or cancel dead orders.
53 customers missing payment terms (billing risk), 74 missing email (blocks dunning & comms). Backfill via CSV import.
No duplicate customers (by email or normalized name), no inactive items on open SOs, only 1 vendor bill pending approval, no stale estimates > 90 days.
All 12 periods: closed = F, aplocked = F, arlocked = F. Prior-year financials can be altered at any time by any user with posting rights.
Recommendation: establish a month-end close cadence β lock AP/AR first, then close periods through at least Q1 2026.
| User | Email domain | Flag |
|---|---|---|
| Burt Brocus (120) | me.com | Internal |
| Kathryn Glass (β5) | anchorgroup.tech | External |
| SDG Manila (1392) | netsuite.com | External |
| Alan Jenkins (1609) | oracle.com | External |
| Eduardo Soto (1671) | netsuite.com | External |
| Michael Farina (1697) | netsuite.com | External |
Long tail of single-user specialized roles is a healthy least-privilege pattern.
giveaccess='T' AND isinactive='T' β 0 rows).Recommendation: confirm each external-domain admin engagement is still active; remove or downgrade departed consultants. Target β€ 2β3 Administrators.
Dominated by bundle-installed script files. No urgent action; revisit if storage limits approach.
The saved-search list page returned zero rows to this session (a "Notice" page β likely a page-access restriction on this role/session). This is flagged honestly rather than guessed.
Action: re-run from an Administrator UI session, or grant search-list page access, then fold results into the next review.
script, scriptdeployment, scriptnote, customfield, customrecordtype, workflow, transaction, customer, accountingperiod, employeerolesforsearch, employee, and file. Every finding cites real internal ids and scriptids. No records were modified. Keep the companion CSV (ns-proactive-review-2026-08-08.csv) as the baseline for delta tracking on the next run.