Skip to content

Oracle NetSuite is a full ERP. Connecting it gives Eagl your general ledger and the context around it.

  • GL accounts and your chart of accounts
  • Transactions and posting detail
  • Cost centers and projects
  • Documents attached in NetSuite

This powers reporting, drill-down, and serves as a reconciliation source.

NetSuite uses token-based authentication (TBA). Connecting is a one-time setup in NetSuite that produces four credentials you’ll paste into Eagl:

  • Account ID
  • Consumer Key and Consumer Secret
  • Token ID and Token Secret

You’ll need the Administrator role in NetSuite to complete the steps below.

Before connecting NetSuite, create and sign in to your Eagl account.

Go to app.eagl.finance and sign in with Google, Microsoft, or an email and password. If you don’t have an account yet, one is created the first time you sign in. For help reaching an existing organization, contact your administrator or support@geteagl.com.

The Eagl sign-in page, with Google, Microsoft, and email options.

Connecting takes the four credentials produced by the NetSuite setup below. Once you have them (see Set up NetSuite), connect the integration in Eagl.

  1. In Eagl, go to Settings → Integrations and click Connect on NetSuite.

    The Eagl integrations settings page with the NetSuite Connect button.

  2. Enter your Account ID, Consumer Key/Secret, and Token ID/Secret. You’ll find your Account ID at the start of your NetSuite URL. For https://1234567.app.netsuite.com/, the Account ID is 1234567.

  3. Click Connect.

  1. Log in as Administrator.

    Make sure you’re signed in with a NetSuite account that has the Administrator role.

  2. Enable Web Services.

    Go to Setup → Company → Enable Features.

    The Setup menu path to Enable Features in NetSuite.

    Open the SuiteCloud tab.

    The SuiteCloud tab on the Enable Features page.

    Under SuiteTalk (Web Services), toggle on REST Web Services and SOAP Web Services.

    The SuiteTalk (Web Services) section with REST and SOAP Web Services toggled on.

    Then scroll to Manage Authentication and make sure Token-Based Authentication is toggled on. Save.

    The Manage Authentication section with Token-Based Authentication enabled.

  3. Create the integration role.

    Go to Setup → Users/Roles → Manage Roles → New.

    Creating a new role under Manage Roles in NetSuite.

    Give the role these details:

    • Name: Integration Role for Eagl
    • ID: eagl
    • Center Type: Accounting Center

    The new role with its name, ID, and Accounting Center type set.

    Select the subsidiaries that should be accessible by Eagl.

    Selecting the subsidiaries accessible to the integration role.

    Select all accounting books (if your account has more than one).

    Selecting all accounting books for the integration role.

    Under Authentication, toggle Web Services Only Role on.

    The Authentication section with Web Services Only Role enabled.

    Then open the Permissions tab and grant the access listed under Role permissions below. Save.

  4. Assign the role to a user.

    Go to Lists → Employees → Employees and open (or create) the user record Eagl will connect as. On the Access tab → Roles sub-tab, select Integration Role for Eagl, click Add, then Save.

  5. Create the integration record.

    Go to Setup → Integration → Manage Integrations → New.

    Creating a new integration record under Manage Integrations.

    Enter a name (e.g. Integration for Eagl) and set State to Enabled.

    The integration record with a name entered and State set to Enabled.

    On the Authentication tab, toggle Token-Based Authentication → Enable on. Do not enable Authorization Flow or Authorization Code Grant.

    The Authentication tab with Token-Based Authentication enabled and the OAuth flows left off.

    Save, then scroll to the bottom and copy the Consumer Key and Consumer Secret.

    The Consumer Key and Consumer Secret shown once at the bottom of the saved integration record.

  6. Generate an access token.

    Go to Setup → Users/Roles → Access Tokens → New and select:

    • Application Name: the integration you just created
    • User: the user you assigned the role to
    • Role: Integration Role for Eagl

    Creating a new access token with the application, user, and role selected.

    Save, then copy the Token ID and Token Secret.

On the integration role’s Permissions tab, grant the access below. These give Eagl read access to your ledger and reporting data, the write access it needs to post corrections and accruals (journal entries and vendor bills/credits) and to record cash applications (customer and bill payments), plus the access tokens and File Cabinet permissions it uses to sync documents.

Grant at least View on every Transaction permission, and Full on the ones Eagl writes to:

PermissionLevelReason
All other Transaction permissionsViewSyncing your ledger. Eagl reads every posted transaction for reporting, reconciliation, the agents, and open invoices and bills. NetSuite leaves out any transaction type the role can’t view, so a missing permission means missing transactions in Eagl.
BillsFullCorrective actions and deferrals: Eagl corrects the account, class, location and department on vendor bill lines, and sets up amortization schedules on them.
Enter Vendor CreditsFullCorrective actions and deferrals: the same line corrections and amortization schedules on vendor credits.
Make Journal EntryFullAccruals and corrective actions: Eagl books accruals and their reversals as journal entries, and corrects journal lines.
Customer PaymentFullCash application: Eagl records the customer payment that applies a bank receipt to the invoices it pays.
Pay BillsFullCash application: Eagl records the bill payment for a direct debit or bank transfer made outside your payment runs.

If corrections get blocked by a workflow lock, see Workflow record locks.

PermissionLevel
SuiteAnalytics WorkbookEdit
Account DetailView
Accounts PayableView
Accounts ReceivableView
Accounts Receivable Un-BilledView
Amortization ReportsView
Balance SheetView
BudgetView
Consolidated ReportingView
Deferred Expense ReportsView
ExpensesView
Financial StatementsView
General LedgerView
Granting access to ReportsView
IncomeView
InventoryView
Net WorthView
Period End Financial StatementsView
Profit and LossView
PurchasesView
Sales Order Transaction ReportView
TaxView
Transaction DetailView
Trial BalanceView
PermissionLevel
AccountsView
Amortization SchedulesFull
Business UnitsView
ClassesView
ContactsView
Cost of Goods Sold RegistersView
CurrencyView
CustomersView
DepartmentView
Documents and FilesFull
EmployeesView
Financial HistoryView
Fixed Asset RegistersView
ItemsView
LocationsView
Memorized TransactionsView
Other Asset RegistersView
Other Current Asset RegistersView
Other Current Liability RegistersView
Other Expense RegistersView
Other Income RegistersView
ProjectsView
SubsidiariesView
System Notes for Analytics and RESTView
Tax SchedulesView
Tax RecordsView
VendorsView
PermissionLevel
Deleted RecordsView
Log in using Access TokensFull
REST Web ServicesFull
SOAP Web ServicesFull
User Access TokensFull
Manage Accounting PeriodsView

If your account has an e-invoice custom record (for example, one managed by Novutech or a similar provider), grant it Full access.

A custom record permission set to Full access on the integration role.

Setting Documents and Files → Full gives the role access to the File Cabinet, but individual folders can still carry restrictions that block Eagl from the files inside them.

Identify the folders Eagl’s agents will need (those containing invoices, bank statements, and similar source documents), and grant access ahead of onboarding for a smooth start. We’ll reach out directly if something is still missing.

To grant access to a folder (e.g. “Folder X”):

  1. Go to Documents → Documents Overview and open Folder X.

  2. Click Edit and note the restrictions. Restrict by group is the most common one we see.

  3. Grant your integration role access. How you do this depends on your security model:

    • Dynamic group (members generated from a saved search, e.g. groups named … loc: <Location>): open the integration employee record under Lists → Employees → Employees, click Edit, add the relevant Location to the Location Folder Access field, and Save. The employee then qualifies for the group automatically.
    • Static group: open the group, go to the Members sub-tab, add the integration employee, and Save.
  4. Confirm the integration employee now appears on the group’s Members sub-tab.

Some accounts run an approval workflow with a Lock Record action on transactions. If that action doesn’t restrict its context, it locks the record in every context — including the REST API Eagl uses to post corrections. When this happens, corrections fail with:

This record has been locked by a user defined workflow.

The lock can’t be bypassed from the API; it has to be narrowed in the workflow itself. This only affects accounts that lock transactions this way — if you don’t use a Lock Record action, you can skip this.

  1. Go to Customization → Workflow → Workflows and open the approval workflow that locks the transaction.

  2. Check every state for a Lock Record action. It commonly sits on Pending Approval and Approved, sometimes both, so review all of them.

  3. Open each Lock Record action and set Context Types to only the contexts you want locked. Keep User Interface, and leave out REST Web Services and Web Services. A blank value means all contexts, which is what causes the block.

  4. Save each action, then re-book a correction to confirm it goes through.

The record stays locked for normal users in the UI, while API integrations like Eagl can still post corrections.