Minimum Permissions (NetSuite)
To use the plugin, you'll need to set up two types of users: a Web Service User and an A/P and/or Accounting User.
Web Service User
This is a generic role designed for accessing and interacting with web services, including your bank plugin in NetSuite. It requires assigning the Bank Integration Web Service Role, to which access tokens are attached for both the Web Service User and the role itself.
While some users choose to assign the Bank Integration Web Service Role directly to a specific person, this creates a risk: if that user loses their NetSuite access or leaves the company, the access tokens will become void. To avoid this, we recommend creating a dedicated Web Services User and assigning the Bank Integration Web Service Role and tokens to them. This significantly reduces the risk of service disruption.
A/P and/or Accounting User Role
This is the role for users who will be performing various plugin functions, such as Vendor Payments, Positive Pay, Cash Management, and Book Transfers.
Configure User Role
To configure the appropriate role, navigate to Setup -> Users/Roles -> Manage Roles. Then, click Edit for the existing role you would like to set up, or click New Role to create a new one.
See the section below for the minimum permissions required for each role.
Bank Integration Web Service Role
Transactions Permissions
Permission | Level | Detail |
|---|---|---|
Bills | View | Required to access bill data |
Enter Vendor Credits | Full | Required to process vendor credits |
Expense Report | View | Required to access expense report data |
Find Transaction | View | Required to search and locate transactions |
Make Journal Entry | Full | Required for book transfers and journal entries |
Pay Bills | Full | Required to process bill payments |
Purchase Order | View | Required to access purchase order data |
Reports Permissions
Permission | Level | Detail |
|---|---|---|
SuiteAnalytics Workbook | Edit | Required for REST API integration |
Lists Permissions
Permission | Level | Detail |
|---|---|---|
Accounts | View | Required to load accounts in the installation wizard |
Address List in Search | Full | Required for address management |
Currency | View | Required for multi-currency operations |
Documents and Files | View | Required to access plugin pages |
Employee Record | View | Required for expense report processing |
Employee Social Security Numbers | View | Required for expense report processing |
Employees | View | Required for expense report processing |
Perform Search | Full | Required for search functionality |
Subsidiaries | Full | Required for multi-subsidiary operations |
Vendors | View | Required to access vendor data |
Setup Permissions
Permission | Level | Detail |
|---|---|---|
Access Token Management | Full | Required to create and manage access tokens |
Custom Record Type | Full | Required for custom record management |
Custom Entity Fields | View | Required to access custom entity fields |
Custom Fields | View | Required to access custom fields |
Enable Features | View | Required to check enabled features |
Log in using Access Tokens | Full | Required to generate an Access Token |
REST Web Services | Full | Required for REST API integration |
Set Up Company | Full | Required for company configuration |
SuiteScript | Full | Required to access custom scripts |
Custom Record Permissions
Permission | Level | Detail |
|---|---|---|
Bank Details | View | Only required if using Electronic Bank Payment (EBP) bundle |
A/P and/or Accountant User Role
Transactions Permissions
Permission | Level | Detail |
|---|---|---|
Check | View (or higher) | Required to load checks in the Positive Pay page |
Transfer Funds | View (or higher) | Required to transfer funds |
Lists Permissions
Permission | Level | Detail |
|---|---|---|
Accounts | View (or higher) | Required to view accounts for various plugin functions |
Currency | View (or higher) | Required to view currencies for various plugin functions |
Customers | View (or higher) | Required to load the Positive Pay page |
Documents and Files | View (or higher) | Required to access plugin pages |
Subsidiaries | View (or higher) | Required to load Subsidiary-related data on plugin pages |
Setup Permissions
Permission | Level | Detail |
|---|---|---|
Accounting Lists | View (or higher) | Required to load vendor category data on plugin pages |
Custom Fields | View (or higher) | Required to load custom fields on plugin pages |
Custom Lists | View (or higher) | Required to load available payment methods from your bank |
SuiteScript | View (or higher) | Required to load plugin pages |
For Legacy Payments module users! If you are using the legacy Vendor Bills or Expense Reports module, also ensure these additional permissions:
Transactions Permissions:
- Bills → View (or higher) → Required to load bills on plugin payable pages
- Expense Reports → View (or higher) → Required to load expense reports on plugin payable pages
- Find Transaction → View (or higher) → Required to load bills on plugin payable pages
- Make Journal Entry → Create (or higher) → Required to transfer funds
- Pay Bills → Full → Required to load bill payments in the Positive Pay page
Lists Permissions:
- Employee Record → View (or higher) → Required to access payment history/employee expense reports pages
- Vendors → View (or higher) → Required to load vendors' bills on the plugin payables pages
Setup Permissions:
- SuiteScript Scheduling → Full → Required to schedule payments
- Set Up Company → Full → Required for the Entity Bank Details bundle users. Used for the EBD Settings RESTlet to access the Company Information page. Optional, but ideal for certain filter options when Customizing Filters on Pay Vendor Bills page.
Custom Record Permissions:
- Entity Bank Details (FI) → View (or higher) → Required to view vendor banking information on the Vendor record and within the Entity Bank Details Overview page