How it works
BridgeOps moves supplier invoices from whatever produces them into a legacy ERP, and nothing reaches the ERP unless policy allows it. AI can be one of the sources, but it never holds authority.
All data here is mock-up data. DemoCorp Manufacturing, its suppliers, purchase orders, invoices, users and the ERP are synthetic. No real company or money is involved.
- 1Source produces data
REST API, signed webhook, CSV upload, manual form or an AI extractor. Each source has its own credential.
- 2Adapter normalizes
Every source becomes the same event shape. The tenant comes from the credential, never from the payload.
- 3Schema validates
Required fields, types and money as exact decimals. AI output is untrusted input and must pass the same schema.
- 4Policy decides
Deterministic rules: thresholds per currency, PO match, supplier status. Missing data or no policy means BLOCK.
- 5Humans authorize
Above-threshold work waits for an APPROVER. The approval is bound to the payload hash, and the submitter can't approve.
- 6Connector executes
Idempotent writes to the (mock) legacy ERP, with retries, a circuit breaker and reconcile-before-retry.
- 7Verifier confirms
BridgeOps reads the record back from the ERP before calling the workflow complete.
- 8Audit records everything
Every step is appended to a hash-chained audit log that anyone with the auditor role can verify.
Run it live
Each button sends a fresh synthetic invoice through the real engine on this server, signed in as the demo operator. The result below is read back from the API.
- A USD 4,250 against PO-5001. Within policy, so it runs straight through to the ERP.
- B USD 8,900 is over the USD 5,000 limit. Policy stops it for a finance manager.
- C An AI extractor returns chatty text instead of an invoice. Schema validation rejects it.
Public API (synthetic data)
Base URL https://bridgeops.enthernetservice.com/api. Send a demo token or API key as Authorization: Bearer …. Rate-limited.
| Method | Path | What it does | Credential |
|---|---|---|---|
| GET | /v1/demo/users | List demo users | none |
| POST | /v1/demo/login | Body {"user_id":"u_ops"} returns that user's token | none |
| GET | /v1/me | Who you are | user token |
| GET | /v1/dashboard | Counters, connector health, circuit state | user token |
| GET | /v1/workflows | Workflows, filter with ?status= | user token |
| GET | /v1/workflows/{id} | Payload, policy decision, approvals, ERP writes, audit | user token |
| GET | /v1/audit/verify | Recompute the audit hash chain | auditor, owner |
| POST | /v1/demo/scenarios/{A|B|C|D} | Run a demo scenario | operator, owner |
| POST | /v1/workflows/{id}/approve · reject | Decide an approval (body {"reason":"…"}) | approver, owner |
| POST | /v1/workflows/{id}/correct · requeue · reverify · cancel | Human recovery actions | operator, owner |
| POST | /v1/events | Submit {"workflow_type":"invoice","payload":{…}} | REST API key |
| POST | /v1/csv | Upload a CSV of invoices | CSV API key or user |
| POST | /v1/ai/events | Raw AI extractor output (treated as untrusted) | AI API key |
| POST | /v1/webhooks/supplier-portal | Signed webhook intake | HMAC signature |
Try it
curl -X POST -H "Authorization: Bearer demo-token-u_ops" \
https://bridgeops.enthernetservice.com/api/v1/demo/scenarios/A
curl -H "Authorization: Bearer demo-token-u_view" \
https://bridgeops.enthernetservice.com/api/v1/workflows
curl -X POST -H "Authorization: Bearer demo-key-rest" -H "Content-Type: application/json" \
-H "Idempotency-Key: my-test-1" \
-d '{"workflow_type":"invoice","payload":{"supplier_id":"SUP-1001","invoice_id":"INV-T1","amount":"1200.00","currency":"USD","purchase_order":"PO-5001"}}' \
https://bridgeops.enthernetservice.com/api/v1/eventsWebhooks: X-BridgeOps-Timestamp (unix seconds), X-BridgeOps-Signature: v1=hex(HMAC-SHA256(secret, "<timestamp>." + raw_body)) and a unique X-BridgeOps-Delivery. Stale timestamps and replayed signatures are rejected.
Demo access
Demo credentials for synthetic data only. The app refuses to start with them outside demo mode.
| User | Role | Bearer token |
|---|---|---|
| owner@democorp.example | OWNER | demo-token-u_owner |
| ops@democorp.example | OPERATOR | demo-token-u_ops |
| finance.manager@democorp.example | APPROVER | demo-token-u_finance |
| auditor@democorp.example | AUDITOR | demo-token-u_audit |
| viewer@democorp.example | VIEWER | demo-token-u_view |
- REST API key
- demo-key-rest
- AI extractor key
- demo-key-ai
- CSV key
- demo-key-csv
- Webhook source
- supplier-portal
- Webhook secret
- whsec_demo_synthetic
In the dashboard you don't need any of these: pick a role on the sign-in screen.
