NetAsset Bulk Custom Role Permissions Import Tool
Overview
The Bulk Custom Role Permissions Import tool provides a single screen for reviewing and updating NetAsset permissions across all custom roles in an account. Permissions are displayed as a matrix, with custom roles as columns and NetAsset permissions as rows, allowing access levels to be set for many roles and permissions at once rather than editing each role record individually.
The tool supports three permission categories:
| Category | What It Controls | Available Values |
|---|---|---|
| Custom Transactions | NetAsset custom transaction types (for example, NetAsset Depreciation) | None, View, Create, Edit, Full |
| Custom Records | NetAsset custom record types (for example, NetAsset Asset) | None, View, Create, Edit, Full |
| Suitelets | Which roles are included in the audience of each active NetAsset Suitelet deployment | Yes, No |
Common uses include initial role configuration during implementation, auditing existing access, and promoting a reviewed permission set from a sandbox account to production by way of an Excel export and import.
Note: Access levels correspond to standard NetSuite permission levels. None removes the permission line from the role entirely; Full grants view, create, edit, and delete access.
Prerequisites
- An Administrator role, or a trusted implementation or system administrator role. Because the tool can change permission levels on any editable custom role, access should be restricted accordingly.
- Permission to edit role records. Editing Suitelet rows additionally requires permission to edit script deployments.
- The role in use must be included in the audience of the tool's Suitelet deployment (
customdeploy_laa_access_sl). - The NetAsset bundle must be updated to a version that includes the tool. If the setup page link is missing, the installed bundle version predates the feature.
Step-by-Step Process
Access the Tool
- Navigate to NetAsset > NetAsset Setup > System Setup.
- Under the Import Tools subtab, locate Bulk Custom Role Permissions Import and click the associated Tool Link.
- The permissions matrix will then load on the next page.
Review the Permission Matrix
The matrix opens with one tab per permission category. Each cell shows the access level currently granted in NetSuite for that role and permission.
- Only active custom roles appear as columns.
- Only Suitelet deployments that are active, released, and NetAsset-specific appear as rows.
- Each permission row includes a description explaining what the record or Suitelet controls.
The tools listed below assist with reviewing and navigating the matrix. Items marked More options are hidden until that toggle is enabled.
| Tool | Purpose | Availability |
|---|---|---|
| Search | Filters the visible permission rows by name | Default |
| Maximize | Expands the matrix to fill the available screen space | Default |
| Take the tour | Walks through the tool's primary features | Default |
| Set [Category] visibility | Selects which permission rows are displayed | More options |
| Set role visibility | Selects which role columns are displayed | More options |
| Compare roles… | Displays two roles side by side, optionally limited to permissions where they differ | More options |
| Highlight changes | Dims unchanged cells, displays the previous value of each changed cell (for example, Edit → Full), and allows changes to be reverted from that view | More options |
| Export matrix… | Opens the export dialog for a current or blank matrix | More options |
The More options toggle is located in the matrix header, next to Maximize, with the tooltip "Show the view and export options." It is off the first time the tool is opened, and its setting is remembered per browser. While it is off, the controls marked above are not present on the page at all.
At least one permission row and one role column must remain visible at all times.
Edit Permissions
All edits are applied locally and are not written to NetSuite until saved. A pencil badge on each category tab displays the number of unsaved changes in that category.
Permissions can be edited in four ways:
- Single cell — Click a cell and select the access level (or Yes / No for Suitelet rows).
- Range — Drag to select a block of cells and apply one value to the entire selection. An undo option is offered immediately after the change.
- Row — Use the row menu to set one permission to the same level across every visible role, or to revert the row to its saved values.
- Column — Use the column menu to set every permission on the active tab for a single role, to revert the role, or to apply a permission set.
Apply a Permission Set
Permission sets are predefined, read-only templates that apply a standard access profile to a single role. Applying a set overwrites that role's levels for the permissions the set covers and reports how many permissions changed.
NetAsset ships the following permission sets:
- AP Clerk
- Asset Accounting Manager
- Asset Specialist
- Edit Only
- NetAsset Administrator
- View Only
To apply a permission set:
- Open the column menu for the target role.
- Select Apply permission set….
- Choose the appropriate set, preview the changes, and then apply.
Import Permissions from Excel
The matrix can be populated in one step from an Excel workbook.
- Drag the file into the drop zone, or browse to select it.
- Review the results summary and any warnings, then close the warnings dialog.
- Confirm the matrix reflects the intended values, then save.
Requirements for the file:
- The file must be .xlsx or .xls. CSV files are accepted by the file picker but are not read.
- The workbook must contain a worksheet named one of the following: Role Access, Granular Permissions, Role Permission Settings, Roles and Permissions, or Sheet1.
- Role column headings must match role names in the account, and permission rows must match NetLease permission names or their display names.
- Valid cell values are None, View, Create, Edit, and Full for record and transaction rows, and Yes or No for Suitelet rows. An empty cell is treated as None or No.
On a successful import, all matched values are applied to the matrix and flagged as changed. Roles and permissions that exist in the account but were not included in the file are hidden automatically. Restoring them requires More options to be enabled, then using Set [Category] visibility and Set role visibility.
The import may also return warnings. The warnings dialog is informational only and is closed without action:
| Warning | Meaning |
|---|---|
| Role(s) not in NetSuite | The file contains a column for a role that does not exist in this account. Values in that column are skipped. |
| Permission(s) not in NetSuite | The file contains a row for a permission that does not exist in this account. The row is skipped. |
| Role(s) hidden | The role exists in the account but was not in the file, so its column has been hidden. |
| Permission(s) hidden | The permission exists in the account but was not in the file, so its row has been hidden. |
Warning: An import is rejected in full, with no changes applied, if the workbook has no readable worksheet, no role columns, no permission rows, no recognizable categories, or any cell containing an unrecognized value. The error message identifies the specific problem.
Export the Permissions Matrix
With More options enabled, select Export matrix… and choose one of two modes:
- Current matrix — Exports the access levels currently displayed, including unsaved edits.
- Blank matrix — Exports every cell as None or No, producing a template that can be completed offline.
Only visible roles and permissions are included in the export. The export dialog identifies anything being excluded. Note that the search filter does not limit the export.
The exported workbook includes a permission level legend, a description for each permission, dropdown validation on each cell, and colored formatting by level. Because the exported sheet is directly re-importable, exporting from one account and importing into another is the recommended way to promote a reviewed permission set between environments.
Save Changes
- Click Save.
- Review the confirmation dialog, which lists the number of pending changes per role.
- Confirm to begin saving.
Changes are written one role or Suitelet deployment at a time, and a progress list shows each target as pending, saving, saved, or failed.
- If a single target fails, the remaining targets still save. The failure is reported inline and can be addressed separately.
- Selecting Cancel stops after the change in progress finishes. Targets already saved retain their new values, and the dialog offers Save remaining changes.
- After each role is saved, the tool re-reads the role record and verifies that every requested change was applied.
Considerations
- Bundle-delivered roles cannot be edited. Netgain roles are excluded from the matrix entirely. Roles locked by other bundles appear as columns but fail verification at save time. In both cases, create an editable copy of the role and apply the permissions to the copy.
- Scope is limited to NetAsset. The tool manages NetAsset custom records, custom transactions, and Suitelet audiences only. It does not manage standard NetSuite permissions, create roles, or assign employees to roles.
- Certain records and Suitelet deployments are intentionally excluded from the matrix and cannot be changed through this tool.
- Name matching during import is case-sensitive. A renamed role or an altered column heading will be reported as not existing in the account rather than matched.
- Saving is sequential. A large change set requires one write per role or deployment and may take several minutes.
Troubleshooting
The Bulk Custom Role Permissions Import link is missing from the NetAsset Setup page.
- Confirm the NetAsset bundle has been updated to a version that includes the tool.
- Confirm the role in use has access to the NetAsset Setup page.
The export, compare roles, highlight changes, or visibility controls are not on the page.
- These controls appear only when More options is enabled in the matrix header. The toggle is off by default and is remembered per browser.
An expected role does not appear as a column.
- Netgain bundle roles are excluded by design.
- The role may be inactive, or may be a standard NetSuite role rather than a custom role.
- The role may be hidden as a result of a prior import. Enable More options, then check Set role visibility.
An expected permission or Suitelet does not appear as a row.
- The record or Suitelet may be intentionally excluded from the matrix.
- Suitelet deployments must be active and released to appear.
- The row may be hidden as a result of a prior import. Enable More options, then check Set [Category] visibility.
A CSV file was imported but nothing changed.
- CSV files are not read by the tool. Save the file as .xlsx and import again.
The import reports that no roles or permissions could be matched.
- The file was likely built for a different account or product, or role and permission names have been renamed. Export the current matrix from the account and compare spelling and capitalization against the file.
The import is rejected because of invalid values.
- One or more cells contain a value other than None, View, Create, Edit, or Full (or Yes and No for Suitelet rows). The error message lists each affected permission, role, and value.
A role reports that its changes were not saved because the role is locked.
- The role was likely installed by a bundle and cannot be edited. Create an editable copy of the role and apply the permissions to the copy.
