Buyer guide

Simplifying and securing document attachments in ERP systems

ERP attachments (supplier invoices, receipts, contracts, delivery notes, employee documents) are business records, and many contain personal or financial information. Keep them simple by attaching them to the right transaction with consistent rules, and keep them secure with role-based access, protected storage, retention rules and tested backups.

The short answer

Most ERP systems, whether Sage X3, ERPNext, NetSuite or another platform, let users attach files to records such as purchase orders, invoices, journal entries, items and employees. Over time, attachments become a second, unmanaged document store: duplicates, unclear names, oversized scans, files visible to more people than necessary and no retention rules.

To simplify: agree what gets attached where, name and type files consistently, and attach documents to the transaction they support. To secure: control access by role, protect the storage behind the ERP, scan uploads, keep records for the required period and include attachments in backups you have actually restored.

Why attachments matter

Attachments are often the evidence behind your accounting entries: the supplier invoice behind a payable, the receipt behind an expense claim, the signed contract behind a recurring bill. Auditors and the Canada Revenue Agency may ask for them. Many also contain personal information (employee records, customer identification, banking details) that privacy laws require you to protect.

Common problems

  • Scattered documents. Some files in the ERP, some in email, some on a shared drive, so nobody is sure which copy is authoritative.
  • Wrong record. A supplier invoice attached to the supplier rather than to the specific purchase invoice it supports.
  • Access too broad. Payroll or HR documents visible to anyone who can open a related record.
  • Large or unreadable files. Phone photos of receipts at full resolution, or scans that are too faint to read.
  • No retention rules. Files kept forever, or deleted too early.
  • Backups that skip files. Database backups that do not include the file store.

Simplifying attachments

1. Define an attachment policy. List the documents you attach (supplier invoices, receipts, contracts, delivery notes, certificates, employee documents) and the ERP record each belongs to. Attach to the transaction, not the master record, unless the document applies to all transactions (for example, a supplier's banking confirmation or insurance certificate).

2. Use consistent names and formats. For example: document type, counterparty, number and date. Prefer PDF for documents and compressed images for photos. Some platforms help: Frappe, the framework ERPNext runs on, can optimize uploaded images and lets administrators limit the number of attachments per document type (Frappe).

3. Capture at the source. Let staff attach receipts from a phone when submitting an expense, and let accounts payable attach supplier invoices as they enter them. Automated capture (email-in or OCR) can reduce re-keying, but check its accuracy before trusting it.

4. Stop parallel stores. Once the ERP is the agreed home for transaction documents, stop saving the same files to a shared drive "just in case".

Securing attachments

Access control. In many ERPs, attachments follow the permissions of the record they are attached to. In Frappe and ERPNext, anyone with read access to a document can access its attachments (Frappe), and permissions are managed through roles (ERPNext). That makes role design critical: if many people can read employee records, they can read the documents attached to them. Review roles for HR, payroll and banking information in particular.

Private storage. Confirm whether your platform stores files as private (served only to authorized users) or public (reachable by anyone with the link). Sensitive documents must never sit in publicly accessible folders or storage buckets. If files are stored in cloud object storage, check that the bucket blocks public access and is encrypted.

Upload controls. Restrict allowed file types, set sensible size limits and scan uploads for malware. Frappe, for example, applies a default per-file size limit that self-hosted administrators can adjust (Frappe).

Safeguards proportionate to sensitivity. PIPEDA requires organizations to protect personal information with safeguards appropriate to its sensitivity, using physical, organizational and technological measures (OPC). Identification documents, banking details and health information deserve the tightest access.

Audit trail. Enable logging of who uploaded, viewed, changed or deleted files where your platform supports it.

Retention, scanning and backups

The CRA generally requires records and supporting documents to be kept for six years from the end of the last tax year they relate to, at a place of business or residence in Canada unless it grants permission otherwise. Electronic records may be kept outside Canada if they are accessible from Canada and available to the CRA on request (CRA).

Records created electronically must be kept in electronically readable form. Paper documents may be imaged if the image is an accurate reproduction meant to replace the paper and significant details are not obscured; the CRA refers to Canadian General Standards Board standards for imaging, and if those cannot be met, originals must be kept. The CRA also expects backup copies on separate media (CRA). This is general information, not tax or legal advice; confirm requirements with your accountant.

Make sure your ERP backups include the file store as well as the database, keep at least one copy offline or immutable, and test that a restore brings back working attachments linked to the right records.

Attachment health check

  • We have a written list of which documents are attached to which ERP records.
  • File naming and format rules are documented and followed.
  • Sensitive documents are stored privately, never at public URLs.
  • Roles that can read HR, payroll and banking records have been reviewed.
  • Allowed file types and size limits are set; uploads are scanned.
  • Retention periods are agreed with our accountant.
  • Our scanning process meets the CRA's imaging expectations, or we keep originals.
  • Backups include attachments, and a restore has been tested.
  • Duplicate document stores (shared drives, inboxes) have been retired.

Limitations

Settings and storage options differ by ERP product, version and hosting model. Some organizations need a dedicated document management system linked to the ERP, especially for large volumes, engineering drawings or complex approval workflows.

Next step

We configure ERPNext and Prometheus with role design, private file storage, backups and retention in mind, and can customize and automate document capture. If attachments are part of a move to a new ERP, read preparing your data for migration.

Sources and further reading

Product capabilities and guidance change. These are the primary sources this article relies on, checked on the review date above.

  1. Attachments, Frappe Framework documentation
  2. Role Based Permissions, ERPNext documentation (Frappe)
  3. Acceptable format, imaging paper documents and backing up electronic files, Canada Revenue Agency
  4. Where to keep your records, for how long and how to request permission to destroy them early, Canada Revenue Agency
  5. PIPEDA Fair Information Principle 7, Safeguards, Office of the Privacy Commissioner of Canada

This article is general information, not legal, accounting or security advice for your specific situation. Examples are hypothetical unless stated otherwise.

Talk to Promatics

Get a straight answer for your situation

General advice only goes so far. Tell us about your environment and we will tell you what we would do, what it would cost and what to watch out for.

  • A named specialist who owns the outcome, not a chat window
  • Advice checked against your actual systems, contracts and risks
  • Written scope and costs in CAD before any work starts