METAMORF GROUP
Vendor Portal
Data Flow Diagram (DFD)
Step-by-Step Process Breakdown
11 Pages  ·  5 Processes + RFQ  ·  5 User Roles  ·  8 Data Stores  ·  11 Data Flows
P1 Vendor Onboarding P2 Orders & Invoices P3 Compliance Tracking P4 Communication P5 Performance RFQ & Tender Finance Admin
May 2026  ·  Confidential — Internal Use Only
METAMORF Group — Vendor Portal
Level 0 — Context Diagram
The entire Vendor Portal as a single system, showing all 6 actors and 11 data flows
Page 2 of 9
May 2026
External Entity
System / Process
Data Flow (solid = into system)
Data Flow (dashed = out of system)
VENDOR PORTAL SYSTEM All Processes P1 · P2 · P3 · P4 · P5 DS1 – DS6 6 data stores · 11 flows E1 Vendor / Our Partner External Supplier E2 Departmental Admin Internal Dept User E3 Super Admin Full Portal Access E4 Compliance Authority Portal Login User E5 Email / Notif. Service Transactional Email E7 Finance Admin Internal Finance User F01 Reg. Form Data F02 Credentials F03 Purchase Orders F04 Invoices / Alerts F05 Config/Rules F06 Reports/Analytics F07 Cert. Validity F08 Notifications F09 Financial Approval F09b Finance Reports Solid arrows = data flowing into the Vendor Portal · Dashed arrows = data flowing out
Flow Numbering Convention
Flows on this diagram are numbered F01 – F09 (top-level, shown above). On the detail process pages (P1–P5, RFQ), each top-level flow is broken into specific sub-flows using a letter suffix:
F01 — Reg. Form Data (Level 0)
F01b Invoice Submission (P2)
F01c Upload Compliance Certs (P3)
F02 — Credentials (Level 0)
F02c Vendor Scorecard (P5)
F03 — Purchase Orders (Level 0)
F03b Delivery Confirm + Rating (P5)
F04 — Invoices / Alerts (Level 0)
F04b Invoice for Approval (P2)
F04c Vendor Compliance Alert (P3)
F04d Dept Performance Summary (P5)
F05 — Config / Rules (Level 0)
F05b Compliance Rule Config (P3)
F05c Report Request + KPI (P5)
F05d Broadcast Announcement (P4)
F06 — Reports / Analytics (Level 0)
F06b Compliance Dashboard (P3)
F06c Full Analytics + League (P5)
F07 — Cert. Validity (Level 0)
F07b Send App. for Review (P1)
F08 — Notifications (Level 0)
F08b Expiry Reminders (P3)
F08c Offline Notif. Email (P4)
F09 — Financial Approval (Level 0)
F09a Invoice for Fin. Review (P2)
F09b Payment Authorisation (P2)
F09c Payment Query / Dispute (P4)
F09d Vendor Payment Reply (P4)
F09e Financial Report Request (P5)
F09f Financial KPI Report (P5)
Rule: no letter = top-level flow (this diagram) · letter suffix (b, c, d…) = same parent flow, specialised for a specific process page.
METAMORF Group — Vendor Portal  ·  Step 1 of 5
P1 — Vendor Onboarding
Accepts registrations → E4 Compliance Authority (portal login) manages full onboarding review → Super Admin (E3) gives final approval → creates accounts
Page 3 of 9
May 2026
P1 Vendor Onboarding E1 Vendor / Our Partner E3 Super Admin Sole Final Approver E4 Compliance Authority Portal Login Manages Onboarding E5 Email / Notif. Service DS1 Vendor Profiles Company info, accounts, status DS2 Documents KYC, trade licence, certificates F01 → Registration Form + KYC ← F02 Login Credentials + Status F05a → Super Admin Approval F07 → Compliance Review Decision ← F07b Send App. for Review ← F08 Welcome / Approval Email Write Profile Read Profile Store Docs Verify Docs Vendor submits → E4 Compliance Authority (portal login) manages full onboarding review → Super Admin (E3) gives sole final approval → Credentials sent → Active
METAMORF Group — Vendor Portal  ·  Registration Process
How Vendor Registration Works — Step by Step
Complete journey: Vendor submits → Compliance reviews → Admin approves → Active account
Page 4 of 9
May 2026
Vendor Step
System Step
Notification
E4 Compliance
Decision Point
Approved Path
Rejected Path
Data Store
START 1 Vendor / Our Partner Visits the Vendor Portal & clicks "Register" 2 Fill Registration Form Company name, address, contact, trade licence, bank details 3 Upload Documents KYC files, ISO certificate, tax clearance, trade licence scan DS1 + DS2 Vendor Profiles & Documents Saved on submit 4 System Auto-Validation Fields, file formats, completeness & duplicate check 5 E4 Compliance Authority Notified — Logs into Portal E5 alert sent · E4 logs into portal to review the pending application 6 E4 Compliance Authority Reviews Application Reviews documents, verifies certificates & compliance history Compliance Decision REJECT APPROVE MORE INFO Rejection Email Sent Reason sent to vendor (via E5) Application Closed Vendor may reapply after addressing the rejection reason 7 Notify Super Admin (E3) System alerts E3 for final approval 8 Super Admin Approval Only Only Super Admin (E3) can approve 9 Account Created Vendor ID saved to DS1 10 Credentials Sent (F02) Login URL + temp password via email ✓ Vendor Active Request More Information Email to vendor: missing / incorrect documents Re-submit Average onboarding time: 3–7 business days · Compliance review is mandatory before admin sign-off
METAMORF Group — Vendor Portal  ·  Step 2 of 5
P2 — Order & Invoice Management
Issues purchase orders to vendors, captures invoice submissions, routes approvals, syncs with main platform
Page 5 of 9
May 2026
P2 Order & Invoice Management E1 Vendor / Our Partner E2 Departmental Admin E5 Email / Notif. Service E7 Finance Admin Invoice Approval & Payment DS3 Orders & Invoices PO number, line items, invoice records, approval history, payment status F01b → Invoice Submission ← F04a PO Issued to Vendor F03 → Raise Purchase Order ← F04b Invoice for Approval ← F08 PO / Invoice Alerts Save Order Read Order ← F09a Invoice for Fin. Review F09b → Payment Authorisation Dept Admin raises PO → Vendor submits invoice → Finance Admin approves financially → Payment authorised
How It Works — Step by Step
1
Dept Admin Creates Purchase Order
Departmental Admin (E2) raises a PO from the dashboard, selecting the vendor and line items.
2
System Saves PO & Notifies Vendor
PO is stored in DS3. Email/Notification Service (E5) alerts the vendor (E1) that a new order has been issued (F04a).
3
Vendor Acknowledges & Fulfils Order
Vendor views the PO in the portal, confirms acceptance, and delivers the goods or services.
4
Vendor Submits Invoice
Vendor uploads the invoice against the PO reference (F01b). Invoice record created in DS3.
5
Dept Admin Approves Goods/Services
System routes invoice to Dept Admin (F04b) to confirm delivery matches what was ordered.
6
Finance Admin Reviews & Approves Invoice
Invoice forwarded to Finance Admin (E7) for financial check (F09a). Finance Admin authorises payment (F09b).
7
Payment Authorised & Status Updated
Payment authorisation recorded in DS3. Invoice marked as paid and vendor notified of the completed transaction.
8
Vendor Notified of Payment
Email confirmation sent to vendor (F08) confirming invoice approval and expected payment date.
METAMORF Group — Vendor Portal  ·  Step 3 of 5
P3 — Compliance Tracking
Monitors vendor certificates, checks expiry dates, sends reminders, flags non-compliant vendors
Page 6 of 9
May 2026
P3 Compliance Tracking E1 Vendor / Our Partner E2 Departmental Admin E3 Super Admin Config + Reports E4 Compliance Authority E5 Email / Notif. Service Expiry Reminders DS2 Documents Certificates, licences, KYC files DS4 Compliance Records Expiry dates, status flags, alerts sent F01c → Upload Compliance Certs ← F04c Vendor Compliance Alert F05b → Compliance Rule Config ← F06b Compliance Dashboard F07 → Certificate Validity Data ← F08b Expiry Reminders Read Docs Update Status Read Records Vendor uploads certs → Compliance Authority confirms validity → Expiry reminders sent automatically → Super Admin receives full report
How It Works — Step by Step
1
Vendor Uploads Compliance Certificates
Vendor (E1) submits certificates — ISO, tax clearance, trade licence — to the portal (F01c). Files saved to DS2.
2
Compliance Authority Verifies Certificates
Compliance Authority (E4) reviews the uploaded documents and returns a validity decision (F07). Status updated in DS4.
3
Super Admin Configures Compliance Rules
Super Admin (E3) sets expiry thresholds and compliance rules (F05b) that the system monitors against DS4 records.
4
System Monitors Certificate Expiry Dates
The system continuously reads DS4 and compares expiry dates against the configured thresholds.
5
Automated Expiry Reminders Sent
When a certificate is nearing expiry, the system triggers email reminders via E5 to the vendor (F08b) to prompt renewal.
6
Non-Compliant Vendors Flagged
If a certificate expires without renewal, vendor is flagged non-compliant. Alert sent to Dept Admin (F04c) for action.
7
Super Admin Reviews Compliance Dashboard
Super Admin receives a full compliance report and dashboard (F06b) showing all vendor statuses across the portal.
8
Vendor Renews & Resubmits
Vendor uploads renewed certificate. Compliance Authority re-verifies, DS2 and DS4 updated, vendor reinstated as compliant.
METAMORF Group — Vendor Portal  ·  Step 4 of 5
P4 — Real-Time Communication
Manages chat threads between vendors, department admins, and super admin with real-time delivery
Page 7 of 9
May 2026
P4 Real-Time Communication E1 Vendor / Our Partner E2 Departmental Admin E3 Super Admin Broadcast + Monitor E7 Finance Admin Payment Queries E5 Email / Notif. Service DS5 Messages Thread ID, sender, message text, file attachments, timestamps, read receipts → Chat Message Query / File / Reply ← Delivered Msg Reply + Read Receipt → Query / Request Doc Request / Clarif. ← Vendor Reply Thread Update F05d → Broadcast Announcement ← F08c Offline Notif. Email Save Thread Load Messages F09c → Payment Query / Dispute ← F09d Vendor Payment Reply Vendor & Dept Admin exchange messages in real-time · Finance Admin handles payment queries · Super Admin can broadcast
How It Works — Step by Step
1
User Opens or Starts a Message Thread
Vendor (E1) or Dept Admin (E2) initiates a chat thread on a specific topic — query, document request, or clarification.
2
System Saves Message to DS5
Message content, attachments, sender ID, and timestamp are stored in DS5. Thread ID links all messages in the conversation.
3
Real-Time Delivery to Recipient
If the recipient is active in the portal, the message appears instantly. Read receipt is recorded in DS5 once viewed.
4
Offline Email Notification Sent
If the recipient is offline, Email/Notification Service (E5) sends an email alert (F08c) directing them back to the portal.
5
Finance Admin Raises Payment Query
Finance Admin (E7) opens a dedicated payment query thread with the vendor (F09c) — e.g. invoice dispute or missing details.
6
Vendor Responds to Payment Query
Vendor replies within the same thread (F09d). Thread updated in DS5. Finance Admin notified of the vendor's response.
7
Super Admin Broadcasts Announcements
Super Admin (E3) can send portal-wide broadcast messages (F05d) — policy updates, deadlines, or system notices — to all users.
8
All Threads Stored for Audit
Every message, attachment, and read receipt is permanently logged in DS5, providing a full audit trail for dispute resolution.
METAMORF Group — Vendor Portal  ·  Step 5 of 5
P5 — Performance Tracking
Calculates vendor KPI scores, generates department reports, shows scorecards to vendors and admins
Page 8 of 10
May 2026
P5 Performance Tracking E1 Vendor / Our Partner E2 Departmental Admin E3 Super Admin Full Analytics E7 Finance Admin Financial Metrics DS3 Orders & Invoices Delivery dates, invoice accuracy DS6 Performance Metrics KPI scores, trends, rankings ← F02c Vendor Scorecard F03b → Delivery Confirm + Rating ← F04d Dept Performance Summary F05c → Report Request + KPI Thresholds ← F06c Full Analytics + League Table Read Order History Write KPI Scores Read Metrics F09e → Financial Report Request ← F09f Financial KPI Report Dept Admin rates deliveries → KPIs calculated → Scorecards to vendors · Full analytics to Super Admin · Financial KPIs to Finance Admin
How It Works — Step by Step
1
Dept Admin Confirms Delivery & Rates Vendor
After goods or services are received, Dept Admin (E2) marks delivery as complete and submits a quality rating (F03b). Saved to DS3.
2
System Reads Order History from DS3
The system pulls all delivery dates, invoice accuracy records, and ratings from DS3 to compute performance data.
3
KPI Scores Calculated & Written to DS6
System calculates on-time delivery rate, invoice accuracy, quality score, and overall KPI ranking. Results stored in DS6.
4
Vendor Scorecard Sent to Vendor
System generates a scorecard for the vendor (F02c) showing their KPIs, trends, and areas for improvement.
5
Dept Admin Receives Performance Summary
Department-level performance summary (F04d) sent to Dept Admin — shows all vendor KPIs relevant to their department.
6
Super Admin Sets KPI Thresholds & Requests Reports
Super Admin (E3) configures KPI pass thresholds and requests cross-department analytics (F05c).
7
Full Analytics & League Table Generated
System generates complete vendor rankings and analytics report (F06c) delivered to Super Admin — covering all departments.
8
Finance Admin Receives Financial KPI Report
Finance Admin (E7) requests financial metrics (F09e). System responds with financial KPI report (F09f) — spend, accuracy, payment cycles.
METAMORF Group — Vendor Portal  ·  Procurement Process
Request for Quotation (RFQ) & Tender Process
Dept Admin creates RFQ → System notifies vendors → Vendors bid → Admin evaluates → Winner awarded → PO issued
Page 9 of 10
May 2026
Dept Admin (E2)
Vendor (E1)
System
Notification
Decision Point
Award Path
Rejected Path
DS7 RFQ Records
START 1 Departmental Admin (E2) — Dashboard Navigates to RFQ / Tender section & clicks "Create New RFQ" 2 Fill RFQ / Tender Details Item · specs · quantity · budget (optional) · submission deadline DS7 RFQ & Tender Records RFQ ID, title, specs Deadline & status All quotations received Evaluation notes Award decision & history 3 System Saves RFQ Draft (DS7) Unique RFQ ID assigned · status = Draft · record created in DS7 4 Departmental Admin Reviews & Publishes RFQ Previews all details, confirms deadline & clicks "Publish" · status → Active E7 — Finance Admin Reviews estimated budget & approves RFQ spend 5 System Broadcasts RFQ to All Approved Vendors (E5 → E1) Portal + email: "New RFQ · [Title] · Deadline: [Date] · Submit your quote" 6 Vendor / Our Partner (E1) — Receives & Reviews RFQ Logs in to portal · views full RFQ: specs, quantity, budget range & deadline 7 Vendor Prepares & Submits Quotation Unit price, total cost, delivery timeline, payment terms & supporting documents 8 Submission Deadline Reached — System Closes RFQ No further submissions accepted · E2 alerted: "X vendors submitted quotations" 9 Dept Admin Evaluates & Compares All Quotations Price comparison, delivery time, vendor compliance status & past performance Evaluation Decision REJECT ALL AWARD CLARIFY Notify All Vendors RFQ cancelled — no award made RFQ Closed Admin may re-issue a new RFQ with revised requirements 10 Award Notification Sent Winning vendor notified via E5 · others informed 11 Vendor Accepts Award Vendor confirms & signs digital acceptance Purchase Order Issued → P2 Order & Invoice Management Request Clarification from Vendor(s) Admin sends specific questions · vendor responds via portal Re-evaluate RFQ links to P2 (Order & Invoice) on award · DS7 stores all RFQ records, quotations & award history · Multiple vendors can bid on the same RFQ
METAMORF Group — Vendor Portal
User Roles & Access Summary
What each role can see and do · E4 Compliance Authority login created by Super Admin (E3) · Only Super Admin can give final vendor approval
Page 10 of 11
May 2026
E1 — EXTERNAL Vendor / Our Partner External Supplier WHAT THEY CAN DO • Register company & submit KYC • Upload compliance certificates • View & acknowledge POs • Submit invoices for approval • Respond to RFQ / Tenders • Chat with Dept Admin • View own performance scorecard DATA ACCESS DS1 — Own vendor profile DS2 — Own documents DS3 — Own POs & invoices DS4 — Own compliance records DS5 — Own message threads DS6 — Own KPI scorecard PROCESSES P1 Onboarding P2 Orders · P3 Compliance P4 Communication P5 Performance RFQ & Tender (bidding) E2 — INTERNAL DEPT Departmental Admin Procurement · Operations WHAT THEY CAN DO • Create & publish RFQ / Tenders • Evaluate quotations & award • Create & issue purchase orders • Approve invoices • Communicate with vendors • Confirm delivery & rate quality • View dept performance & alerts DATA ACCESS DS1 — Approved vendor profiles DS2 — Vendor compliance docs DS3 — Dept orders & invoices DS4 — Vendor compliance status DS5 — Dept message threads DS6 — Dept vendor KPIs PROCESSES P1 Onboarding (routing only) P2 Orders · P3 Compliance P4 Communication P5 Performance RFQ & Tender ACCOUNT CREATION Created exclusively by Super Admin (E3) via User Management. → See Page 11 — Login Module E3 — FULL ACCESS Super Admin Full Portal Manager All Departments WHAT THEY CAN DO • Sole authority: final vendor approval • Create & manage all user accounts • Create E2 / E4 / E7 portal logins • Configure compliance rules • Full vendor dashboard (all depts) • Cross-dept performance analytics • Audit logs & broadcast DATA ACCESS DS1 — ALL vendor profiles DS2 — ALL documents DS3 — ALL orders & invoices DS4 — ALL compliance records DS5 — ALL message threads DS6 — ALL performance metrics DS8 — ALL user accounts PROCESSES P1 Onboarding (final approval) P3 Compliance · P4 Broadcast P5 Performance (full analytics) RFQ (oversight) E4 — COMPLIANCE Compliance Authority Portal Login · Created by E3 WHAT THEY CAN DO • Review vendor applications queue • Verify KYC & compliance documents • Validate certificates & licences • Log decisions: approve / reject • Request additional information • Manage onboarding review history • Update certificate validity status DATA ACCESS DS2 — Vendor documents (review) DS4 — Compliance records (write) DS8 — Own account profile PROCESSES P1 Onboarding (review & decision) P3 Compliance (cert verification) ACCOUNT CREATION Created exclusively by Super Admin (E3) via User Management module. Credentials sent by E5 email. → See Page 11 — Login Module Flow E7 — FINANCE Finance Admin Invoice Approval & Payment Processing WHAT THEY CAN DO • Review & approve invoices • Authorise payment processing • Set payment terms & rules • Approve RFQ estimated budgets • View financial performance reports • Audit invoice & payment history • Communicate on vendor payments DATA ACCESS DS3 — ALL orders & invoices DS5 — Finance message threads DS6 — Financial KPI metrics PROCESSES P2 Orders & Invoices P4 Communication P5 Performance (financial) RFQ & Tender (budget) FINANCE RESTRICTION Invoice payment requires Finance Admin approval — no other role can authorise. ACCOUNT CREATION Created exclusively by Super Admin (E3) → See Page 11 — Login Module
METAMORF Group — Vendor Portal  ·  User Account Setup
Portal User Login Module — Accounts Created by Super Admin
Departmental Admin (E2) · Compliance Authority (E4) · Finance Admin (E7) — all portal user accounts created and managed exclusively by Super Admin (E3)
Page 11 of 11
May 2026
Super Admin (E3)
System
Email Service (E5)
Dept Admin (E2)
Compliance Auth (E4)
Finance Admin (E7)
DS8 User Accounts
START Super Admin (E3) ONLY SUPER ADMIN CREATES USER ACCOUNTS Only Super Admin (E3) has permission to create, edit, or deactivate any portal user account. E3 can also: • Reset passwords • Change role / dept • Deactivate accounts • Audit login history • Reassign permissions ACCOUNTS CREATED E2 Dept Admin E4 Compliance Auth E7 Finance Admin 1 Super Admin (E3) — User Management Navigates to Settings → User Management → clicks "Add New User" 2 Fill Account Creation Form Name · Email · Role: Dept Admin / Compliance Auth / Finance Admin · Department 3 System Creates Account & Assigns Role User ID generated · Role & permissions set · Record saved to DS8 User Accounts DS8 User Accounts User ID, name, email Role, department Status, last login Hashed credentials 4 E5 Email Service — Sends Welcome Credentials Portal login URL · Temporary password · Role overview email → delivered to user's inbox ↓ User Receives Login Credentials ↓ 5 User (E2 / E4 / E7) Receives Welcome Email Opens welcome email · clicks portal login URL · arrives at Vendor Portal login page 6 First-Time Login with Temporary Password Enters email + temporary password assigned by system at account creation 7 System Enforces Mandatory Password Reset User sets a new secure password · strength validated · updated credentials saved to DS8 8 User Accesses Their Role-Specific Dashboard Portal loads role-scoped view: E2 / E4 / E7 modules only — see right panel for scope 9 User Performs Their Assigned Portal Duties Manages tasks within their role scope · all actions logged & auditable by Super Admin ✓ Portal User Account Active Role-specific portal access live · full activity visible to Super Admin DASHBOARD ACCESS BY ROLE E2 — Departmental Admin • Purchase Orders & RFQ / Tender management • Vendor communication & message threads • Delivery confirmation & quality rating • Dept performance summary & alerts E4 — Compliance Authority • Pending vendor applications queue • Document & certificate verification (DS2) • Compliance decision log (DS4) • Onboarding review history E7 — Finance Admin • Invoice review & payment authorisation • Financial KPI reports (P5) • RFQ budget approval (DS7) • Payment query threads (P4) All accounts in DS8 · no cross-role visibility E2 · E4 · E7 portal accounts created exclusively by Super Admin (E3) · No self-registration · All logins use mandatory first-time password reset
Account Lifecycle — Portal Users Created by Super Admin (E2 · E4 · E7)
1
Super Admin Creates the User Account
Only Super Admin (E3) can create portal accounts for Dept Admin (E2), Compliance Authority (E4), and Finance Admin (E7). No self-registration is possible for any of these roles.
2
System Stores Account in DS8
A unique User ID is generated, the role (E2 / E4 / E7) and scoped permissions are set, and all account data — including department — is saved to DS8 (User Accounts).
3
Welcome Email with Temporary Credentials
Email Service (E5) automatically delivers the portal login URL and a system-generated temporary password to the user's registered email address.
4
Mandatory First-Login Password Reset
On first login the system blocks portal access until the user sets a new secure password. The new hash replaces the temporary credential in DS8.
5
Role-Scoped Dashboard — No Cross-Role Visibility
E2: POs, RFQ, vendor comms, delivery, performance.  E4: compliance queue, document review, decision log.  E7: invoices, payment auth, financial KPIs. Each role sees only their assigned modules.
6
Super Admin Retains Full Lifecycle Control
Super Admin can reset passwords, reassign departments, change roles, or deactivate any portal user account at any time. All user activity is logged in DS8 and auditable.