Invoice work
AP Clerk prepares bills and supporting evidence. Approver decides own-scope bills; AP Manager and Controller / CFO act within the configured amount tiers.
Separate invoice entry, bill approval, payment release and supplier access.
Summarised from the authored role permissions. Scope restrictions such as “own records” still apply; these symbols do not indicate completeness or runtime access.
| Table | Controller / CFO | AP Manager | AP Clerk | Approver | Vendor User | Viewer |
|---|---|---|---|---|---|---|
| master | ||||||
Vendors | View: View all Vendors.BankAccount / RoutingNumber / EIN fields in clear | View: View all Vendors.BankAccount / RoutingNumber / EIN fields | —No table-specific permission stated | —No table-specific permission stated | —No table-specific permission stated | —No table-specific permission stated |
BillApprovalMatrix | Specific actions: Approve Bills in the highest tier of BillApprovalMatrix (typically >$50k or >$250k depending on configuration) | Specific actions: initiate bank-account changes — Controller confirms), VendorContacts, RecurringBills, Bills (approve mid-tier per BillApprovalMatrix), BillApprovalSteps (own tier), PaymentRuns (create, edit selections, flip Status: Draft → Approved), PaymentRunItems (add / remove / hold), Payments (issue off-cycle one-offs), PaymentBatches, Disputes (assigned-to default), VendorCredits, OneOffPayees, Form1099Tracking (review and pre-flight before Controller signoff) | —No table-specific permission stated | —No table-specific permission stated | —No table-specific permission stated | —No table-specific permission stated |
RecurringBills | —No table-specific permission stated | Specific actions: initiate bank-account changes — Controller confirms), VendorContacts, RecurringBills, Bills (approve mid-tier per BillApprovalMatrix), BillApprovalSteps (own tier), PaymentRuns (create, edit selections, flip Status: Draft → Approved), PaymentRunItems (add / remove / hold), Payments (issue off-cycle one-offs), PaymentBatches, Disputes (assigned-to default), VendorCredits, OneOffPayees, Form1099Tracking (review and pre-flight before Controller signoff) | —No table-specific permission stated | —No table-specific permission stated | —No table-specific permission stated | —No table-specific permission stated |
OneOffPayees | —No table-specific permission stated | Specific actions: initiate bank-account changes — Controller confirms), VendorContacts, RecurringBills, Bills (approve mid-tier per BillApprovalMatrix), BillApprovalSteps (own tier), PaymentRuns (create, edit selections, flip Status: Draft → Approved), PaymentRunItems (add / remove / hold), Payments (issue off-cycle one-offs), PaymentBatches, Disputes (assigned-to default), VendorCredits, OneOffPayees, Form1099Tracking (review and pre-flight before Controller signoff) | —No table-specific permission stated | —No table-specific permission stated | —No table-specific permission stated | —No table-specific permission stated |
| transaction | ||||||
Bills | Specific actions: Approve Bills in the highest tier of BillApprovalMatrix (typically >$50k or >$250k depending on configuration) | Specific actions: initiate bank-account changes — Controller confirms), VendorContacts, RecurringBills, Bills (approve mid-tier per BillApprovalMatrix), BillApprovalSteps (own tier), PaymentRuns (create, edit selections, flip Status: Draft → Approved), PaymentRunItems (add / remove / hold), Payments (issue off-cycle one-offs), PaymentBatches, Disputes (assigned-to default), VendorCredits, OneOffPayees, Form1099Tracking (review and pre-flight before Controller signoff) | —No table-specific permission stated | —No table-specific permission stated | —No table-specific permission stated | —No table-specific permission stated |
Disputes | —No table-specific permission stated | Specific actions: initiate bank-account changes — Controller confirms), VendorContacts, RecurringBills, Bills (approve mid-tier per BillApprovalMatrix), BillApprovalSteps (own tier), PaymentRuns (create, edit selections, flip Status: Draft → Approved), PaymentRunItems (add / remove / hold), Payments (issue off-cycle one-offs), PaymentBatches, Disputes (assigned-to default), VendorCredits, OneOffPayees, Form1099Tracking (review and pre-flight before Controller signoff) | —No table-specific permission stated | —No table-specific permission stated | —No table-specific permission stated | —No table-specific permission stated |
VendorCredits | —No table-specific permission stated | Specific actions: initiate bank-account changes — Controller confirms), VendorContacts, RecurringBills, Bills (approve mid-tier per BillApprovalMatrix), BillApprovalSteps (own tier), PaymentRuns (create, edit selections, flip Status: Draft → Approved), PaymentRunItems (add / remove / hold), Payments (issue off-cycle one-offs), PaymentBatches, Disputes (assigned-to default), VendorCredits, OneOffPayees, Form1099Tracking (review and pre-flight before Controller signoff) | —No table-specific permission stated | —No table-specific permission stated | —No table-specific permission stated | —No table-specific permission stated |
Form1099Tracking | —No table-specific permission stated | Specific actions: initiate bank-account changes — Controller confirms), VendorContacts, RecurringBills, Bills (approve mid-tier per BillApprovalMatrix), BillApprovalSteps (own tier), PaymentRuns (create, edit selections, flip Status: Draft → Approved), PaymentRunItems (add / remove / hold), Payments (issue off-cycle one-offs), PaymentBatches, Disputes (assigned-to default), VendorCredits, OneOffPayees, Form1099Tracking (review and pre-flight before Controller signoff) | —No table-specific permission stated | —No table-specific permission stated | —No table-specific permission stated | —No table-specific permission stated |
| line item | ||||||
VendorContacts | —No table-specific permission stated | Specific actions: initiate bank-account changes — Controller confirms), VendorContacts, RecurringBills, Bills (approve mid-tier per BillApprovalMatrix), BillApprovalSteps (own tier), PaymentRuns (create, edit selections, flip Status: Draft → Approved), PaymentRunItems (add / remove / hold), Payments (issue off-cycle one-offs), PaymentBatches, Disputes (assigned-to default), VendorCredits, OneOffPayees, Form1099Tracking (review and pre-flight before Controller signoff) | —No table-specific permission stated | —No table-specific permission stated | —No table-specific permission stated | —No table-specific permission stated |
BillApprovalSteps | —No table-specific permission stated | Specific actions: initiate bank-account changes — Controller confirms), VendorContacts, RecurringBills, Bills (approve mid-tier per BillApprovalMatrix), BillApprovalSteps (own tier), PaymentRuns (create, edit selections, flip Status: Draft → Approved), PaymentRunItems (add / remove / hold), Payments (issue off-cycle one-offs), PaymentBatches, Disputes (assigned-to default), VendorCredits, OneOffPayees, Form1099Tracking (review and pre-flight before Controller signoff) | —No table-specific permission stated | —No table-specific permission stated | —No table-specific permission stated | —No table-specific permission stated |
| finance | ||||||
PaymentRuns | —No table-specific permission stated | Specific actions: initiate bank-account changes — Controller confirms), VendorContacts, RecurringBills, Bills (approve mid-tier per BillApprovalMatrix), BillApprovalSteps (own tier), PaymentRuns (create, edit selections, flip Status: Draft → Approved), PaymentRunItems (add / remove / hold), Payments (issue off-cycle one-offs), PaymentBatches, Disputes (assigned-to default), VendorCredits, OneOffPayees, Form1099Tracking (review and pre-flight before Controller signoff) | —No table-specific permission stated | —No table-specific permission stated | —No table-specific permission stated | —No table-specific permission stated |
PaymentRunItems | —No table-specific permission stated | Specific actions: initiate bank-account changes — Controller confirms), VendorContacts, RecurringBills, Bills (approve mid-tier per BillApprovalMatrix), BillApprovalSteps (own tier), PaymentRuns (create, edit selections, flip Status: Draft → Approved), PaymentRunItems (add / remove / hold), Payments (issue off-cycle one-offs), PaymentBatches, Disputes (assigned-to default), VendorCredits, OneOffPayees, Form1099Tracking (review and pre-flight before Controller signoff) | —No table-specific permission stated | —No table-specific permission stated | —No table-specific permission stated | —No table-specific permission stated |
Payments | —No table-specific permission stated | Specific actions: initiate bank-account changes — Controller confirms), VendorContacts, RecurringBills, Bills (approve mid-tier per BillApprovalMatrix), BillApprovalSteps (own tier), PaymentRuns (create, edit selections, flip Status: Draft → Approved), PaymentRunItems (add / remove / hold), Payments (issue off-cycle one-offs), PaymentBatches, Disputes (assigned-to default), VendorCredits, OneOffPayees, Form1099Tracking (review and pre-flight before Controller signoff); View all Payments.Amount in clear | —No table-specific permission stated | —No table-specific permission stated | —No table-specific permission stated | —No table-specific permission stated |
PaymentBatches | —No table-specific permission stated | Specific actions: initiate bank-account changes — Controller confirms), VendorContacts, RecurringBills, Bills (approve mid-tier per BillApprovalMatrix), BillApprovalSteps (own tier), PaymentRuns (create, edit selections, flip Status: Draft → Approved), PaymentRunItems (add / remove / hold), Payments (issue off-cycle one-offs), PaymentBatches, Disputes (assigned-to default), VendorCredits, OneOffPayees, Form1099Tracking (review and pre-flight before Controller signoff) | —No table-specific permission stated | —No table-specific permission stated | —No table-specific permission stated | —No table-specific permission stated |
AP Clerk prepares bills and supporting evidence. Approver decides own-scope bills; AP Manager and Controller / CFO act within the configured amount tiers.
AP Manager reviews the payment proposal. Controller / CFO releases it. A technical connector or an editable item does not confer release authority.
AP Manager initiates a change and Controller independently confirms it. Retain both identities and protect bank, routing and tax information from operational roles that do not need it.
Vendor User can access only own-supplier bills, documents and permitted payment status. Internal allocations and other vendors remain outside that scope.
Admin configures roles and integrations. Any exceptional override requires its own explicit authorization and audit evidence; configuration access is not the normal payment signature.
Final signoff on payment runs, top-tier bill approval, year-end 1099 release. Sees every Vendor, every Bill, every Payment in full detail.
Read on all tablesCRUD on Bills (approve top tier per BillApprovalMatrix), PaymentRuns (sign off Status: Approved → Funded — releases the bank file), Form1099Tracking (review and flip Status: Computed → ReadyToFile to hand off to Payroll FilingPartner)View all Vendors.BankAccount / RoutingNumber / EIN fields in clearApprove Bills in the highest tier of BillApprovalMatrix (typically >$50k or >$250k depending on configuration)Confirm Vendor bank-account changes initiated by the AP Manager (the second pair of eyes on the BEC-fraud control)Cannot bypass the three-way match — a Bills row in Status: Disputed from a match mismatch routes through the Disputes workflow first, not direct to ApprovedOwns the AP function end-to-end. Runs the weekly payment cycle, manages Vendor relationships, tracks Disputes through to resolution, owns the year-end 1099 file readiness. The named approver in mid-tier bill bands.
CRUD on Vendors (approve new Vendor onboarding once W-9 is on fileinitiate bank-account changes — Controller confirms), VendorContacts, RecurringBills, Bills (approve mid-tier per BillApprovalMatrix), BillApprovalSteps (own tier), PaymentRuns (create, edit selections, flip Status: Draft → Approved), PaymentRunItems (add / remove / hold), Payments (issue off-cycle one-offs), PaymentBatches, Disputes (assigned-to default), VendorCredits, OneOffPayees, Form1099Tracking (review and pre-flight before Controller signoff)View all Vendors.BankAccount / RoutingNumber / EIN fieldsView all Payments.Amount in clearCannot release PaymentRuns.Status: Approved → Funded (Controller signature) and cannot post the GL JE (fin-accounting Controller)Operational role — the day-to-day Bills processor. Captures / keys / OCRs vendor invoices, runs three-way match, prepares PaymentRunItems for AP Manager review.
CRUD on Bills (Status IN Draft, PendingMatch, PendingApproval), BillLines, BillAttachmentsTrigger the three-way match action on a Bill (writes ThreeWayMatchResults)CRUD on PaymentRunItems (within an AP-Manager-created PaymentRuns in Status: Draft — add Bills, mark Held, set PaymentMethod)Read on Vendors (BankAccount / RoutingNumber / EIN masked), PurchaseOrders, POLineItems, GoodsReceipts, ReceiptLineItems, BillApprovalMatrix, MatchTolerancesOpen Disputes rowsCannot approve own Bill entries beyond the auto-approve tier, cannot initiate Vendor bank-account changes, cannot approve PaymentRuns, cannot release PaymentRuns to bank, cannot configure BillApprovalMatrix or MatchTolerancesLine-of-business approver — typically a Department head or Project lead. Approves Bills against own cost-center per the BillApprovalMatrix tier band that maps to the Approver role. Sees own department / project bills only.
Read on Bills and BillLines where Bills.Department or Bills.ProjectCode matches the Approver's own cost-center assignmentRead on BillApprovalSteps and BillAttachments for own-scope billsCRUD on BillApprovalSteps where AssignedTo = self (set Decision: Approved / Rejected / Delegated with notes)Read own-scope Payments (Amount visible) so the Approver sees what was paid against their cost-centerCannot see other departments' Bills, cannot edit Bills content, cannot configure BillApprovalMatrix, cannot see any Vendors.BankAccount or RoutingNumber fields, cannot create DisputesExternal portal seat — implicit (typically delivered via a vendor-portal sub-app or a shared-link mechanism). Submits invoices via email or portal upload, sees own payment status, updates own remit-to address (subject to AP Manager verify).
CRUD on own BillAttachments for AttachmentType: VendorInvoicePDF (uploads create a new Bills row in Status: Draft via the bill-intake-from-email-or-ocr workflow)Read on own Bills (Status, AmountPaid, AmountOutstanding, DueDate visible — but not internal GLAccount / Department / ProjectCode tags)Read on own Payments (Amount, SentAt, ClearedAt, Reference)Submit remit-to-address change requests (routes to AP Manager)Cannot see other Vendors, cannot see internal approval state, cannot see other Vendors' Payments| Bill Number | Vendor Invoice Number | Bill Date | Due Date | Total |
|---|---|---|---|---|
| BLL-38639 | BLL-44507 | 14 Sep | 23 Sep | 9,648.40 |
| BLL-93137 | BLL-57945 | 05 Sep | 09 Sep | 34,050.51 |
| BLL-96491 | BLL-89840 | 24 Sep | 27 Sep | 4,988.04 |
| BLL-51662 | BLL-60219 | 12 Sep | 16 Sep | 4,940.36 |
| BLL-62147 | BLL-54061 | 18 Sep | 20 Sep | 26,379.40 |
| BLL-37537 | BLL-15246 | 28 Sep | 02 Oct | 37,330.63 |
Executive read-only — board members, outside auditors, FP&A analysts.
Read on Vendors (Name + Status only — no EIN, no BankAccount, no RoutingNumber), Bills (header + AmountOutstanding — line detail aggregated), Payments (aggregated by period only — individual amounts masked), Disputes (Status, Reason, ResolutionType only)Read on the eight reports — AP Aging, Top Vendors by Spend, Discount Capture, etcCannot see BillApprovalMatrix, MatchTolerances, Form1099Tracking detail (aggregate count only), or any individual approver decisionsAll access is audit-loggedCreate your ERP.AI account and get started with Proto.
We use essential cookies to run the site and optional cookies for features, analytics, and relevant content. See Cookie policy
We use cookies to enhance your experience, analyze site traffic, and serve relevant content. By clicking "Accept All," you agree to our use of cookies. You can customize your preferences at any time.
Learn more about how we use cookiesThese cookies are required for the website to function properly. They ensure security, enable basic features like page navigation, and store user session data. You cannot disable these cookies.
These cookies enable additional features that enhance your experience, such as live chat, video playback, personalized content recommendations, and remembering user preferences.
These cookies help us understand how visitors interact with our site by collecting anonymous usage data. This allows us to measure performance, detect issues, and continuously improve the user experience.
These cookies allow us and advertising partners, including X, to deliver ads tailored to your interests. They track browsing habits across sites to provide relevant advertising and measure ad effectiveness.