This article is the central NetSuite permission reference for CloudExtend apps. Use it to prepare the NetSuite roles that users will connect to ExtendSync or ExtendInsights.
This guide applies to:
ExtendSync for Outlook
ExtendSync for Google Workspace
ExtendInsights for NetSuite
The exact permissions a role needs depend on the CloudExtend app and features your organization uses. Assign only the permissions required for the user’s workflow.
How CloudExtend Authentication Works
Users complete two authentication steps:
Sign in to CloudExtend using their Microsoft or Google identity.
Authorize CloudExtend to connect to a NetSuite account and role.
The Microsoft or Google email address must match the email address assigned to the user’s CloudExtend license.
The email address used for the CloudExtend license does not need to match the user’s NetSuite login email. After authentication, users can connect to multiple NetSuite accounts and roles and switch between their available connections.
CloudExtend supports NetSuite’s secure authorization flow, including accounts configured with:
Two-Factor Authentication
SAML Single Sign-On
Token-Based Authentication
Basic Credentials
Before You Begin
Confirm that the user has:
An active CloudExtend license
Access to the appropriate NetSuite account
Access to the NetSuite role they need to connect
The NetSuite account ID
A role that is not configured as Web Services Only
Find the NetSuite Account ID
Users can find the account ID in the NetSuite URL while signed in through a browser.
They can also follow this guide:
NetSuite Role and User Requirements
A NetSuite administrator must configure the role that the user will connect to CloudExtend.
In NetSuite, go to:
Setup → Users/Roles → Manage Roles
Locate the applicable role, click Edit, and review the following requirements.
Step 1: Verify That Web Services Only Is Disabled
The role must not be restricted to web services access.
Open the applicable NetSuite role.
Confirm that Web Services Only Role is disabled.
Save the role if you make a change.
A Web Services Only role cannot complete the interactive CloudExtend authorization flow.
Step 2: Set Up NetSuite Shared Connection Permissions
Permission | Requirement | Purpose |
SOAP Web Services | Required | Allows CloudExtend to communicate with NetSuite through supported APIs. |
User Access Tokens | Required | Allows NetSuite to generate the access token used by the CloudExtend connection. |
Log in using Access Tokens | Required for token authentication | Allows the role to authenticate using an access token. |
SAML Single Sign-On | Conditional | Add only when the organization uses SAML SSO. |
Allow JS/HTML Uploads | Conditional | Add when users need to upload |
REST Web Services | Global Autopilot only | Required for ExtendSync Outlook Global Autopilot API operations. |
Do not add SAML Single Sign-On when the organization does not use SAML. Adding it unnecessarily can prevent users from completing the expected login flow.
ExtendSync Outlook and Google Permissions
The following permissions apply to ExtendSync features. They are not all required for ExtendInsights.
Step 1: Enable the user preference
Rich Text Editing
In NetSuite, go to Home → Set Preferences.
Enable Rich Text Editing.
While not required, we have found that certain emails with HTML may transfer as blank or with all the HTML coding if this setting is not enabled at the user level. This may result in a NetSuite error, such as the field message containing more than the maximum number (1000000) of characters allowed.
Exclude Inactive Records from Search Results
In NetSuite, go to Home → Set Preferences.
Open the Analytics subtab.
Locate Include Inactives in Global & Quick Search.
Clear the checkbox.
Save the preference.
➡️ Full Guide: How to Exclude Inactive Records from Search Results
Step 2: Set Email and File Permissions
Under Permissions → Lists, review the following permissions:
Permission | Details / Purpose |
Documents and Files | Recommended for Global Autopilot and ExtendDocs users: Full
Minimum: Create |
Track Messages | Recommended for Global Autopilot and ExtendDocs users: Full
|
Global Autopilot Permissions (Outlook)
Global Autopilot is available with ExtendSync Outlook Enterprise.
Under Permissions → Setup, add:
REST Web Services
Under Permissions → Lists, review:
Permission | Details / Purpose |
Contacts | Recommended for Global Autopilot Auto-Create Contact feature
Required for Contact matching |
Customers | Recommended for Global Autopilot Required for Customer matching |
Vendors | Recommended for Global Autopilot Required for Vendor matching |
The role must have access to each record type that Global Autopilot needs to search, match, or create.
Send from Outlook Permission
For users who use Send from Outlook, open the role’s Permissions → Custom Record subtab and add:
Permission | Details / Purpose |
Celigo Send from Outlook Email Config | Recommended for Send from Outlook users: Full |
Custom Field Permissions
If your organization uses custom NetSuite fields, the connected role must have access to those fields.
Use the applicable guide:
ExtendSync for Outlook and Google Workspace: Manage records and custom field permissions
ExtendInsights: Troubleshooting custom fields missing from a template
Custom field access is separate from the permissions needed to establish the NetSuite connection.
Custom Record and Transaction Type Permissions
As of NetSuite 2026.2, NetSuite strictly enforces permissions when CloudExtend retrieves custom record type and custom transaction type metadata.
Under Permissions → Setup, add:
Permission | Minimum level |
Custom Record Types | View |
Custom Transaction Types | View |
These permissions are required when ExtendSync or ExtendInsights needs to retrieve the corresponding custom metadata.
Without them:
Custom record types may be missing from CloudExtend.
Custom transaction types may be unavailable when building templates.
Fields associated with those record types may be missing.
Earlier app versions may display:
Errors were reported while looking up record types on this account.
Current app versions may omit the affected record types without displaying a warning.
For complete troubleshooting steps, see:
Connect CloudExtend to NetSuite
After the NetSuite administrator configures the role, the end user can create the connection.
Go to Menu and select Connection.
Click Add, then enter your NetSuite account ID and click Connect to NetSuite.
➡️ Learn how to find your NetSuite account ID here.Enter your NetSuite credentials. Select the role you want to log in with and hit Allow.
Click Yes. Now, you have a new connection in CloudExtend.
🚨 IMPORTANT
You will be logged out of your current NetSuite session the first time you log in. Don't worry, though; once logged in, you'll be able to have both sessions active at the same time. As long as you don't log out of CloudExtend, you won't need to enter your credentials again, even if your password expires.
Common Errors
Cannot Continue This Authorization Flow
The following error indicates that the role cannot complete the NetSuite authorization process:
Cannot continue this authorization flow. Your current role has insufficient permission.
The role usually does not have the required User Access Tokens permission.
A NetSuite administrator should:
Go to Setup → Users/Roles → Manage Roles.
Edit the applicable role.
Open Permissions → Setup.
Add User Access Tokens.
Save the role.
Ask the user to retry the connection.
For more information, see:
Unexpected Two-Factor Authentication Prompt
NetSuite requires two-factor authentication when a role contains certain elevated permissions. This behavior is controlled by NetSuite.
If users receive an unexpected 2FA prompt, review the permissions assigned to their role.
See NetSuite’s documentation for the complete list:
Best Practices
Create permissions based on the CloudExtend app and features each user needs.
Avoid assigning feature-specific permissions to users who do not use those features.
Test the configuration with the same NetSuite role the user will connect.
Allow up to 30 minutes for NetSuite role permission changes to take effect.
Refresh the CloudExtend connection or record type list after changing role permissions.
Review role permissions whenever your organization enables a new CloudExtend feature.
Need Help?
If users still cannot connect after the role is updated, contact CloudExtend Support at cloudextend-support@celigo.com.
Include:
The CloudExtend app being used
The NetSuite account ID
The connected NetSuite role
The exact error message
A screenshot of the role’s relevant permission subtabs
The feature or action the user is trying to access





