Skip to main content

CloudExtend NetSuite Login Prerequisites

Configure the NetSuite role permissions required to connect ExtendSync and ExtendInsights

This article is the central NetSuite permission reference for CloudExtend apps. Use it to prepare the NetSuite roles that users will connect to ExtendSync or ExtendInsights.

This guide applies to:

  • ExtendSync for Outlook

  • ExtendSync for Google Workspace

  • ExtendInsights for NetSuite

The exact permissions a role needs depend on the CloudExtend app and features your organization uses. Assign only the permissions required for the user’s workflow.


How CloudExtend Authentication Works

Users complete two authentication steps:

  1. Sign in to CloudExtend using their Microsoft or Google identity.

  2. Authorize CloudExtend to connect to a NetSuite account and role.

The Microsoft or Google email address must match the email address assigned to the user’s CloudExtend license.

The email address used for the CloudExtend license does not need to match the user’s NetSuite login email. After authentication, users can connect to multiple NetSuite accounts and roles and switch between their available connections.

CloudExtend supports NetSuite’s secure authorization flow, including accounts configured with:

  • Two-Factor Authentication

  • SAML Single Sign-On

  • Token-Based Authentication

  • Basic Credentials


Before You Begin

Confirm that the user has:

  • An active CloudExtend license

  • Access to the appropriate NetSuite account

  • Access to the NetSuite role they need to connect

  • The NetSuite account ID

  • A role that is not configured as Web Services Only

Find the NetSuite Account ID

Users can find the account ID in the NetSuite URL while signed in through a browser.

They can also follow this guide:


NetSuite Role and User Requirements

A NetSuite administrator must configure the role that the user will connect to CloudExtend.

In NetSuite, go to:

Setup → Users/Roles → Manage Roles

Locate the applicable role, click Edit, and review the following requirements.

Step 1: Verify That Web Services Only Is Disabled

The role must not be restricted to web services access.

  1. Open the applicable NetSuite role.

  2. Confirm that Web Services Only Role is disabled.

  3. Save the role if you make a change.

A Web Services Only role cannot complete the interactive CloudExtend authorization flow.

Step 2: Set Up NetSuite Shared Connection Permissions

Permission

Requirement

Purpose

SOAP Web Services

Required

Allows CloudExtend to communicate with NetSuite through supported APIs.

User Access Tokens

Required

Allows NetSuite to generate the access token used by the CloudExtend connection.

Log in using Access Tokens

Required for token authentication

Allows the role to authenticate using an access token.

SAML Single Sign-On

Conditional

Add only when the organization uses SAML SSO.

Allow JS/HTML Uploads

Conditional

Add when users need to upload .js or .htm files. This is not required for the initial connection.

REST Web Services

Global Autopilot only

Required for ExtendSync Outlook Global Autopilot API operations.

Do not add SAML Single Sign-On when the organization does not use SAML. Adding it unnecessarily can prevent users from completing the expected login flow.


ExtendSync Outlook and Google Permissions

The following permissions apply to ExtendSync features. They are not all required for ExtendInsights.

Step 1: Enable the user preference

Rich Text Editing

  1. In NetSuite, go to Home → Set Preferences.

  2. Enable Rich Text Editing.

  3. While not required, we have found that certain emails with HTML may transfer as blank or with all the HTML coding if this setting is not enabled at the user level. This may result in a NetSuite error, such as the field message containing more than the maximum number (1000000) of characters allowed.

Exclude Inactive Records from Search Results

  1. In NetSuite, go to Home → Set Preferences.

  1. Open the Analytics subtab.

  2. Locate Include Inactives in Global & Quick Search.

  3. Clear the checkbox.

  4. Save the preference.

Step 2: Set Email and File Permissions

Under Permissions → Lists, review the following permissions:

Permission

Details / Purpose

Documents and Files

Recommended for Global Autopilot and ExtendDocs users: Full

Minimum: Create

Track Messages

Recommended for Global Autopilot and ExtendDocs users: Full


Minimum: Create

Global Autopilot Permissions (Outlook)

Global Autopilot is available with ExtendSync Outlook Enterprise.

Under Permissions → Setup, add:

  • REST Web Services

Under Permissions → Lists, review:

Permission

Details / Purpose

Contacts

Recommended for Global Autopilot Auto-Create Contact feature

Required for Contact matching

Customers

Recommended for Global Autopilot

Required for Customer matching

Vendors

Recommended for Global Autopilot

Required for Vendor matching

The role must have access to each record type that Global Autopilot needs to search, match, or create.

Send from Outlook Permission

For users who use Send from Outlook, open the role’s Permissions → Custom Record subtab and add:

Permission

Details / Purpose

Celigo Send from Outlook Email Config

Recommended for Send from Outlook users: Full


Custom Field Permissions

If your organization uses custom NetSuite fields, the connected role must have access to those fields.

Use the applicable guide:

Custom field access is separate from the permissions needed to establish the NetSuite connection.


Custom Record and Transaction Type Permissions

As of NetSuite 2026.2, NetSuite strictly enforces permissions when CloudExtend retrieves custom record type and custom transaction type metadata.

Under Permissions → Setup, add:

Permission

Minimum level

Custom Record Types

View

Custom Transaction Types

View

These permissions are required when ExtendSync or ExtendInsights needs to retrieve the corresponding custom metadata.

Without them:

  • Custom record types may be missing from CloudExtend.

  • Custom transaction types may be unavailable when building templates.

  • Fields associated with those record types may be missing.

  • Earlier app versions may display:

    Errors were reported while looking up record types on this account.

Current app versions may omit the affected record types without displaying a warning.

For complete troubleshooting steps, see:


Connect CloudExtend to NetSuite

After the NetSuite administrator configures the role, the end user can create the connection.

  1. Go to Menu and select Connection.

  2. Click Add, then enter your NetSuite account ID and click Connect to NetSuite.
    ➡️ Learn how to find your NetSuite account ID here.

  3. Enter your NetSuite credentials. Select the role you want to log in with and hit Allow.

  4. Click Yes. Now, you have a new connection in CloudExtend.

🚨 IMPORTANT

You will be logged out of your current NetSuite session the first time you log in. Don't worry, though; once logged in, you'll be able to have both sessions active at the same time. As long as you don't log out of CloudExtend, you won't need to enter your credentials again, even if your password expires.


Common Errors

Cannot Continue This Authorization Flow

The following error indicates that the role cannot complete the NetSuite authorization process:

Cannot continue this authorization flow. Your current role has insufficient permission.

The role usually does not have the required User Access Tokens permission.

A NetSuite administrator should:

  1. Go to Setup → Users/Roles → Manage Roles.

  2. Edit the applicable role.

  3. Open Permissions → Setup.

  4. Add User Access Tokens.

  5. Save the role.

  6. Ask the user to retry the connection.

For more information, see:

Unexpected Two-Factor Authentication Prompt

NetSuite requires two-factor authentication when a role contains certain elevated permissions. This behavior is controlled by NetSuite.

If users receive an unexpected 2FA prompt, review the permissions assigned to their role.

See NetSuite’s documentation for the complete list:


Best Practices

  • Create permissions based on the CloudExtend app and features each user needs.

  • Avoid assigning feature-specific permissions to users who do not use those features.

  • Test the configuration with the same NetSuite role the user will connect.

  • Allow up to 30 minutes for NetSuite role permission changes to take effect.

  • Refresh the CloudExtend connection or record type list after changing role permissions.

  • Review role permissions whenever your organization enables a new CloudExtend feature.


Need Help?

If users still cannot connect after the role is updated, contact CloudExtend Support at cloudextend-support@celigo.com.

Include:

  • The CloudExtend app being used

  • The NetSuite account ID

  • The connected NetSuite role

  • The exact error message

  • A screenshot of the role’s relevant permission subtabs

  • The feature or action the user is trying to access

Did this answer your question?