Access type determines how users other than the owner can reach custom record instances. In NetSuite, it can require a custom record entries permission, limit access to a defined permission list, or make the instances public with no permission required.
What Access Type Means in Practice
Access type is the rule that decides how non-owner users reach a custom record, so it is really a visibility and permission model, not just a label on a form field. In practice, it tells NetSuite whether access stays tightly controlled, follows a named permission list, or becomes public.
That distinction matters because the same record structure can produce very different exposure depending on how access is set. A record that requires a custom record entries permission behaves like a governed object; a record on a defined permission list limits who can interact with it; a public record removes that permission gate altogether.
How Access Type Shapes Record Visibility
Access type changes the audience for a custom record instance. The owner can always reach it, but the configured access type determines whether everyone with the right permission can see it, only selected roles can reach it, or anyone can access it without a specific record-level permission.
That makes access type part of record design. It influences whether the record behaves like a controlled business object, a shared operational object, or an openly reachable data container. The practical effect is not only who can read the record, but also who can create, update, or rely on it in downstream workflows.
Because the setting is about reachability, it should be read alongside the permissions model around the record. The same platform can support both coarse access and fine-grained restriction, but access type is the switch that sets the baseline.
Permission Models Behind the Setting
NetSuite’s access type options map to three common patterns. The first is a permission-gated model, where users need the custom record entries permission to work with the record. The second is a restricted sharing model, where access is limited to a defined permission list. The third is an open model, where the record is public and no explicit permission is required.
Those patterns reflect a basic control choice: whether access is enforced centrally through a permission gate or distributed through explicit role assignment. That is why access type is often one of the first settings to review when a custom record stores operational data, reference data, or information that should not be broadly exposed.
Why Access Type Matters for Security and Governance
Access type affects more than convenience. A permissive configuration can widen exposure, create accidental over-sharing, and make it harder to prove that only intended users can interact with a record. A restrictive configuration reduces that risk, but it can also slow adoption if the permission model is too rigid for the business process.
In environments where records carry sensitive operational detail, access type becomes part of the control surface for least privilege and data segregation. The setting is therefore not just a functional preference, it is a governance decision about who should be trusted to reach the record and under what conditions.
Used well, access type gives teams a simple way to align record visibility with business need. Used loosely, it can turn a custom record into an unintended shared data store.
Risk and Threat Considerations
Misconfigured access type can expose custom records to broader audiences than intended, especially when a record is made public or when permission lists are too permissive. The main risk is not abstract, it is unauthorized visibility or modification of record data that was expected to stay controlled.
Failure mechanism: An overly open access type removes the record-level barrier, while weak role design or incomplete permission review leaves users able to reach data they should not see or change.
Impact: Unauthorized access can lead to data leakage, workflow manipulation, incorrect business decisions, or a control gap that is hard to detect after the fact.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5, CIS Controls v8 and OWASP ASVS set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | AC-6 — Least Privilege | Access type governs who can reach custom records. |
| AC-3 — Access Enforcement | Access type enforces who may interact with a record instance. | |
| Recommendation — Apply AC-6 to limit custom record access to the minimum roles required. Use AC-3 to enforce record-level permission checks for custom records. | ||
| ISO/IEC 27001:2022 | A.5.15 — Access control | Access type is a control decision about record access rights. |
| A.5.18 — Access rights | Access type depends on who is granted rights to the record. | |
| Recommendation — Set A.5.15-aligned rules to restrict custom record access by business need. Review A.5.18 access rights so only intended users can reach the record. | ||
| CIS Controls v8 | CIS-6 — Access Control Management | Access type is part of managing and constraining user access. |
| Recommendation — Use CIS-6 to define and review who can access custom records. | ||
| OWASP ASVS | V8 — Authorization | Access type is an authorization decision for record access. |
| Recommendation — Apply V8 to verify that record access is authorized as intended. | ||
Practitioner Guidance
Governance implication: Treat access type as a design-time control decision, not a default setting to accept blindly. Choose the narrowest model that still supports the process, and confirm that the record’s reach matches the sensitivity of the data it holds.
Practitioner note: Public access is easy to justify during implementation and hard to justify later if the record becomes operationally important. Revisit the setting whenever the record’s use, audience, or contents change.
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 27, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org