Compare

Manual review, a shared inbox + spreadsheet, or a quiet five-rule audit.

The two default setups a controller names before greenlighting anything new — manual invoice review, and a shared inbox + spreadsheet tracking — both work at low volume. Below is where each one starts to slip past 200 invoices a month, and what PODetect does instead.

The contrast

Three approaches, the same five-rule audit.

Each card lands on the same five checks — PO match, vendor drift, duplicate pay, split-allocation, sales-tax anomalies. The difference is who runs them, when, and what wakes you up the next morning.

Manual review

A controller or AP clerk reads every invoice, by hand.

The original setup — every AP invoice gets a human set of eyes. Works fine while the queue fits inside one person's morning. Becomes the bottleneck the morning it stops fitting.

  • Split-allocation errors slip through when a multi-engagement line looks like a single-cost-center one on a tired afternoon.
  • Sales-tax out-of-band readings don't jump out of a spreadsheet column — they surface at quarter-end rec, too late to reverse.
  • Perfectly viable under ~200 invoices a month. Past that, the reviewer becomes the queue.
Shared inbox + spreadsheet

Vendor forwards to a shared finance inbox, a tracker sheet rows the status.

A pragmatic upgrade once volume passes one person's morning — a shared inbox absorbs the inflow and a spreadsheet rows who-owns-what. The rules are whatever a tired human remembers to apply.

  • Vendor-master drift goes uncaught until year-end rec — a remit-to change that looks like a shell company just becomes the new normal in the cell.
  • Recurring subscriptions double-bill month-over-month because the tracker doesn't carry enough state to flag a near-identical re-post.
  • Confidence scoring is binary — either it posted or it didn't. There's no middle ground to ask one quick question on.
PODetect

Read-only OAuth, the same five rules, a daily digest of only what failed.

The same three-rules pass on every line — except the rules run automatically, the homework doesn't pile on a human, and the next-morning digest lists only the lines that failed.

  • Read-only OAuth — the audit never holds the ledger keys, and the connection is re-consented on the vendor's consent screen before any new scope is requested.
  • Confidence scoring on the same scale a human reviewer would apply — a low-confidence line never posts, and a 30-day reversal window backs every clean post.
  • Daily Slack or email digest ships only the exceptions — three minutes a week of review, not three hours a day of triage.

When it starts to matter

Both default setups work at 100 invoices a month.

The case for switching is when volume passes the point a single person can review a queue, not before. PODetect is the same audit — automated instead of manual, and described in the same vocabulary.

Both default setups work at a hundred invoices a month. PODetect is the same three-rules pass on every line, but a) you don't have to be the reviewer, b) it never posts a low-confidence line, and c) it survives scaling past the first quarter without you becoming the bottleneck.

By week two, the pipeline is fully autonomous and your morning digest is the only surface left. Three minutes a week, not three hours a day — the same target the product sets for the controller's weekly review.

Next step

Read the next piece, then start your audit.

If the case above lines up with the queue you're sitting on, choose a Pro or Firm plan and put the detector to work today.

Or read the trust posture → Security