Vendor portal setup
What this page is — the administrator's guide to switching on the Orbit Books vendor portal for one legal entity, deciding what suppliers may send you, and giving named supplier contacts a way in.
What it is for — turning the invoice inbox you keep in your mail client into a controlled channel: every invoice arrives against a known vendor, on a known entity, with a limit on size, type and volume, and an audit trail from upload to payment.
The problem it solves — invoices that arrive as attachments on personal mailboxes are lost, paid twice, or paid to bank details somebody changed in an e-mail signature. Suppliers then phone the accounts team to ask where their money is, and nobody can answer without digging.
Route: Orbit Books → Settings → Vendor portal (with the entity selected) Permission: Configure the vendor portal per legal entity and invite / revoke vendor portal users. Roles marked as organization administrator hold it already.
Why you would use it
Accounts payable is the one place where an organization accepts documents from outsiders and then pays money against them. Keeping that intake inside Orbit buys four things at once: the supplier is identified before the document is read, duplicates are caught against bills you already hold, the sensitive fields on a supplier record can only change with an approval, and the supplier can answer its own "has this been paid?" question instead of asking you.
It is also the cheapest way to raise data quality. A supplier that types its own invoice number and purchase-order reference on upload gives the duplicate checks something to work with before a single page has been read.
Before this works — the admin contract
Four things must be true before a supplier can sign in, and each is set somewhere different.
| Requirement | Where it is set | What happens without it |
|---|---|---|
| Orbit Books is enabled for the organization and a legal entity exists | Super Admin, then Books → Settings → Entities | The Vendor portal tab does not appear |
| At least one project is mapped to that entity | Books → Settings → Entities → the entity | There is nowhere to publish the portal, and invitations are refused |
| The vendor pages are published on that project | Experience Manager → Vendor → Pages | The supplier signs in and lands on an empty page |
| The supplier exists as a vendor party | Books → Purchases → Vendors | Only vendor parties can have portal users |
Uploads are stored as attachments. If your environment has no object storage configured, files up to 5 MB are held in the database instead; larger ones are refused. Ask whoever runs the environment to confirm storage before you invite real suppliers.
Turning the portal on
- Open Orbit Books and pick the legal entity in the entity selector. Books is scoped by entity, not by project, so the setting you are about to change belongs to that company alone.
- Go to Settings → Vendor portal.
- Switch Enabled on. Nothing vendor-facing answers until you do, and switching it off again closes the portal for every supplier of that entity immediately.
- Work down the settings below, then Save.
- Choose the portal projects. Leave the list empty and every project mapped to the entity exposes the portal; name one or more and only those do.
Field reference — every setting on the tab
| Setting | Default | What it does |
|---|---|---|
| Enabled | Off | The master switch for this entity |
| Allowed file types | PDF, JPEG, PNG | WebP can also be selected. Anything else is refused with a message naming what is accepted |
| Maximum file size | 15 MB | You may lower it to as little as 1 MB. 15 MB is also the platform ceiling |
| Uploads per vendor per day | 50 | Counted per vendor company, not per contact. Between 1 and 1000 |
| Auto-accept | Off | When on, a clearly read invoice with no blocking flag becomes a draft bill with no human step |
| Auto-accept minimum confidence | 0.95 | How sure the reading has to be before auto-accept applies. Between 0.5 and 1 |
| Require a purchase-order reference | Off | An invoice with no purchase-order reference is flagged as blocking |
| Require KYC | On | An invoice from a supplier whose required documents are not all approved is flagged as blocking |
| Portal projects | Empty, meaning all mapped projects | Only projects already mapped to this entity may be chosen |
| Welcome note | Empty | Free text shown to suppliers on the portal home |
Auto-accept creates a draft bill. Drafts still have to be posted, or sent through an approval workflow, before they touch the ledger. It removes the review step, not the accounting step.
Portal projects and the addresses suppliers use
The portal is served on the project's public site, so its address follows whatever domain that project uses. The five pages are:
| Page | Address | What the supplier does there |
|---|---|---|
| Home | /vendor | Sees counts by status and a place to upload |
| Invoices | /vendor/invoices | Uploads an invoice and browses everything sent so far |
| Invoice | /vendor/invoices/view | One invoice: file, status, timeline, reply form |
| Profile | /vendor/profile | Billing details, tax numbers, masked bank details, payments received |
| KYC documents | /vendor/kyc | Uploads the documents you asked for and sees each decision |
Books → Settings → Vendor portal lists each mapped project with its portal address and whether the current settings expose it, so you can copy the exact link you are about to send someone.
Inviting and revoking supplier contacts
- Books → Purchases → Vendors, open the supplier, then the Portal users section.
- Invite: e-mail address, name, the project to enrol them on, and a role of owner or member. Add a short message if you want it to appear in the invitation.
- The invitation creates the sign-in if the person does not have one, enrols them on the project, and e-mails them a link. They set their own password with Forgot password on the sign-in page, so no password ever passes through you.
- Resend refreshes the invitation of somebody who has not signed in yet.
- Revoke ends that contact's access to the supplier's data. Their sign-in survives, because the same person may be a customer or a portal user elsewhere.
A supplier may have several contacts. Every non-revoked contact of the supplier receives the vendor-facing e-mails, so a shared mailbox and a named buyer contact can both be enrolled.
Suppliers you already keep in the CRM can be invited from there instead: CRM → Vendors shows a Portal column and an Invite to portal action on each row, which prefills the contact details it already holds. The column appears only for users who may manage the portal, and only where the selected project is mapped to a Books legal entity.
KYC documents
Each entity keeps its own list of documents it asks suppliers for, at Purchases → Vendor KYC → Document types. Four are created for you: GST registration certificate, PAN card and bank proof as required, and the MSME or Udyam certificate as optional with an expiry date.
For each type you set whether it is required, whether it expires, and how many days before expiry the supplier should be warned. Required types are exactly what the Require KYC setting checks, so a type you mark required immediately starts flagging invoices from suppliers who have not had it approved.
Bill approvals, if you want them
Accepting a supplier invoice creates a draft bill. If your organization has an active Books Bill Approvals workflow, that draft is sent into it automatically and waits for the approvers named by the workflow; without one, nothing changes and the draft behaves exactly like a bill somebody typed in by hand. Build the workflow under Org Settings → Approval Workflows, give it at least one step and activate it. Approvers then work from Orbit Books → Approvals.
Notifications
| Moment | Who hears about it |
|---|---|
| A contact is invited | That contact, by e-mail |
| An invoice is uploaded | The supplier gets a receipt; your reviewers get an internal notice |
| A reviewer asks for information, accepts or rejects | Every portal contact of that supplier |
| A payment run including the supplier's bills is approved | Every portal contact, with the scheduled date |
| A payment is posted | Every portal contact, as remittance advice |
| A KYC document is decided, or is about to expire | Every portal contact |
| A supplier asks to change tax or bank details | The people who can decide it, as an in-app notice |
WhatsApp copies of the supplier-facing messages exist but are dormant: each template has to be submitted to Meta and its mapping activated for your organization first. Until then e-mail carries everything and nothing is silently lost.
Worked example
Northwind Manufacturing runs one legal entity and buys from about forty suppliers. The finance lead:
- Enables the portal on the entity, lowers the maximum file size to 10 MB, leaves the daily limit at 50 and leaves auto-accept off for the first quarter.
- Leaves Require KYC on, and deactivates the MSME type because nobody asks for it.
- Publishes the vendor pages on the one project that carries the public site.
- Invites two contacts at the largest supplier: the accounts mailbox as owner and the account manager as member.
- Watches the first ten invoices arrive, accepts them by hand, and only then builds a Books Bill Approvals workflow with a single step for anything the reviewers accept.
Three weeks later the reviewers have stopped receiving invoices by e-mail, and the supplier has stopped asking when it will be paid.
Troubleshooting
| What you see | Why | What to do |
|---|---|---|
| No Vendor portal tab in Settings | The role lacks the vendor portal permission, or the permission list was cached at sign-in | Grant it, then sign out and in again |
| The supplier reports "portal disabled" | The entity's portal is off, or the project they were invited on is not in the portal projects list | Switch the portal on, or add the project |
| The invitation is refused | The project is not mapped to the entity, or the party is a customer rather than a vendor | Map the project; change the party kind to vendor or both |
| The invitation saved but no e-mail arrived | The invite is created even when the e-mail fails; the response says so | Check the organization's mail channel, then use Resend |
| The supplier signs in and sees an empty page | The vendor pages were never published on that project | Publish them in Experience Manager → Vendor |
| Uploads are refused as too large | The file is above the entity's limit, or above 15 MB, or storage is not configured | Raise the entity limit, or ask the supplier to send a smaller scan |
| Nothing moves out of "received" | The processing job is switched off in your environment | A reviewer can read any single upload with Process now; ask for the job to be enabled |