Operations · Reporting · Food halls

The invoice line that was not on that order

An invoice typed against the wrong purchase order. The line named belonged elsewhere, so nothing was written — and the screen still said saved.


Here is a quiet one from the paperwork end of a kitchen. A delivery arrives, somebody opens the purchase order it belongs to, and types what the supplier's invoice actually says, line by line: this many, at this price. They press save. The screen says saved.

Now suppose one of those lines does not belong to that order. Two orders from the same supplier, two tabs open, a line identifier from the wrong one — the kinds of thing that happen on a Tuesday morning in a goods-in area. What should happen is a refusal naming the line. What happened instead was that the update matched no row, wrote nothing, and the answer was still a plain success.

The fence was right; the reporting was not

This is worth separating carefully, because the security half was never broken. The write was correctly fenced: it only ever touches a line belonging to the order you are on, so a line from somewhere else cannot be edited through this door. That is the right design. The failure was that a write which touched nothing and a write which touched everything you asked for gave back the identical answer.

There was a second version of the same fault in the same nine lines. A quantity that is not a number — an empty-looking cell that is really a stray character, a paste from a PDF — was turned into zero. On an invoice, zero is a claim: the supplier delivered none. It is not a neutral default for "could not read that".

What it costs later

Nothing breaks on the day. It breaks when somebody reconciles the month and the invoiced figures do not line up with what came through the door, and there is no record of a failure anywhere to explain it — because from the system's point of view nothing failed. Reconstructing that is hours of work against paper, and the answer, when you get there, is "a save that said it saved".

Ours now refuses and names the line, writes all the lines in one go so that half an invoice cannot land, and reports how many rows it actually changed rather than how many statements it sent. If you run goods-in off a screen, the question worth asking your supplier is simple: when a save matches no rows, what does it say? "Saved" is the wrong answer, and it is the common one.


Try it on tonight’s service.

Nothing to install, no card. Not better by the weekend? Close the tab.