Skip to main content
    Best Practices

    Connecting AI to NetSuite? Read This First.

    Why AI governance matters more than you think.

    Yiting Sun
    Yiting Sun
    The Doctor

    With official NetSuite connectors now available in platforms like ChatGPT and Claude, connecting your ERP to AI is easier than ever. Finance teams are using it to summarize reports, answer operational questions, explain transactions, and surface trends that once required saved searches or custom reports. Users can now interact with their ERP system in entirely new ways. Instead of spending fifteen minutes building a saved search to answer every business question, they can simply ask those questions in natural language:

    • "Show me customers with overdue invoices."
    • "Summarize last month's sales by subsidiary."
    • "Analyze inventory trends for this product line."

    Faster access to accurate information gives your user community an extra gear. AI can become a virtual consultant that helps users retrieve data faster, identify trends, explain transactions, and make better business decisions.

    That’s great for productivity, but it also introduces a new governance challenge: employees may be connecting to your ERP through personal AI accounts that IT doesn’t know exist.

    As consultants, we love seeing NetSuite become more accessible and users more productive. But it’s important to know:

    Who is connecting AI to your NetSuite environment, and how?

    The Easy Button for Creating Information Security Risks

    Both ChatGPT and Claude now include ready-to-use NetSuite applications. These connectors are available in business and enterprise AI subscriptions, as well as in free, personal accounts.

    From the user's perspective, connecting to NetSuite is remarkably simple. After selecting the NetSuite connector, the AI platform guides them through a few prompts and establishes the connection within seconds. Behind the scenes, NetSuite automatically creates a new Integration Record.

    At first glance, everything appears normal. However, several characteristics of these native connectors make them difficult to distinguish from company-approved integrations:

    • The Integration Record is created automatically.
    • It uses a generic name such as "ChatGPT" or "Claude AI."
    • No Client ID or Client Secret is required for the generic connection.
    • NetSuite does not automatically notify administrators when these integrations are created.

    None of these behaviors are necessarily wrong; they're designed to make setup easy. But together, they reduce visibility into how AI is connecting to your ERP and increase the risk of your data being used to train LLMs.

    Ill Intent Not Required

    One of the most interesting behaviors we observe is how seamless the connection process has become. If a user is already authenticated to NetSuite through Single Sign-On (SSO) in the same browser session, the connector can often leverage that existing authenticated session. From the user's perspective, there may be no indication that a new integration has just been established.

    Consider the following.

    An employee regularly uses the company’s ChatGPT Business account to help interpret NetSuite data. One afternoon, they’re logged into a personal ChatGPT account – so when they open the NetSuite connector, they’re prompted to connect again. It looks routine, so they click through the setup. Within a minute, they’ve authorized their personal AI account to access company ERP data, and may have no idea they’ve done anything different.

    Meanwhile, the NetSuite administrator isn’t notified that a new AI account has been authorized. Because the connection uses the existing NetSuite user's credentials and the same Integration Record, the API activity appears to come from the employee's legitimate NetSuite account. From an administrator's perspective, nothing immediately stands out as unusual.

    Nobody intended to create a security issue. The employee simply believed they were reconnecting a tool they had already been using. The administrator wasn't aware it happened. But now OpenAI may be your company’s data to train its models.

    Our Recommendation: Create One Approved Path

    Rather than allowing everyone to use the native connector, we recommend creating a single, company-approved, custom connection for users, and driving AI traffic through that connection.

    Our recommended approach is:

    0. Confirm Role Permissions

    It’s important to note that AI connectors don’t automatically bypass NetSuite’s existing permissions. They operate using the permissions of the authenticated NetSuite user. That means the AI cannot see information the user normally couldn’t access. If your users don’t have permission to create new integration records in NetSuite (and most of them shouldn’t), then the approach below is just about airtight.

    The AI connection inherits everything that user’s role already allows.

    1. Create a Custom Connector in Your AI Business Account

    Instead of relying on the native NetSuite app inside the AI platform, create a custom connector for your organization. This allows the business to define exactly how AI should connect to NetSuite while maintaining greater administrative control.

    2. Create a Clearly Named Integration Record in NetSuite

    Rather than allowing Integration Records with generic names such as "ChatGPT" or "Claude AI," create a custom Integration Record with a meaningful name, such as:

    • Company ABC | ChatGPT Integration
    • Company ABC | Claude Connection

    A descriptive name makes it immediately obvious which connections are company-approved.

    For ChatGPT, a custom connector does not require a Client ID or Client Secret. Claude currently requires these credentials when configuring a custom connector.

    3. Disable the Native Connector in the Business AI Account

    If your organization provides ChatGPT Business or Claude for Enterprise, consider disabling the native NetSuite App within those AI platforms. This encourages users to connect only through the approved company connector, ensuring all AI access follows the same governance process.

    4. Block Generic Native Integrations in NetSuite

    As an additional safeguard, you can intentionally establish the native NetSuite connection once, allow the generic Integration Record to be created, and then block that record within NetSuite. Doing so helps prevent users from creating unmanaged AI connections through the native application.

    5. Periodically Review Your Integration Records in NetSuite

    Just as organizations periodically review roles, permissions, and integrations, AI connections should become part of regular system governance. A simple quarterly review can quickly identify new integrations that deserve further investigation.

    If you’d prefer an administrator be notified immediately, create a MapReduce scripted notification on the Integration record to notify on new generic AI connections. This will enable the administrator to capture the unauthorized connection as soon as possible.

    Governance Enables Innovation

    AI will enable the most valuable productivity tools ever introduced to the NetSuite ecosystem. By creating an approved connector for employees, you establish a NetSuite environment that the business can understand, manage, and trust where employees can thrive.