---
title: Minimum Permissions (NetSuite)
slug: customersbank/minimum-permissions-netsuite
description: Learn about the minimum permissions required for the plugin, then set up your Web Service Users and Accounts Payable (A/P) or Accounting users with the appropriate permissions.
docTags: bSho0M8HRjDvZq9EBIWDy
createdAt: 2025-04-21T22:45:41.707Z
---

To use the plugin, you'll need to set up two types of users: a Web Service User and an A/P (Accounts Payable) and/or Accounting User.

### Web Service User

This is a generic role designed for accessing and interacting with web services, including your bank plugin in NetSuite. It requires assigning the Bank Integration Web Service Role, to which access tokens are attached for both the Web Service User and the role itself.

While some users choose to assign the Bank Integration Web Service Role directly to a specific person, this creates a risk: if that user loses their NetSuite access or leaves the company, the access tokens will become void. To avoid this, we recommend creating a dedicated Web Services User and assigning the Bank Integration Web Service Role and tokens to them. This significantly reduces the risk of service disruption.

### A/P (Accounts Payable) and/or Accounting User Role

This is the role for users who will be performing various plugin functions, such as Vendor Payments, Positive Pay, Cash Management, and Book Transfers.

***

## Configure User Role

To configure the appropriate role, navigate to **Setup -> Users/Roles -> Manage Roles**. &#x20;



![](https://api.archbee.com/api/optimize/MM6nC_bKbIkwCRqiFZqEu/vHPdB1cXNCOcHix2fliLo_screenshot-2026-05-27-at-132111.png)

Then, click **Edit** for the existing role you would like to set up, or click **New Role&#x20;**&#x74;o create a new one.

See the section below for the minimum permissions required for each role.&#x20;

### Bank Integration Web Service Role

| **Permission** **Sub-tab** | **Permission**             | **Level**              | **Detail**                                                        |
| -------------------------- | -------------------------- | ---------------------- | ----------------------------------------------------------------- |
| Transactions               | Find Transaction           | View (or higher)       | Required to void erroneous payments                               |
| Transactions               | Make Journal Entry         | Create (or higher)     | Required to void erroneous payments                               |
| Transactions               | Pay Bills                  | Full                   | Required to void erroneous payments                               |
| Lists<br />                | Accounts<br />             | View (or higher)<br /> | Required to load accounts in the installation wizard for matching |
| Lists                      | Documents and Files        | View (or higher)       | Required to access plugin pages                                   |
| Setup                      | Access Token Management    | Full                   | Required to create and manage access tokens                       |
| Setup                      | Log in Using Access Tokens | Full                   | Required to generate an Access Token                              |
| Setup                      | SuiteScript                | View (or higher)       | Required to access custom scripts                                 |
| Setup                      | SuiteScript Scheduling     | Full                   | Required to schedule payments                                     |

