Belle Vue (Manchester) Ltd · Prepared by IC Studio
Invoices arriving at the finance mailbox are read, identified and filed under the supplier that issued them — usually within a minute. What the system cannot identify with confidence it hands to a person, with the reason attached.
One branch carries the whole design: the system is either confident, or it asks.
The supplier is taken from the content of the document, never from who sent the email — which is why forwarded invoices are identified correctly even though every one of them arrives from the same internal address.
| Format | How it is handled |
|---|---|
| PDF with text | Text extracted and read |
| Scans & photos | JPG, PNG, TIFF read visually by the AI model |
Word .docx | Unpacked and read |
| Spreadsheets | XLSX, XLS, ODS and CSV converted to text and read |
| Archives | ZIP, TAR, GZ unpacked; each file inside processed as though attached on its own, including archives within archives |
Each filed document keeps its original name with the document’s own date appended — Invoice INV-5573 21.09.26.pdf. Where a document carries no readable date, common on supplier statements, the date the email arrived is used instead. Without that, next month’s statement under an identical name would look like this month’s file and be skipped.
Four behaviours do most of the work. Each exists because of something that can go wrong quietly.
A supplier is accepted only at 80% confidence or above. Below that the document goes to review with the reason recorded. An invoice whose date cannot be read is held to the same standard: inventing the date of a payable document is not an acceptable trade. Statements are treated more leniently and may be filed under the email’s date.
Every document gets a key built from the supplier, the invoice number, the date and the file size.
Firstcom sent an invoice, a report and an itemised call statement — three different documents, all numbered 592815, all dated the same day. Without the file size they collapse onto one key: whichever arrived first is filed and the real invoice is discarded as a duplicate, silently, looking like correct behaviour in the log.
A call statement or parts breakdown with no supplier name of its own is filed into the same supplier’s folder as the invoice it arrived with.
An email is marked once something from it has been filed, or once it is confirmed as a duplicate. Anything sent for review stays unread. In practice that means unread in the finance mailbox now means this still needs a person.
Filed documents land in a supplier folder in OneDrive inside Belle Vue’s own Microsoft 365 tenant, and a scheduled script on Belle Vue’s side copies them onto the shared network drive.
The direction is deliberate. The automation writes to a place Belle Vue can reach, and Belle Vue’s own script brings the files inside. Nothing from outside ever reaches into the internal network.
Supplier folders are matched by exact name against the folders that already exist, rather than by search. OneDrive’s own search is loose and cannot be limited to one parent folder, which would eventually file a document under the wrong supplier.
Names are normalised before they are compared. OneDrive stores FASTVPS EESTI OÜ with a decomposed umlaut; the AI returns the precomposed character. The two render identically and compare as different. Left alone, that would have quietly produced a second folder for every supplier with an accent in its name.
It goes to an Unidentified folder under its original name, the reason is written to the log, the source email stays unread, and an alert is raised. Nothing is discarded and nothing is filed on a guess.
The reason is always specific, because a vague one costs someone an investigation. A RAR archive says so and suggests asking the supplier for a ZIP. A corrupt or too deeply nested archive says that instead. An unsupported format names the format.
A waste-services invoice arrived as a PDF whose text layer was laid out in columns. The extracted text came out scrambled and the supplier’s legal name appeared nowhere in it — only an email domain and a website. The model inferred the name from the domain, scored itself 0.72, and said in its notes that the name was partly inferred. It was almost certainly right. It still went for review, which is the correct outcome.
A dedicated server, separate from Belle Vue’s infrastructure and holding no access into it. Mail is received in the EU region throughout.
| Access | SSH by key only; password login disabled |
| Firewall | Everything closed except SSH and HTTPS, plus a rule closing a bypass Docker would otherwise leave open |
| Intrusion defence | Automatic banning of repeat offenders, with escalating ban lengths that survive a reboot |
| Backups | Nightly at 02:30, verified on creation, 14 days retained. A restore has been tested by booting a second instance from one |
| Updates | Operating system patched nightly at 03:00, with a reboot when required |
| Recovery | Service updates take a backup first and roll themselves back automatically if the service does not come back up |
In the twenty-four hours before it was applied, the server logged 10,072 failed SSH login attempts against an account that accepted passwords. Two faults in the supplier’s base image were also found and corrected: the SSH configuration directory was not being read at all, so security settings placed there had no effect, and the automatic update timers were disabled, meaning the machine would never have patched itself.
Stated plainly, so that none of them arrives as a surprise.
The proposal mentions them. The format is proprietary, the platform has no reader for it, and its official container has no package manager, so a RAR tool cannot be added. Supporting it would mean running a second service for one archive format, and no RAR has arrived in the live traffic to date. A RAR is filed for review with a note asking for a ZIP; nothing is lost.
Detected but not read, and handed to a person rather than guessed at. Whether to add character recognition is worth deciding once we see how many real invoices arrive as scans.
.doc filesThe pre-2007 Word format is reported as an unsupported format. The modern .docx is read normally.
The largest document so far is 1.4 MB, so there is room. A large scan will eventually exceed it and will need a different upload path.
Names come from the documents themselves, so a supplier may be filed under its legal name rather than the name the finance team knows it by — one invoice from BlueBox was filed under Black Sheep Business Communications Ltd. A list of the folder names already in use would settle this permanently.
The system is processing live invoices daily. These are the items that would make it harder to break and easier to trust.
The most valuable of these. If the service stopped accepting mail, invoices would stop arriving silently — no error, no bounce, nothing to notice until someone saw the folders were not filling. A check every few minutes removes that failure mode.
It settles the naming question above, and lets a recognised supplier be accepted even when the model is unsure, because the name matches one already known rather than being invented.
Alerts currently reach IC Studio. A short daily note — filed 14, for review 1, duplicates 2 — also means its absence signals that something has stopped.
They are verified nightly but stored on the same disk as the data they protect.
The access granted for marking emails as read currently reaches the whole tenant rather than the finance mailbox alone; the restriction was configured but has not taken effect. The automation itself touches nothing else, but the permission is broader than intended and should be corrected.