What it is
The role your NetSuite administrator builds so Tightly can read your account. Hand this page to them. When they have finished, they send back five values and the connection is made.
Tightly reads from NetSuite. The one thing its code can write back is a purchase order, and only where purchase-order sending is switched on for your NetSuite connection, NetSuite is your system of record, and Tightly has switched that write on for its own service; with that off, nothing is created, edited or deleted there. The permissions below are the reading role, so each sits at View except the Setup ones, which have no View level.
Why the list is what it is
Every read Tightly makes after the first handshake is a SuiteQL query. SuiteQL is gated by SuiteAnalytics Workbook, which NetSuite grants separately from REST Web Services. A role holding REST Web Services without SuiteAnalytics Workbook signs in, passes a record probe, and then fails on the first real read. Tightly tests for it at connect, so a role missing it is refused there rather than halfway through the first import.
Create the role
The menu paths on this page are NetSuite's own and can read slightly differently on your edition. Setup, then Users/Roles, then Manage Roles, then New. Name it something like Tightly Integration. It never signs in interactively, so a non-UI role is fine.
Setup permissions, each at Full:
| Permission | Why |
|---|---|
| REST Web Services | The route every call goes to |
| SuiteAnalytics Workbook | SuiteQL. Every read needs it, and it is the one most often missed |
| Log in using Access Tokens | Token-based authentication itself |
| User Access Tokens | So the token can be created against this role |
| Access Token Management | The token's lifecycle |
| Integration Application | The record holding the consumer key and secret |
Lists permissions, each at View:
| Permission | Why |
|---|---|
| Items | Products and variants, their vendors, and the parts of kits and assemblies |
| Locations | Your stock locations, and the first thing the connect test queries |
| Vendors | Suppliers, and the per-vendor minimum order quantity |
| Subsidiaries | Read on locations, orders, refunds and supplier links, single-subsidiary accounts included |
| Customers | Every sales order query joins it, and the connection checks read it |
| Perform Search | Paging through the result sets |
Transactions permissions, each at View:
| Permission | Why |
|---|---|
| Sales Order | Sales history and demand |
| Purchase Order | Open orders on the water, and how much of each line is received |
| Cash Refund | Refunds against cash sales, read as returns |
| Credit Memo | Refunds against invoices, read as returns |
| Item Receipt | Part of the recommended role; received quantities are read off the purchase order's own lines |
The role needs access to every subsidiary whose stock and sales you want planned. NetSuite can leave out of a query the rows a role cannot see without refusing it, so a subsidiary the role cannot see can be absent from Tightly with no error.
Turn on one feature
Setup, then Company, then Enable Features, then Items and Inventory, then Multiple Vendors.
Without it NetSuite does not answer for the vendor's minimum order quantity, so Tightly loads each supplier link without one and plans without it. The import still succeeds, so nobody is told.
Create the integration record and the token
- Setup, then Integration, then Manage Integrations, then New. Name it
Tightly. Tick Token-Based Authentication. Untick TBA Authorization Flow and both OAuth 2.0 boxes. Save. - NetSuite shows the consumer key and consumer secret once, on that screen only. Copy them now.
- Assign the role to the user the integration runs as: Setup, then Users/Roles, then Manage Users, then that user, then Access.
- Setup, then Users/Roles, then Access Tokens, then New. Pick the application, that user and that role. Save.
- NetSuite shows the token ID and token secret once, on that screen only. Copy them now.
The five values Tightly asks for
The account ID (1234567, or 1234567_SB1 for a sandbox), the consumer key, the consumer secret, the token ID and the token secret. They go into the NetSuite form in Tightly, and nothing else is needed.
If the connection is refused, Tightly's sentence for the refusal is printed under the form. A role missing SuiteAnalytics Workbook reads:
NetSuite accepted these credentials but refused the SuiteQL query every Tightly sync depends on. Enable the 'SuiteAnalytics Workbook' permission on this token's role (it is separate from 'REST Web Services') and test again.
A refusal naming the role means it is missing one of the rows above, and SuiteAnalytics Workbook is the first to check.
Configure purchasing mappings
Open Settings → Integrations → NetSuite. An administrator can configure each connection here.
- Subsidiaries & suppliers: select each purchasing subsidiary and its channels and warehouses, then Save mappings. Warehouse choices show verified NetSuite subsidiary ownership when available.
- Order settings: select named NetSuite currencies, receiving warehouses and, if needed, a default subsidiary. Search the warehouse list to find a location.
Match from NetSuite fills missing currency and warehouse mappings from verified source records. It preserves existing choices and stages changes for review; select Save settings to apply them. Unavailable saved mappings stay visible so they can be corrected.
Purchase-order exports remain separately controlled. Saving mappings does not send an order.