Security and access
Last reviewed
CO2 Lab authenticates to NetSuite with certificate-based OAuth 2.0 (client credentials) and reads through a dedicated integration role your administrator controls. This page documents how it authenticates, the exact records and permission levels the role uses, and how access is granted and revoked.
At a glance
| NetSuite access | A role in your account with View access to agreed records |
|---|---|
| Authentication | OAuth 2.0 client credentials with a certificate-signed JWT |
| Credentials you share | Account, Client and Certificate IDs only |
| Tokens | Short-lived access tokens requested when the connector runs |
| Transport | HTTPS to NetSuite SuiteTalk REST and the RESTlet |
| Writes to NetSuite | None |
Certificate-based OAuth 2.0
An administrator maps CO2 Lab's public certificate to an integration record, user and role. Each connection is then authorised by a certificate-signed request rather than a stored secret, and the signing key never leaves CO2 Lab. The Account, Client and Certificate IDs you share cannot grant access without that key and the active mapping in your NetSuite account.
What the connector can see
| Area | Records | Data used | Why CO2 Lab reads them |
|---|---|---|---|
| Transactions | Vendor bills and credits | Transaction and line references, dates, signed amounts, accounts and vendors | Every spend line becomes an emissions estimate, and vendor credits net that spend back out so refunds and returns are not double counted |
| Accounting | Chart of accounts | Account code, name and type | The account on each line tells us what was bought, so we can map it to an emission factor |
| Accounting periods | Period identity and close status | The period places each line in the right reporting window | |
| Accounting book | The primary book, detected under Multi-Book Accounting | We read the primary book only, so Multi-Book accounts are not double counted | |
| Organisation | Subsidiaries and currency | Subsidiary tree, line subsidiary and permitted currencies | Subsidiaries define which entities sit inside your reporting boundary, and the currency lets us convert every amount into a single reporting currency |
| Dimensions | Items and dimensions | Quantity, unit, item attributes, vendor, location, department and class where present | Item quantities give measured activity, and the labels let you break your footprint down by vendor, site, department or class |
| Documents | Attached files | Permitted files attached to imported transactions | Invoices carry measured quantities such as kilowatt-hours and litres, which replace a spend-based estimate with the actual activity behind it |
Never reads employee and payroll records, customer records and sales orders, or bank account and payment details.
Permissions and access boundaries
See Connect NetSuite for the exact permissions, their levels, and what bounds each one.
Controlling and revoking access
Your NetSuite administrator controls all of these, without involving CO2 Lab:
- Permissions
- Which records the role can read
- Subsidiaries
- The OneWorld scope available to the role
- Certificate mapping
- The user and role that sign each request
- Invoice-file access
- Whether file access is on
To stop all imports, do any one of these:
- Revoke the OAuth 2.0 client credentials mapping.
- Disable the CO2 Lab integration record.
- Remove the CO2 Lab role from the mapped user.
To narrow rather than cut, remove individual permissions or subsidiaries. CO2 Lab can never widen the role's scope without a change you make.
Sandbox and production are separate
Production, sandbox and Release Preview are independent connections. Each needs its own Account ID, Certificate ID and authorisation. Credentials never carry across environments.