Buyer guide

Simplifying and securing document attachments in ERP systems

ERP attachments (supplier invoices, receipts, contracts, delivery notes, employee documents) are business records, and many contain personal or financial information. Keep them simple by attaching them to the right transaction with consistent rules, and keep them secure with role-based access, protected storage, retention rules and tested backups.

The short answer

Most ERP systems, whether Sage X3, ERPNext, NetSuite or another platform, let users attach files to records such as purchase orders, invoices, journal entries, items and employees. Over time, attachments become a second, unmanaged document store: duplicates, unclear names, oversized scans, files visible to more people than necessary and no retention rules.

To simplify: agree what gets attached where, name and type files consistently, and attach documents to the transaction they support. To secure: control access by role, protect the storage behind the ERP, scan uploads, keep records for the required period and include attachments in backups you have actually restored.

Why attachments matter

Attachments are often the evidence behind your accounting entries: the supplier invoice behind a payable, the receipt behind an expense claim, the signed contract behind a recurring bill. Auditors and the Nigeria Revenue Service (NRS) may ask for them. Many also contain personal data (employee records, customer identification, banking details) that the Nigeria Data Protection Act 2023 (NDPA) requires you to protect.

Common problems

  • Scattered documents. Some files in the ERP, some in email, some on a shared drive or in a WhatsApp chat, so nobody is sure which copy is authoritative.
  • Wrong record. A supplier invoice attached to the supplier rather than to the specific purchase invoice it supports.
  • Access too broad. Payroll or HR documents visible to anyone who can open a related record.
  • Large or unreadable files. Phone photos of receipts at full resolution, or scans that are too faint to read.
  • No retention rules. Files kept forever, or deleted too early.
  • Backups that skip files. Database backups that do not include the file store.

Simplifying attachments

1. Define an attachment policy. List the documents you attach (supplier invoices, receipts, contracts, delivery notes, certificates, employee documents) and the ERP record each belongs to. Attach to the transaction, not the master record, unless the document applies to all transactions (for example, a supplier's banking confirmation or insurance certificate).

2. Use consistent names and formats. For example: document type, counterparty, number and date. Prefer PDF for documents and compressed images for photos, which also helps staff uploading over slow mobile connections. Some platforms help: Frappe, the framework ERPNext runs on, can optimise uploaded images and lets administrators limit the number of attachments per document type (Frappe).

3. Capture at the source. Let staff attach receipts from a phone when submitting an expense, and let accounts payable attach supplier invoices as they enter them. Automated capture (email-in or OCR) can reduce re-keying, but check its accuracy before trusting it.

4. Stop parallel stores. Once the ERP is the agreed home for transaction documents, stop saving the same files to a shared drive "just in case".

Securing attachments

Access control. In many ERPs, attachments follow the permissions of the record they are attached to. In Frappe and ERPNext, anyone with read access to a document can access its attachments (Frappe), and permissions are managed through roles (ERPNext). That makes role design critical: if many people can read employee records, they can read the documents attached to them. Review roles for HR, payroll and banking information in particular.

Private storage. Confirm whether your platform stores files as private (served only to authorised users) or public (reachable by anyone with the link). Sensitive documents must never sit in publicly accessible folders or storage buckets. If files are stored in cloud object storage, check that the bucket blocks public access and is encrypted.

Upload controls. Restrict allowed file types, set sensible size limits and scan uploads for malware. Frappe, for example, applies a default per-file size limit that self-hosted administrators can adjust (Frappe).

Safeguards proportionate to sensitivity. The NDPA requires organisations to protect personal data with appropriate technical and organisational measures, proportionate to the risk (NDPC). Identification documents, banking details and health information deserve the tightest access. If the file store is hosted outside Nigeria, the NDPA's rules on transfers outside Nigeria also apply.

Audit trail. Enable logging of who uploaded, viewed, changed or deleted files where your platform supports it.

Retention, scanning and backups

Tax law, company law and sector rules all set minimum periods for keeping accounting records and supporting documents. The periods and the form in which records must be kept depend on your organisation and sector, so confirm them with your accountant and the Nigeria Revenue Service (or your state internal revenue service) rather than relying on a rule of thumb.

In general, records created electronically should be kept in a readable electronic form. Paper documents can be scanned only if the image is an accurate, legible reproduction and significant details are not obscured, so check with your accountant and auditor whether you must also keep the originals. Backup copies on separate media are good practice in any case. This is general information, not tax or legal advice.

Make sure your ERP backups include the file store as well as the database, keep at least one copy offline or immutable, and test that a restore brings back working attachments linked to the right records. Where power is unreliable, put the file server and backup storage on UPS or inverter supply so an outage does not corrupt files mid-write.

Attachment health check

  • We have a written list of which documents are attached to which ERP records.
  • File naming and format rules are documented and followed.
  • Sensitive documents are stored privately, never at public URLs.
  • Roles that can read HR, payroll and banking records have been reviewed.
  • Allowed file types and size limits are set; uploads are scanned.
  • Retention periods are agreed with our accountant.
  • Our scanning process meets our accountant's expectations, or we keep originals.
  • Backups include attachments, and a restore has been tested.
  • Duplicate document stores (shared drives, inboxes, chat groups) have been retired.

Limitations

Settings and storage options differ by ERP product, version and hosting model. Some organisations need a dedicated document management system linked to the ERP, especially for large volumes, engineering drawings or complex approval workflows.

Next step

We configure ERPNext and Prometheus with role design, private file storage, backups and retention in mind, and can customise and automate document capture. If attachments are part of a move to a new ERP, read preparing your data for migration.

Sources and further reading

Product capabilities and guidance change. These are the primary sources this article relies on, checked on the review date above.

  1. Attachments, Frappe Framework documentation
  2. Role Based Permissions, ERPNext documentation (Frappe)
  3. Nigeria Data Protection Act 2023 and guidance on security of personal data, Nigeria Data Protection Commission

This article is general information, not legal, accounting or security advice for your specific situation. Examples are hypothetical unless stated otherwise.

Talk to Promatics

Get a straight answer for your situation

General advice only goes so far. Tell us about your environment and we will tell you what we would do, what it would cost and what to watch out for.

  • A named specialist who owns the outcome, not a chat window
  • Advice checked against your actual systems, contracts and risks
  • Written scope and costs in NGN before any work starts