Accounts Payable Agent
ATC-AGT-0002094
64
moderate risk
Identity
Who owns it, and what it is for
- Declared purpose
- Parse supplier invoices, match them to purchase orders and queue payment runs.
- Business owner
- Marit Halvorsen · Finance Operations
- Technical owner
- Anders Kohl · Platform Engineering
- Provider and model
- OpenAI · gpt-4.1
- Framework
- LangChain
- Environment
- production
- Data classes reached
- Confidential, Financial data, PCI
- Last activity
- 2 minutes ago
Risk
Why the score is 64
Every point is accounted for. Remove a factor and the score moves by exactly that much.
- +18
Data
Handles payment instruments and supplier bank references
- +16
Action
Queues payment runs a human then releases
- +10
Tool
Can post journal entries through Finance MCP
- +8
Privilege
Two level-3 grants, both in active use
- +6
Dependency
Depends on a PDF parser with a known advisory
- +6
Compliance
Recertification due in 9 days
- 64Total
Access
What it may do, action by action
Permissions are held at the level of the action, so reading a record and changing its banking details are separate grants that can be decided separately.
- read_invoiceERPL0 ReadGranted
- match_purchase_orderERPL1 DraftGranted
- queue_payment_runERPL3 SensitiveGranted
- initiate_payoutERPL4 CriticalWithheld
- send_emailEmailL2 Execute, low riskGranted
Dependencies
MCP servers it is bound to
- approved
Microsoft MCP
Microsoft
read_emailsearch_files - approved
Finance MCP
Internal · Finance Platform
read_ledgerpost_journal
Execution identity
What it authenticates as
An agent does not reach anything by itself. It runs as a machine identity, and that identity is what actually holds the credential — so the agent's permissions are only ever a subset of what this can do.
- Production Billing Service81
ATC-MID-0001188 · Microsoft Entra ID
API keyClient secret - Invoice Parser Workload20
ATC-MID-0005266 · Kubernetes · prod-eu
SPIFFE SVID
Supply chain
Bill of materials
What this agent is assembled from. It is also the answer to the blast-radius question when one of these is compromised.
Model
Framework
Tools
MCP servers
Databases
Packages
Runtime
Decisions taken on its behalf
Every governed action produces one of these, and each records the rule that decided it.
- 11:20:04read_invoiceerp:inv-99214Allowed
rule: finance.read.invoices
- 11:20:09match_purchase_ordererp:po-4471Allowed
rule: finance.draft
- 11:20:33queue_payment_runerp:run-2209Approval required
rule: finance.level-3.human-approval
- 11:31:50initiate_payouterp:run-2209Denied
rule: finance.level-4.prohibited