Book a Check-up
For IT and admins

Security and access

Last reviewed

CO2 Lab authenticates to NetSuite with certificate-based OAuth 2.0 (client credentials) and reads through a dedicated integration role your administrator controls. This page documents how it authenticates, the exact records and permission levels the role uses, and how access is granted and revoked.

At a glance

NetSuite connector security facts
NetSuite accessA role in your account with View access to agreed records
AuthenticationOAuth 2.0 client credentials with a certificate-signed JWT
Credentials you shareAccount, Client and Certificate IDs only
TokensShort-lived access tokens requested when the connector runs
TransportHTTPS to NetSuite SuiteTalk REST and the RESTlet
Writes to NetSuiteNone

Certificate-based OAuth 2.0

An administrator maps CO2 Lab's public certificate to an integration record, user and role. Each connection is then authorised by a certificate-signed request rather than a stored secret, and the signing key never leaves CO2 Lab. The Account, Client and Certificate IDs you share cannot grant access without that key and the active mapping in your NetSuite account.

What the connector can see

NetSuite records read by the connector
AreaRecordsData usedWhy CO2 Lab reads them
TransactionsVendor bills and creditsTransaction and line references, dates, signed amounts, accounts and vendorsEvery spend line becomes an emissions estimate, and vendor credits net that spend back out so refunds and returns are not double counted
AccountingChart of accountsAccount code, name and typeThe account on each line tells us what was bought, so we can map it to an emission factor
Accounting periodsPeriod identity and close statusThe period places each line in the right reporting window
Accounting bookThe primary book, detected under Multi-Book AccountingWe read the primary book only, so Multi-Book accounts are not double counted
OrganisationSubsidiaries and currencySubsidiary tree, line subsidiary and permitted currenciesSubsidiaries define which entities sit inside your reporting boundary, and the currency lets us convert every amount into a single reporting currency
DimensionsItems and dimensionsQuantity, unit, item attributes, vendor, location, department and class where presentItem quantities give measured activity, and the labels let you break your footprint down by vendor, site, department or class
DocumentsAttached filesPermitted files attached to imported transactionsInvoices carry measured quantities such as kilowatt-hours and litres, which replace a spend-based estimate with the actual activity behind it

Never reads employee and payroll records, customer records and sales orders, or bank account and payment details.

Permissions and access boundaries

See Connect NetSuite for the exact permissions, their levels, and what bounds each one.

Controlling and revoking access

Your NetSuite administrator controls all of these, without involving CO2 Lab:

Permissions
Which records the role can read
Subsidiaries
The OneWorld scope available to the role
Certificate mapping
The user and role that sign each request
Invoice-file access
Whether file access is on

To stop all imports, do any one of these:

  • Revoke the OAuth 2.0 client credentials mapping.
  • Disable the CO2 Lab integration record.
  • Remove the CO2 Lab role from the mapped user.

To narrow rather than cut, remove individual permissions or subsidiaries. CO2 Lab can never widen the role's scope without a change you make.

Sandbox and production are separate

Production, sandbox and Release Preview are independent connections. Each needs its own Account ID, Certificate ID and authorisation. Credentials never carry across environments.