Belle Vue (Manchester) Ltd · Prepared by IC Studio

Invoices file themselves, and say so when they can’t

Invoices arriving at the finance mailbox are read, identified and filed under the supplier that issued them — usually within a minute. What the system cannot identify with confidence it hands to a person, with the reason attached.

As at 2 October 2026 Status Live, processing daily Mailbox finance@bellevue-mcr.com
53documents logged since go-live
36supplier folders in the archive
1awaiting a person’s decision
0documents lost or filed on a guess

The journey of an invoice

One branch carries the whole design: the system is either confident, or it asks.

Supplier emails invoice attached finance@ mailbox original never moves Copy forwarded to the automation Every attachment is opened and read supplier and date come from the document, not the sender Confident enough? no yes Sent for review Unidentified folder, alert raised email stays unread Filed under the supplier named with the document date email marked as read Shared network drive copied in by Belle Vue’s own script
Four steps, one decision, two outcomes. Nothing in the finance mailbox is moved or deleted at any point.

What it reads

The supplier is taken from the content of the document, never from who sent the email — which is why forwarded invoices are identified correctly even though every one of them arrives from the same internal address.

FormatHow it is handled
PDF with textText extracted and read
Scans & photosJPG, PNG, TIFF read visually by the AI model
Word .docxUnpacked and read
SpreadsheetsXLSX, XLS, ODS and CSV converted to text and read
ArchivesZIP, TAR, GZ unpacked; each file inside processed as though attached on its own, including archives within archives

Naming

Each filed document keeps its original name with the document’s own date appended — Invoice INV-5573 21.09.26.pdf. Where a document carries no readable date, common on supplier statements, the date the email arrived is used instead. Without that, next month’s statement under an identical name would look like this month’s file and be skipped.

The safeguards

Four behaviours do most of the work. Each exists because of something that can go wrong quietly.

It escalates rather than guesses

A supplier is accepted only at 80% confidence or above. Below that the document goes to review with the reason recorded. An invoice whose date cannot be read is held to the same standard: inventing the date of a payable document is not an acceptable trade. Statements are treated more leniently and may be filed under the email’s date.

The same document is never filed twice

Every document gets a key built from the supplier, the invoice number, the date and the file size.

Why the file size is in that key

Firstcom sent an invoice, a report and an itemised call statement — three different documents, all numbered 592815, all dated the same day. Without the file size they collapse onto one key: whichever arrived first is filed and the real invoice is discarded as a duplicate, silently, looking like correct behaviour in the log.

Companion documents stay with their invoice

A call statement or parts breakdown with no supplier name of its own is filed into the same supplier’s folder as the invoice it arrived with.

Processed emails are marked as read

An email is marked once something from it has been filed, or once it is confirmed as a duplicate. Anything sent for review stays unread. In practice that means unread in the finance mailbox now means this still needs a person.

Where documents end up

Filed documents land in a supplier folder in OneDrive inside Belle Vue’s own Microsoft 365 tenant, and a scheduled script on Belle Vue’s side copies them onto the shared network drive.

The direction is deliberate. The automation writes to a place Belle Vue can reach, and Belle Vue’s own script brings the files inside. Nothing from outside ever reaches into the internal network.

Supplier folders are matched by exact name against the folders that already exist, rather than by search. OneDrive’s own search is loose and cannot be limited to one parent folder, which would eventually file a document under the wrong supplier.

A bug worth knowing about

Names are normalised before they are compared. OneDrive stores FASTVPS EESTI OÜ with a decomposed umlaut; the AI returns the precomposed character. The two render identically and compare as different. Left alone, that would have quietly produced a second folder for every supplier with an accent in its name.

When a document can’t be read

It goes to an Unidentified folder under its original name, the reason is written to the log, the source email stays unread, and an alert is raised. Nothing is discarded and nothing is filed on a guess.

The reason is always specific, because a vague one costs someone an investigation. A RAR archive says so and suggests asking the supplier for a ZIP. A corrupt or too deeply nested archive says that instead. An unsupported format names the format.

Why the threshold earns its place

A waste-services invoice arrived as a PDF whose text layer was laid out in columns. The extracted text came out scrambled and the supplier’s legal name appeared nowhere in it — only an email domain and a website. The model inferred the name from the domain, scored itself 0.72, and said in its notes that the name was partly inferred. It was almost certainly right. It still went for review, which is the correct outcome.

What it runs on

A dedicated server, separate from Belle Vue’s infrastructure and holding no access into it. Mail is received in the EU region throughout.

AccessSSH by key only; password login disabled
FirewallEverything closed except SSH and HTTPS, plus a rule closing a bypass Docker would otherwise leave open
Intrusion defenceAutomatic banning of repeat offenders, with escalating ban lengths that survive a reboot
BackupsNightly at 02:30, verified on creation, 14 days retained. A restore has been tested by booting a second instance from one
UpdatesOperating system patched nightly at 03:00, with a reboot when required
RecoveryService updates take a backup first and roll themselves back automatically if the service does not come back up
The hardening was not theoretical

In the twenty-four hours before it was applied, the server logged 10,072 failed SSH login attempts against an account that accepted passwords. Two faults in the supplier’s base image were also found and corrected: the SSH configuration directory was not being read at all, so security settings placed there had no effect, and the automatic update timers were disabled, meaning the machine would never have patched itself.

Known limits

Stated plainly, so that none of them arrives as a surprise.

Not supported

RAR archives

The proposal mentions them. The format is proprietary, the platform has no reader for it, and its official container has no package manager, so a RAR tool cannot be added. Supporting it would mean running a second service for one archive format, and no RAR has arrived in the live traffic to date. A RAR is filed for review with a note asking for a ZIP; nothing is lost.

Goes to review

Poor-quality scans

Detected but not read, and handed to a person rather than guessed at. Whether to add character recognition is worth deciding once we see how many real invoices arrive as scans.

Not supported

Older .doc files

The pre-2007 Word format is reported as an unsupported format. The modern .docx is read normally.

Headroom

Uploads cap at 4 MB

The largest document so far is 1.4 MB, so there is room. A large scan will eventually exceed it and will need a different upload path.

Needs input

Supplier naming

Names come from the documents themselves, so a supplier may be filed under its legal name rather than the name the finance team knows it by — one invoice from BlueBox was filed under Black Sheep Business Communications Ltd. A list of the folder names already in use would settle this permanently.

What we recommend next

The system is processing live invoices daily. These are the items that would make it harder to break and easier to trust.

  1. Monitoring of the inbound endpoint

    The most valuable of these. If the service stopped accepting mail, invoices would stop arriving silently — no error, no bounce, nothing to notice until someone saw the folders were not filling. A check every few minutes removes that failure mode.

  2. The list of supplier folder names already in use

    It settles the naming question above, and lets a recognised supplier be accepted even when the model is unsure, because the name matches one already known rather than being invented.

  3. Alerts and a daily summary to whoever works the review queue

    Alerts currently reach IC Studio. A short daily note — filed 14, for review 1, duplicates 2 — also means its absence signals that something has stopped.

  4. A copy of the backups off the server

    They are verified nightly but stored on the same disk as the data they protect.

  5. Narrowing the mailbox permission

    The access granted for marking emails as read currently reaches the whole tenant rather than the finance mailbox alone; the restriction was configured but has not taken effect. The automation itself touches nothing else, but the permission is broader than intended and should be corrected.