Private — diagram only
Purchase Invoice OCR
Private AP automation for a company: invoices arrive in Outlook, Microsoft Graph API picks them up, Azure Document Intelligence extracts the fields, .NET validates and enriches vendor data, SFTP delivers to the AP system.
A private, internal AP automation that moves purchase invoices from an Outlook inbox to the AP system without manual keying. Built on .NET, Microsoft Graph and Azure Document Intelligence, engineered for auditability over cleverness.
Stack
How it works
AI boundary
Where AI is used
- Azure Document Intelligence reads invoice layouts; every extracted field is validated before use
- Evaluated only: exception-email classification to route failures faster
Where AI is excluded
- Totals and VAT: checked by rules after extraction
- Vendor matching and dedupe: deterministic keys and master data
- Delivery to AP: explicit system action with reconciliation, never generated text
Guardrails
- Idempotent ingestion: same invoice twice = one posting
- Poison queue and retry policy with alerting on repeated SFTP failures
- Full audit trail from email receipt to AP delivery
- No invoice content sent to public LLM APIs
What it demonstrates
- No manual keying in the happy path, and no LLM in the posting path.
- Idempotency keys survive duplicate emails and SFTP retries without double-posting.
- Private internal system: architecture diagram only, no screenshots or customer data.
Notes
Invoice totals, supplier identity and AP posting need determinism, schema validation and replayable logs. OCR reads the document; rules and master data decide what is accepted.
Ingestion, extraction, enrichment, validation and SFTP delivery run as separate stages with observability, poison queues and reconciliation.
Presented diagram-only because it runs inside the organisation. In an interview I walk through duplicate handling, vendor enrichment, SFTP failure modes and reconciliation.