- Original artifact, channel, and duplicate family
- Allow approved receipt paths; retain messages, payloads, files, digests, pages and attachments; detect duplicate and revision families across channels; quarantine hostile content; preserve sender and transmission evidence; and never replace originals with OCR or generated text.
- Entity, supplier, bank, period, and provenance
- Use stable mastered identifiers; bind supplier and buying entity before processing; treat remit-to and bank-detail changes as separate high-risk workflows; preserve every field source and transformation; enforce currency and period rules; and expose missing or conflicting identity.
- Schema, code, decimal, and total validation
- Version applicable syntax, semantic profile, code lists, units, currency and tax rules; use exact decimals; validate lines, allowances, charges, tax subtotals, rounding and payable totals; compare rendered and structured views; and show every failure without auto-repair.
- Commercial match and prior-use control
- Match orders, contracts, receipts and acceptance at member level; calculate quantity and price tolerances deterministically; prevent reused receipt quantities or duplicate invoices; retain partial and alternative matches; and require qualified ownership for non-PO, over-tolerance and disputed items.
- Permission, segregation, and financial commit
- Separate receive, extract, validate, master-data change, accept, code, approve, post, pay, reconcile, reverse and administer capabilities; scope credentials to entity and tool; enforce thresholds and conflicts; use idempotency and target receipts; and keep payment authorization distinct.
- Exceptions, security, retention, and recovery
- Own unreadable, duplicate, changed-bank, missing-order, partial-receipt, tax, approval, posting and payment exceptions; set age and escalation rules; isolate tenants, protect secrets, test restore and replay, reconcile after outages, retain and export by policy and correct visibly.