Skip to content

NetSuite ​

AEVU imports from NetSuite so that the project register and finance never disagree. It reads a saved search that you or your finance team own in NetSuite. Each project arrives together with the client it is billed to.

Who does this: a workspace administrator with Manage settings, together with a NetSuite administrator. The organisation must allow NetSuite (Organization → Integrations → NetSuite) and your plan must include it (Enterprise).

Settings → Connections with the NetSuite form open, showing the Account ID, consumer key, consumer secret and token fields

What gets imported ​

  • Projects from the saved search, with the client each is billed to. NetSuite sub-customers are collapsed into one client, so a health authority with thirty sub-accounts is one client in AEVU.
  • Projects are matched on their NetSuite project code (the entityId), and clients on the parent customer name, so importing twice updates rather than duplicates. On a re-import AEVU changes only a project's name and its client link, and a client's name. Everything else you maintain in AEVU is left alone.
  • Customers and vendors are not imported as separate lists. Clients arrive only as the client of an imported project. (The organisation policy toggle still reads NetSuite customer and vendor sync; it is the same switch.)
  • A new project starts at Initiation. After that its stage, status and portfolio belong to AEVU and no import moves them back.
  • Import runs on demand (Import now) or nightly at 02:00 UTC.

Technical note

AEVU connects over NetSuite SuiteTalk SOAP (WSDL 2025.2) with token-based authentication (a signed token passport, HMAC-SHA256). The role behind the token needs SOAP Web Services permissions, not the REST permissions.

Step 1. Prepare NetSuite ​

Ask a NetSuite administrator to do the following. Menu names can vary slightly by NetSuite version.

Vendor menus may change

NetSuite renames menus between releases. The values AEVU needs (SOAP Web Services and token-based authentication, the role permissions, the saved search script ID) stay the same.

  1. Enable features. Setup → Company → Enable Features → SuiteCloud: tick SOAP Web Services and Token-Based Authentication, then Save.
  2. Create an integration record. Setup → Integration → Manage Integrations → New. Give it a name such as AEVU, tick Token-Based Authentication, untick the user-credential options, and Save. NetSuite shows the Consumer Key and Consumer Secret once. Copy them now.
  3. Create a role (or use an existing one) with the permissions SOAP Web Services and Log in using Access Tokens, plus view access to the records your saved search reads.
  4. Assign the role to the user that will own the token.
  5. Create an access token. Setup → Users/Roles → Access Tokens → New. Choose the integration record, the user and the role. Save, then copy the Token ID and Token Secret once.
  6. Find your Account ID. Setup → Company → Company Information. It looks like 1234567, or 1234567_SB1 for a sandbox.
  7. Create (or choose) the project saved search. It is a Project (Job) saved search that joins the customer, and it must return the project's ID and name, its start date, and the customer's ID, name, address and web address (AEVU reads the columns entityId, altName, the customer join's entityId, altName, address and url). Note its script ID, for example customsearch1106. Pointing at their saved search lets finance decide what is in scope and change it in NetSuite without anyone editing AEVU.

Account ID shapes

The Account ID appears in two shapes: lower-case with hyphens in the web address (1234567-sb1) and upper-case with underscores in the sign-in realm (1234567_SB1). AEVU lower-cases the Account ID and swaps underscores for hyphens to reach <account>.suitetalk.api.netsuite.com (the form shows the host it will call). Enter the form shown in Company Information (1234567_SB1).

Step 2. Enter the details in AEVU ​

  1. Open Settings → Connections, find the NetSuite row and choose Configure.
  2. Fill in:
FieldValue
Account IDFrom Step 1.6
Consumer key / Consumer secretFrom the integration record
Token ID / Token secretFrom the access token
Project saved searchThe saved search script ID, e.g. customsearch1106
Only codes beginningOptional filter, e.g. INF-, that you can change without editing a search others rely on
Connection is onNeeded before importing
Import every nightRuns at 02:00 UTC. Off by default so the first import is one somebody watched
  1. Save, then Test connection. Fix any message before relying on it.
  2. Choose Import now for the first run and read the result: a summary, any skipped rows (listed, not hidden), and a note if the search had more pages than one run reads.

Rotating credentials ​

Create a new access token in NetSuite, paste the new Token ID and Token secret (dots with Replace), and Save. Empty fields keep what is stored. Old values can never be read back.

Disconnect ​

Disconnect discards the stored token and stops imports. Clients and projects already imported stay as they are.

Common errors ​

SymptomLikely cause
Authentication failed on TestA wrong key, secret, token, or Account ID shape; or the role lacks SOAP Web Services / Log in using Access Tokens
Couldn't reach NetSuiteWrong Account ID, or the AEVU server cannot reach NetSuite
Import now is disabledConnection is on is off
Some rows listed as skippedA row with no project code, a project with no name, or a code AEVU cannot file because another project already uses it; fix them in the saved search or in AEVU
credentials.unreadableThe server cannot decrypt the stored secret (shown for a test job); re-enter the credentials
Test refused: capabilityThe organisation or workspace has NetSuite off

Security ​

Credentials are encrypted at rest, never shown again, and AEVU refuses a secret that equals your own AEVU password. Saves are rate limited. Every save, test, import and disconnect is audited.

INFO

Import is not queued as a background job: Import now runs while you wait, and the nightly run is separate. Avoid pressing it around 02:00 UTC.

AEVU documentation