VaultAP Docs

Processing Your First Invoice

This guide walks through what happens when an invoice enters VaultAP, from upload to final review decision.

Uploading an invoice

There are two ways to get invoices into VaultAP:

Via the dashboard

Navigate to Invoices > Upload and drag in one or more files. Supported formats:

  • PDF (including scanned documents)
  • PNG, JPG, TIFF images
  • Multi-page documents (each page is processed)

You can upload up to 50 invoices at once via the dashboard.

Via email

Every VaultAP organization gets a unique ingestion email address (e.g., invoices-acme@ingest.vaultap.com). You'll find yours under Settings > Ingestion.

Forward invoices — or have vendors send directly — to this address. Attachments are automatically extracted and queued for processing.

Only file attachments are processed. Email body text is ignored, so there's no risk of non-invoice content being ingested.

What happens after upload

Every invoice passes through six stages in sequence. The entire pipeline typically completes in under 15 seconds.

Extraction

VaultAP's OCR engine reads the document and extracts structured data:

  • Vendor name and address
  • Invoice number and date
  • Due date and payment terms
  • Line items with descriptions, quantities, and amounts
  • Total amount and currency
  • Bank account and routing details

Extraction confidence scores are shown alongside each field. Low-confidence fields are highlighted so reviewers can verify them.

Vendor matching

The extracted vendor information is compared against your vendor database. VaultAP looks for:

  • Exact matches — vendor name and details match a known record
  • Fuzzy matches — similar names that could indicate a typo or impersonation attempt (e.g., "Acme Supp1ies" vs. "Acme Supplies")
  • New vendors — no match found, flagged for review if your policy requires it
  • Bank account changes — the vendor is known, but payment details differ from what's on file

Duplicate check

VaultAP checks the invoice against your entire history to catch:

  • Exact duplicates — same invoice number from the same vendor
  • Near-duplicates — same amount and date from the same vendor but different invoice numbers
  • Recurring pattern breaks — an invoice that looks like a regular recurring charge but arrives off-schedule or at an unusual amount

Risk scoring

All checks feed into VaultAP's risk scoring engine, which produces a single 0-100 score:

RangeMeaning
0-25Low risk — no significant flags detected
26-50Moderate risk — minor anomalies worth noting
51-75Elevated risk — one or more flags require review
76-100High risk — strong indicators of fraud or error

Each contributing flag is listed with its own weight, so you can see exactly what drove the score.

AI explanation

VaultAP generates a plain-language explanation summarizing the risk assessment. For example:

"This invoice from Delta Office Supply for $4,280.00 was flagged with a risk score of 68. The bank account on this invoice differs from the last three payments to this vendor, and the amount is 3.2x higher than the typical order. No duplicate was detected."

These explanations are designed to give reviewers immediate context without needing to interpret raw flag data.

Routing

Based on the risk score and your configured thresholds, VaultAP routes the invoice:

  • Below threshold — the invoice is marked as cleared and ready for payment approval in your normal workflow
  • Above threshold — the invoice is routed to the assigned reviewer(s) with the full risk breakdown and AI explanation
  • Critical flags — certain flags (e.g., bank account change on a high-value invoice) can trigger immediate escalation regardless of score

VaultAP never approves or rejects an invoice on its own. Cleared invoices still go through your normal payment approval process — VaultAP simply indicates it found no significant risk.

Reviewing a flagged invoice

When an invoice lands in your review queue, you'll see:

  1. The extracted invoice data alongside the original document
  2. The risk score and individual flag breakdown
  3. The AI-generated explanation
  4. A full audit trail of how the invoice was processed

From here, you can:

  • Approve — mark the invoice as safe and return it to your payment workflow
  • Reject — flag the invoice as fraudulent or erroneous
  • Escalate — send the invoice to a senior reviewer or manager
  • Add notes — attach comments for audit purposes

Every action is logged with a timestamp and user ID for compliance.

What's next