This assessment reviewed identity & access, roles & permissions, authentication posture, sensitive-data exposure, custom code & integrations, and audit signals across the production OneWorld account TD3092577. The account is a heavily-customized SuiteSuccess Manufacturing instance (229 roles, ~100+ scripts from installed bundles). Overall posture is ELEVATED RISK, driven chiefly by identity-management weaknesses rather than platform mis-configuration.
| ID | Finding | Area | Severity |
|---|---|---|---|
| F-01 | Personal-email Administrator w/ anomalous multi-IP logins & lockout | Identity | Critical |
| F-02 | Shared login email across 25 active users | Identity | Critical |
| F-03 | Administrator sprawl — 11 admin users | Roles | High |
| F-04 | Provisioning / vendor admin accounts still active post-go-live | Identity | High |
| F-05 | No accounting periods locked for 11 of last 12 months | Integrity | High |
| F-06 | Login-capable account on system id −5 (Kathryn Glass) with Administrator | Identity | High |
| F-07 | Core Administration Permission on 4 operational MFG roles | Roles | High |
| F-08 | File Cabinet Full (delete) granted to 130 roles, incl. Employee Center | Data | Medium |
| F-09 | Employee SSN Full access on 6 roles | Data | Medium |
| F-10 | 2,364 files marked “Available Without Login” | Data | Medium |
| F-11 | Role bloat — 229 roles, many demo/DNU duplicates | Roles | Medium |
| F-12 | 8 web-service-only roles — review integration attack surface | Code | Medium |
| F-13 | Integration app “Claude AI” & “SDF Account Warmer” enabled | Code | Low |
| F-14 | Future-dated record: “Default Web Services Integrations” created 2027-08-22 | Audit | Low |
| F-15 | No token-based-auth (TBA) tokens present — positive control | Code | Info |
The account has 205 employee records (204 active); 27 carry the login-access flag on the employee record, while a role-assignment enumeration surfaced 35 distinct login-capable identities (the delta is largely internal NetSuite/Oracle provisioning accounts and multi-role users). Of these, 11 hold Administrator.
Employee Zees Zeeshan (id 8) authenticates with the personal address user1@example.com and is assigned the Administrator role (alongside two shop-floor roles). The login-audit trail shows a highly unusual pattern for a privileged account:
A personal free-mail address, holding full administrative control of a production ERP, logging in from many rotating mobile IPs in a single foreign region, with a recent account-lockout, is the highest-risk configuration in this account. The pattern is consistent with a single legitimate user on a mobile connection abroad — but is indistinguishable from credential compromise without owner confirmation.
Recommendation: Confirm account ownership out-of-band immediately. Enforce mandatory 2FA on this login. Remove the Administrator role (grant only the operational role actually needed). Replace the personal email with a corporate, provisioned address. Consider an IP-range restriction on any retained privileged access.
Twenty-five active, login-capable employee records share the identical email partner-admin@example.com. Because NetSuite authenticates by email address, these records collapse into a small number of shared credentials spanning sensitive roles including MFG CFO, MFG Controller, MFG AP Analyst, MFG AR Analyst, and MFG Cost Accountant.
Impact: no per-user accountability. Audit trails, approvals, and Segregation-of-Duties controls cannot attribute an action to an individual. This is a control failure in its own right and undermines every other detective control in the account.
Recommendation: Assign each human a unique corporate email. If these are demo/training personas from the SuiteSuccess build, inactivate the ones not in real use and re-home the rest. Treat this as a prerequisite for any meaningful SoD program.
Several Administrator accounts belong to NetSuite/Oracle/partner provisioning identities that are typically created during a SuiteSuccess implementation and should be removed at go-live:
Recommendation: Confirm which vendor accounts are still required for support. Inactivate the rest. For any retained partner access, prefer time-boxed, 2FA-enforced logins and review quarterly.
The entity Kathryn Glass resolves to internal id -5 — a reserved/system identifier that also owns the majority of installed bundle scripts — yet appears as a login-capable Administrator on the shared anchorgroup.tech email. A system/bundle-owner identity doubling as an interactive admin login blurs the line between automation and human access.
Recommendation: Verify whether interactive login is intended for this identity. If it is a bundle/service owner, it should not be login-capable; if a human uses it, migrate them to a normal named user.
The account defines 229 roles — an order of magnitude above a typical mid-market deployment — reflecting stacked SuiteSuccess Manufacturing, WMS, Ship Central, Quality, and Dunning bundles, plus numerous (Demo) and (DNU / "Do Not Use") duplicates. High role counts are not inherently insecure but sharply increase the surface area for privilege mistakes and make review expensive.
11 distinct users hold the built-in Administrator role (internal id 3), which bypasses subsidiary restrictions and grants every permission implicitly (note: ADMI_* setup permissions return no explicit rolepermissions rows precisely because Administrator grants them implicitly). Leading practice is 2–3 named, individually-owned, 2FA-enforced administrators.
Recommendation: Reduce to a minimal named set. Move day-to-day work onto least-privilege functional roles. Enforce 2FA on every retained admin and review the list monthly.
Four active custom roles carry coreadminpermission = T, which layers elevated core-administration setup access on top of the role's normal permissions:
Operational manager roles generally should not carry core-admin rights; this is a lateral path toward administrative capability.
Recommendation: Review each. Remove Core Administration Permission unless there is a documented, specific need; if needed, split the admin duties into a dedicated role held by fewer people.
Many roles are clearly non-production artifacts — e.g. AM Production Control (DNU), several (Demo) WMS/AM roles, and DNU_MFG … entries. Some are already inactive; others are still active and assigned (e.g. shop-floor users on (Demo) roles). Clutter obscures real privilege and slows every future access review.
Recommendation: Inventory and inactivate demo/DNU roles not in genuine use. Establish a naming/lifecycle convention so bundle-provided demo roles never reach production users.
Authentication posture was assessed from role security flags and the login-audit trail. Some controls (the global 2FA-required policy, password-policy strength, and enforced-2FA-by-role configuration) live on UI-only setup pages that are not exposed to SuiteQL — see Limitations.
Bar length is scaled for readability; the count is shown at right. Zero values render as a hairline.
The account relies on password (plus 2FA where configured) as the primary gate — there is no SSO-only enforcement and no device binding. Given F-01 (a privileged personal-email account logging in from many foreign mobile IPs with a lockout event), the absence of confirmed, enforced 2FA on all Administrator and financial roles is a material exposure.
Recommendation: In Setup › Company › Enable Features › SuiteCloud / Setup › Users/Roles › Two-Factor Authentication Roles, require 2FA for Administrator, all MFG CFO/Controller/Analyst roles, and any web-service-capable role. Verify the password policy (length/complexity/expiry) on the same screens.
| Successful logins | Distinct IPs | Last login | Note | |
|---|---|---|---|---|
| user1@example.com | 37 | 21 | 2026-07-11 | Personal email + Admin; PK mobile IPs; lockout |
| partner-admin@example.com | 13 | 1 | 2026-07-21 | Shared by 25 users |
| timdietrich@me.com | 8 | 1 | 2026-07-28 | Report runner (Burt Brocus) |
The LIST_FILECABINET ("Documents and Files") permission is granted very widely across active roles:
Most striking: portal-style Employee Center roles (ids 15, 1132, 1205, 1210) and MFG Employee Center (3560) carry Full file-cabinet access. Employee Center users are typically low-trust self-service accounts; Full (including delete) access to shared documents is disproportionate and creates both a data-leak and a data-destruction path.
Recommendation: Reduce Employee/portal roles to View (or none). Apply least-privilege on file-cabinet access broadly; reserve Full for content administrators. Consider folder-level restrictions for HR/finance document folders.
LIST_EMPLOYEESSN (Employee Social Security Numbers) is held at Full by 6 roles and View by 5. Full holders include Administrator, System Administrator, Chief People Officer, HR Generalist, MFG IT Manager, and NOAM MFG PRM - IT Manager.
HR/CPO access is expected; the two IT-Manager roles with Full SSN access are the ones to challenge — IT administration rarely requires plaintext SSN visibility.
Recommendation: Remove SSN access from IT-manager roles unless justified. Confirm the Employee Center "View" is limited to a user's own record only.
2,364 file-cabinet files are flagged isonline = T (publicly retrievable by URL without authentication). A content sample shows the population is overwhelmingly web/template assets — 1,042 GIF + 755 PNG + 308 JPG images, 98 JS, 37 CSS, fonts — i.e. rendering assets for email/PDF templates, which is normal. However the tail includes 24 PDFs (≈53 MB), 39 CSVs and 2 Word docs.
Recommendation: No mass PII leak was observed, but review the non-asset tail (CSVs, Word docs, any invoice/COA PDFs) to confirm none contain customer or financial data. Establish a policy that new uploads default to not public.
The account carries a large, bundle-heavy customization footprint. A script inventory returned 100+ script records dominated by SuiteSuccess Manufacturing, Quality (QM), Ship Central, Dunning (3805), WMS, and Anchor Group / WebDocs (NAW/SAS) bundles. The bulk are owned by the bundle/system identity (id −5) with a few named developers (Thomas Henderson, Christopher Bermundo, Mark De Asis, Francis Teves).
8 active roles are flagged iswebserviceonlyrole = T (e.g. WMS Web Services Admin). These are integration identities; each is an API attack surface. With 0 active TBA tokens today, current exposure is limited, but any future token issued against these roles inherits their permissions.
Recommendation: Confirm each WS-only role is still needed and least-privileged. When tokens are issued, scope them to a dedicated minimal role and monitor oauthtoken / login-audit for their use.
Five integration application records exist, all enabled (state 2):
None currently back an active OAuth token. Claude AI and SDF Account Warmer are developer/AI-tooling integrations — appropriate in a dev/demo context but worth confirming for a production account.
Recommendation: Confirm each integration app is expected and owned. Disable any not in active use; when re-enabled, pair with a least-privilege WS role and monitored tokens.
The oauthtoken table returned 0 rows — there are no standing token-based-auth credentials to steal or rotate today. This is a genuinely good posture; maintain it by issuing tokens only when required and expiring them promptly.
Of the last 12 monthly accounting periods, only one (2025-08) is closed and locked. Every period from 2025-09 through 2026-07 is open and unlocked:
Open, unlocked prior periods let any user with transaction edit rights post or alter entries into closed months — a core internal-control and financial-integrity weakness (and an audit finding in its own right). It also amplifies the impact of the identity findings above: a shared or compromised financial login could backdate or alter historical entries undetected.
Recommendation: Implement a monthly close discipline — lock A/P, A/R, and G/L sub-periods promptly after each month and set period-close checklists. Restrict "Override Period Restrictions" to a minimal set of finance roles.
The Default Web Services Integrations record reports a creation date of 2027-08-22 — over a year in the future relative to the review date (2026-07-28). This is almost certainly a demo/seed-data artifact but is a data-quality anomaly worth noting; future-dated system records can distort audit timelines and date-based reporting.
Recommendation: No action required for security; flag to whoever manages the demo/seed data.
Login-audit availability: 66 events spanning 2026-05-12 → 2026-07-28 (58 success / 8 failure). NetSuite retains this trail for a limited window; for continuous monitoring, export it periodically or feed it to a SIEM.
| Observation | Why it stands out | Ref |
|---|---|---|
| Admin logins from 21 IPs in Pakistan mobile ranges on a Hotmail account | Classic compromise-shaped pattern; needs owner verification | F-01 |
| 25 users → 1 email | Destroys per-user accountability | F-02 |
| Entity id −5 is login-capable Administrator | System/bundle owner id acting as a human login | F-06 |
| Record created 2027-08-22 (future) | Impossible creation date; seed-data artifact | F-14 |
| Scripts named “Record Eradicator”, “Prevent Removal of Admin Access” | Powerful/oddly-named bundle scripts — confirm provenance | §5 |
| Many “(Demo)” / “(DNU)” roles assigned to real users | Demo constructs reaching production access | F-11 |
| “Claude AI” integration app on a production account | AI/dev tooling in prod — confirm intent | F-13 |
| # | Action | Addresses |
|---|---|---|
| 1 | Verify ownership of user1@example.com out-of-band; if unconfirmed, disable immediately. Remove its Administrator role regardless. | F-01 |
| 2 | Enforce mandatory 2FA on Administrator + all financial (CFO/Controller/AP/AR) roles. | F-01,F-03,Auth |
| 3 | Give each human a unique corporate email; retire the shared partner-admin@example.com identity. | F-02 |
| 4 | Inactivate NetSuite/Oracle/partner provisioning admin accounts no longer needed. | F-04 |
| # | Action | Addresses |
|---|---|---|
| 5 | Reduce Administrator holders to 2–3 named users; move daily work to least-privilege roles. | F-03 |
| 6 | Remove Core Administration Permission from the 4 operational MFG roles unless justified. | F-07 |
| 7 | Lock closed accounting periods; establish monthly close & lock discipline. | F-05 |
| 8 | Downgrade File Cabinet access on Employee-Center/portal roles to View or None. | F-08 |
| 9 | Remove Employee-SSN Full access from IT-manager roles. | F-09 |
| # | Action | Addresses |
|---|---|---|
| 10 | Inventory & inactivate demo/DNU roles; enforce a role-lifecycle naming convention. | F-11 |
| 11 | Review WS-only roles & integration apps; least-privilege & monitor tokens. | F-12,F-13 |
| 12 | Audit the non-asset public files (CSV/Word/PDF); default new uploads to private. | F-10 |
| 13 | Export login-audit periodically (or to a SIEM) for retention beyond NetSuite's window. | F-01,§6 |
| 14 | Run a formal Segregation-of-Duties review once per-user identities are restored. | F-02 |
All evidence was gathered read-only; no records, roles, scripts, or settings were modified. Data sources and techniques:
Severity model: Critical = active, exploitable identity/access risk; High = strong control weakness or excessive privilege; Medium = least-privilege / data-exposure gap; Low/Info = hygiene or positive control.