Step 14: NetSuite Role Permission Setup
If you receive an "INSUFFICIENT_PERMISSION" error or can't see all the accounts, it's because your NetSuite user role does not have the correct permissions. You'll need to update your permissions following these steps.
Update Role Permissions
The Administrator has full access to the plugin features. To set permissions for user roles, follow these steps.
Go to Manage Roles
Go to Setup → Users/Roles → Manage Roles.

On the Manage Roles page, click Edit beside the role of choice.
Add List Permissions
After selecting Edit, go to Permissions → List.
Click the dropdown in the last row of the Permissions table.

Scroll through the list, or begin typing to find and select the following permissions:
- Accounts (Level: View): Required to access the chart of accounts to fulfill the payment request.
- Currency (Level: View): Required to load the table of open bills on the Bill Payments page.
- Customers (Level: View): Required to load the Positive Pay page of the plugin.
- Documents and Files (Level: View): Required to access plugin pages and scripts to run and display the plugin.
- Vendors (Level: View): Required to load vendor bills on the plugin pay page.
- Employee Record (Level: View): Required to view transactions on the Bill History page and to load employee expense reports on the Expense Reports page.
- Subsidiaries (Level: View): Required to add and view subsidiaries as a column option when customizing the Pay Vendor Bills page.
Add Setup Permissions
Next, click Permissions → Setup.
Click the dropdown in the last row of the Permissions table.

Scroll through the list, or begin typing to find and select the following permissions:
- Accounting Lists (Level: View): Required to be able to use the Pay Bills page.
- Custom Fields (Level: View): Required to pull in custom fields from the Bill record, which are then used for customizable columns on the Pay Vendor Bills page. This is necessary for the Pay Vendor Bills page to load if a user has any customizations.
- Custom Lists (Level: Full): Required to load the available payment methods from your bank on the Pay page.
- SuiteScript (Level: View): Required to check if there are currently payments being processed.
- SuiteScript Scheduling (Level: Full): Required to schedule payments for processing.
Select Save.
Grant View-Only Access
NOTE: This section is only applicable to permissions for pages under Accounts Payables (New) tab in the Citizens plugin.
By default, users with the permissions to the Citizens plugin Suitelets have full access to create, edit, and manage data on the plugin pages. If you need certain roles to have view-only access (they can see data but cannot make changes), follow these additional steps.
Supported Pages
- Payments - Users can see bills but cannot submit payments
- Payment Methods - Users can view vendor payment info but cannot edit
- Expense Reimbursements - Users can see reports but cannot process them
Configuration Steps
- Go to Setup → Users/Roles → Manage Roles and open the role
- Scroll to Permissions tab → Custom Record subsection
- Click Add to add a new permission line
- In "Record Type", select the appropriate custom record:
Record | Level | Page |
|---|---|---|
Citizens View Only: Payments | View | Payments |
Citizens View Only: Pay Methods | View | Payment Methods |
Citizens View Only: Exp Reimb | View | Expense Reimbursements |
- Set permission level to View (not Create, Edit, or Full)
NOTE: If you grant any other level (Create, Edit, or Full), the plugin will provide full access. To restrict access to view-only, the permission level must be set to View.
- Repeat for additional pages if needed
- Click Save

What Changes
View-only users CAN: View data, use filters, search, export View-only users CANNOT: Submit payments, edit records, approve, or change data
To Remove View-Only Access
- Go to the role's Permissions tab → Custom Record subsection
- Find the view-only custom record permission line
- Change level from "View" to another level, or delete the line entirely
- Click Save