ANS-0298 · ROLES, PERMISSIONS & SECURITY

How to Configure Custom Record Access Types and Permissions in NetSuite

Understanding NetSuite's custom record access types is crucial for managing user permissions and data visibility effectively.

Short answer

NetSuite custom records offer three access types: 'Require Custom Record Entries Permission', 'Use Permission List', and 'No Permissions Required for Internal Roles'. Each type dictates how user roles gain access, from requiring a general permission to enforcing specific record-level permissions or making the record publicly accessible without explicit role setup.

Scenario

Organizations often need to control who can view, create, or edit specific custom records within NetSuite. Improper configuration of custom record access types can lead to either overly restrictive access, preventing legitimate users from performing their tasks, or overly permissive access, posing a security risk by exposing sensitive data to unauthorized personnel.

Solution

Custom records in NetSuite can be configured with three distinct access type levels, each dictating how user roles interact with the record type. The available access types are:

  • Require Custom Record Entries Permission
  • Use Permission List
  • No Permissions Required for Internal Roles

When the 'Require Custom Record Entries Permission' access type is selected, any role needing access to this custom record must have the Lists->Custom Record Entries permission assigned. For instance, if all custom records are configured with this default access type, adding the Custom Record Entries Permission to a specific role will grant access to all such custom records. Supported permission levels include view, create, edit, and full.

When the 'Use Permission List' access type is selected, individual custom record permissions configured directly on the role are enforced. To review all roles with access to a custom record, navigate to the custom record type via Customization > Lists, Records & Fields > Record Types and select the Permissions tab. If this access level is in use and a role possesses the "Custom Record Entries" permission, that general permission will be disregarded.

Selecting 'No Permissions Required for Internal Roles' makes access to the custom record type public for internal roles. No specific permission setup is necessary at the role level for internal users to access this record.

Expert NetSuite Support

Need help with this NetSuite issue?

Roles, Permissions & Security consulting and configuration support

Talk to a consultant