
Employee spend and travel, inside Business Central.
One engine for the whole spend lifecycle — receipts, trips, mileage, per-diem, corporate cards, approvals, commitments and posting — with Claude where it earns its keep and nowhere else. Standalone by architecture. Per-tenant pricing, never per-employee.
- 22 modules · one coherent lifecycle
- Claude: OCR · capture · policy · anomaly · copilot
- Country packs: W1 · EU · UK · GCC · US
- Zero AppSource dependencies · per-tenant price
- Standard Gen. Jnl. posting · project ledger aware
- Immutable vault · write-only audit · DSAR-safe
Where SpendFlow shows up for the people who use it
Insights, approvals, posting run
iOS + Android · capture + submit
Conversational capture · one-tap
Queue + Copilot summary
Statement files · API providers
The T&E stack most BC customers run is four systems in a trench coat.
Employees submit through one tool. OCR happens in a second tool. Approvers work in email. Cards reconcile in a spreadsheet. Finance re-keys everything into Business Central. Every hand-off drops context and the GL entry lands two weeks after the trip. Meanwhile standard BC's employee-expense feature stops at "post a Gen. Journal Line" — it does not model trips, per-diem, mileage, cards, commitments or advance authorisations. SpendFlow puts the whole lifecycle inside BC, with Claude only where a human would ask "can you help me read this?" and never where finance would say "a machine did what?".
Capture → Approve → Post → Vault → Govern. Modules are independently licensable — Core + Cards without Commitments is a valid mix.
A 50-employee company and a 500-employee company on the same modules pay the same price. Only country packs and module tiers move the number.
app.json declares no required AppSource dependency. Sibling apps detected at runtime through ISiblingIntegration — the extension keeps working with or without them.
One journey. Twenty-two modules. Five clean stages.
A spend document travels from Capture to Govern. Each stage is a small set of modules doing one clear job. You license the stages you use — Core + Cards without Commitments is a valid mix.
Employees submit through mobile, web or a chat surface. Claude reads the receipt, Merchant Memory pre-fills the category and GL account from what this employee usually books. Trip Folders bundle a journey's expenses, mileage and per-diem into one unit. Corporate-card feeds land as unmatched transactions and auto-match to submitted receipts by amount, merchant, date and employee.
- Unified spend document (expense · advance · refund · card charge)
- Trip Folder groups mixed spend + mileage + per-diem
- Mileage engine: route templates, GPS route points, vehicle rates, fuel-tax split
- Per-diem engine: cross-border trips with destination legs
- Card feed factory: statement import shipped; card-network APIs plug in
Managers authorise budgets before travel, not just receipts after. Approval Rules route by amount, category, employee or dimension. Every item carries an Approver Copilot summary — risk score, policy verdict, comparison to the employee's past pattern, plain-English narrative of what changed. Group holding companies get a Cross-Company Approvals query that surfaces items from every subsidiary in one queue.
- Advance Authorisation pre-approves budgets before travel
- Rule-driven routing by amount, category, employee, dimension
- Request · Approve · Reject · Hold · Forward · Delegate
- Approver Copilot summary cached for 24h to keep latency instant
- Cross-Company Approvals query for group-level queues
Approved spend posts through standard Gen. Jnl.-Post Batch — the GL entries look exactly like the rest of BC. Allocation Profiles split a single spend across GL accounts and dimensions by percentage. Job-linked lines post to the project ledger as a separate transaction. Settlement Method routes contra to the employee (reimbursement), a vendor (via employee-as-vendor), or a card-clearing account.
- Posts via standard Gen. Jnl.-Post Batch — no parallel ledger
- Allocation Profile splits by % across GL + dimensions
- Separate Project ledger post when Job No. is set
- Settlement Method: reimburse · vendor · card clearing
- Post-approval edit lock · Posted G/L Entry No. write-back
Every posted document lands in the Vault with the original receipt, a rendered PDF and a SHA-256 hash of the content. Retention policies per document type. Updates create new revisions rather than overwriting. Auditors get one place to walk from a GL entry back to the receipt — with cryptographic proof it hasn't been tampered with.
- Original artefact + rendered PDF + SHA-256 hash
- Write-once · every change creates a new revision
- Per-document-type retention policies
- Standard-BC Navigate event subscriber for traceability
- DSAR-safe erasure: creates a tombstone, never a silent delete
Policies authored in natural language plus structured rules, versioned per company; every evaluation logged. Anomaly engine flags duplicates via receipt fingerprint plus statistical outliers with a resolution workflow. Commitment register tracks recurring vendor obligations. Write-only audit log for every state change. Per-field redaction before any AI call.
- Policy Engine: NL + structured, Advisory or Enforcing mode
- Duplicate detection via SSF Receipt Fingerprint
- Anomaly Engine: statistical outliers with resolution workflow
- Commitment Register for recurring vendor obligations
- Write-only audit log · per-field redaction · DSAR workflow
Eight capabilities finance teams actually notice.
The features that show up in month-end close, in the approver's inbox, and in the auditor's trace.
Receipt OCR that learns
Claude extracts merchant, date, total, line items, tax splits and payment method — with per-field confidence. Merchant Memory closes the loop from every user correction, so month two is faster than month one.
Conversational capture
Employees describe an expense in plain language and the app builds the spend document with GL account, tax and dimensions from context. No form to fill. Full conversation log per user.
Trip Folders
One journey → one folder → one approval. Spend, mileage and per-diem inside a Trip Folder submit and approve together. A single Travel Statement report prints the whole trip.
Corporate cards, matched
Card statements land as unmatched transactions. SSF Card Match Rule auto-matches by amount, merchant, date, employee. Unmatched rows can generate draft spend documents. Every card row carries a receipt-missing flag until proven otherwise.
Policy in your words
Author policies as "no alcohol on training trips" or "managers can approve up to ₹50k". Claude evaluates alongside structured rules; every evaluation is logged with the verdict and the rule text used.
Duplicate + anomaly detection
Receipt fingerprint catches duplicate submissions across employees, months and mobile / web. Statistical outliers surface with an explanation the approver can act on — nothing auto-rejected without a human step.
Approver Copilot
Per-item risk score, policy verdict, comparison to the employee's past pattern and plain-English narrative of what changed. Cached 24h so instant on repeat views.
Commitment Register
Recurring vendor obligations — SaaS subscriptions, retainers, rentals, insurance. Renewal + review reminders to named owners. Linked spend auto-approves up to the committed amount.
Five places AI earns its keep. Three places it never touches.
Every AI call flows through a small companion broker so finance always knows what left the tenant, what came back, and how confident the model was. The broker is the only outbound HTTP endpoint the AL layer uses. Every call is logged with a per-field confidence score.
There are also things AI is explicitly not allowed to do — deliberately, structurally, not just by convention. The most important one: no AI call can trigger a ledger post on its own. A human approval sits between every AI verdict and every Gen. Journal Line.
- Receipt OCR
Extract merchant, date, total, tax lines with per-field confidence. Merchant Memory learns per user.
- Conversational capture
Natural-language expense entry — mobile chat surface builds the structured spend document.
- Policy evaluation
Advisory or Enforcing verdicts on natural-language rules alongside structured checks. Fully logged.
- Anomaly + duplicate
Statistical outliers with explanations; duplicate fingerprint across time and users.
- Approver Copilot
Per-item risk, policy verdict, employee-baseline comparison, plain-English change summary.
- Ledger posting
No AI call ever triggers a Gen. Journal Line. Human approval is mandatory before the GL is touched.
- Approver identity
Routing is rule-driven, not AI-driven. Approvers are deterministic per Approval Rule.
- Tax rate determination
Tax pack tables are authoritative. AI never picks a tax rate — the ITaxPack implementation does.
Snap a receipt on the move. Post it clean.
One flow the app runs a thousand times a month for a typical mid-market customer. Every step is auditable in one place, every human action is captured, every AI call is logged.
- 1Employee snaps a receipt on the mobile surface.
- 2Broker calls Claude for OCR — merchant, date, total, tax lines, per-field confidence.
- 3Merchant Memory pre-fills GL account, category and dimensions from this employee's past pattern.
- 4Employee confirms in mobile and submits.
- 5Policy Engine evaluates — Advisory or Enforcing verdict, logged with rule text.
- 6Approval Rule routes to the right approver; Copilot pre-summarises risk and comparison.
- 7Approver acts from mobile.
- 8Posting Mgt. builds balanced Gen. Journal Lines, applies Allocation Profile, posts through the standard Post Batch codeunit.
- 9Vault archives the original + rendered PDF + SHA-256 hash with a retention policy.
- 10Employee is reimbursed via the next payroll run or the card-clearing account settles.
Client dinner · Bengaluru ──────────────────────────── Merchant Sarson Ke Khet Date 2026-03-14 Category Meals & Entertainment Trip BLR-2026-04 Job / Project ACME-Impl-B Line items Food subtotal ₹ 800 Service charge (5%) ₹ 40 GST (CGST 2.5% + SGST) ₹ 42 ──────────────────────────── Total ₹ 882 AI extracted Confidence 0.94 Merchant memory GL 6420 · Dim BLR-Sales Approval Policy verdict Approved (Meals under ₹1,200) Anomalies none Approver mgr-002 Posted Gen. Journal batch SPENDFLOW Posted G/L Entry G/L-2026-04117 Vault revision v1 · SHA-256 f1a3…9c
Five packs shipped. New countries drop in as packs, not code.
A vendor-neutral ITaxPack interface means new country packs ship rates, layouts and metadata — never a change to the SpendFlow core. India is on the roadmap; talk to us if you need it earlier than the public timeline.
W1 · worldwide core
Baseline pack for any country without its own pack yet.
- Generic VAT model + per-diem + mileage engine
- Unallocated and clearing account patterns
- Common employee-vs-vendor distinction for tax direction
- Sensible defaults you can start on before a full pack ships
EU pack
European Union VAT and cross-border travel patterns.
- EU VAT model with cross-border input-tax recovery hooks
- Employee-vs-vendor distinction for VAT direction
- Common EU per-diem tables (indicative, validate locally)
- Cross-country trip legs handled by Allowance Destination Line
UK pack
HMRC-aligned mileage and VAT treatment.
- UK VAT with fuel-scale-charge accommodation
- HMRC AMAP mileage rate tables
- VAT-inclusive fuel treatment
- Standard corporate benefit-in-kind flags
GCC pack
Gulf VAT with bilingual print — Saudi, UAE, Bahrain, Oman.
- VAT for Saudi (ZATCA), UAE (FTA), Bahrain (NBR), Oman (TA)
- Arabic bilingual layouts on the travel tax statement report
- Per-emirate rate table stubs
- GCC per-diem rate seeds you can override per country
US pack
GSA-aligned per-diem and IRS mileage rates.
- GSA-aligned per-diem tables
- IRS standard mileage rate
- State / municipal tax categorisation
- Mid-quarter convention for tax-year cutoffs
Six architectural decisions that keep SpendFlow clean for the long run.
Each one is enforced — by AppSourceCop, by our own ruleset, or by the guard rails baked into the code paths themselves.
Standalone by architecture
app.json declares zero required dependencies on any other AppSource app. Nothing to break during a BC major upgrade cycle. Sibling apps discovered at runtime through ISiblingIntegration — SpendFlow keeps working whether they're installed or not.
AI cannot post to the ledger
Every Claude call is advisory. Approval is a human step. Posting is a codeunit path that never accepts an AI output as its trigger. This is a rule enforced in the SSF Posting Mgt. codeunit, not a convention.
Redaction before AI leaves the tenant
SSF Redaction Field marks columns that never reach the broker. Employee identifiers, sensitive dimensions and tenant-restricted fields are stripped before any call. What Claude sees is exactly the receipt image and the fields required for the specific call — no bulk export, no side-channel.
Write-only audit log
SSF Audit Log records every state change with the actor, before/after values and timestamp. No update, no delete — an audit row is written once and outlives the source record. Auditors get a full narrative of who did what and when, without needing to reconstruct from BC change-log tables.
Immutable document vault
SHA-256 hash on every artefact. Post-approval edit lock on the source document. Retention policies per document type. Auditors trace GL entry → SpendFlow document → vault artefact with cryptographic proof of no tampering.
DSAR + erasure built in
SSF Data Governance Request handles subject-access and erasure requests end-to-end. Erasure creates a tombstone in the Vault rather than a silent delete — the audit trail survives even after PII is removed. Compliant with GDPR-style workflows out of the box.
4–6 weeks single country. One extra week per additional pack.
Implementation scales with the country packs you activate and the sibling systems SpendFlow needs to talk to. A single-country company on Entra ID with one card provider is the fast path. Multi-country and multi-card-provider adds discovery and training time.

Per-Tenant Extension while AppSource clears. Same code, same license.
Week 1
Country pack selection, module set agreed, card provider(s) identified, employee data source confirmed (Entra ID / HRIS export / manual). Assisted-setup wizard run in a sandbox tenant.
Week 2
Approval rules authored per amount / category / dimension. Allocation profiles for recurring splits. Per-diem and mileage rate tables loaded from the country pack. First card agreement configured.
Weeks 3–4
10–20 employees on the mobile surface. Real receipts, real cards, real approvals, real posting in the sandbox. Policy verdicts reviewed with finance. AI confidence thresholds tuned per category.
Week 5
Historical open items brought over or left in the legacy system with a cut-off date. All employees onboarded via bulk import. Notifications enabled. Approvers trained on the queue + copilot.
Week 6+
Card feed on schedule, month-end close includes SpendFlow posting run, merchant memory improves per-user OCR accuracy each week. Quarterly policy review with finance.
Beyond
Turn on Commitment Register for recurring vendor obligations. Add Advance Authorisation flow for planned travel. Enable Approver Copilot for high-volume approvers. Extend to sibling companies via cross-company approvals.
Frequently asked questions
Business Central 27.0 and later, cloud (SaaS) tenants. On-premises and older versions are not targeted for the AppSource release; existing on-prem BC customers can still deploy via PTE (Per-Tenant Extension) with the same object range.
Bring a real receipt and a real approver. We'll post it live.
A 60-minute working session, not a slide deck. Bring a real receipt (or a card statement), your approval structure and any country pack you need. We install in a BC sandbox, capture the receipt, run it through policy and approval, post to the GL and walk through the vault entry. You leave with a written summary of what changed for you.
- Live install + country pack activation in your BC sandbox
- Real receipt captured, approved and posted end-to-end
- Honest answer on which modules and packs you actually need
- Written proposal within one working day
