Skip to main content
Connecting NetSuite happens in two stages. An owner or admin sets up the shared Workspace OAuth connection once, and then every member authorizes their own NetSuite user before agents can act on their behalf. This page covers that second stage — your personal authorization.

Why authorization is per user

Erstan uses per-user authorization for NetSuite. When an agent calls a NetSuite tool, it calls it as you — using the NetSuite user and role you authorized. Your own NetSuite permissions decide what the agent can read and write.
Because agents inherit your NetSuite role, you only ever grant Erstan the access you already have. Two people running the same agent may see different results if their NetSuite roles differ.
This is why the shared workspace connection alone is not enough: it establishes the OAuth client for the workspace, but each member still needs to sign in and approve access individually.
When you authorize, choose a non-Administrator role in the NetSuite sign-in popup. Agents act with the role you pick, so a least-privilege role keeps writes scoped to the work you actually do. Writes still pause for approval based on each tool’s write policy.

Authorize your NetSuite user

You can authorize from the connector page or directly from chat when an agent needs access.
1

Open the NetSuite connector

Go to Connectors in the sidebar and open NetSuite. The workspace connection must already be set up by an owner or admin — see Connecting NetSuite.
2

Go to Authorizations

Open the Authorizations tab. The Your NetSuite user card shows your current status: Authorization required, You authorized, or Authorization expired.
3

Click Authorize

Click Authorize (or Re-authorize if your access expired). A NetSuite popup opens — allow popups if your browser blocks it.
4

Sign in and approve in NetSuite

Sign in to NetSuite, choose a non-Administrator role, and approve access. Erstan polls until the card reports You authorized.

Manage or revoke your authorization

NetSuite access tokens are short-lived and refresh automatically, so you rarely re-authorize during normal use. You do need to re-authorize if your authorization shows Authorization expired or if your NetSuite role changes.
Open the NetSuite connector’s Authorizations tab and click Re-authorize on the Your NetSuite user card. This refreshes your personal authorization without touching the workspace connection.
Use Disconnect your NetSuite user to revoke only your personal authorization. The shared workspace connection and other members’ authorizations are unaffected. Agents can no longer act as you in NetSuite until you authorize again.

The Workspace members roster (owners and admins)

Owners and admins see a Workspace members roster on the Authorizations tab — a table of who has authorized their NetSuite user, with a summary like 3/5 members authorized.
Use the roster to spot members who still show Authorization required before assigning them NetSuite agent work, and to find expired authorizations that need a nudge to re-authorize.
Managing the workspace connection and authorizations requires the Owner or Admin role. Members can authorize their own user but cannot change the shared connection.

Next steps

Connecting NetSuite

How an owner or admin sets up the shared workspace connection.

Managing NetSuite tools & write policy

Control which tools agents can use and which actions need approval.

Approving AI actions

Review and approve writes before they run in NetSuite.

Security & write safety

How per-user authorization and approvals keep you in control.