The full upstream README, mirrored here for reference. Install config, tool schemas, adoption signals, and an original overview live on the Invoice Intake (reference) listing page.
Reference implementation of the tool-design rules in Designing MCP servers and tools that agents can use safely, on a real back-office process: supplier invoice intake.
It is small on purpose. The fake ERP is a JSON file; everything else is the shape we use in production systems.
| Rule | Where |
|---|---|
| Model the business operation, not the API | erp_match_po, erp_stage_invoice, not PATCH /invoices |
| Separate reads, drafts and commits | --role read server (reads + reversible staging) vs --role commit server (irreversible post) |
| Strict schemas | Literal enums for currency, ids not names, found=false as a valid empty result |
| Permissions on the server and credential | specialist agents get read; only the orchestrator connects to commit |
| Tool results are untrusted input | invoices_extract says so in its description; the eval set includes a prompt-injection case |
| Typed errors | {"error": "approval_required" | "validation_failed" | "business_rule" | "not_found", "retryable": bool, ...} |
| Log for the auditor | audit.jsonl: actor, tool, ids, approval reference |
| Human checkpoint enforced server-side | erp_post_invoice refuses without a recorded approval, whatever the client believes |
Expected first run:
The orchestrator is deterministic so the flow replays without an API key.
An LLM belongs in the places marked in orchestrator.py (ambiguous vendor
candidates, free-text remarks, the note back to the requester), not in the
match rule, the tolerance or the approval limit.
Give an agent only the read server unless it is the orchestrator.
MIT. Built by JustDukkan, AI solutions architecture.