
Connectors
Open the NetSuite connector from Connectors in the sidebar and click the NetSuite row. Managing tools, authorizations, and the workspace connection requires the Owner or Admin role; Members see the tools and policies in a read-only view and cannot change them.
The connector detail tabs
The NetSuite connector page is organized into tabs. Each one manages a different part of the connection.Setup and authorization are covered in their own pages: Connecting NetSuite and Authorizing your NetSuite user. This page focuses on the Tools and Knowledge tabs.
The Tools tab
The Tools tab lists every NetSuite tool agents can call — both the static built-ins and the ones discovered from the NetSuite MCP endpoint. Each tool shows a short description, a risk hint, and its current write policy.Write policy per tool
Every tool can be set to one of three policies. This is how you control whether an agent can change NetSuite data on its own or must wait for a person.
Read-only tools (looking up records, running SuiteQL queries) are safe to leave on Allow. Anything that creates, edits, or deletes NetSuite records is a write and should stay on Require approval unless you have a deliberate reason to change it.
1
Open the Tools tab
On the NetSuite connector page, select Tools to see the Available Tools list.
2
Find the tool
Locate the tool whose behavior you want to change. The risk hint and description tell you whether it reads or writes.
3
Set its write policy
Choose Allow, Require approval, or Deny for that tool. The change applies to how agents in this workspace call it.
4
Test it (optional)
Use the tool’s test action to run it once yourself and confirm it returns what you expect before agents rely on it.
The Knowledge tab
The Knowledge tab surfaces NetSuite product updates — Erstan-managed release notes and feature changes. Erstan retrieves this source automatically for clear NetSuite release, version, feature, and product-update questions, unless the workspace disables or removes it. This product knowledge is separate from a team’s Team Files. See Agent knowledge for making your own files searchable, and Knowledge, tools, web search & models for how automatic product-update retrieval and Team File scope work.How this fits write safety
Per-user authorization decides who an agent acts as in NetSuite; write policy decides what it can do without asking. Together they are the core of Erstan’s write safety model.Who can change write policy?
Who can change write policy?
Only Owners and Admins. Members can see the tools and their current policies but cannot change them.
Does write policy override an agent's own approval settings?
Does write policy override an agent's own approval settings?
The connector’s write policy is the workspace default for each tool. Agent configuration and chat-level Auto-approve writes build on top of it. When in doubt, leave writes on Require approval so a person always sees the change first.
What if a tool isn't listed?
What if a tool isn't listed?
The list combines static tools with ones discovered from the NetSuite MCP endpoint. If a tool is missing, re-sync the connector from the Connectors list (Refresh) and confirm the connection is healthy on the Setup tab.
Next steps
Security & write safety
How per-user authorization, write policy, and approvals keep your NetSuite data safe.
Approving AI actions
What an approval card looks like and how to run or decline a write.
Authorizing your NetSuite user
Each member authorizes their own NetSuite user and role.
Connection troubleshooting
Fix expired auth, unhealthy connections, and the busy queue.