Agents act as you, never above you
Erstan uses per-user authorization for NetSuite. An Owner or Admin sets up the shared Workspace OAuth connection once, and then every member individually authorizes their own NetSuite user before any agent can act on their behalf. When an agent calls a NetSuite tool, it calls it as you — using your NetSuite user, your role, and your permissions. An agent can never see or change anything your own NetSuite login could not.Erstan steers you toward a non-Administrator NetSuite role when you authorize. The connect dialog says “Choose a non-Administrator role” precisely so that agents inherit the least privilege needed for finance work, not full admin rights.
1
A workspace connection is established once
An Owner or Admin connects NetSuite for the workspace using the Erstan app (recommended) or Your own setup. This stores the OAuth client — no member re-enters connection details.
2
You authorize your own NetSuite user
From the NetSuite connector’s Authorizations tab (or an Authorization required card in chat), you sign in and approve access in a NetSuite popup. Agents now act with your role.
3
You can revoke just yourself, any time
Use Disconnect your NetSuite user to revoke your personal authorization without affecting the workspace connection or anyone else.
Authorizing your NetSuite user
Step-by-step on per-user authorization and the members roster.
Write safety: nothing changes without permission
Reading NetSuite data is safe by default. Writing to NetSuite — creating a record, editing a transaction, sending a payment — is treated differently, and you control it at two levels.Per-tool write policy
On the NetSuite connector’s Tools tab, each tool has a write policy:Human-in-the-loop approvals
When a tool requires approval, the agent stops and shows an approval card. You review the action — often with a before/after preview of the change — and choose Run action or Don’t run. Those authenticated controls are the only way to decide the pending approval; chat replies remain feedback and do not resume it. In a built agent, the AI Approval step does the same thing as a deliberate human-in-the-loop checkpoint in the run.Approving and rejecting AI actions
How approval cards work, plus the Queued and Authorization Required cards.
Auto-approve writes — use with care
You can turn on Auto-approve writes to let an agent skip the approval prompt for a session. This is convenient for trusted, repetitive work, but it removes the per-action checkpoint.One workspace, one NetSuite environment
A workspace is bound to a single NetSuite environment — one production account or one sandbox. This keeps a clear line between what an agent can touch and which company’s data it is grounded in.- Connecting NetSuite ties the workspace to that specific NetSuite account (its realm). Work in one workspace never reaches into another company’s data.
- Production and sandbox are kept separate. Many teams run a sandbox workspace to build and test agents, and a production workspace for live finance work.
- You can belong to several workspaces and switch between them; each carries its own connection, members, and content.
Need to work against both production and a sandbox? Use separate workspaces — one per environment — rather than reconnecting a single workspace back and forth.
Roles, permissions, and the audit trail
Access inside a workspace is governed by three roles:
Managing the workspace NetSuite connection, setting tool write policies, and changing authorizations require Owner or Admin. Members see these controls as read-only where they apply.
Every agent run is tracked. A run produces a step-by-step trace with live status, and writes that needed approval record who approved them. From a run you can open Audit in Erstan to follow what happened, and Admins can review workspace activity in the audit log.
Audit log and usage
Review the workspace audit trail and keep an eye on usage and cost.
How the pieces fit together
Can an agent do something I can't do in NetSuite?
Can an agent do something I can't do in NetSuite?
No. Agents call NetSuite as your authorized user, so your NetSuite role and permissions are the ceiling. If your login cannot see or change a record, neither can an agent acting as you.
What stops an agent from writing to NetSuite on its own?
What stops an agent from writing to NetSuite on its own?
Write-capable tools default to Require approval, so the agent pauses for a person. An Admin can change a tool to Allow or Deny, and a user can turn on Auto-approve writes — both are deliberate choices, and Deny always wins.
Who can change the connection or write policies?
Who can change the connection or write policies?
Only Owners and Admins. Setting up the workspace NetSuite connection, editing per-tool write policy, and managing authorizations all require the right role.
How do I revoke access?
How do I revoke access?
Any member can run Disconnect your NetSuite user to revoke just their own authorization. Owners and Admins can disconnect the workspace connection, which removes access for everyone.
Next steps
Managing NetSuite: tools & write policy
Set which tools agents can use and which actions need approval.
Authorizing your NetSuite user
Authorize your own NetSuite user and review the members roster.
Approving and rejecting AI actions
Review write actions before they run, and decide when to auto-approve.
Workspaces and people
Manage roles, members, and the people in your workspace.