The Business Situation

Harborline Wholesale Supply is a fictional 85-person distributor serving commercial customers from two distribution facilities. The company manages 42 active suppliers and processes approximately 1,100 purchase-order lines each month.

The supplier-review process involves a procurement manager, a procurement analyst, two buyers, a quality manager, a supply chain manager, and receiving staff. Suppliers are reviewed quarterly, producing an average of 14 scorecards per month.

The company already uses Microsoft 365. Procurement records supplier metrics in Excel, supporting files are stored across SharePoint folders and email, and approvals are requested through Outlook. The enterprise resource planning system remains the source for purchase-order, receipt, and pricing reports, but it does not provide a complete supplier-performance workflow.

The team wants a consistent way to compare suppliers across six measures:

  • On-time delivery
  • Quality acceptance
  • Fill rate
  • Responsiveness
  • Unapproved price changes
  • Issue resolution

The main problem is not the absence of data. It is the absence of agreed definitions, controlled evidence, consistent weighting, clear ownership, conditional approval, and a repeatable process for turning a score into a supplier action plan.

Note: This case study is provided as a representative example of the types of AI integration and digital transformation solutions Intelligex designs and delivers. Actual engagements are tailored to each client’s goals, constraints, existing systems, timeline, and available resources, so the approach, tools, and outcomes may vary.

The Existing Process

The original process was completed separately for every supplier at the end of each quarter.

  1. The procurement analyst exported purchase-order, receipt, rejection, and price reports from the ERP system.
  2. The analyst copied selected totals into a supplier-specific Excel workbook.
  3. Buyers supplied email-response times and issue-resolution details from personal inboxes and local trackers.
  4. Receiving staff sent quality reports and photographs by email.
  5. The analyst applied formulas that differed slightly between workbooks and review periods.
  6. The workbook was emailed to the procurement manager, quality manager, or supply chain manager depending on the issues found.
  7. Comments and revised files circulated as email attachments.
  8. The analyst prepared a separate supplier-meeting document and later saved available evidence to SharePoint.

Process weaknesses

  • Metrics were copied manually from multiple reports.
  • Supplier workbooks contained different formulas.
  • Evidence was split between email, local folders, and SharePoint.
  • There was no standard approval route.
  • Follow-ups depended on the procurement analyst.
  • Actions discussed during supplier meetings were tracked separately.

Business effects

  • Suppliers could be compared using inconsistent definitions.
  • Reviewers spent time checking calculations rather than evaluating performance.
  • Missing evidence delayed meetings and approvals.
  • Management could not reliably identify overdue reviews.
  • Issue ownership was unclear after supplier meetings.
  • Historical decisions were difficult to reconstruct.

The process required an estimated 165 minutes of administrative and review-preparation work for each scorecard. At 14 scorecards per month, this represented 38.5 labour hours before supplier meeting time.

The business needed to change the process because supplier volume and purchasing activity were increasing while the same analyst remained responsible for data collection, calculation, approval follow-up, and archiving. The dependency on one employee created both a capacity problem and a continuity risk.

What the New System Needed to Do

The team defined the business rules before selecting the automation design. This prevented the technology from embedding unresolved disagreements about metric definitions or supplier treatment.

Business and technical requirements
Requirement Expected behavior
Controlled intake Collect one structured submission for each supplier and review period, with evidence attached.
Validation Reject impossible counts, inactive supplier codes, invalid periods, and missing evidence before approval.
Unique identification Create a permanent scorecard ID and prevent duplicate processing of the same form response.
Agreed definitions Apply one versioned definition and threshold set to all suppliers in the review period.
Calculation Convert raw measures into metric scores, apply weights, and assign a rating.
Ownership Assign each scorecard to the buyer responsible for the supplier.
Conditional approval Route normal scorecards to procurement and higher-risk scorecards to quality and supply chain before final approval.
Evidence Copy source reports and attachments into a consistently named SharePoint folder.
Action plans Require corrective actions when total or individual metric thresholds are missed.
Reminders Notify owners about incomplete, overdue, or pending work without approving anything automatically.
Supplier meeting output Provide an approved scorecard, evidence links, discussion topics, actions, owners, and due dates.
Reporting Show reviews by status, supplier, owner, rating, due date, and exception type.
Audit evidence Retain input values, calculation version, approval responses, comments, timestamps, and archived evidence.
Exception handling Place failed or incomplete records in a visible manual-review queue.
Human control Keep score approval, supplier communication, action acceptance, and commercial decisions under human control.

Metric definitions

The company adopted definition version SPD-1.0. The definitions were documented in a version-controlled SharePoint document and referenced by every scorecard.

Supplier performance measures and weights
Measure Definition Weight Primary evidence
On-time delivery Supplier-caused order lines received within the agreed delivery window divided by eligible lines due. 25% ERP due-date and receipt report
Quality acceptance Accepted units divided by total units received. 20% Receiving and rejection report
Fill rate Eligible lines filled in full on the first receipt divided by eligible lines due. 20% Purchase-order and first-receipt report
Responsiveness Average business hours taken to acknowledge a defined sample of buyer or quality requests. 10% Communication sample log
Price change control Positive comparable-cost variance after subtracting documented approved price adjustments. 10% Baseline and actual price comparison
Issue resolution Issues closed by their target date divided by issues due during the period. 15% Issue register and closure evidence

If no issues were due during the review period, issue-resolution performance was set to 100. This was an explicit policy decision rather than an automation assumption. Organizations that prefer not to score a non-applicable measure can instead redistribute its weight, but that requires a more complex calculation and clear reporting.

Implementation Approaches Considered

Supplier scorecard implementation options
Approach Connected tools Effort Customization Primary limitation
Standardized spreadsheet Excel, email, SharePoint Low Moderate Approval, concurrency, and audit controls remain weak.
Microsoft 365 workflow Forms, Lists, SharePoint, Power Automate, Outlook Moderate High for this volume Requires disciplined list design and flow maintenance.
BI reporting layer Microsoft 365 workflow plus Power BI Moderate to high High for analytics BI improves analysis but does not replace intake, evidence, or approval controls.
Dedicated supplier-management platform ERP, supplier portal, quality and sourcing modules High Depends on platform Implementation and data migration may be disproportionate for 42 suppliers.
Custom application Power Apps or custom interface, Dataverse or database, APIs High Very high More development, licensing, security, and support responsibility.

Standardized spreadsheet

A protected Excel template would improve formula consistency and could be stored in SharePoint. It would not adequately solve record ownership, conditional approvals, duplicate submissions, evidence validation, or operational queues. Excel also becomes harder to govern when several employees update the same reporting dataset.

Microsoft 365 workflow

Forms, Lists, SharePoint, and Power Automate matched the organization’s existing environment. These tools could support the required volume without introducing a separate supplier platform. They also allowed the process to be implemented in stages.

Power BI reporting layer

Power BI would improve trend analysis, supplier segmentation, and executive reporting. It was not selected for the first release because the immediate problem was workflow control rather than visualization. Lists and SharePoint views were sufficient for operational reporting, while the data structure remained suitable for a later BI connection.

Dedicated supplier-management software

A supplier relationship management or supplier quality platform would provide broader portal, sourcing, risk, and compliance functions. Harborline did not yet require external supplier login, complex qualification workflows, or formal regulatory reporting. Purchasing a larger platform would not remove the need to define metrics and clean source data.

Custom application

A custom application could provide more precise field-level security and a tailored user interface. It would also require more development, deployment, licensing review, testing, and ongoing support. The expected transaction volume did not justify that effort for the initial implementation.

The Selected Solution

The selected implementation uses a group-owned Microsoft Form for intake, Microsoft Lists as the operational system of record, SharePoint for evidence and archived outputs, and Power Automate for validation, calculation, assignment, approval, reminders, and archiving.

Microsoft 365 Outlook and the Power Automate Approvals connector deliver notifications and approval requests. Operational reporting is provided through indexed Microsoft Lists views displayed on a restricted SharePoint page.

Selected tools and responsibilities
Tool Responsibility
Microsoft Forms Collect quarterly metric inputs, review-period details, comments, and supporting files from internal employees.
Microsoft Lists Store suppliers, scorecard reviews, issues, actions, approval evidence, and automation logs.
SharePoint Store controlled metric definitions, source evidence, meeting minutes, and archived scorecard snapshots.
Power Automate Validate requests, create IDs, calculate scores, assign owners, route approvals, send reminders, archive records, and log failures.
Microsoft 365 Outlook Send confirmations, requests for more information, reminders, escalation notices, and meeting-preparation messages.
SharePoint pages and Lists views Provide operational queues and scorecard reporting without a separate BI deployment.
Optional AI service Draft a supplier-meeting brief from approved structured data and sanitized issue notes.

The ERP system was retained as the source of purchasing, receiving, and pricing reports. The first release did not write to the ERP. Analysts continued exporting controlled reports and uploading them as evidence because the available ERP integration options had not yet been approved.

The implementation removed spreadsheet formula maintenance, duplicate score entry, manual folder creation, ad hoc approval routing, and most reminder emails. Human reviewers retained authority over metric evidence, approval outcomes, supplier communication, action-plan commitments, and commercial decisions.

System Architecture and Data Flow

  • Intake: A group-owned Microsoft Form completed by authorized employees.
  • System of record: Microsoft Lists for supplier master data, reviews, issues, actions, approval audit, and automation logs.
  • Automation layer: Power Automate cloud flows using Microsoft 365 connections.
  • Document storage: A SharePoint evidence library with a supplier, period, and scorecard folder hierarchy.
  • Notifications: Power Automate Approvals and Microsoft 365 Outlook.
  • Reporting: Indexed Microsoft Lists views presented on a restricted SharePoint operations page.
  • AI layer: None in the core workflow; an optional service can draft a meeting brief after calculation.

End-to-end data flow

  1. Submission: The procurement analyst submits supplier and period data through Microsoft Forms. Forms returns a response identifier and stores uploaded files in the Microsoft 365 group’s SharePoint-backed form folder. A failed trigger remains visible in Power Automate run history.
  2. Duplicate check: Power Automate checks the Supplier Reviews list for the Forms response identifier. If it already exists, the flow logs a duplicate event and stops without creating another review.
  3. Supplier validation: The flow reads the Supplier Master list using the submitted supplier code. The supplier must exist, be active, have an assigned owner, and have a valid review frequency. Invalid submissions enter the Needs Information queue.
  4. Input validation: Counts, dates, monetary values, and attachment presence are checked. Cross-field validation confirms that on-time lines do not exceed due lines, rejected units do not exceed received units, and closed issues do not exceed issues due.
  5. Record creation: Power Automate creates a Supplier Reviews item. The returned SharePoint list item ID is converted into a scorecard ID such as SPR-2026-000318.
  6. Evidence creation: A SharePoint folder is created using the supplier code, year, quarter, and scorecard ID. Uploaded files are copied into that folder and prefixed with the scorecard ID.
  7. Calculation: Valid raw values are transformed into percentages, metric points, a weighted total, and an A through D rating. The calculation definition version is recorded.
  8. Assignment and routing: The supplier owner is copied from Supplier Master. Standard reviews go to the procurement manager. Reviews with a low total, a weak individual measure, a critical issue, or a material unapproved price variance follow the enhanced route.
  9. Approval: Reviewers receive the scorecard link, evidence link, metric summary, and allowed responses. Their identities, timestamps, outcomes, and comments are written to the Approval Audit list and included in an archive snapshot.
  10. Meeting and action plan: Approved scorecards enter supplier-meeting preparation. Required corrective actions are stored in the Action Plans list with an owner and due date.
  11. Closure and archive: After meeting minutes and required action evidence are present, the review is closed. Power Automate writes a JSON snapshot to SharePoint and marks the review as archived according to the retention workflow.
  12. Failure path: Connector failures, invalid records, missing files, and timed-out approvals update the Automation Status, write an Automation Log record, and notify the support owner. No failed record is silently treated as approved.

Data Structure

The implementation uses related SharePoint lists rather than one very wide spreadsheet. Supplier Master has a one-to-many relationship with Supplier Reviews. Each review can have multiple issues, actions, approval records, log entries, and evidence files.

Core records and relationships
Record Primary key Relationship Purpose
Supplier Master SupplierCode One supplier to many reviews Stores active status, owner, review frequency, and supplier settings.
Supplier Reviews RecordID Many reviews to one supplier Stores raw measures, scores, workflow status, and archive references.
Performance Issues IssueID Many issues to one review Stores quality, delivery, price, and service exceptions.
Action Plans ActionID Many actions to one review Tracks supplier and internal corrective actions.
Approval Audit ApprovalAuditID Many approval events to one review Preserves route, reviewer, response, comments, and timestamp.
Automation Log EventKey Many events to one review Records execution, failure, retry, and recovery information.
Evidence library SharePoint file identifier Many files to one review folder Stores source reports, photographs, minutes, and archive snapshots.

Supplier Reviews fields

Important Supplier Reviews fields
Field Type Required Source and validation Purpose and update owner
RecordID Single line text, unique Yes Generated after the list item is created Permanent scorecard reference; updated by automation
SourceResponseID Single line text, unique Yes Microsoft Forms response ID Prevents duplicate processing; updated by automation
DefinitionVersion Single line text Yes Controlled value such as SPD-1.0 Identifies the metric and threshold rules used
Created and Modified System date and time Yes SharePoint system fields Provides record history and operational timing
Requester Person Yes Forms responder identity Identifies the employee responsible for the submission
Supplier Lookup Yes Validated against Supplier Master Relates the review to the supplier
SupplierCode Single line text Yes Copied from Supplier Master Supports folders, filters, and exports
Owner Person Yes Supplier Master owner Buyer accountable for review completion
PeriodStart Date Yes Form; must precede PeriodEnd Defines the scoring period
PeriodEnd Date Yes Form; cannot be in the future Defines the scoring period and due-date calculations
DueLines Whole number Yes Form; must be greater than zero On-time and fill-rate denominator
OnTimeLines Whole number Yes Form; zero through DueLines On-time delivery numerator
FirstFillLines Whole number Yes Form; zero through DueLines Fill-rate numerator
UnitsReceived Number Yes Form; must be greater than zero Quality denominator
UnitsRejected Number Yes Form; zero through UnitsReceived Quality rejection quantity
ResponseSampleCount Whole number Yes Form; must be greater than zero Responsiveness denominator
TotalResponseHours Number Yes Form; non-negative business hours Used to calculate average response time
BaselineComparableCost Currency Yes Form; must be greater than zero Baseline for price-change control
ActualComparableCost Currency Yes Form; non-negative Actual cost for matching quantities and specifications
ApprovedPriceAdjustment Currency Yes Form; non-negative and evidence required when greater than zero Excludes documented approved changes
IssuesDue Whole number Yes Form; zero or greater Issue-resolution denominator
IssuesClosedOnTime Whole number Yes Form; zero through IssuesDue Issue-resolution numerator
CriticalIssue Yes or no Yes Form; default No Forces enhanced review when Yes
OTDPercent and OTDScore Number After validation Calculated by Power Automate Stores on-time result and threshold points
QualityPercent and QualityScore Number After validation Calculated by Power Automate Stores quality result and threshold points
FillPercent and FillScore Number After validation Calculated by Power Automate Stores fill-rate result and threshold points
ResponseHours and ResponseScore Number After validation Calculated by Power Automate Stores responsiveness result and threshold points
PriceVariancePercent and PriceScore Number After validation Calculated by Power Automate Stores uncontrolled positive price variance and points
ResolutionPercent and ResolutionScore Number After validation Calculated by Power Automate Stores issue-resolution result and points
WeightedScore Number After validation Calculated from six metric scores Overall score from zero through 100
Rating Choice After validation A, B, C, or D Overall performance band
Status Choice Yes Controlled workflow values Current business stage; updated by users and flows
ApprovalStatus Choice Yes Not Started, Pending, Approved, Returned, Rejected, Timed Out Separates approval state from business status
ApprovalRoute Choice After calculation Standard or Enhanced Records the routing rule used
ApprovalID Single line text No Returned by the Approvals connector Links the review to its approval request
ApprovalGeneration Whole number Yes Starts at zero and increments on reissue Prevents stale approval responses from changing the record
ExceptionType Choice No Validation, Evidence, Approval, File, Connector, Notification, AI, Other Supports manual-review queues
DocumentLink Hyperlink No Target SharePoint evidence folder Connects the record to evidence
ExternalSystemID Single line text No ERP report or batch reference Supports source reconciliation
AutomationStatus Choice Yes Not Started, Processing, Completed, Warning, Failed, Manual Review Shows technical processing state
LastAutomationRun Date and time No Updated by every flow Supports monitoring and reconciliation
RetryCount Whole number Yes Default zero Limits repeated processing
ErrorMessage Multiple lines text No Failure scope output Provides a safe operational error summary
Notes Multiple lines text No Requester, owner, or reviewer Stores relevant context without replacing evidence

SharePoint list versioning is enabled on operational and audit lists. Views are not treated as security controls. Sensitive approval evidence is stored in a separate Approval Audit list with narrower edit permissions.

Workflow Statuses and Ownership

Supplier scorecard workflow statuses
Status Meaning and owner Entry and exit conditions Reminder and escalation
Submitted Automation owns initial processing. Entered when the Forms response is received; exits after validation. Flagged if still processing after 30 minutes.
Needs Information Requester and assigned buyer own corrections. Entered for missing, invalid, or unsupported data; exits after a corrected submission or controlled update. Reminder after two business days; escalation after five.
Ready for Approval Automation owns routing. Entered when calculations and evidence copying succeed; exits when an approval request is created. Flagged if unchanged after 30 minutes.
Approval Pending Assigned reviewers own the decision. Entered after an approval ID is stored; exits on approval, return, rejection, or timeout. Reminder after two business days; escalation after three; timeout handling after seven calendar days.
Returned Buyer owns clarification or correction. Entered when a reviewer requests more information; exits when resubmitted for a new approval generation. Reminder after two business days; escalation after five.
Rejected Procurement manager owns disposition. Entered when evidence cannot support the scorecard or the review must be restarted; exits only through documented manual recovery. Included in weekly exception review.
Approved Buyer owns supplier-meeting preparation. Entered after all required approvals succeed; exits after meeting results are recorded. Meeting reminder based on NextReviewDate or scheduled meeting date.
Action Plan Open Named action owners are responsible. Entered when one or more actions remain open; exits when required closure evidence is accepted. Reminder three days before due date; escalation one day after due date.
Closed Procurement analyst owns final completeness check. Entered after meeting minutes and required actions are complete; exits after archive creation. Flagged if archive is not created within one day.
Archived Procurement manager and records owner govern retention. Entered after the archive snapshot and evidence checks succeed. No operational reminders; subject to retention review.

A record moves backward when a reviewer selects Return for Information, evidence is found to be incomplete, or a material source-data correction changes the score. Rejection is reserved for unsupported or invalid reviews, not for poor supplier performance. A weak supplier score normally results in an approved scorecard with a corrective action plan.

Step-by-Step Implementation

Step 1: Prepare the Accounts and Permissions

  1. Create a SharePoint site or restricted site area for supplier performance. Use a Microsoft 365 group owned by the procurement manager and an IT administrator.
  2. Confirm that the tenant has access to Microsoft Forms, Microsoft Lists, SharePoint, Power Automate, Microsoft 365 Outlook, and the Approvals connector features required by the design. Licensing terms vary, so verify connector and service-account entitlements before deployment.
  3. Create a group-owned Microsoft Form rather than an individual-owned form. This reduces dependency on one employee and stores organizational file uploads in the group’s SharePoint-backed storage.
  4. Create a dedicated automation identity if organizational policy permits it. License it appropriately, apply multifactor authentication and conditional access, and use it only for approved flow connections.
  5. Add at least one backup flow owner. A flow should not depend solely on the procurement analyst’s personal account.
  6. Create separate production and test sites, lists, libraries, forms, and flows. Prefix test resources with TEST so links and notifications cannot be confused with production.
  7. Create test accounts or approved test users representing the requester, buyer, procurement manager, quality manager, supply chain manager, read-only manager, and unauthorized user.
  8. Create Microsoft 365 security groups for Supplier Performance Owners, Contributors, Reviewers, and Readers.
  9. Grant site owners full control, contributors edit access to operational records, reviewers read access plus approval rights, and readers read-only access.
  10. Restrict Approval Audit editing to the automation identity and site owners. Contributors may read approval evidence if business policy permits, but they should not be able to rewrite it.

The core implementation uses Microsoft 365 OAuth connections created through Power Automate. It does not require an external API key, webhook URL, or database credential. Optional AI integration is configured separately after the base workflow is stable.

Step 2: Build the Intake

Create a group-owned form named Supplier Performance Review Submission. Restrict responses to authenticated employees. Suppliers do not complete this internal form.

Microsoft Forms intake fields
Field Type and values Validation
Submission type Choice: New Review, Correction Required; Correction branches to Original Record ID
Original Record ID Text Required only for a correction
Supplier code Text Required; validated against Supplier Master after submission
Period start and end Date Required; cross-field validation occurs in Power Automate
Eligible lines due Number Required and greater than zero
Lines delivered on time Number Required and non-negative
Lines filled on first receipt Number Required and non-negative
Units received Number Required and greater than zero
Units rejected Number Required and non-negative
Response samples Number Required and greater than zero
Total business response hours Number Required and non-negative
Comparable baseline cost Number Required and greater than zero
Comparable actual cost Number Required and non-negative
Approved price adjustment Number Required; enter zero when none
Issues due Number Required and non-negative
Issues closed on time Number Required and non-negative
Critical issue present Choice: Yes, No Required
ERP report reference Text Required according to internal reporting convention
Review notes Long text Optional; must not contain unnecessary personal or confidential information
Supporting evidence File upload Required; permitted types and size follow tenant policy

Microsoft Forms can validate individual numeric fields, but it cannot enforce all cross-field rules. Power Automate therefore checks that numerators do not exceed denominators and that the period end is not in the future.

Use form branching so a Correction submission requests the original scorecard ID and an explanation. Do not allow unrestricted anonymous responses. Authentication, responder identity, supplier-master validation, and response-ID uniqueness provide the principal duplicate and spam controls.

The completion message should explain that the submission has been received and that a separate confirmation email will contain the scorecard ID. Forms cannot include the newly generated Lists ID in its static completion message.

Add a short privacy notice explaining that uploads are stored in SharePoint, used for supplier-performance review, and retained according to company policy. Avoid collecting personal data that is not required for the review.

Step 3: Create the System of Record

  1. Create the Supplier Master, Supplier Reviews, Performance Issues, Action Plans, Approval Audit, and Automation Log lists.
  2. Create internal column names without spaces where practical, such as SupplierCode, PeriodEnd, and AutomationStatus. Display names can be made more readable later.
  3. Set Supplier Master SupplierCode, Supplier Reviews SourceResponseID, and Automation Log EventKey to enforce unique values.
  4. Add indexes to SupplierCode, Status, PeriodEnd, Owner, ApprovalStatus, AutomationStatus, ReviewID, and action DueDate fields used by filtered views and flows.
  5. Enable list version history. Set the retained version count according to records policy and available storage.
  6. Create a lookup from Supplier Reviews to Supplier Master and lookups from Issues, Actions, Approval Audit, and Automation Log to Supplier Reviews.
  7. Create default values: Status equals Submitted, ApprovalStatus equals Not Started, AutomationStatus equals Not Started, RetryCount equals zero, and ApprovalGeneration equals zero.
  8. Do not rely on complex Microsoft Lists calculated columns for the weighted score. Power Automate calculates and writes the result so the calculation version, thresholds, errors, and rounding are controlled in one place.
  9. Create the SharePoint library Supplier Performance Evidence and enable versioning.
  10. Create a version-controlled metric-definition document containing exclusions, thresholds, weights, evidence requirements, and change-approval history.

Use naming conventions such as SPR-YYYY-000000 for reviews, ISS-YYYY-000000 for issues, and ACT-YYYY-000000 for actions. Power Automate creates the formatted reference after receiving the underlying list item ID.

Create operational views for My Open Reviews, Needs Information, Pending Approval, Enhanced Review, Open Actions, Overdue Actions, Recently Approved, Automation Failures, and Archive Pending.

Step 4: Connect the Tools

Create Power Automate connections using the approved automation identity. Connection labels and configuration screens can vary by tenant interface, but each connection must use the source, destination, and mapping described below.

Tool connection and field mapping
Source Destination Trigger or action Key mapping and returned value
Microsoft Forms Power Automate When a new response is submitted, followed by Get response details Response ID, responder, supplier code, period, raw measures, notes, attachments
Power Automate Supplier Master Get items using SupplierCode and Active status Returns supplier lookup ID, owner, review frequency, and status
Power Automate Supplier Reviews Create item, then Update item Returns list item ID used to generate RecordID
Forms file storage Evidence library Get file content using the verified source path, then Create file Returns target file identifier and link
Supplier Reviews Approvals connector Create an approval when Status is Ready for Approval Returns ApprovalID and later reviewer outcomes
Approvals connector Approval Audit Create audit items for responses Stores reviewer, response, comments, time, route, and generation
Supplier Reviews Microsoft 365 Outlook Send confirmation, reminder, return, escalation, and completion emails Uses record ID, owner, status, score, due date, and links
Supplier Reviews SharePoint archive Create JSON snapshot after closure Returns archive file identifier and URL

Run a test file upload before completing the attachment flow. Open the group’s SharePoint files and identify the actual Forms upload folder. The generated path includes the form and file-upload question and can differ if the form is renamed or localized.

Store the verified source folder path as a flow configuration value. Do not guess it or hard-code a personal OneDrive path into a group-owned production process.

Step 5: Build the Core Automation

Flow 1: Intake, validation, calculation, and evidence

  • Trigger: Microsoft Forms submits a new response.
  • Conditions: Response ID is new, supplier is active, required values are valid, and evidence is present.
  • Actions: Get response details, check duplicates, resolve supplier, create review, generate ID, validate values, create evidence folder, copy files, calculate scores, assign owner, and set approval route.
  • Fields updated: RecordID, Supplier, Owner, raw measures, scores, rating, DocumentLink, ApprovalRoute, Status, AutomationStatus, and LastAutomationRun.
  • Notification: Send the requester a confirmation or a request for correction.
  • Exception: Set Needs Information or Manual Review, write an Automation Log item, and notify the support owner.

Configure the actions in this order:

  1. Trigger on a new Forms response.
  2. Get response details using the response ID.
  3. Initialize variables for source response ID, supplier code, numeric inputs, configuration version, and error collection.
  4. Query Supplier Reviews for the SourceResponseID. If a record exists, log the duplicate and terminate successfully.
  5. Query Supplier Master for the active supplier code. Require exactly one result.
  6. Create a provisional Supplier Reviews item with Status Submitted and AutomationStatus Processing. The unique SourceResponseID column prevents a race condition from creating two records.
  7. Generate RecordID from the returned list item ID and update the item.
  8. Evaluate cross-field validation. Store a concise list of validation failures if any rule fails.
  9. If invalid, update Status to Needs Information, AutomationStatus to Manual Review, and ExceptionType to Validation. Notify the requester and stop.
  10. Create the supplier, year, quarter, and RecordID evidence folders.
  11. Parse the Forms attachment array and copy each source file into the evidence folder.
  12. Verify that at least one target file exists. If copying is incomplete, stop before calculation and set ExceptionType to File.
  13. Calculate raw percentages, metric points, weighted score, and rating.
  14. Determine Standard or Enhanced approval routing.
  15. Update Status to Ready for Approval and AutomationStatus to Completed.
  16. Send a confirmation containing RecordID, owner, rating, score, status, and links.

Flow 2: Conditional approval

  • Trigger: A Supplier Reviews item changes to Ready for Approval while ApprovalStarted is false.
  • Conditions: AutomationStatus is Completed and the approval generation has not already started.
  • Actions: Select approvers, increment generation, create approval, store ApprovalID, wait for responses, validate generation, record audit details, and update status.
  • Fields updated: ApprovalStarted, ApprovalID, ApprovalGeneration, ApprovalStatus, Status, LastAutomationRun, and approval timestamps.
  • Notification: Approvers receive links to the record and evidence. The buyer receives the outcome.
  • Exception: Timeout, connector failure, or stale response goes to Manual Review without changing the scorecard to approved.

For Standard routing, assign the procurement manager. For Enhanced routing, request quality-manager and supply-chain-manager responses in parallel, then start a sequential final approval for the procurement manager.

After any approval response, retrieve the latest list item and compare its ApprovalGeneration with the generation captured at the start of the flow. Ignore a response from an older generation. This prevents a late response to a superseded request from altering the current record.

Flow 3: Reminders and escalations

  • Trigger: Scheduled recurrence each weekday morning in the business time zone.
  • Conditions: Records are pending, returned, incomplete, or overdue.
  • Actions: Query indexed views, calculate record age, send due reminders, notify backup reviewers, and record ReminderSentDate.
  • Fields updated: LastReminderDate, EscalationLevel, LastAutomationRun, and AutomationStatus when required.
  • Notification: Owner, current reviewer, backup reviewer, or procurement manager depending on age and status.
  • Exception: Invalid recipient addresses are logged and routed to the support owner.

The reminder flow does not approve, reject, or close records. It only communicates the current state and escalation rule.

Flow 4: Action monitoring and archive

  • Trigger: Action Plans changes or a Supplier Review changes to Closed.
  • Conditions: Required actions have acceptable closure evidence and the archive has not already been created.
  • Actions: Validate open actions, create an archive snapshot, write the archive URL, and set the final status.
  • Fields updated: Action status, ClosedDate, ArchiveLink, ArchivedDate, Status, and AutomationStatus.
  • Notification: Send closure confirmation to the buyer and procurement manager.
  • Exception: Missing minutes or closure evidence returns the record to Action Plan Open or Manual Review.

Flow 5: Technical reconciliation

  • Trigger: Scheduled nightly.
  • Conditions: Processing records older than 30 minutes, missing evidence links, failed automation, or closed records without archives.
  • Actions: Compare list state with expected evidence and log state, retry eligible operations, and assign unresolved failures.
  • Fields updated: RetryCount, AutomationStatus, ErrorMessage, ExceptionType, and LastAutomationRun.
  • Notification: Daily exception digest to the support owner and procurement analyst.
  • Exception: Records reaching the retry limit stay in Manual Review until explicitly recovered.

Step 6: Add Approvals, Reminders, and Escalations

The approval route is based on deterministic rules.

Approval routing rules
Condition Route Required approval
Weighted score is at least 80, all metric scores are at least 60, no critical issue, and price variance is no more than 2.5% Standard Procurement manager
Weighted score is below 80 Enhanced Quality and supply chain in parallel, then procurement manager
Any individual metric score is below 60 Enhanced Quality and supply chain in parallel, then procurement manager
Critical issue is Yes Enhanced Quality and supply chain in parallel, then procurement manager
Unapproved price variance exceeds 2.5% Enhanced Quality and supply chain in parallel, then procurement manager

Use approval responses of Approve, Return for Information, and Reject. Return for Information sends the record back to the buyer without deleting calculations or evidence. A corrected record increments ApprovalGeneration and starts a new approval.

The approval request should contain:

  • Record ID, supplier code, review period, owner, weighted score, and rating
  • All six raw percentages and metric scores
  • Reason for Enhanced routing, when applicable
  • Links to the Supplier Reviews item and evidence folder
  • Definition version
  • Required response choices and expected response date

Send a reminder after two business days. Escalate to the configured backup reviewer after three business days. At seven calendar days, mark the approval Timed Out and place the record in Manual Review. A designated owner can reassign or reissue the approval after confirming the correct approver.

Maintain primary and backup role addresses in a restricted Role Configuration list or controlled flow settings. If a delegate has an active start and end date, the approval flow selects that delegate before creating the request.

Approval evidence includes route, generation, approval identifier, assigned reviewer, actual responder, response, comments, request time, response time, and resulting status.

Step 7: Add Documents and File Management

Configure the evidence library with this folder structure:

Supplier Performance Evidence/
  SUP-014/
    2026/
      Q2/
        SPR-2026-000318/
          Source Evidence/
          Approval/
          Meeting/
          Action Closure/
          Archive/

Power Automate creates each folder in sequence and stores the final folder URL in DocumentLink. Supplier codes come from the validated Supplier Master rather than unrestricted form text.

Prefix copied files with the RecordID and retain a recognizable source name, for example:

SPR-2026-000318_ERP-Delivery-Report.xlsx
SPR-2026-000318_Quality-Rejections.pdf
SPR-2026-000318_Response-Sample.xlsx
SPR-2026-000318_Price-Comparison.xlsx

Uploaded Forms files already have valid Microsoft 365 filenames, but the flow should still prevent a target overwrite. If a target name exists, append the Forms response ID or a sequence number.

Enable versioning in the evidence library. Replacements should create a new version or use a clearly marked corrected filename. The original evidence should not be silently deleted after an approval has started.

Do not share the internal evidence folder directly with a supplier. The buyer prepares a reviewed supplier-facing output that excludes internal comments, personal information, and unrelated commercial data.

Test representative file sizes and types against Forms, SharePoint, and Power Automate connector limits in the organization’s tenant. Large files should use an approved secure upload process, with the resulting SharePoint link stored on the review.

If any required upload fails, set EvidenceStatus to Incomplete, stop approval routing, and place the record in Manual Review. The recovery flow should copy only missing files rather than duplicating files that succeeded.

Step 8: Add Reporting and Operational Views

Operational views
View Filter Primary user
New Reviews Status is Submitted or Ready for Approval Procurement analyst
My Open Reviews Owner is current user and Status is not Archived Buyers
Awaiting Approval ApprovalStatus is Pending Reviewers
Overdue Reviews Target date is before today and Status is open Procurement manager
Incomplete Records Status is Needs Information Requesters and buyers
Enhanced Reviews ApprovalRoute is Enhanced Quality and supply chain
Rejected or Returned Status is Rejected or Returned Procurement manager
Open Actions Action status is Open or In Progress Action owners
Overdue Actions Due date is before today and action is not closed Procurement manager
Recent Completions Closed date is within the last 30 days Management
Automation Failures AutomationStatus is Failed or Manual Review Support owner
Manual Review Queue ExceptionType is not blank and AutomationStatus is not Completed Procurement analyst and support owner

Create a restricted SharePoint operations page containing List web parts for the most important views. Display score, rating, status, owner, review period, next action date, and exception type.

Use calculated or flow-populated duration fields for SubmissionToApprovalHours and ApprovalToClosureDays. Power Automate updates these values when the relevant timestamp becomes available.

List views refresh when users reload the page. The daily reminder and reconciliation flows query the underlying list directly, so they do not depend on a user opening a dashboard.

The procurement manager owns reporting definitions. An alert threshold is triggered when more than three reviews remain in Manual Review, any approval is older than three business days, or an action is overdue. These are internal operating thresholds and should be adjusted after the first review cycle.

Step 9: Add Security and Governance Controls

  • Grant the minimum access required for each role.
  • Use Microsoft 365 groups rather than maintaining large numbers of direct permissions.
  • Do not treat a filtered view as a security boundary.
  • Store approval records in a list with restricted write access.
  • Restrict supplier evidence links to authenticated internal users.
  • Prevent anonymous sharing from the supplier-performance site unless there is an approved business requirement.
  • Use an approved automation identity and at least one backup flow owner.
  • Enable secure inputs and outputs on actions that process sensitive values.
  • Do not store credentials, tokens, or API keys in Microsoft Lists.
  • Review flow connections after employee role changes and departures.
  • Enable versioning and retain flow run history according to operational and legal requirements.
  • Back up configuration documents, flow exports, list schemas, and metric definitions.
  • Apply retention labels or policies if supplier quality evidence is subject to contractual or regulatory retention.
  • Record definition changes with an effective date. Do not recalculate historical reviews under a new definition without an explicit restatement process.
  • Keep supplier approval, commercial remedies, payment decisions, and contract changes under human control.

Microsoft Lists does not provide general-purpose column-level security. If a field must be hidden from contributors, place it in a separate restricted list or use a more suitable application and data platform. Hiding a column from a view is not sufficient.

Step 10: Deploy and Test

  1. Build all components in the test SharePoint site and test form.
  2. Use invented supplier records and sample evidence. Do not test with live supplier information until security and retention controls are confirmed.
  3. Run developer tests for every validation, routing, file, approval, reminder, failure, and recovery branch.
  4. Ask the procurement analyst, one buyer, the quality manager, the supply chain manager, and procurement manager to complete user acceptance testing.
  5. Compare calculated outputs with an independently checked spreadsheet for at least ten varied scorecards.
  6. Test permissions using contributor, reviewer, reader, and unauthorized accounts.
  7. Pilot the workflow with five suppliers for one review cycle.
  8. Freeze metric definitions during the pilot. Record requested changes for controlled evaluation rather than changing the rules mid-cycle.
  9. Export production-ready flows as managed configuration backups where the environment supports it.
  10. Create the production lists, library, form, and connections from the approved build documentation.
  11. Activate flows in order: intake, approval, reminders, archive, and reconciliation.
  12. Monitor every run during the first production week and review exceptions daily during the first month.
  13. Prepare a rollback plan that disables triggers, preserves submitted records, and temporarily returns to the controlled spreadsheet template without deleting data.
  14. Publish a short user guide covering submissions, corrections, approvals, evidence, actions, and support contacts.

Code and Configuration

No general-purpose code is required for the core implementation. The selected Microsoft 365 services provide the required triggers, list actions, file actions, approvals, expressions, and notifications through native Power Automate capabilities.

The following configuration and expressions make the calculation and routing reproducible. Replace the placeholder values with the identifiers from the target tenant.

Core configuration values

FORM_ID=YOUR_FORM_ID
SITE_ADDRESS=YOUR_SHAREPOINT_SITE
SUPPLIER_MASTER_LIST=Supplier Master
REVIEWS_LIST=Supplier Reviews
ISSUES_LIST=Performance Issues
ACTIONS_LIST=Action Plans
APPROVAL_AUDIT_LIST=Approval Audit
AUTOMATION_LOG_LIST=Automation Log
EVIDENCE_LIBRARY=Supplier Performance Evidence
SOURCE_ATTACHMENT_FOLDER=YOUR_VERIFIED_FORMS_UPLOAD_PATH
DEFINITION_VERSION=SPD-1.0
BUSINESS_TIME_ZONE=YOUR_BUSINESS_TIME_ZONE
PROCUREMENT_MANAGER_EMAIL=YOUR_EMAIL_ADDRESS
QUALITY_MANAGER_EMAIL=YOUR_EMAIL_ADDRESS
SUPPLY_CHAIN_MANAGER_EMAIL=YOUR_EMAIL_ADDRESS
SUPPORT_OWNER_EMAIL=YOUR_EMAIL_ADDRESS
MAX_AUTOMATED_RETRIES=3

Place these values in initialized variables near the start of each flow or in an approved configuration source. Limit edit access to flow owners. Configuration values are not secrets, but unauthorized changes could alter routing.

Attachment parsing

Use a Parse JSON action after Get response details. Set its content to the attachment answer, converting an empty response to an empty array. Replace YOUR_ATTACHMENT_FIELD with the dynamic field returned by the form.

json(coalesce(outputs('Get_response_details')?['body/YOUR_ATTACHMENT_FIELD'],'[]'))

Use this schema:

{
  "type": "array",
  "items": {
    "type": "object",
    "properties": {
      "name": {
        "type": "string"
      },
      "link": {
        "type": "string"
      },
      "id": {
        "type": ["string", "null"]
      },
      "type": {
        "type": ["string", "null"]
      },
      "size": {
        "type": ["integer", "number", "null"]
      },
      "referenceId": {
        "type": ["string", "null"]
      },
      "driveId": {
        "type": ["string", "null"]
      },
      "status": {
        "type": ["integer", "number", "null"]
      }
    },
    "required": [
      "name",
      "link"
    ],
    "additionalProperties": true
  }
}

For each array item, get the source file content from the verified group Forms folder and create a file in the target evidence folder. Test the actual response shape in flow run history because optional Forms metadata can vary.

Record ID expression

Place this expression in a Compose action immediately after Create Review. Rename the action if necessary and update the reference.

concat(
  'SPR-',
  formatDateTime(utcNow(),'yyyy'),
  '-',
  formatNumber(outputs('Create_review')?['body/ID'],'000000')
)

The output is a string such as SPR-2026-000318. Write it to RecordID and use it in folder and file names.

Cross-field validation

Initialize the numeric variables with Integer or Float types before using this expression. The expression returns true only when the main quantitative relationships are valid.

and(
  greater(variables('DueLines'),0),
  greaterOrEquals(variables('OnTimeLines'),0),
  lessOrEquals(variables('OnTimeLines'),variables('DueLines')),
  greaterOrEquals(variables('FirstFillLines'),0),
  lessOrEquals(variables('FirstFillLines'),variables('DueLines')),
  greater(variables('UnitsReceived'),0),
  greaterOrEquals(variables('UnitsRejected'),0),
  lessOrEquals(variables('UnitsRejected'),variables('UnitsReceived')),
  greater(variables('ResponseSampleCount'),0),
  greaterOrEquals(variables('TotalResponseHours'),0),
  greater(variables('BaselineComparableCost'),0),
  greaterOrEquals(variables('ActualComparableCost'),0),
  greaterOrEquals(variables('ApprovedPriceAdjustment'),0),
  greaterOrEquals(variables('IssuesDue'),0),
  greaterOrEquals(variables('IssuesClosedOnTime'),0),
  lessOrEquals(variables('IssuesClosedOnTime'),variables('IssuesDue')),
  less(ticks(variables('PeriodStart')),ticks(variables('PeriodEnd'))),
  lessOrEquals(ticks(variables('PeriodEnd')),ticks(utcNow()))
)

Supplier existence, active status, attachment count, and correction-record matching are separate conditions because they depend on connector results rather than numeric variables.

Metric calculations

Create one Compose action for each percentage. Format percentages to two decimal places before writing them to Lists.

OTD percent:
float(formatNumber(
  mul(
    div(float(variables('OnTimeLines')),float(variables('DueLines'))),
    100
  ),
  '0.00',
  'en-US'
))

Quality percent:
float(formatNumber(
  mul(
    div(
      sub(float(variables('UnitsReceived')),float(variables('UnitsRejected'))),
      float(variables('UnitsReceived'))
    ),
    100
  ),
  '0.00',
  'en-US'
))

Fill percent:
float(formatNumber(
  mul(
    div(float(variables('FirstFillLines')),float(variables('DueLines'))),
    100
  ),
  '0.00',
  'en-US'
))

Average response hours:
float(formatNumber(
  div(
    float(variables('TotalResponseHours')),
    float(variables('ResponseSampleCount'))
  ),
  '0.00',
  'en-US'
))

Raw price variance percent:
mul(
  div(
    sub(
      sub(
        float(variables('ActualComparableCost')),
        float(variables('BaselineComparableCost'))
      ),
      float(variables('ApprovedPriceAdjustment'))
    ),
    float(variables('BaselineComparableCost'))
  ),
  100
)

Controlled positive price variance:
float(formatNumber(
  if(
    less(float(outputs('Raw_price_variance_percent')),0),
    0,
    float(outputs('Raw_price_variance_percent'))
  ),
  '0.00',
  'en-US'
))

Resolution percent:
if(
  equals(variables('IssuesDue'),0),
  100,
  float(formatNumber(
    mul(
      div(
        float(variables('IssuesClosedOnTime')),
        float(variables('IssuesDue'))
      ),
      100
    ),
    '0.00',
    'en-US'
  ))
)

If the tenant uses a different numeric locale, keep the calculation numeric and test conversions carefully. Lists number fields should receive numeric outputs rather than formatted percentage symbols.

Threshold score expressions

OTD score:
if(greaterOrEquals(outputs('OTD_percent'),98),100,
  if(greaterOrEquals(outputs('OTD_percent'),95),90,
    if(greaterOrEquals(outputs('OTD_percent'),92),75,
      if(greaterOrEquals(outputs('OTD_percent'),88),60,30)
    )
  )
)

Quality score:
if(greaterOrEquals(outputs('Quality_percent'),99.5),100,
  if(greaterOrEquals(outputs('Quality_percent'),99),90,
    if(greaterOrEquals(outputs('Quality_percent'),98),75,
      if(greaterOrEquals(outputs('Quality_percent'),96),60,30)
    )
  )
)

Fill score:
if(greaterOrEquals(outputs('Fill_percent'),98),100,
  if(greaterOrEquals(outputs('Fill_percent'),95),90,
    if(greaterOrEquals(outputs('Fill_percent'),92),75,
      if(greaterOrEquals(outputs('Fill_percent'),88),60,30)
    )
  )
)

Response score:
if(lessOrEquals(outputs('Average_response_hours'),4),100,
  if(lessOrEquals(outputs('Average_response_hours'),8),90,
    if(lessOrEquals(outputs('Average_response_hours'),16),75,
      if(lessOrEquals(outputs('Average_response_hours'),24),60,30)
    )
  )
)

Price score:
if(lessOrEquals(outputs('Controlled_positive_price_variance'),0),100,
  if(lessOrEquals(outputs('Controlled_positive_price_variance'),1),90,
    if(lessOrEquals(outputs('Controlled_positive_price_variance'),2.5),75,
      if(lessOrEquals(outputs('Controlled_positive_price_variance'),5),50,20)
    )
  )
)

Resolution score:
if(greaterOrEquals(outputs('Resolution_percent'),95),100,
  if(greaterOrEquals(outputs('Resolution_percent'),90),90,
    if(greaterOrEquals(outputs('Resolution_percent'),80),75,
      if(greaterOrEquals(outputs('Resolution_percent'),70),60,30)
    )
  )
)

Weighted score and rating

float(formatNumber(
  add(
    add(
      add(
        mul(float(outputs('OTD_score')),0.25),
        mul(float(outputs('Quality_score')),0.20)
      ),
      add(
        mul(float(outputs('Fill_score')),0.20),
        mul(float(outputs('Response_score')),0.10)
      )
    ),
    add(
      mul(float(outputs('Price_score')),0.10),
      mul(float(outputs('Resolution_score')),0.15)
    )
  ),
  '0.00',
  'en-US'
))

Use this rating expression after the Weighted Score Compose action:

if(greaterOrEquals(outputs('Weighted_score'),90),'A',
  if(greaterOrEquals(outputs('Weighted_score'),80),'B',
    if(greaterOrEquals(outputs('Weighted_score'),70),'C','D')
  )
)

Approval route expression

if(
  or(
    less(outputs('Weighted_score'),80),
    less(outputs('OTD_score'),60),
    less(outputs('Quality_score'),60),
    less(outputs('Fill_score'),60),
    less(outputs('Response_score'),60),
    less(outputs('Price_score'),60),
    less(outputs('Resolution_score'),60),
    equals(variables('CriticalIssue'),true),
    greater(outputs('Controlled_positive_price_variance'),2.5)
  ),
  'Enhanced',
  'Standard'
)

Approval trigger condition

Add a trigger condition to the approval flow so normal list updates do not create repeated approvals. The exact choice-field path should be confirmed from a test trigger output.

@and(
  equals(triggerOutputs()?['body/Status/Value'],'Ready for Approval'),
  equals(triggerOutputs()?['body/ApprovalStarted'],false),
  equals(triggerOutputs()?['body/AutomationStatus/Value'],'Completed')
)

If the tenant returns a choice as a plain string, use the corresponding body/Status path instead of body/Status/Value.

Archive snapshot

Use a Compose action to create the final snapshot, then use SharePoint Create file to save it as RecordID_scorecard.json in the Archive folder.

{
  "record_id": "@{triggerOutputs()?['body/RecordID']}",
  "supplier_code": "@{triggerOutputs()?['body/SupplierCode']}",
  "period_start": "@{triggerOutputs()?['body/PeriodStart']}",
  "period_end": "@{triggerOutputs()?['body/PeriodEnd']}",
  "definition_version": "@{triggerOutputs()?['body/DefinitionVersion']}",
  "weighted_score": "@{triggerOutputs()?['body/WeightedScore']}",
  "rating": "@{triggerOutputs()?['body/Rating/Value']}",
  "approval_route": "@{triggerOutputs()?['body/ApprovalRoute/Value']}",
  "approval_status": "@{triggerOutputs()?['body/ApprovalStatus/Value']}",
  "approval_generation": "@{triggerOutputs()?['body/ApprovalGeneration']}",
  "document_link": "@{triggerOutputs()?['body/DocumentLink']}",
  "closed_date": "@{utcNow()}",
  "automation_snapshot_created": "@{utcNow()}"
}

Test the output in the flow’s run history and verify that the created file contains valid JSON. A malformed expression, missing field path, unauthorized library connection, or duplicate filename will cause Create file to fail. Route that failure to the archive exception scope rather than marking the record Archived.

Failure Handling and Operational Reliability

Each flow uses a main processing scope and a failure scope. Configure the failure scope to run after the main scope fails, times out, or is skipped unexpectedly. The failure scope updates the record, writes an Automation Log item, and sends an operational alert.

Failure handling and recovery
Failure Automated response Manual recovery Owner
Missing required data Status becomes Needs Information and requester receives field details. Submit a controlled correction referencing the original record. Requester
Duplicate form event SourceResponseID check stops processing and logs the duplicate. No action unless the original record is incomplete. Automation owner
Concurrent duplicate creation Unique-column enforcement rejects the second create action. Confirm the first record and close the duplicate failure log. Support owner
Inactive supplier Record enters Needs Information without calculation. Correct the code or reactivate the supplier through approved master-data control. Procurement manager
Invalid numeric relationship Validation details are stored and approval is blocked. Reconcile source reports and submit corrected values. Procurement analyst
Partial evidence copy Successful file IDs remain logged; record enters Manual Review. Retry only missing files and verify the folder before routing. Support owner
Authentication expiry Connector action fails and the flow failure scope sends an alert. Reauthenticate the connection, test it, and replay the failed record. Flow owner
Connector throttling Built-in retry uses an exponential policy for eligible transient errors. Reduce concurrency, wait for limits to reset, and replay failed items. Support owner
Approval timeout ApprovalStatus becomes Timed Out and the item enters Manual Review. Confirm delegate, increment generation, and reissue approval. Procurement manager
Stale approval response Generation check ignores the old result. Reviewer responds to the current approval request. Reviewer
Invalid recipient email Email branch fails and logs Notification as the exception type. Correct the role or owner address and resend the notice. Site owner
Archive creation failure Status remains Closed and AutomationStatus becomes Failed. Resolve file or permission issue and rerun archive processing. Records owner
Unexpected flow termination Nightly reconciliation finds records left in Processing. Review run history and restart from the documented recovery point. Support owner

The Automation Log acts as a practical dead-letter queue. A failed record remains there until its status is changed to Recovered, Accepted Exception, or Closed after correction.

Set retry policies only for transient connector failures. Do not repeatedly retry business validation failures. A suggested maximum is three automated attempts, with RetryCount incremented after each attempt.

For idempotency, every flow event receives an EventKey such as FLOWNAME:RecordID:Generation:Operation. The EventKey column enforces uniqueness. Before creating an archive, approval, or action reminder, the flow checks whether the corresponding event already exists.

Reconciliation should compare current list state, expected files, approval status, and archive links. It should not silently reconstruct missing evidence or approve incomplete records.

A Complete Example

The procurement analyst submits a quarterly review for supplier code SUP-014 covering April 1 through June 30, 2026. Microsoft Forms assigns response ID 1276.

Example scorecard input and result
Measure Input Calculated result Metric score
On-time delivery 228 on-time lines from 240 due 95.00% 90
Quality acceptance 12,000 received units and 60 rejected 99.50% 100
Fill rate 230 first-fill lines from 240 due 95.83% 90
Responsiveness 72 business hours across 12 samples 6.00 hours 90
Price change control $84,000 baseline, $84,900 actual, no approved adjustment 1.07% positive variance 75
Issue resolution 9 of 10 issues closed on time 90.00% 90

The flow validates that the supplier is active, all denominators are positive, numerators are within range, the period has ended, and evidence files are present.

Supplier Master returns the assigned buyer and supplier lookup ID. Power Automate creates list item 318 and generates SPR-2026-000318. It then creates the SharePoint folder and copies four evidence files into Source Evidence.

The weighted score is calculated as follows:

(90 × 0.25)
+ (100 × 0.20)
+ (90 × 0.20)
+ (90 × 0.10)
+ (75 × 0.10)
+ (90 × 0.15)
= 90.50

The resulting rating is A. No metric is below 60, there is no critical issue, and the price variance does not exceed 2.5%. The Standard route therefore assigns the approval to the procurement manager.

The approval request includes the score summary, raw measures, definition version, review link, and evidence link. The procurement manager checks the price-comparison evidence and approves the scorecard with a comment requesting that the next supplier meeting address the increase.

Power Automate writes the approval response to Approval Audit, changes ApprovalStatus to Approved, changes Status to Approved, and emails the assigned buyer.

During the supplier meeting, the buyer records an action to confirm the next-quarter quoted price before the first purchase order is released. The action receives an owner and due date. Meeting minutes are uploaded to the Meeting folder.

After the buyer closes the action with evidence, the review changes to Closed. Power Automate creates the archive JSON file, stores its returned URL, and changes the scorecard status to Archived. If the archive file creation had failed, the review would have remained Closed with AutomationStatus set to Failed.

Implementation Cost

The following amounts are representative assumptions, not verified client costs. Harborline is assumed to have existing Microsoft 365 subscriptions with the required standard services and sufficient SharePoint storage. Actual licensing and connector entitlements must be confirmed.

Representative one-time implementation costs
Activity Hours Assumed rate Estimated cost
Requirements and metric definitions 8 $58 per hour $464
Forms, Lists, SharePoint, and permissions 14 $58 per hour $812
Power Automate flow configuration 18 $58 per hour $1,044
Technical and user acceptance testing 10 $58 per hour $580
Training 4 $58 per hour $232
Documentation and handover 4 $58 per hour $232
Total internal implementation 58 Blended assumption $3,364
Representative recurring and optional costs
Cost type Assumption Estimated amount
Incremental Microsoft 365 software Required services already licensed $0 incremental in this model
Power Automate connectors Core design uses available Microsoft 365 connector entitlements $0 incremental in this model
Additional SharePoint storage Evidence remains within existing allocation $0 incremental in this model
Monthly maintenance labour 3 hours at $48 per hour $144 per month
Core API or AI usage No external API or AI used in the base workflow $0
Optional AI usage budget Low-volume meeting-brief generation $12 per month assumption
Optional professional implementation 55 to 80 hours at an assumed $150 per hour $8,250 to $12,000

The optional professional implementation estimate is an alternative delivery assumption, not an amount to add automatically to the internal build cost. Internal coordination, source-data preparation, and user participation are still required when an external implementation team is used.

Estimated Time and Cost Savings

The estimate uses these representative assumptions:

  • 14 supplier scorecards per month
  • 165 minutes of current handling per scorecard
  • 55 minutes of new handling per scorecard
  • 15% of reviews require an additional 25 minutes of exception handling
  • 3 hours of monthly automation maintenance
  • $48 loaded hourly labour cost
  • $0 incremental recurring core software cost in the modeled environment
  • $3,364 one-time internal implementation cost

Current monthly labour hours: Monthly volume × current minutes per record ÷ 60

New monthly labour hours: Monthly volume × new minutes per record ÷ 60, plus exception handling and maintenance

Monthly hours recovered: Current monthly labour hours minus new monthly labour hours

Estimated monthly labour value: Monthly hours recovered × loaded hourly labour cost

Net estimated monthly value: Monthly labour value minus recurring tool costs

Estimated payback period: One-time implementation cost ÷ net estimated monthly value

Representative savings calculation
Calculation Formula Result
Current labour 14 × 165 ÷ 60 38.50 hours
New base labour 14 × 55 ÷ 60 12.83 hours
Exception labour 14 × 15% × 25 ÷ 60 0.88 hours
Maintenance labour Monthly assumption 3.00 hours
Total new labour 12.83 + 0.88 + 3.00 16.71 hours
Hours recovered 38.50 – 16.71 21.79 hours
Monthly labour value 21.79 × $48 $1,046
Net monthly value $1,046 – $0 incremental tool cost $1,046
Modeled payback $3,364 ÷ $1,046 Approximately 3.2 months

Recovered time does not automatically reduce payroll. It may instead provide capacity for supplier negotiations, sourcing work, faster issue follow-up, reduced overtime, better quality investigation, and a higher review volume without adding the same amount of administrative effort.

Non-financial benefits include clearer ownership, fewer follow-up emails, consistent scoring, faster access to evidence, better auditability, more reliable action tracking, and a more structured supplier meeting.

Readers should replace the review volume, handling times, exception rate, labour rate, maintenance requirement, licensing cost, storage cost, and implementation cost with their own figures.

Adding AI to the Automation

AI should be added only after the structured workflow, definitions, calculations, approvals, evidence links, and failure handling work reliably.

The principal benefits of the core implementation come from normal automation:

  • Required fields and validation
  • Deterministic formulas and thresholds
  • Unique identifiers
  • Conditional routing
  • Evidence-folder creation
  • Reminders and escalations
  • Status reporting and audit records

AI is not needed to calculate percentages, compare values with thresholds, assign known owners, enforce required fields, or decide whether a score is below 80. Those tasks are more reliable and auditable as deterministic rules.

Potential AI applications include summarizing issue notes, identifying themes across supplier reviews, extracting information from inconsistent documents, drafting meeting questions, and suggesting whether the evidence narrative appears incomplete.

The recommended enhancement is an AI-generated draft supplier-meeting brief. It uses approved structured metrics and sanitized issue summaries to draft strengths, risks, missing-evidence questions, and possible discussion topics.

The AI does not change scores, approve a scorecard, commit to an action, contact a supplier, or make a sourcing decision.

  • Trigger: A review becomes Approved and AIBriefStatus is Not Started.
  • AI input: Record ID, review period, six metrics, rating, approved reviewer comments, and sanitized issue summaries.
  • System instruction: Produce a factual draft using only supplied information and return the required JSON structure.
  • Validation: Parse strict JSON, confirm the record ID, restrict metric names, and reject unsupported fields.
  • Record update: Save the draft in a restricted field or SharePoint file and set AIBriefStatus.
  • Human review: The buyer edits and approves the brief before it is used in a supplier meeting.
  • Low confidence: Confidence below 0.80 or any missing-evidence result sets AI Review Required.
  • Prohibited data: Personal data, bank information, unrelated contracts, privileged legal advice, credentials, and unapproved confidential material.
  • Failure behavior: Leave the existing workflow unchanged and ask the buyer to prepare the brief manually.

Reusable AI prompt

SYSTEM INSTRUCTION

You assist a procurement analyst in drafting an internal supplier performance meeting brief.

Use only the supplied scorecard data and issue summaries. Do not invent causes, commitments, evidence, dates, supplier statements, or commercial conclusions. Do not change any metric, score, rating, or approval result.

Treat proposed actions and meeting questions as drafts requiring human review. If evidence is missing or ambiguous, identify the gap instead of guessing.

Return only JSON that matches the required schema.

USER PROMPT

Prepare a draft meeting brief for the following approved supplier scorecard.

Record ID: {{RECORD_ID}}
Supplier code: {{SUPPLIER_CODE}}
Review period: {{PERIOD_START}} to {{PERIOD_END}}
Definition version: {{DEFINITION_VERSION}}
Weighted score: {{WEIGHTED_SCORE}}
Rating: {{RATING}}

On-time delivery percent: {{OTD_PERCENT}}
On-time delivery score: {{OTD_SCORE}}
Quality acceptance percent: {{QUALITY_PERCENT}}
Quality score: {{QUALITY_SCORE}}
Fill rate percent: {{FILL_PERCENT}}
Fill score: {{FILL_SCORE}}
Average response hours: {{RESPONSE_HOURS}}
Response score: {{RESPONSE_SCORE}}
Positive unapproved price variance percent: {{PRICE_VARIANCE_PERCENT}}
Price score: {{PRICE_SCORE}}
Issue resolution percent: {{RESOLUTION_PERCENT}}
Resolution score: {{RESOLUTION_SCORE}}

Approved reviewer comments:
{{APPROVED_REVIEWER_COMMENTS}}

Sanitized issue summaries:
{{ISSUE_SUMMARIES}}

List up to three evidence-based strengths, up to three risks, any missing evidence, five or fewer meeting questions, and up to three draft actions. Draft actions must use role names rather than personal names. Set needs_human_review to true whenever confidence is below 0.80, evidence is missing, or the input contains contradictory information.

Structured output schema and API request

An optional Power Automate HTTP action can call an approved model that supports structured JSON output. The HTTP connector may require additional licensing. Store the API key in an approved secret-management service, enable secure inputs and outputs, and never place the key in a list.

Use POST with endpoint https://api.openai.com/v1/chat/completions. Set Authorization to Bearer YOUR_API_KEY and Content-Type to application/json. Replace YOUR_APPROVED_MODEL with a model approved for structured output.

{
  "model": "YOUR_APPROVED_MODEL",
  "messages": [
    {
      "role": "system",
      "content": "You assist a procurement analyst in drafting an internal supplier performance meeting brief. Use only supplied data. Do not invent evidence, causes, commitments, dates, supplier statements, or commercial conclusions. Do not change metrics, scores, ratings, or approval results. Return only JSON matching the schema."
    },
    {
      "role": "user",
      "content": "@{outputs('AI_User_Prompt')}"
    }
  ],
  "response_format": {
    "type": "json_schema",
    "json_schema": {
      "name": "supplier_meeting_brief",
      "strict": true,
      "schema": {
        "type": "object",
        "additionalProperties": false,
        "properties": {
          "record_id": {
            "type": "string"
          },
          "summary": {
            "type": "string"
          },
          "strengths": {
            "type": "array",
            "maxItems": 3,
            "items": {
              "type": "string"
            }
          },
          "risks": {
            "type": "array",
            "maxItems": 3,
            "items": {
              "type": "object",
              "additionalProperties": false,
              "properties": {
                "metric": {
                  "type": "string"
                },
                "evidence": {
                  "type": "string"
                },
                "confidence": {
                  "type": "string",
                  "enum": ["high", "medium", "low"]
                }
              },
              "required": [
                "metric",
                "evidence",
                "confidence"
              ]
            }
          },
          "missing_evidence": {
            "type": "array",
            "items": {
              "type": "string"
            }
          },
          "meeting_questions": {
            "type": "array",
            "maxItems": 5,
            "items": {
              "type": "string"
            }
          },
          "draft_actions": {
            "type": "array",
            "maxItems": 3,
            "items": {
              "type": "object",
              "additionalProperties": false,
              "properties": {
                "action": {
                  "type": "string"
                },
                "owner_role": {
                  "type": "string"
                },
                "due_in_days": {
                  "type": "integer",
                  "minimum": 1,
                  "maximum": 90
                }
              },
              "required": [
                "action",
                "owner_role",
                "due_in_days"
              ]
            }
          },
          "confidence": {
            "type": "number",
            "minimum": 0,
            "maximum": 1
          },
          "needs_human_review": {
            "type": "boolean"
          }
        },
        "required": [
          "record_id",
          "summary",
          "strengths",
          "risks",
          "missing_evidence",
          "meeting_questions",
          "draft_actions",
          "confidence",
          "needs_human_review"
        ]
      }
    }
  }
}

Extract the JSON string from the response with this Power Automate expression, then pass it to Parse JSON using the same inner schema:

body('HTTP_-_AI_Brief')?['choices']?[0]?['message']?['content']

Validate that record_id matches the current record. Permit only the six configured metric names in risk items. Set AIBriefStatus to Review Required if confidence is below 0.80, missing evidence is not empty, or needs_human_review is true.

Use an exponential retry policy for transient timeouts, HTTP 429 responses, and eligible server errors, with no more than three retries. Provider-specific rate limits vary. The flow should honor any returned retry interval, keep concurrency low, and route repeated failures to manual preparation.

The API processes one scorecard per request, so pagination is not relevant. Log request time, model identifier, response status, approximate usage, validation outcome, and reviewer disposition without storing the API key or unnecessary prompt data.

Benefits of the AI Enhancement

  • Less time spent turning structured metrics into a first meeting draft
  • More consistent presentation of strengths and risks
  • Faster identification of missing or contradictory narrative evidence
  • More consistent meeting questions across suppliers
  • Improved analysis of unstructured issue summaries
  • A searchable structured record of recurring supplier themes

These are AI-specific benefits. The score calculation, approval routing, evidence storage, action tracking, reminders, and audit trail already exist without AI.

What Remains Rule-Based or Human-Controlled

Deterministic and human-controlled decisions
Decision Control Reason
Metric calculations and weights Rule-based They must be repeatable, testable, and auditable.
Approval route Rule-based Thresholds and critical-issue flags provide clear routing evidence.
Scorecard approval Human-controlled A reviewer must assess evidence quality and business context.
Supplier corrective action Human-controlled Actions create operational and commercial commitments.
Contract or pricing response Human-controlled Commercial terms require authorized judgment.
Supplier suspension or replacement Human-controlled This is a high-impact sourcing decision.
External supplier communication Human-controlled Internal notes and AI drafts require review before release.
Legal, safety, or compliance conclusion Qualified human review An AI summary is not an authoritative legal or safety assessment.

Estimating the Additional Value of AI

The AI estimate uses 14 reviews per month, 15 gross minutes of drafting assistance per review, five minutes of required human review, a 15% correction rate requiring eight extra minutes, and a 5% service-failure rate that removes the expected saving for that record.

Manual, automated, and AI-assisted handling comparison
Process Minutes per review Human involvement
Original manual process 165 Data entry, calculation, routing, evidence collection, and drafting
Core automation 55 Source verification, exception handling, approval, and meeting preparation
Core automation with AI draft 46.95 estimated Source verification, AI review, correction, approval, and final editing
Gross AI saving per review: 15.00 minutes
Required human review:       -5.00 minutes
Expected correction effort:  -1.20 minutes
Expected failure adjustment: -0.75 minutes
Net additional saving:        8.05 minutes per review

Monthly capacity:
14 × 8.05 ÷ 60 = 1.88 hours

Estimated labour value:
1.88 × $48 = approximately $90.16 per month

Less AI usage budget:
$90.16 - $12.00 = approximately $78.16 net monthly value

This estimate assumes that every AI output receives human review. AI does not eliminate errors, corrections, service failures, or manual fallback.

Testing Checklist

Use invented sample data and non-sensitive files before processing real supplier information.

Required workflow tests
Test Expected result
Normal submission One review, evidence folder, score, owner, and correct approval route are created.
Missing required field Submission is blocked by Forms or routed to Needs Information.
Invalid field relationship Calculation and approval are blocked with a clear validation message.
Duplicate submission Duplicate is detected using source response or correction reference.
Duplicate trigger event No second review, archive, or approval is created.
Failed authentication Flow fails safely, logs the error, and sends a support alert.
Expired connection Record remains unapproved and recovery instructions identify the connection.
Failed connector request Eligible transient error retries; final failure enters Manual Review.
Unavailable approver Configured delegate or escalation process is used.
Approval rejection Status becomes Rejected and no archive claims approval.
Return for information Status becomes Returned and correction starts a new generation.
Reassignment New approver receives the request and old generation cannot alter the record.
Overdue item Record appears in the overdue view.
Reminder Correct recipient receives one reminder for the configured interval.
Escalation Backup or manager receives escalation without automatic approval.
Failed file upload Approval is blocked and missing file is identified.
Failed folder or archive creation Status remains incomplete and recovery can safely retry.
Failed notification Business record remains valid, but Notification exception is logged.
Unauthorized user User cannot access restricted lists, evidence, or approval data.
Metric boundary values Values at every threshold receive the expected points.
Zero issues due Resolution percent and score follow the documented 100-point policy.
Approval timeout Status becomes Timed Out and record enters Manual Review.
Malformed AI output Parse fails safely and manual meeting preparation remains available.
Inaccurate AI output Human reviewer rejects or corrects the draft without changing the scorecard.
AI service failure Core workflow completes and AIBriefStatus records the failure.
Successful completion Meeting, actions, closure, and archive occur in the correct order.
Correct reporting Record appears in the expected owner, status, rating, and exception views.
Correct audit record Input, versions, approval, comments, timestamps, and archive link are preserved.
Correct retry behavior Transient failures retry within the limit and business validation failures do not loop.

Ongoing Maintenance

The procurement operations manager is the primary business owner. The procurement analyst is the backup business owner, and an IT or automation administrator owns technical support and connection recovery.

Maintenance schedule
Frequency Activity Owner
Daily Review failed runs, Manual Review records, and approval timeouts. Procurement analyst
Weekly Review overdue scorecards, actions, rejected records, and archive failures. Procurement manager
Monthly Check flow health, connector usage, evidence growth, retry patterns, and notification failures. Automation administrator
Quarterly Review permissions, supplier owners, delegates, inactive suppliers, and former-user access. Site owner
Quarterly Sample score calculations and compare them with source reports. Quality manager
Semiannually Test backup procedures, flow exports, recovery instructions, and test environment. Automation administrator
Annually Review metric definitions, weights, thresholds, retention, and reporting requirements. Procurement, supply chain, and quality leaders
After any change Update documentation, test cases, configuration inventory, and definition version. Change owner
Monthly when AI is enabled Review usage cost, failures, corrections, confidence, and a sample of outputs. AI service owner and procurement manager

Credential rotation and connection review should follow company policy. Former employees must be removed from SharePoint groups, flow ownership, form ownership, approval roles, and distribution lists.

Archive or remove obsolete operational records only under an approved retention schedule. Confirm that backups include list schemas, flow packages, configuration values, metric definitions, and any templates required for recovery.

When to Move to Dedicated Software

The Microsoft 365 implementation can remain appropriate while the workflow is primarily internal, volumes are moderate, and the organization can maintain its definitions and flows. It should not be replaced only because it has been in use for several years.

Reassess dedicated supplier relationship management, supplier quality management, procurement, or custom application platforms when several of these conditions appear:

  • Suppliers require an external portal for evidence, action updates, or approvals.
  • Transaction and review volume makes form-based aggregated input impractical.
  • Direct ERP integration becomes necessary for line-level calculations.
  • Multiple business units need different permissions, definitions, currencies, or workflows.
  • Formal regulatory controls require stronger electronic signatures, validation, or audit reporting.
  • Field-level security becomes essential.
  • Supplier qualification, onboarding, risk, compliance, sourcing, and performance must share one data model.
  • Exception rates create substantial manual reconciliation.
  • Flow maintenance consumes more time than the workflow saves.
  • Operational reporting requires advanced trends, predictive analysis, or large-scale data modeling.
  • Users require mobile, offline, or supplier-facing capabilities beyond the available Microsoft 365 interface.
  • Data retention, legal hold, or segregation requirements exceed the current site design.
  • The business requires vendor-supported service levels for the complete supplier-management process.

A Power BI reporting layer can be added without replacing the workflow. A custom Power Apps and Dataverse solution can also be considered when user experience and field-level controls become more important, while a dedicated supplier platform is more appropriate when external collaboration and broader supplier lifecycle management are required.

Implementation Checklist

  • Confirm supplier-performance goals, review frequency, and responsible departments.
  • Approve metric definitions, exclusions, weights, thresholds, and evidence requirements.
  • Confirm Microsoft 365 services, connectors, licensing, storage, and administrative access.
  • Create production and test accounts, groups, sites, forms, lists, and libraries.
  • Assign primary and backup business and technical owners.
  • Configure least-privilege permissions and restricted approval records.
  • Create Supplier Master and validate owner, status, and supplier codes.
  • Create Supplier Reviews, Issues, Actions, Approval Audit, and Automation Log lists.
  • Enable unique fields, indexes, default values, lookups, and version history.
  • Build the authenticated Microsoft Form with required fields, branching, validation, and privacy notice.
  • Verify the Forms attachment storage path using a test submission.
  • Document every source-to-destination field mapping.
  • Build duplicate checks, validation, ID generation, score calculation, and assignment.
  • Configure Standard and Enhanced approval routes.
  • Configure returns, rejection, delegation, reminders, escalation, and timeout handling.
  • Create the evidence folder hierarchy, naming rules, versioning, and failed-upload recovery.
  • Create operational views for new, pending, overdue, incomplete, failed, and completed work.
  • Configure structured failure scopes, retry limits, logging, and nightly reconciliation.
  • Validate all formulas and score thresholds against independently calculated examples.
  • Complete security, permission, retention, backup, and former-user access tests.
  • Run technical tests, user acceptance testing, and a controlled supplier pilot.
  • Document activation, rollback, recovery, support, and change-control procedures.
  • Replace representative cost and savings assumptions with company-specific figures.
  • Deploy optional AI only after the core workflow is stable and governed.
  • Require human review for every AI-generated meeting brief.
  • Schedule maintenance, permission reviews, calculation sampling, and documentation updates.
  • Define the volume, security, integration, reporting, and portal criteria that would justify dedicated software.

You need a similar solution?

Get a FREE
Proof of Concept
& Consultation

No Cost, No Commitment!