procure-to-pay-protocol
Use this skill to orchestrate the procure-to-pay (source-to-pay) process across Dynamics 365 Supply Chain Management, Finance, and compliance-aware separation-of-duties governance. It coordinates the journey from purchase requisition through purchase order approval, goods or serv
Install
npx skills add https://github.com/VincentChuWaiChow/vanguard-frontier-agentic/tree/master/skills/cross-functional/procure-to-pay-protocol
claude plugin marketplace add https://llmmart.ai/marketplace.json && claude plugin install vincentchuwaichow-vanguard-frontier-agentic@llmmart
git clone https://github.com/VincentChuWaiChow/vanguard-frontier-agentic.git
The skills CLI installs just this skill, for any of its supported agents. Claude Code installs the whole vincentchuwaichow/vanguard-frontier-agentic collection as a plugin from our marketplace. Git is the plain clone.
Skill manifest
Procure-to-Pay Protocol
Purpose
This skill orchestrates the end-to-end procure-to-pay (P2P) / source-to-pay (S2P) business process in Microsoft Dynamics 365 environments. It coordinates Dynamics 365 Supply Chain Management (requisitions, purchase orders, and goods receipt), Dynamics 365 Finance (vendor invoice processing and payment), and Dynamics 365 security and compliance governance (segregation of duties on PO approval). The protocol ensures that no single agent approves, receives, and pays for the same purchase, and that SoD violations are identified and escalated before they reach the general ledger.
When to use
- A purchase requisition must be evaluated, converted to a PO, approved, and tracked through receipt and payment.
- A vendor invoice must be matched to a PO and goods receipt before payment is released.
- A segregation-of-duties concern exists on a PO approval workflow.
- Multiple Dynamics 365 modules are involved and cross-agent coordination is required.
- A procurement compliance review is needed before a vendor payment run.
When NOT to use
- The matter is confined to sales order fulfillment — use order-to-cash-protocol.
- Direct configuration of Dynamics 365 procurement workflows is required — route to the supply chain specialist.
- The matter is a vendor master data change — escalate to the supply chain specialist and finance owner.
- The ask is for strategic sourcing or vendor selection advice without an active procurement request.
Participating agents
- d365-supply-chain-plan-to-produce-agent — owns purchase requisitions, purchase orders, and goods/services receipt
- d365-finance-close-to-report-agent — owns vendor invoice processing, accounts payable, and payment settlement
- d365-security-sod-governance-agent — reviews and flags segregation-of-duties violations on PO approval workflows
Inputs required
- Purchase requisition or purchase order number
- Vendor account and legal entity
- Goods or services description, quantities, and agreed pricing
- Applicable procurement policy and approval workflow configuration
- Budget availability confirmation (if applicable)
Evidence required
- Approved purchase requisition with budget check result
- Purchase order confirmation from vendor
- Goods receipt note or service entry sheet
- Vendor invoice with three-way match result (PO, receipt, invoice)
- SoD clearance from d365-security-sod-governance-agent for PO approval
Workflow
- Receive purchase requisition; validate against procurement catalog and purchasing policy.
- Perform budget availability check; if budget is insufficient, pause and escalate to finance owner.
- Convert approved requisition to a purchase order; confirm vendor, pricing, and delivery terms.
- Route purchase order through the configured approval workflow.
- SoD gate: invoke d365-security-sod-governance-agent to verify that the PO approver is not the same person who raised the requisition or will receive the goods.
- If SoD conflict is detected, halt PO approval; escalate to compliance owner and document the conflict.
- Send confirmed purchase order to vendor; record confirmation reference.
- Monitor delivery against PO delivery date; flag overdue deliveries.
- Record goods receipt or service entry sheet upon delivery; perform quantity and quality check against PO.
- Receive vendor invoice in Dynamics 365 Finance; perform three-way match (PO, receipt, invoice).
- If match discrepancy exists, hold invoice and route to d365-supply-chain-plan-to-produce-agent and vendor for resolution.
- Approved and matched invoices are queued for payment; d365-finance-close-to-report-agent manages payment run per payment terms.
- Release payment; apply to vendor open transactions and close accounts payable entries.
Decision gates
| Gate | Condition | Action if not met |
|---|---|---|
| Budget availability | Sufficient budget in the appropriate cost center | Pause; escalate to finance owner for budget approval |
| Procurement policy | Request conforms to catalog and purchasing policy | Reject and return to requester |
| SoD on PO approval | Approver, requisitioner, and receiver are different people | Halt; escalate to d365-security-sod-governance-agent and compliance owner |
| Three-way match | PO, goods receipt, and invoice quantities and prices align | Hold invoice; route to supply chain agent and vendor for resolution |
| Payment authorization | Payment run approved by authorized finance signatory | Do not release payment without documented authorization |
Refusal triggers
- PO approval is requested for a person who also raised the requisition — refuse; escalate SoD violation.
- Vendor payment is requested without a matched invoice and goods receipt — refuse.
- Vendor credentials, banking details, or PII are included in any input — stop; redact and escalate.
- A purchase order is requested to be back-dated — refuse; escalate to compliance owner.
- An invoice is requested to be paid without three-way match and no documented exception approval — refuse.
Handoff rules
- Every handoff carries a structured capsule: matter_id, po_id, current_stage, gate_outcomes, sod_status, open_questions, do_not_do_list.
- Supply Chain owns requisition through goods receipt; Finance owns invoice processing through payment.
- d365-security-sod-governance-agent is invoked at PO approval and again at payment authorization if personnel assignments have changed.
- No agent releases a vendor payment — all payments require a human-authorized payment run.
KPIs
- Purchase order cycle time (requisition to PO confirmation)
- Three-way match rate (first-pass match without manual intervention)
- Invoice processing time (receipt to posting)
- Payment on-time rate (payments within agreed vendor terms)
- SoD violation rate (conflicts detected per period)
References
Files (vanguard-frontier-agentic)
-
references
-
workflow-and-output.md 7.4 KB
# Procure-to-Pay Protocol — Workflow and Output Contract ## Overview This document provides the detailed step-by-step workflow, decision tree, and output contract for the procure-to-pay-protocol skill. It covers the full source-to-pay cycle from purchase requisition through vendor payment settlement, with explicit SoD gate definitions. --- ## Detailed Step-by-Step Workflow ### Phase 1 — Requisition and Budget Check (d365-supply-chain-plan-to-produce-agent) **Step 1.1 — Receive and validate purchase requisition** - Confirm the purchase requisition is submitted by an authorized requester in Dynamics 365 Supply Chain Management. - Validate that the requested goods or services are within the approved procurement catalog. - Check that procurement policies (spending limits, preferred vendor requirements) are met. - If the request is outside the catalog or policy, reject and return to the requester with an explanation. **Step 1.2 — Budget availability check** - Query available budget for the relevant cost center and account in Dynamics 365 Finance. - If budget is insufficient, pause immediately and escalate to the finance owner for budget approval. - Do not convert a requisition to a PO without a confirmed budget check pass. **Step 1.3 — Vendor selection and pricing validation** - Confirm vendor account, trade agreement pricing, and delivery terms in Dynamics 365 Supply Chain Management. - For new vendors, flag for vendor master review before PO creation — do not create a PO for an unvalidated vendor. --- ### Phase 2 — Purchase Order Approval and SoD Gate (d365-supply-chain-plan-to-produce-agent + d365-security-sod-governance-agent) **Step 2.1 — Convert requisition to purchase order** - Create the purchase order in Dynamics 365 Supply Chain Management with all line items, quantities, prices, and delivery dates. - Assign the PO to the configured approval workflow. **Step 2.2 — SoD gate: PO approval review** - Invoke d365-security-sod-governance-agent to verify: - The PO approver is not the same person who created the purchase requisition. - The PO approver is not the designated goods receiver for this PO. - No single person can complete all three roles: requisition, approval, and receipt. - If any SoD conflict is detected, halt the approval immediately; escalate to the compliance owner and document the conflict with evidence. - Do not proceed with PO approval until the SoD conflict is resolved by the compliance owner. **Step 2.3 — PO confirmation and vendor communication** - Once approved and SoD-cleared, confirm the purchase order. - Send the confirmed PO to the vendor; record the vendor's acknowledgment reference. - Set the expected delivery date in the system. --- ### Phase 3 — Goods/Services Receipt (d365-supply-chain-plan-to-produce-agent) **Step 3.1 — Delivery monitoring** - Track delivery against the promised date on the PO. - Flag overdue deliveries to the supply chain agent and human owner. **Step 3.2 — Goods receipt or service entry sheet** - Upon delivery, record the goods receipt note (GRN) or service entry sheet in Dynamics 365 Supply Chain Management. - Perform quantity check: received quantity must match or be documented against PO quantity. - Perform quality check (where applicable) and record any discrepancies. - The goods receiver must be a different person than the PO requisitioner and approver (SoD). --- ### Phase 4 — Vendor Invoice Processing (d365-finance-close-to-report-agent) **Step 4.1 — Invoice receipt and capture** - Receive vendor invoice in Dynamics 365 Finance (manual entry, OCR via Azure AI Document Intelligence, or EDI). - Match invoice header to the correct vendor account and PO reference. **Step 4.2 — Three-way match** - Perform three-way match: purchase order line quantities and prices, goods receipt quantities, and vendor invoice quantities and amounts. - If the match passes within configured tolerances, route for payment approval. - If the match fails (price discrepancy, quantity mismatch, or missing receipt), hold the invoice; route to d365-supply-chain-plan-to-produce-agent and the vendor for resolution. - Document all match exceptions with reason codes. **Step 4.3 — Invoice approval and payment queue** - Approved and matched invoices are queued for payment in Dynamics 365 Finance per the vendor's payment terms. - Invoices above the configured materiality threshold require a second human approval before payment is included in the payment run. --- ### Phase 5 — Payment Settlement (d365-finance-close-to-report-agent + human) **Step 5.1 — Payment authorization** - The payment run proposal is generated by d365-finance-close-to-report-agent and presented to the authorized finance signatory. - No payment is released without explicit human authorization of the payment run. - SoD check: the person authorizing the payment run must not be the same person who approved the invoice. **Step 5.2 — Payment execution and settlement** - Human-authorized payment run is executed in Dynamics 365 Finance. - Payment is applied to the vendor's open transactions; accounts payable entries are settled. - Payment confirmation and remittance advice are sent to the vendor. --- ## Decision Tree ``` START: Purchase requisition received │ ├─ Request within procurement catalog and policy? │ └─ NO → REJECT; return to requester │ ├─ Budget available? │ └─ NO → PAUSE; escalate to finance owner │ ├─ Vendor validated in vendor master? │ └─ NO → FLAG for vendor master review; do not create PO │ ├─ SoD: Approver ≠ Requisitioner ≠ Receiver? │ └─ NO → HALT; escalate to d365-security-sod-governance-agent and compliance owner │ ├─ Vendor acknowledged PO? │ └─ NO → MONITOR; escalate on overdue acknowledgment │ ├─ Delivery received and GRN created? │ └─ NO → MONITOR; flag overdue delivery │ ├─ Three-way match passes? │ └─ NO → HOLD invoice; route to supply chain and vendor │ ├─ Invoice above materiality threshold? │ └─ YES → REQUIRE second human approval │ ├─ Payment run authorized by finance signatory? │ └─ NO → DO NOT release payment │ └─ SoD on payment: Authorizer ≠ Invoice approver? └─ NO → HALT; escalate to compliance owner ``` --- ## Output Contract Every execution of this protocol produces a structured output capsule: | Field | Type | Description | |---|---|---| | matter_id | string | Unique identifier for this P2P instance | | po_id | string | Purchase order number | | current_stage | enum | One of: requisition, budget_check, po_approval, sod_check, goods_receipt, invoice_matching, payment_queue, settled | | gate_outcomes | object | Pass/fail/escalated: budget, policy, sod_po, three_way_match, sod_payment, payment_auth | | agents_involved | array | Agent IDs that participated | | escalations | array | Each escalation: {trigger, timestamp, escalated_to, reason} | | open_questions | array | Unresolved items requiring human input | | do_not_do_list | array | Actions explicitly prohibited in the current state | | evidence_quality | enum | high / medium / low | | privilege_sensitivity | boolean | True if commercially sensitive vendor terms are involved | | last_updated | ISO8601 timestamp | When the capsule was last updated | --- ## Audit Log Fields - matter_id, skill_id, skill_version, invoked_by, input_hash, evidence_quality, output_verdict, escalation_fired, sod_conflict_detected, timestamp
-
-
metadata.json 1.9 KB
{ "id": "procure-to-pay-protocol", "name": "Procure-to-Pay Protocol", "type": "skill", "provider": "generic", "harnesses": ["codex", "claude-code", "cursor", "gemini", "kiro", "other"], "summary": "Orchestration protocol for the procure-to-pay (source-to-pay) process in Dynamics 365 environments, coordinating Supply Chain Management (requisitions, purchase orders, and goods receipt), Finance (vendor invoice processing and AP payment), and security/SoD governance (segregation-of-duties checks on PO approval). Enforces three-way match before payment, SoD gates at PO approval and payment authorization, and structured handoffs between d365-supply-chain-plan-to-produce-agent, d365-finance-close-to-report-agent, and d365-security-sod-governance-agent.", "source_type": "original", "official_docs": [ "https://learn.microsoft.com/dynamics365/guidance/business-processes/source-to-pay-overview", "https://learn.microsoft.com/dynamics365/guidance/techtalks/supply-chain-procure-to-pay-overview", "https://learn.microsoft.com/dynamics365/supply-chain/procurement/procurement-sourcing-overview" ], "security_notes": "This protocol is a recommendation and orchestration guide only — it is never an authorization to approve purchase orders, release vendor payments, override procurement policies, or bypass segregation-of-duties controls. All production-impacting steps require confirmation by the relevant human owner or specialist agent. The protocol never requests vendor credentials, banking details, tenant IDs, or personal data. SoD violations detected at PO approval or payment authorization always halt the process and escalate to the compliance owner — no agent resolves a SoD conflict unilaterally. Back-dating of purchase orders and payment without a three-way match are explicitly refused.", "last_verified": "2026-06-16", "path": "skills/cross-functional/procure-to-pay-protocol", "author": "github: VincentChuWaiChow", "version": "0.1.0" } -
SKILL.md 7.4 KB
--- name: procure-to-pay-protocol description: Use this skill to orchestrate the procure-to-pay (source-to-pay) process across Dynamics 365 Supply Chain Management, Finance, and compliance-aware separation-of-duties governance. It coordinates the journey from purchase requisition through purchase order approval, goods or services receipt, vendor invoice processing, and payment settlement. The skill enforces segregation-of-duties gates on purchase order approval, defines agent handoff rules, and escalates SoD conflicts to d365-security-sod-governance-agent. It does not approve purchase orders, release vendor payments, override procurement policies, or access vendor credentials; all production-impacting steps are escalated to the relevant specialist or human owner. allowed-tools: Read Grep Glob metadata: author: "github: VincentChuWaiChow" version: "0.1.0" updated: "2026-06-16" category: operational lifecycle: experimental --- # Procure-to-Pay Protocol ## Purpose This skill orchestrates the end-to-end procure-to-pay (P2P) / source-to-pay (S2P) business process in Microsoft Dynamics 365 environments. It coordinates Dynamics 365 Supply Chain Management (requisitions, purchase orders, and goods receipt), Dynamics 365 Finance (vendor invoice processing and payment), and Dynamics 365 security and compliance governance (segregation of duties on PO approval). The protocol ensures that no single agent approves, receives, and pays for the same purchase, and that SoD violations are identified and escalated before they reach the general ledger. ## When to use - A purchase requisition must be evaluated, converted to a PO, approved, and tracked through receipt and payment. - A vendor invoice must be matched to a PO and goods receipt before payment is released. - A segregation-of-duties concern exists on a PO approval workflow. - Multiple Dynamics 365 modules are involved and cross-agent coordination is required. - A procurement compliance review is needed before a vendor payment run. ## When NOT to use - The matter is confined to sales order fulfillment — use order-to-cash-protocol. - Direct configuration of Dynamics 365 procurement workflows is required — route to the supply chain specialist. - The matter is a vendor master data change — escalate to the supply chain specialist and finance owner. - The ask is for strategic sourcing or vendor selection advice without an active procurement request. ## Participating agents - d365-supply-chain-plan-to-produce-agent — owns purchase requisitions, purchase orders, and goods/services receipt - d365-finance-close-to-report-agent — owns vendor invoice processing, accounts payable, and payment settlement - d365-security-sod-governance-agent — reviews and flags segregation-of-duties violations on PO approval workflows ## Inputs required - Purchase requisition or purchase order number - Vendor account and legal entity - Goods or services description, quantities, and agreed pricing - Applicable procurement policy and approval workflow configuration - Budget availability confirmation (if applicable) ## Evidence required - Approved purchase requisition with budget check result - Purchase order confirmation from vendor - Goods receipt note or service entry sheet - Vendor invoice with three-way match result (PO, receipt, invoice) - SoD clearance from d365-security-sod-governance-agent for PO approval ## Workflow 1. Receive purchase requisition; validate against procurement catalog and purchasing policy. 2. Perform budget availability check; if budget is insufficient, pause and escalate to finance owner. 3. Convert approved requisition to a purchase order; confirm vendor, pricing, and delivery terms. 4. Route purchase order through the configured approval workflow. 5. SoD gate: invoke d365-security-sod-governance-agent to verify that the PO approver is not the same person who raised the requisition or will receive the goods. 6. If SoD conflict is detected, halt PO approval; escalate to compliance owner and document the conflict. 7. Send confirmed purchase order to vendor; record confirmation reference. 8. Monitor delivery against PO delivery date; flag overdue deliveries. 9. Record goods receipt or service entry sheet upon delivery; perform quantity and quality check against PO. 10. Receive vendor invoice in Dynamics 365 Finance; perform three-way match (PO, receipt, invoice). 11. If match discrepancy exists, hold invoice and route to d365-supply-chain-plan-to-produce-agent and vendor for resolution. 12. Approved and matched invoices are queued for payment; d365-finance-close-to-report-agent manages payment run per payment terms. 13. Release payment; apply to vendor open transactions and close accounts payable entries. ## Decision gates | Gate | Condition | Action if not met | |---|---|---| | Budget availability | Sufficient budget in the appropriate cost center | Pause; escalate to finance owner for budget approval | | Procurement policy | Request conforms to catalog and purchasing policy | Reject and return to requester | | SoD on PO approval | Approver, requisitioner, and receiver are different people | Halt; escalate to d365-security-sod-governance-agent and compliance owner | | Three-way match | PO, goods receipt, and invoice quantities and prices align | Hold invoice; route to supply chain agent and vendor for resolution | | Payment authorization | Payment run approved by authorized finance signatory | Do not release payment without documented authorization | ## Refusal triggers - PO approval is requested for a person who also raised the requisition — refuse; escalate SoD violation. - Vendor payment is requested without a matched invoice and goods receipt — refuse. - Vendor credentials, banking details, or PII are included in any input — stop; redact and escalate. - A purchase order is requested to be back-dated — refuse; escalate to compliance owner. - An invoice is requested to be paid without three-way match and no documented exception approval — refuse. ## Handoff rules - Every handoff carries a structured capsule: matter_id, po_id, current_stage, gate_outcomes, sod_status, open_questions, do_not_do_list. - Supply Chain owns requisition through goods receipt; Finance owns invoice processing through payment. - d365-security-sod-governance-agent is invoked at PO approval and again at payment authorization if personnel assignments have changed. - No agent releases a vendor payment — all payments require a human-authorized payment run. ## KPIs - Purchase order cycle time (requisition to PO confirmation) - Three-way match rate (first-pass match without manual intervention) - Invoice processing time (receipt to posting) - Payment on-time rate (payments within agreed vendor terms) - SoD violation rate (conflicts detected per period) ## References - [Source to pay end-to-end overview — Dynamics 365](https://learn.microsoft.com/dynamics365/guidance/business-processes/source-to-pay-overview) - [TechTalk: Procure to pay in Dynamics 365 Supply Chain Management](https://learn.microsoft.com/dynamics365/guidance/techtalks/supply-chain-procure-to-pay-overview) - [TechTalk: Source to pay in Dynamics 365 Finance and Supply Chain Management](https://learn.microsoft.com/dynamics365/guidance/techtalks/dynamics-365-finance-supply-chain-management-source-to-pay) - [Procurement and sourcing overview — Dynamics 365 Supply Chain Management](https://learn.microsoft.com/dynamics365/supply-chain/procurement/procurement-sourcing-overview)
Comments (0)
Sign in to join the conversation.
Reviews (0)
No reviews yet.
No comments yet.