NetSuite Scoreboard security

Approve the data, audience, and display boundary before the scoreboard goes live.

Security decisions depend on the customer's NetSuite account, reporting sources, fields, roles, display locations, hosting method, and agreed implementation. Xillix does not publish absolute guarantees.

Start with data minimization.

Include only the approved fields needed to answer the scoreboard question for its intended audience.

NetSuite reporting access

Keep source access narrow and customer-approved.

Approved reporting

Use only the saved searches or other reporting sources, formulas, filters, locations, and fields approved for the implementation.

Least privilege

Use the narrowest access appropriate for scheduled result collection and avoid broad administrative permissions when they are not required.

Credential handling

Do not place NetSuite credentials in a shared display, browser URL, public form, or other viewer-accessible location.

Secure transmission

Confirm the customer-specific retrieval or transfer method, endpoint, access controls, and responsibilities before implementation.

Display access

A public-floor screen and a management view should not be treated alike.

Public-floor view

Minimize sensitive detail, use approved labels, and mask or omit fields not appropriate for broad viewing.

Management view

Use denser or more sensitive information only when the display location, browser access, and intended viewers are approved.

Customer-specific configuration

Confirm display groups, URLs, access paths, network placement, device behavior, and audience before launch.

Data-as-of timestamp

Show the latest available NetSuite snapshot time so viewers can interpret freshness without assuming real-time data.

Data lifecycle

Retention and deletion depend on the implemented data path.

Current resultsRetain only what the active scoreboard and agreed operations require.
Historical snapshotsDo not assume retention exists; include it only when available and specifically scoped.
End of scopeConfirm customer-specific export, deletion, access removal, and transition responsibilities.

Shared responsibilities

Security requires decisions on both sides of the implementation.

Xillix responsibilities

  • Document the implemented data and display path
  • Use approved fields and access within the agreed scope
  • Surface assumptions and environment-specific decisions
  • Maintain only the controls and checks included in the implementation

Customer responsibilities

  • Approve reporting sources, fields, roles, locations, and audiences
  • Protect NetSuite credentials and manage source-system access
  • Control physical and network access to display devices
  • Notify Xillix of relevant reporting, role, workflow, or audience changes

Review the fields and the screen before deployment.

Share the intended NetSuite reporting, audience, display location, and sensitivity concerns so the security boundary can be scoped with the scoreboard.

Request a Security Review