The entire Vendor Portal as a single system, showing all 6 actors and 11 data flows
Page 2 of 9 May 2026
External Entity
System / Process
Data Flow (solid = into system)
Data Flow (dashed = out of system)
Flow Numbering Convention
Flows on this diagram are numbered F01 – F09 (top-level, shown above). On the detail process pages (P1–P5, RFQ), each top-level flow is broken into specific sub-flows using a letter suffix:
F01 — Reg. Form Data (Level 0) F01b Invoice Submission (P2) F01c Upload Compliance Certs (P3)
Vendor (E1) submits certificates — ISO, tax clearance, trade licence — to the portal (F01c). Files saved to DS2.
2
Compliance Authority Verifies Certificates
Compliance Authority (E4) reviews the uploaded documents and returns a validity decision (F07). Status updated in DS4.
3
Super Admin Configures Compliance Rules
Super Admin (E3) sets expiry thresholds and compliance rules (F05b) that the system monitors against DS4 records.
4
System Monitors Certificate Expiry Dates
The system continuously reads DS4 and compares expiry dates against the configured thresholds.
5
Automated Expiry Reminders Sent
When a certificate is nearing expiry, the system triggers email reminders via E5 to the vendor (F08b) to prompt renewal.
6
Non-Compliant Vendors Flagged
If a certificate expires without renewal, vendor is flagged non-compliant. Alert sent to Dept Admin (F04c) for action.
7
Super Admin Reviews Compliance Dashboard
Super Admin receives a full compliance report and dashboard (F06b) showing all vendor statuses across the portal.
8
Vendor Renews & Resubmits
Vendor uploads renewed certificate. Compliance Authority re-verifies, DS2 and DS4 updated, vendor reinstated as compliant.
METAMORF Group — Vendor Portal · Step 4 of 5
P4 — Real-Time Communication
Manages chat threads between vendors, department admins, and super admin with real-time delivery
Page 7 of 9 May 2026
How It Works — Step by Step
1
User Opens or Starts a Message Thread
Vendor (E1) or Dept Admin (E2) initiates a chat thread on a specific topic — query, document request, or clarification.
2
System Saves Message to DS5
Message content, attachments, sender ID, and timestamp are stored in DS5. Thread ID links all messages in the conversation.
3
Real-Time Delivery to Recipient
If the recipient is active in the portal, the message appears instantly. Read receipt is recorded in DS5 once viewed.
4
Offline Email Notification Sent
If the recipient is offline, Email/Notification Service (E5) sends an email alert (F08c) directing them back to the portal.
5
Finance Admin Raises Payment Query
Finance Admin (E7) opens a dedicated payment query thread with the vendor (F09c) — e.g. invoice dispute or missing details.
6
Vendor Responds to Payment Query
Vendor replies within the same thread (F09d). Thread updated in DS5. Finance Admin notified of the vendor's response.
7
Super Admin Broadcasts Announcements
Super Admin (E3) can send portal-wide broadcast messages (F05d) — policy updates, deadlines, or system notices — to all users.
8
All Threads Stored for Audit
Every message, attachment, and read receipt is permanently logged in DS5, providing a full audit trail for dispute resolution.
METAMORF Group — Vendor Portal · Step 5 of 5
P5 — Performance Tracking
Calculates vendor KPI scores, generates department reports, shows scorecards to vendors and admins
Page 8 of 10 May 2026
How It Works — Step by Step
1
Dept Admin Confirms Delivery & Rates Vendor
After goods or services are received, Dept Admin (E2) marks delivery as complete and submits a quality rating (F03b). Saved to DS3.
2
System Reads Order History from DS3
The system pulls all delivery dates, invoice accuracy records, and ratings from DS3 to compute performance data.
3
KPI Scores Calculated & Written to DS6
System calculates on-time delivery rate, invoice accuracy, quality score, and overall KPI ranking. Results stored in DS6.
4
Vendor Scorecard Sent to Vendor
System generates a scorecard for the vendor (F02c) showing their KPIs, trends, and areas for improvement.
5
Dept Admin Receives Performance Summary
Department-level performance summary (F04d) sent to Dept Admin — shows all vendor KPIs relevant to their department.
6
Super Admin Sets KPI Thresholds & Requests Reports
Super Admin (E3) configures KPI pass thresholds and requests cross-department analytics (F05c).
7
Full Analytics & League Table Generated
System generates complete vendor rankings and analytics report (F06c) delivered to Super Admin — covering all departments.
8
Finance Admin Receives Financial KPI Report
Finance Admin (E7) requests financial metrics (F09e). System responds with financial KPI report (F09f) — spend, accuracy, payment cycles.
METAMORF Group — Vendor Portal · Procurement Process
Request for Quotation (RFQ) & Tender Process
Dept Admin creates RFQ → System notifies vendors → Vendors bid → Admin evaluates → Winner awarded → PO issued
Page 9 of 10 May 2026
Dept Admin (E2)
Vendor (E1)
System
Notification
Decision Point
Award Path
Rejected Path
DS7 RFQ Records
METAMORF Group — Vendor Portal
User Roles & Access Summary
What each role can see and do · E4 Compliance Authority login created by Super Admin (E3) · Only Super Admin can give final vendor approval
Page 10 of 11 May 2026
METAMORF Group — Vendor Portal · User Account Setup
Portal User Login Module — Accounts Created by Super Admin
Departmental Admin (E2) · Compliance Authority (E4) · Finance Admin (E7) — all portal user accounts created and managed exclusively by Super Admin (E3)
Page 11 of 11 May 2026
Super Admin (E3)
System
Email Service (E5)
Dept Admin (E2)
Compliance Auth (E4)
Finance Admin (E7)
DS8 User Accounts
Account Lifecycle — Portal Users Created by Super Admin (E2 · E4 · E7)
1
Super Admin Creates the User Account
Only Super Admin (E3) can create portal accounts for Dept Admin (E2), Compliance Authority (E4), and Finance Admin (E7). No self-registration is possible for any of these roles.
2
System Stores Account in DS8
A unique User ID is generated, the role (E2 / E4 / E7) and scoped permissions are set, and all account data — including department — is saved to DS8 (User Accounts).
3
Welcome Email with Temporary Credentials
Email Service (E5) automatically delivers the portal login URL and a system-generated temporary password to the user's registered email address.
4
Mandatory First-Login Password Reset
On first login the system blocks portal access until the user sets a new secure password. The new hash replaces the temporary credential in DS8.
5
Role-Scoped Dashboard — No Cross-Role Visibility
E2: POs, RFQ, vendor comms, delivery, performance. E4: compliance queue, document review, decision log. E7: invoices, payment auth, financial KPIs. Each role sees only their assigned modules.
6
Super Admin Retains Full Lifecycle Control
Super Admin can reset passwords, reassign departments, change roles, or deactivate any portal user account at any time. All user activity is logged in DS8 and auditable.