The short answer
Most ERP systems, whether Sage X3, ERPNext, NetSuite or another platform, let users attach files to records such as purchase orders, invoices, journal entries, items and employees. Over time, attachments become a second, unmanaged document store: duplicates, unclear names, oversized scans, files visible to more people than necessary and no retention rules.
To simplify: agree what gets attached where, name and type files consistently, and attach documents to the transaction they support. To secure: control access by role, protect the storage behind the ERP, scan uploads, keep records for the required period and include attachments in backups you have actually restored.
Why attachments matter
Attachments are often the evidence behind your accounting entries: the vendor invoice behind a payable, the receipt behind an expense claim, the signed contract behind a recurring bill. Auditors, the IRS and state tax agencies may ask for them. Many also contain personal information (employee records, customer identification, banking details) that privacy and security laws require you to protect.
Common problems
- Scattered documents. Some files in the ERP, some in email, some on a shared drive, so nobody is sure which copy is authoritative.
- Wrong record. A vendor invoice attached to the supplier rather than to the specific purchase invoice it supports.
- Access too broad. Payroll or HR documents visible to anyone who can open a related record.
- Large or unreadable files. Phone photos of receipts at full resolution, or scans that are too faint to read.
- No retention rules. Files kept forever, or deleted too early.
- Backups that skip files. Database backups that do not include the file store.
Simplifying attachments
1. Define an attachment policy. List the documents you attach (vendor invoices, receipts, contracts, delivery notes, certificates, employee documents) and the ERP record each belongs to. Attach to the transaction, not the master record, unless the document applies to all transactions (for example, a vendor's banking confirmation or insurance certificate).
2. Use consistent names and formats. For example: document type, counterparty, number and date. Prefer PDF for documents and compressed images for photos. Some platforms help: Frappe, the framework ERPNext runs on, can optimize uploaded images and lets administrators limit the number of attachments per document type (Frappe).
3. Capture at the source. Let staff attach receipts from a phone when submitting an expense, and let accounts payable attach vendor invoices as they enter them. Automated capture (email-in or OCR) can reduce re-keying, but check its accuracy before trusting it.
4. Stop parallel stores. Once the ERP is the agreed home for transaction documents, stop saving the same files to a shared drive "just in case".
Securing attachments
Access control. In many ERPs, attachments follow the permissions of the record they are attached to. In Frappe and ERPNext, anyone with read access to a document can access its attachments (Frappe), and permissions are managed through roles (ERPNext). That makes role design critical: if many people can read employee records, they can read the documents attached to them. Review roles for HR, payroll and banking information in particular.
Private storage. Confirm whether your platform stores files as private (served only to authorized users) or public (reachable by anyone with the link). Sensitive documents must never sit in publicly accessible folders or storage buckets. If files are stored in cloud object storage, check that the bucket blocks public access and is encrypted.
Upload controls. Restrict allowed file types, set sensible size limits and scan uploads for malware. Frappe, for example, applies a default per-file size limit that self-hosted administrators can adjust (Frappe).
Safeguards proportionate to sensitivity. The US has no single federal privacy law, but the expectation is consistent: the FTC treats failure to protect personal data with reasonable security as a potential unfair practice, state privacy and breach laws expect reasonable safeguards, and sector rules such as the HIPAA Security Rule and the GLBA Safeguards Rule set specific requirements (FTC). Identification documents, banking details and health information deserve the tightest access.
Audit trail. Enable logging of who uploaded, viewed, changed or deleted files where your platform supports it.
Retention, scanning and backups
IRS recordkeeping guidance generally ties how long you keep tax records to the period in which a return can be examined or amended, which is commonly three years from filing but longer in some situations, and certain employment tax records must be kept for at least four years. State tax agencies, payroll and employment laws (including Form I-9 retention) and contracts can set different periods, so the safe approach is to agree a retention schedule with your accountant and counsel (IRS).
Records created electronically should be kept in a form that can be read and reproduced on request. Paper documents may generally be imaged and the originals destroyed if the images are legible, accurately reproduce the originals, are indexed so they can be found and can be printed when an examiner asks. Where those conditions cannot be met, keep the originals. Keep backup copies on separate media. This is general information, not tax or legal advice; confirm requirements with your accountant.
Make sure your ERP backups include the file store as well as the database, keep at least one copy offline or immutable, and test that a restore brings back working attachments linked to the right records.
Attachment health check
- We have a written list of which documents are attached to which ERP records.
- File naming and format rules are documented and followed.
- Sensitive documents are stored privately, never at public URLs.
- Roles that can read HR, payroll and banking records have been reviewed.
- Allowed file types and size limits are set; uploads are scanned.
- Retention periods are agreed with our accountant.
- Our scanning process meets IRS expectations for electronic records, or we keep originals.
- Backups include attachments, and a restore has been tested.
- Duplicate document stores (shared drives, inboxes) have been retired.
Limitations
Settings and storage options differ by ERP product, version and hosting model. Some organizations need a dedicated document management system linked to the ERP, especially for large volumes, engineering drawings or complex approval workflows.
Next step
We configure ERPNext and Prometheus with role design, private file storage, backups and retention in mind, and can customize and automate document capture. If attachments are part of a move to a new ERP, read preparing your data for migration.
Sources and further reading
Product capabilities and guidance change. These are the primary sources this article relies on, checked on the review date above.
- Attachments, Frappe Framework documentation
- Role Based Permissions, ERPNext documentation (Frappe)
- Internal Revenue Service, US Department of the Treasury
- Data security guidance, Federal Trade Commission
This article is general information, not legal, accounting or security advice for your specific situation. Examples are hypothetical unless stated otherwise.