Extracted is not approved: review document data before it becomes a business record
Skavio Flow turns invoices, orders, scans and text into structured outputs with source evidence and review warnings. That makes the extraction reviewable—not automatically ready for an accounting ledger or ERP. A dependable workflow keeps six steps distinct: extract, validate, compare with the source, correct, approve and import. Destination checks and the approval gate belong in your integration.
Start with a reviewable draft
[Skavio Flow](https://www.skavio.eu/flow/) supports custom extraction fields and saved company workflows, with XLSX document and line-item worksheets, CSV and JSON outputs. Define those fields around the record you intend to create: which values are required, which may be missing and which need a business decision before import. Flow flags missing or ambiguous fields for review. The API documentation specifies that missing extraction values are represented as null. Preserve that distinction in your staging data: a missing amount should not silently become zero, and an unresolved date should not become a guessed date. Keep extracted output separate from live business records. Whether the next step is a spreadsheet import or a server-side integration, treat extraction as a candidate record that can still be inspected and corrected.
A valid schema is only the first check
For JSON integrations, validate required properties, data types and permitted nulls before mapping values into the destination. These checks establish whether the output meets your declared data contract. They do not establish whether an invoice number, currency or total matches the source document. Date handling deserves an explicit rule. Under [JSON Schema Draft 2020-12](https://json-schema.org/draft/2020-12/json-schema-validation), the Format-Annotation vocabulary treats format as an annotation; format assertion is disabled by default. Configure and test your validator rather than assuming that a date-format annotation will reject an invalid date. An illustrative source date such as “04/05/2026” also needs interpretation, not just syntax validation. If the document does not resolve the day–month order, route it for review instead of silently choosing a locale. A structurally valid date can still be the wrong business date.
Compare values with the document—and check line items separately
The [Processing API documentation](https://www.skavio.eu/api/docs/) states that evidence is checked against source text. Use that evidence to support review alongside the original document; it is not a guarantee that the extracted value or its business interpretation is correct. For an invoice workflow, the following are recommended integration controls—not claims that Flow automatically performs every check. Apply your own rules for discounts, charges and rounding when reconciling amounts. Dashboard corrections cover extracted scalar fields and regenerate exports without another processing charge. Do not extend that capability into an assumption about line-item editing: line items still require checking against the original document. After a correction, use the regenerated output rather than an earlier downloaded copy.
- Supplier and invoice identity: confirm the supplier, invoice identifier and intended destination account; check for an existing record before creating another.
- Currency and dates: compare the currency, invoice date and due date with the source, resolving ambiguous or missing values.
- Totals: reconcile the relevant subtotal, tax, discounts, charges and final amount under your business rules.
- Line items: compare descriptions, quantities, unit prices and amounts, including whether rows have been omitted or duplicated.
Approve the proposed write, not just the document
Review should end with a specific decision: approve these values for this destination record. Present the source evidence, corrected values and proposed mapping together, resolve exceptions, and record who approved the write and when. If the values or destination change afterward, require a fresh approval. Treat uploaded documents and extracted content as untrusted data. Text inside an invoice must not authorize posting a record, changing supplier details or invoking another system. [OWASP’s prompt-injection guidance](https://cheatsheetseries.owasp.org/cheatsheets/LLM_Prompt_Injection_Prevention_Cheat_Sheet.html) recommends separating external content from trusted instructions, validating downstream actions and enforcing least privilege outside the model. An action-specific approval gate is an integration control. It is not a claim that Flow implements your accounting system’s approval policy or provides a built-in ERP connector.
Make the API handoff reliable without skipping review
For a server-side workflow, the Skavio Processing API provides idempotent job submissions, signed completion webhooks and authenticated result downloads. Verify completion callbacks using the documented procedure, download results into staging, and run validation and review before any destination write. Successful processing does not mean a reviewer has approved the result. The documentation specifies at-least-once webhook delivery, so handle repeated events through event deduplication. Separately prevent duplicate destination writes. Submission idempotency addresses job submission; do not assume it also makes an ERP import idempotent. Your integration needs its own record-identity and retry rules for that boundary. Plan record retention before deployment. API results have seven-day retention. Preserve source material, reviewed outputs and approval records according to your company’s policy before platform results expire. Result availability is not a business-record archiving guarantee.