Approved reporting
Use only the saved searches or other reporting sources, formulas, filters, locations, and fields approved for the implementation.
NetSuite Scoreboard security
Security decisions depend on the customer's NetSuite account, reporting sources, fields, roles, display locations, hosting method, and agreed implementation. Xillix does not publish absolute guarantees.
Include only the approved fields needed to answer the scoreboard question for its intended audience.
NetSuite reporting access
Use only the saved searches or other reporting sources, formulas, filters, locations, and fields approved for the implementation.
Use the narrowest access appropriate for scheduled result collection and avoid broad administrative permissions when they are not required.
Do not place NetSuite credentials in a shared display, browser URL, public form, or other viewer-accessible location.
Confirm the customer-specific retrieval or transfer method, endpoint, access controls, and responsibilities before implementation.
Display access
Minimize sensitive detail, use approved labels, and mask or omit fields not appropriate for broad viewing.
Use denser or more sensitive information only when the display location, browser access, and intended viewers are approved.
Confirm display groups, URLs, access paths, network placement, device behavior, and audience before launch.
Show the latest available NetSuite snapshot time so viewers can interpret freshness without assuming real-time data.
Data lifecycle
Shared responsibilities
Share the intended NetSuite reporting, audience, display location, and sensitivity concerns so the security boundary can be scoped with the scoreboard.
Request a Security Review