Sample output from the NetSuite Security & Access Review with Vulnerability Report prompt in the Sonar AI Prompt Library, run against a NetSuite test account. Every name and number here is test data. Back to the post · The library

🛡️ NetSuite Security Review

Comprehensive risk assessment & vulnerability analysis
Account TD3092577 Environment PRODUCTION Platform OneWorld Reviewer Sonar AI Run by Burt Brocus (id 120) Date 2026-07-28 Method Read-only

Executive Summary

This assessment reviewed identity & access, roles & permissions, authentication posture, sensitive-data exposure, custom code & integrations, and audit signals across the production OneWorld account TD3092577. The account is a heavily-customized SuiteSuccess Manufacturing instance (229 roles, ~100+ scripts from installed bundles). Overall posture is ELEVATED RISK, driven chiefly by identity-management weaknesses rather than platform mis-configuration.

2
Critical findings
5
High findings
5
Medium findings
3
Low / informational

The three things to fix this week

  1. Personal-email Administrator with anomalous logins. User Zees Zeeshan holds the Administrator role on a personal @hotmail.com address, with 37 successful logins from 21 distinct IPs (predominantly Sialkot, Pakistan / Mobilink GSM) plus a lockout and repeated wrong-password failures. Verify ownership, enforce 2FA, and downgrade or remove.
  2. Shared login identity. 25 active users authenticate under the same email partner-admin@example.com. NetSuite keys login by email, so per-user accountability is effectively lost across roles up to MFG CFO / Controller.
  3. Administrator sprawl. 11 distinct users hold the Administrator role (recommended: 2–3 named, 2FA-enforced). Several are NetSuite/Oracle provisioning accounts that should be removed now that the account is live.
This is a point-in-time, read-only review. No settings were changed. Evidence was collected via SuiteQL, SuiteScript N/query/N/search, the login-audit trail, and file-cabinet metadata. See Methodology and Limitations.

Contents

Consolidated Risk Register

IDFindingAreaSeverity
F-01Personal-email Administrator w/ anomalous multi-IP logins & lockoutIdentityCritical
F-02Shared login email across 25 active usersIdentityCritical
F-03Administrator sprawl — 11 admin usersRolesHigh
F-04Provisioning / vendor admin accounts still active post-go-liveIdentityHigh
F-05No accounting periods locked for 11 of last 12 monthsIntegrityHigh
F-06Login-capable account on system id −5 (Kathryn Glass) with AdministratorIdentityHigh
F-07Core Administration Permission on 4 operational MFG rolesRolesHigh
F-08File Cabinet Full (delete) granted to 130 roles, incl. Employee CenterDataMedium
F-09Employee SSN Full access on 6 rolesDataMedium
F-102,364 files marked “Available Without Login”DataMedium
F-11Role bloat — 229 roles, many demo/DNU duplicatesRolesMedium
F-128 web-service-only roles — review integration attack surfaceCodeMedium
F-13Integration app “Claude AI” & “SDF Account Warmer” enabledCodeLow
F-14Future-dated record: “Default Web Services Integrations” created 2027-08-22AuditLow
F-15No token-based-auth (TBA) tokens present — positive controlCodeInfo

1 Identity & Access

The account has 205 employee records (204 active); 27 carry the login-access flag on the employee record, while a role-assignment enumeration surfaced 35 distinct login-capable identities (the delta is largely internal NetSuite/Oracle provisioning accounts and multi-role users). Of these, 11 hold Administrator.

35
Login-capable identities
11
Administrator users
25
Users on one shared email
204
Active employees

F-01 · Personal-email Administrator with anomalous login patternCritical · Identity

Employee Zees Zeeshan (id 8) authenticates with the personal address user1@example.com and is assigned the Administrator role (alongside two shop-floor roles). The login-audit trail shows a highly unusual pattern for a privileged account:

37 successful logins from 21 DISTINCT IP addresses (last: 2026-07-11) 8 failed logins incl. 2× "LockedOut" and 6× "WrongPassword" Source IP 154.80.37.140 → Sialkot, Punjab, PK (AS45669 Mobilink GSM, mobile) Additional ranges: 154.80.x / 154.81.x (PK mobile), 110.38.183.x (PK)

A personal free-mail address, holding full administrative control of a production ERP, logging in from many rotating mobile IPs in a single foreign region, with a recent account-lockout, is the highest-risk configuration in this account. The pattern is consistent with a single legitimate user on a mobile connection abroad — but is indistinguishable from credential compromise without owner confirmation.

Recommendation: Confirm account ownership out-of-band immediately. Enforce mandatory 2FA on this login. Remove the Administrator role (grant only the operational role actually needed). Replace the personal email with a corporate, provisioned address. Consider an IP-range restriction on any retained privileged access.

F-02 · Shared login identity across 25 usersCritical · Identity

Twenty-five active, login-capable employee records share the identical email partner-admin@example.com. Because NetSuite authenticates by email address, these records collapse into a small number of shared credentials spanning sensitive roles including MFG CFO, MFG Controller, MFG AP Analyst, MFG AR Analyst, and MFG Cost Accountant.

Distinct users on partner-admin@example.com ....... 25 Roles reached via this email include: MFG CFO, MFG Controller, MFG AP Analyst, MFG AR Analyst, MFG Cost Accountant, MFG Purchasing Manager, MFG Senior Executive, Employee Center - Manager, ...

Impact: no per-user accountability. Audit trails, approvals, and Segregation-of-Duties controls cannot attribute an action to an individual. This is a control failure in its own right and undermines every other detective control in the account.

Recommendation: Assign each human a unique corporate email. If these are demo/training personas from the SuiteSuccess build, inactivate the ones not in real use and re-home the rest. Treat this as a prerequisite for any meaningful SoD program.

F-04 · Vendor / provisioning admin accounts still activeHigh · Identity

Several Administrator accounts belong to NetSuite/Oracle/partner provisioning identities that are typically created during a SuiteSuccess implementation and should be removed at go-live:

Administrator holders by domain: @netsuite.com 5 (Lokesh Koralla, P Teku, R Chigullapally, SDG Dev, Todd Henry) @oracle.com 2 (Matt Gutierrez, Peter Ries) @nexttechnik.com 1 (Aidan Jessen) @hotmail.com 1 (Zees Zeeshan) ← see F-01 @me.com 1 (Burt Brocus) ← report runner anchorgroup.tech 1 (Kathryn Glass, sys id -5) ← see F-06

Recommendation: Confirm which vendor accounts are still required for support. Inactivate the rest. For any retained partner access, prefer time-boxed, 2FA-enforced logins and review quarterly.

F-06 · Login-capable Administrator on system id −5High · Identity

The entity Kathryn Glass resolves to internal id -5 — a reserved/system identifier that also owns the majority of installed bundle scripts — yet appears as a login-capable Administrator on the shared anchorgroup.tech email. A system/bundle-owner identity doubling as an interactive admin login blurs the line between automation and human access.

Recommendation: Verify whether interactive login is intended for this identity. If it is a bundle/service owner, it should not be login-capable; if a human uses it, migrate them to a normal named user.

2 Roles & Permissions

The account defines 229 roles — an order of magnitude above a typical mid-market deployment — reflecting stacked SuiteSuccess Manufacturing, WMS, Ship Central, Quality, and Dunning bundles, plus numerous (Demo) and (DNU / "Do Not Use") duplicates. High role counts are not inherently insecure but sharply increase the surface area for privilege mistakes and make review expensive.

F-03 · Administrator sprawlHigh · Roles

11 distinct users hold the built-in Administrator role (internal id 3), which bypasses subsidiary restrictions and grants every permission implicitly (note: ADMI_* setup permissions return no explicit rolepermissions rows precisely because Administrator grants them implicitly). Leading practice is 2–3 named, individually-owned, 2FA-enforced administrators.

Recommendation: Reduce to a minimal named set. Move day-to-day work onto least-privilege functional roles. Enforce 2FA on every retained admin and review the list monthly.

F-07 · Core Administration Permission on operational rolesHigh · Roles

Four active custom roles carry coreadminpermission = T, which layers elevated core-administration setup access on top of the role's normal permissions:

id 1217 MFG Project Manager 1 id 1125 MFG Purchasing Manager id 1129 MFG Supply Chain Manager id 1329 IPT Internal

Operational manager roles generally should not carry core-admin rights; this is a lateral path toward administrative capability.

Recommendation: Review each. Remove Core Administration Permission unless there is a documented, specific need; if needed, split the admin duties into a dedicated role held by fewer people.

F-11 · Role bloat & demo/DNU duplicatesMedium · Roles

Many roles are clearly non-production artifacts — e.g. AM Production Control (DNU), several (Demo) WMS/AM roles, and DNU_MFG … entries. Some are already inactive; others are still active and assigned (e.g. shop-floor users on (Demo) roles). Clutter obscures real privilege and slows every future access review.

Recommendation: Inventory and inactivate demo/DNU roles not in genuine use. Establish a naming/lifecycle convention so bundle-provided demo roles never reach production users.

Positive signal: 0 roles are configured as SSO-only and no roles carry device restrictions — meaning access control today rests almost entirely on password + (where enabled) 2FA. That elevates the importance of the authentication findings in §3.

3 Authentication & Sessions

Authentication posture was assessed from role security flags and the login-audit trail. Some controls (the global 2FA-required policy, password-policy strength, and enforced-2FA-by-role configuration) live on UI-only setup pages that are not exposed to SuiteQL — see Limitations.

Web-service-only roles8
Core-admin roles4
SSO-only roles0
Device-restricted roles0
Active OAuth/TBA tokens0

Bar length is scaled for readability; the count is shown at right. Zero values render as a hairline.

Auth exposure — privileged accounts without confirmed 2FAHigh · Auth

The account relies on password (plus 2FA where configured) as the primary gate — there is no SSO-only enforcement and no device binding. Given F-01 (a privileged personal-email account logging in from many foreign mobile IPs with a lockout event), the absence of confirmed, enforced 2FA on all Administrator and financial roles is a material exposure.

Recommendation: In Setup › Company › Enable Features › SuiteCloud / Setup › Users/Roles › Two-Factor Authentication Roles, require 2FA for Administrator, all MFG CFO/Controller/Analyst roles, and any web-service-capable role. Verify the password policy (length/complexity/expiry) on the same screens.

Login activity (2026-05-12 → 2026-07-28)

EmailSuccessful loginsDistinct IPsLast loginNote
user1@example.com37212026-07-11Personal email + Admin; PK mobile IPs; lockout
partner-admin@example.com1312026-07-21Shared by 25 users
timdietrich@me.com812026-07-28Report runner (Burt Brocus)

4 Sensitive-Data Exposure

F-08 · File Cabinet Full/delete over-grantedMedium · Data

The LIST_FILECABINET ("Documents and Files") permission is granted very widely across active roles:

Full (delete) — lvl 4130
Edit — lvl 319
Create — lvl 25
View — lvl 132

Most striking: portal-style Employee Center roles (ids 15, 1132, 1205, 1210) and MFG Employee Center (3560) carry Full file-cabinet access. Employee Center users are typically low-trust self-service accounts; Full (including delete) access to shared documents is disproportionate and creates both a data-leak and a data-destruction path.

Recommendation: Reduce Employee/portal roles to View (or none). Apply least-privilege on file-cabinet access broadly; reserve Full for content administrators. Consider folder-level restrictions for HR/finance document folders.

F-09 · Employee SSN accessMedium · Data

LIST_EMPLOYEESSN (Employee Social Security Numbers) is held at Full by 6 roles and View by 5. Full holders include Administrator, System Administrator, Chief People Officer, HR Generalist, MFG IT Manager, and NOAM MFG PRM - IT Manager.

Full (4): Administrator, System Administrator, Chief People Officer (CPO), Human Resources Generalist, MFG IT Manager, NOAM MFG PRM - IT Manager View (1): Employee Center + variants, MFG Employee Center

HR/CPO access is expected; the two IT-Manager roles with Full SSN access are the ones to challenge — IT administration rarely requires plaintext SSN visibility.

Recommendation: Remove SSN access from IT-manager roles unless justified. Confirm the Employee Center "View" is limited to a user's own record only.

F-10 · 2,364 files “Available Without Login”Medium · Data

2,364 file-cabinet files are flagged isonline = T (publicly retrievable by URL without authentication). A content sample shows the population is overwhelmingly web/template assets — 1,042 GIF + 755 PNG + 308 JPG images, 98 JS, 37 CSS, fonts — i.e. rendering assets for email/PDF templates, which is normal. However the tail includes 24 PDFs (≈53 MB), 39 CSVs and 2 Word docs.

Public files by type (top): GIF 1042 · PNG 755 · JPG 308 · JS 98 · CSV 39 · CSS 37 · PDF 24 · XML 18 · SVG 10 · fonts 9 · Word 2 Sampled PDFs = SuiteSuccess help docs + tiny COA-LOT certificates (low sensitivity)

Recommendation: No mass PII leak was observed, but review the non-asset tail (CSVs, Word docs, any invoice/COA PDFs) to confirm none contain customer or financial data. Establish a policy that new uploads default to not public.

5 Custom Code & Integrations

The account carries a large, bundle-heavy customization footprint. A script inventory returned 100+ script records dominated by SuiteSuccess Manufacturing, Quality (QM), Ship Central, Dunning (3805), WMS, and Anchor Group / WebDocs (NAW/SAS) bundles. The bulk are owned by the bundle/system identity (id −5) with a few named developers (Thomas Henderson, Christopher Bermundo, Mark De Asis, Francis Teves).

F-12 · Web-service-only rolesMedium · Code

8 active roles are flagged iswebserviceonlyrole = T (e.g. WMS Web Services Admin). These are integration identities; each is an API attack surface. With 0 active TBA tokens today, current exposure is limited, but any future token issued against these roles inherits their permissions.

Recommendation: Confirm each WS-only role is still needed and least-privileged. When tokens are issued, scope them to a dedicated minimal role and monitor oauthtoken / login-audit for their use.

F-13 · Integration apps enabledLow · Code

Five integration application records exist, all enabled (state 2):

id 2 IQity Advanced Manufacturing (2026-03-23) id 3 SuiteCloud Development Integration (2026-06-09) id 103 SDF Account Warmer (2026-06-13) id 104 Claude AI (2026-06-30) id -2 Default Web Services Integrations (created 2027-08-22 ← future date, see F-14)

None currently back an active OAuth token. Claude AI and SDF Account Warmer are developer/AI-tooling integrations — appropriate in a dev/demo context but worth confirming for a production account.

Recommendation: Confirm each integration app is expected and owned. Disable any not in active use; when re-enabled, pair with a least-privilege WS role and monitored tokens.

F-15 · No TBA tokens present (positive control)Info · Code

The oauthtoken table returned 0 rows — there are no standing token-based-auth credentials to steal or rotate today. This is a genuinely good posture; maintain it by issuing tokens only when required and expiring them promptly.

6 Audit, Logins & Data Integrity

F-05 · Accounting periods left open & unlockedHigh · Integrity

Of the last 12 monthly accounting periods, only one (2025-08) is closed and locked. Every period from 2025-09 through 2026-07 is open and unlocked:

Open, unlocked prior periods let any user with transaction edit rights post or alter entries into closed months — a core internal-control and financial-integrity weakness (and an audit finding in its own right). It also amplifies the impact of the identity findings above: a shared or compromised financial login could backdate or alter historical entries undetected.

Recommendation: Implement a monthly close discipline — lock A/P, A/R, and G/L sub-periods promptly after each month and set period-close checklists. Restrict "Override Period Restrictions" to a minimal set of finance roles.

F-14 · Future-dated system recordLow · Audit

The Default Web Services Integrations record reports a creation date of 2027-08-22 — over a year in the future relative to the review date (2026-07-28). This is almost certainly a demo/seed-data artifact but is a data-quality anomaly worth noting; future-dated system records can distort audit timelines and date-based reporting.

Recommendation: No action required for security; flag to whoever manages the demo/seed data.

Login-audit availability: 66 events spanning 2026-05-12 → 2026-07-28 (58 success / 8 failure). NetSuite retains this trail for a limited window; for continuous monitoring, export it periodically or feed it to a SIEM.

7 Oddities & Anomalies

ObservationWhy it stands outRef
Admin logins from 21 IPs in Pakistan mobile ranges on a Hotmail accountClassic compromise-shaped pattern; needs owner verificationF-01
25 users → 1 emailDestroys per-user accountabilityF-02
Entity id −5 is login-capable AdministratorSystem/bundle owner id acting as a human loginF-06
Record created 2027-08-22 (future)Impossible creation date; seed-data artifactF-14
Scripts named “Record Eradicator”, “Prevent Removal of Admin Access”Powerful/oddly-named bundle scripts — confirm provenance§5
Many “(Demo)” / “(DNU)” roles assigned to real usersDemo constructs reaching production accessF-11
“Claude AI” integration app on a production accountAI/dev tooling in prod — confirm intentF-13

8 Recommended Actions

Immediate (this week)

#ActionAddresses
1Verify ownership of user1@example.com out-of-band; if unconfirmed, disable immediately. Remove its Administrator role regardless.F-01
2Enforce mandatory 2FA on Administrator + all financial (CFO/Controller/AP/AR) roles.F-01,F-03,Auth
3Give each human a unique corporate email; retire the shared partner-admin@example.com identity.F-02
4Inactivate NetSuite/Oracle/partner provisioning admin accounts no longer needed.F-04

Short-term (this month)

#ActionAddresses
5Reduce Administrator holders to 2–3 named users; move daily work to least-privilege roles.F-03
6Remove Core Administration Permission from the 4 operational MFG roles unless justified.F-07
7Lock closed accounting periods; establish monthly close & lock discipline.F-05
8Downgrade File Cabinet access on Employee-Center/portal roles to View or None.F-08
9Remove Employee-SSN Full access from IT-manager roles.F-09

Ongoing / hygiene

#ActionAddresses
10Inventory & inactivate demo/DNU roles; enforce a role-lifecycle naming convention.F-11
11Review WS-only roles & integration apps; least-privilege & monitor tokens.F-12,F-13
12Audit the non-asset public files (CSV/Word/PDF); default new uploads to private.F-10
13Export login-audit periodically (or to a SIEM) for retention beyond NetSuite's window.F-01,§6
14Run a formal Segregation-of-Duties review once per-user identities are restored.F-02

9 Methodology

All evidence was gathered read-only; no records, roles, scripts, or settings were modified. Data sources and techniques:

Severity model: Critical = active, exploitable identity/access risk; High = strong control weakness or excessive privilege; Medium = least-privilege / data-exposure gap; Low/Info = hygiene or positive control.

10 Limitations