IRIS (Intelligent Recognition Invoice Service)
IRIS takes the stress out of Accounts Payable (AP) processes. Using the power of Agilyx Integration Machine, a robust integration & processing platform built on Microsoft Azure services. IRIS utilises Azure’s Artificial Intelligence (AI) functionality to scan PDF invoices received via email and imports these invoices into Unit4 ERP seamlessly.
Features
- Streamlined invoice processing
- Improved accuracy
- Reduced processing times
- Seamless integration with existing ERP Systems
- tailored for business across diverse industries
Benefits
- Improved accuracy
- Reduced processing times
- streamlined invoice processing
- greater accuracy in financial operations
- minimised risk associated with human error
- more streamlined workflows and processing
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
2 7 5 3 5 4 3 4 5 3 5 5 2 0 6
Contact
AGILYX EMEA LTD
Julie Taylor
Telephone: 01628 637266
Email: julie.taylor@agilyxgroup.com
About your service
- Service categories
-
Applications
Enterprise resource management
- Order management and orchestration
Financial
- Financial and Accounting Applications
- Accounts Payable Applications
- Accounts Receivable Applications
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
-
- Public cloud
- Private cloud
- Service constraints
- None that we are aware of
- System requirements
-
- ERP System
- Finance module including Invoice processing
User support
- Email or online ticketing support
- Yes
- Support response times
- We will respond within 4 hours to tickets been raised from Monday to Friday, 9am to 5:30pm.
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- None or don’t know
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
- We have various support packages available on request
- Support available to third parties
- No
Onboarding and offboarding
- Getting started
- The service is deplyed by our in house development team and configured to the customers own system requirements. Offsite training and documentation is supplied.
- Service documentation
- Yes
- Documentation formats
- End-of-contract data extraction
- Data is not stored by the service per se, data passes through the services for process purposes. Users can extract their audit data and any stored data via query when desired.
- End-of-contract process
- The contract includes base costs, 2 environments, basic support and upto 3000 invoices per year along with template configuration and installation. Any additional implementation work would be extra cost along with any additional clients required or additional invoice costs.
- Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
- Via Link
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Other
- Application to install
- No
- Designed for use on mobile devices
- No
- Service interface
- No
- User support accessibility
- None or don’t know
- API
- Yes
- What users can and can't do using the API
- The API is configured as part of the deployment
- API documentation
- Yes
- API documentation formats
- HTML
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
- Buyers can customise the incoming XML and the application configuration.
Scaling
- Independence of resources
- Our services uses the latest Microsoft Azure technology meaning every interaction is independent of the next, we user commercially reasonable efforts to make IRIS available 99.5% of the time.
Analytics
- Service usage metrics
- Yes
- Metrics types
- Number of transactions passed/failed and success/failure metrics.
- Reporting types
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Staff screening not performed
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- Other locations
- User control over data storage and processing locations
- No
- Datacentre security standards
- Supplier-defined controls
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
- Scale, obfuscating techniques, or data storage sharding
- Data sanitisation process
- No
- Equipment disposal approach
- A third-party destruction service
Data importing and exporting
- Data export approach
- This is not usually required, however, users can extract logs via code work if required.
- Data export formats
-
- CSV
- Other
- Data import formats
-
- CSV
- Other
Data-in-transit protection
- Data protection between buyer and supplier networks
- Other
- Other protection between networks
- Agilyx operate an information security program designed to protect Customer Data processed through the Hosting Environment using industry standard policies and technologies.
- Data protection within supplier network
- Other
- Other protection within supplier network
- Agilyx operate an information security program designed to protect Customer Data processed through the Hosting Environment using industry standard policies and technologies.
Availability and resilience
- Guaranteed availability
- Agilyx will use commercially reasonable efforts to make IRIS available 99.5% of the time excluding any of the following periods: (a) planned downtime; and (b) unscheduled downtime caused by: (i) circumstances beyond Agilyx’s reasonable control (including, but not limited to: acts of God, acts of government, flood, fire, earthquake, civil unrest, acts of terror, strike or other labour problem, hosting provider failure or delay, issues related to Third Party Integrated Applications, or denial of service attacks); (ii) circumstances entitling Agilyx to suspend access to IRIS under the terms of this Agreement; and (iii) the Customer’s or a User’s failure to use IRIS in accordance with Agilyx documentation.
- Approach to resilience
- Working with MS Azure our data follows all MS Azure resilience protocols. Further information is available on request.
- Outage reporting
- Email alerts
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
- Access restrictions in management interfaces and support channels
- Access is limited to authorised users only
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
- The Agilyx global Information Security Policy can be provided upon request. Agilyx is accredited to ISO 27001 Information Security Management.
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- IRIS relies on the expert services of Azure, who provided the underlying platform, network connectivity and System software. The Azure platform offers High Availability, Fault Tolerance, and redundancy at all levels, and components are automatically replaced at the end of their lifetimes or when failed - deployments within Azure allow everyone to benefitfrom their experience of running highly secure and compliant online services
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- Deployments within Microsoft Azure allow everyone to benefit from their experience of running highly secure and compliant online services around the globe (such as Microsoft Cyber Defense Operations Centre, a 24x7x365 state-of-the-art cybersecurity and defence facility). IRIS works with R&D teams to identify, mitigate and share information about known risks. Agilyx uses log monitoring and analyses to identify usage anomalies and exceptions. Software patches are applied during the maintenance window, but security patches are applied immediately.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- IRIS’s service includes system software, monitoring, management and maintenance of the Agilyx software and environment in Azure. A continuous 24x7x365 monitoring program is in place to detect and resolve infrastructure and application issues in order to meet the Agilyx application availability targets. The monitoring covers solution health, availability and response times. Prioirity 1 alerts generated are handled by Agilyx staff 24/7/365. see also response concerning Incident Management Approach.
- Incident management type
- Supplier-defined controls
- Incident management approach
- Agilyx will take prompt action to respond to any Security Incident and to prevent the further unauthorized use or disclosure of Customer Data, and/or to correct the issues within IRIS(to the extent that IRIS gave rise to such Security Incident).
- Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Supplier-defined process
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- BSI
- ISO/IEC 27001 accreditation date
- Wednesday 15 January 2025
- What the ISO/IEC 27001 doesn’t cover
- The scope of this approval is applicable to: The design, development, provision and support of Unit4 software products and associated consultancy, technical and managed IT services. Statement of Applicability v2. The scope covers all UK activities, and also include Global activities, hosting, SaaS etc
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- QAS International
- ISO 9001 accreditation date
- Monday 10 November 2025
- What the ISO 9001 doesn’t cover
- We are exempt from M08 monitoring and Measuring equipment
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- Yes
- Who accredited the PCI DSS certification
- SyberNet Self Assessed Certification
- PCI DSS accreditation date
- Saturday 14 January 2017
- What the PCI DSS doesn’t cover
- The service is deployed as a hosted service, via our partner SyberNet, who are required to run and maintain it in a PCI compliant environment. Sybernet are currently a Level 2 service provider with less than 300,000 transactions annually and so they complete an SAQ, a Quarterly scan by an ASV (they use Qualys as their Approved Scanning Vendor) and provide an attestation of compliance (AOC).
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 29a5e660-848c-4905-bd25-51c0df414642
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- None of the criteria
- Other security certifications
- Yes
- Any other security certifications
-
- ISO 270017
- SOC 1 (type 1 and 2)
- SOC 2
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Plans to engage the contract workforce in deciding the most important workplace issues to address
- Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
- Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Volunteering opportunities for staff
-