Back to Blog
Published:
Last Updated:
Fresh Content
Copilot BoundaryChapter 22

What are the published limits on the Payables Agent?

5 min read
1,158 words
high priority
Ali Ahmed

Ali Ahmed

AI Solutions Engineer, Cognilium AI

TL;DR

What Microsoft documents the Payables Agent can and cannot do, taken from its own pages, including where a person still has to approve the work.

Microsoft publishes them as a list, and it is short. PDF attachments only · ten per email · no PDF over ten pages or five megabytes · daily caps on emails and invoices. Two whole capabilities are named as unsupported. That list decides whether the agent fits your accounts payable — before any configuration question does.

What actually gets through to the agent?

Six constraints, all from Microsoft's own limitations section:

ConstraintMicrosoft's words
File type"The agent only processes emails with PDF attachments"
Attachments per email"skips emails with more than 10 attachments"
Page count"doesn't process PDFs with more than 10 pages"
File size"doesn't process PDFs larger than 5 MB"
Daily email volume"doesn't process more than 100 emails per day"
Daily invoice volume"doesn't process more than 500 invoices per day"

Emails without a PDF are not silently dropped. Microsoft: they "are not processed for invoice creation" and "appear as agent tasks that require manual attention." So the work still arrives — it arrives as a task for a person.

The attachment cap has a sharp edge worth knowing. An email with eleven attachments is not partly processed. "The agent skips emails with more than 10 attachments"the whole email, not the eleventh file. A supplier who batches a month of invoices into one message hits this immediately.

And each PDF becomes its own unit of work: "Each PDF document found in an email becomes an entry in Inbound E-Documents… A distinct agent task processes each entry." That is also why the per-document metering works the way it doesthe event breakdown is published per document.

What does the agent refuse to do?

*Two capabilities, named by Microsoft under its own Feature limitations heading:*

Approval flows · Anomaly detection

This is a published limitation list, not a search that found nothing — which is the strongest form this kind of claim takes.

Both absences matter more than they read. An accounts payable process without approval routing is not an accounts payable process in most organisations, so the approval step has to live somewhere else — Business Central's own workflow engine, with its own events and responses. And anomaly detection is the control most people assume an AI feature includes: the agent extracts and matches, it does not flag the invoice that is subtly wrong.

The agent also does not post. Microsoft's flow ends at a purchase invoice — the drafts are reviewed "so invoices are ready for approval and posting." Ready for, not posted.

Where does it stop and hand back?

At the vendor, and the stop is deliberate.

If it cannot identify the vendor confidently, the agent halts and asks a supervisor. A supervisor can instruct it to create the vendor from the extracted details — and Microsoft is careful about what happens next:

"When the agent creates a new vendor, the Blocked field on the vendor card is set to All… leaving the newly created vendor in a blocked state ensures no invoicing processing can happen until the vendor is unblocked."

And it says plainly why: "vendors and their bank accounts are approved by having communication with the vendor and doing human callbacks to the vendor's finance department. In many places, this action is a requirement for a successful audit."

Read that as a design principle, not a quirk. Counterparty-supplied data is not trusted by default. The agent will create the record and then refuse to let it transact until a person has done something outside the system.

Microsoft states the boundary flatly: "The agent itself doesn't provide any capabilities for vendor approvals."

Why does the mailbox setup matter so much?

Because the mailbox is the trust boundary, and Microsoft treats it that way.

"We recommend you use a shared mailbox that you keep as an internal-only mailbox and don't expose this mailbox to your vendors… by not exposing invoices to vendors, your employees become the first to review and identify potential fraud."

Three operational rules follow, all published:

  • "The monitored mailbox should only be attended from within Business Central."
  • "Users shouldn't access the monitored mailbox from Outlook."
  • Do not share it with another agent — "If other agents, like the Sales Order Agent, use the same mailbox, it can cause conflicts with ownership of incoming emails."

The second rule is the one that breaks quietly in practice. An email a person has already opened in Outlook is an email the dispatcher may not pick up — and nothing tells you the invoice was missed, because from the agent's side nothing happened.

So does it fit your accounts payable?

Answer four questions about your own mail, in this order, before anything else:

  1. Do your suppliers send PDFs? If a meaningful share send links, portals or spreadsheets, those invoices arrive as manual tasks regardless of how the agent is configured.
  2. How long is a typical invoice? The page cap is the limit most likely to bite a construction, logistics or professional-services supplier with itemised backup.
  3. Does anyone batch? One supplier attaching a month of invoices to a single email is skipped entirely.
  4. Where does approval live today? It cannot live in the agent, so it has to live in a workflow, and that is a separate design decision.

Those four answers decide fit. Everything else — permissions, profiles, supervisors — is configuration, and configuration only matters once the documents can actually get through.

And the limits are worth reading as a family rather than one at a time. Where all the built-in agents stop is the same exercise across Sales Order, Payables and Expense, and the pattern is more useful than any single cap.

About Cognilium Cognilium builds AI optimization apps for Microsoft Dynamics 365 — companion apps that optimize the pricing, inventory, warehouse and planning decisions your ERP manages but can't optimize. Dynamics is your system of record. Cognilium is your system of intelligence. https://cognilium.ai · https://www.linkedin.com/company/37180269/

Agentic ERP. We build turnkey AI optimization apps for Dynamics 365 — sidecar applications that run in your own Azure tenancy and solve the calculations a standard ERP is not built to compute. Built on Azure OpenAI, Microsoft Fabric and Copilot Studio. We build these on request, against your data and your environment.

More on the boundary between what Copilot does and what you build: Agentic ERP on Dynamics 365.

Run the four questions above against one month of your own supplier mail. Bring the answers to a 15-minute call and we will tell you where the agent fits and where it does not.

Sources

Sources and fact-check
#§ClaimTierPrimary sourceVerdict
11Six document and usage constraints, quoted individuallyT1 — verbatim ×6payables-agent, Limitations, verified against raw page source 2026-09-10 and re-read 2026-09-15PASS — load-bearing
21Emails without PDFs "are not processed for invoice creation" and "appear as agent tasks that require manual attention"T1 — verbatim ×2Same pagePASS
31The attachment cap skips the whole emailT1 — verbatim, "skips emails with more than 10 attachments"Same pagePASS — the word is emails, not attachments
41Each PDF becomes an Inbound E-Documents entry with a distinct taskT1 — verbatim, form name character-exactSame pagePASS
52"Approval flows" and "Anomaly detection" listed under Feature limitationsT1 — verbatimSame pagePASS — a published absence, quoted
62Drafts are finalised "so invoices are ready for approval and posting"T1 — verbatimSame pagePASS
73New vendor gets Blocked = All; the stated audit rationale; human callbacksT1 — verbatim ×2Same page, NotePASS
83"The agent itself doesn't provide any capabilities for vendor approvals"T1 — verbatimSame pagePASS
94Shared internal mailbox recommended, with the fraud rationaleT1 — verbatimSame pagePASS
104Attend only from within Business Central; not from Outlook; agent-conflict warningT1 — verbatim ×3Same page, Caution and NotePASS
114A read email may not be picked up, and nothing reports itT2 — ours, reasoned from claims 9 and 10, marked as oursPASS — not attributed to Microsoft
125The four fit questionsT2 — ours, methodPASS
135"the limit most likely to bite a construction, logistics or professional-services supplier"T2 — ours, a judgement about document length, no figure and no study claimedPASS — opinion, labelled

Tier summary: 11 × T1 (all verbatim), 2 × T2 — 0 × T4.

🔴 No pricing anywhere in this article, per the founder ruling of 2026-09-15. The credit consumption for these documents is a separate article and carries no currency figure either. This piece is about what the agent will and will not accept.

The absences here are Microsoft's own. "Approval flows" and "Anomaly detection" sit under Microsoft's Feature limitations heading. We are quoting a published limitation list rather than reporting a search that found nothing — the strongest form an absence claim takes, and the reason this article needs no bounding statement for them.

Status. The Payables Agent overview carries no preview banner and is not described as preview here. The Expense Agent is preview and is not discussed in this article.

No figures of ours. Every number is a Microsoft published constraint, quoted. No digits appear in either lifted block — the caps are described there in words.

Share this article

The work behind this series

What Microsoft ships, what it does not, and the layer we build where a general assistant runs out.

Ali Ahmed

Ali Ahmed

AI Solutions Engineer, Cognilium AI

Ali Ahmed is an AI Solutions Engineer at Cognilium AI.

Applied AI AgentsAgentic SystemsRetrieval-Augmented Generation (RAG)LLM Product Engineering
Next in this series
Which Business Central version do you need for agents and MCP?
Chapter 23 · 6 min
In short

Key takeaways

  • Microsoft publishes a limitations list, which is stronger evidence than any search that found nothing.
  • PDF only, and only from an email. Anything else becomes a task for a person rather than an invoice.
  • The attachment cap skips the whole email, not the surplus file. One supplier batching a month of invoices hits it immediately.
  • Approval flows and anomaly detection are named as unsupported. Approval has to live in a workflow elsewhere.
  • A vendor the agent creates is blocked from transacting until a person clears it — counterparty data is not trusted by default.
  • The mailbox is the trust boundary. Microsoft recommends an internal-only shared mailbox and warns against opening it in Outlook.
What goes wrong

Common mistakes to avoid

  • Letting suppliers email the monitored mailbox directly. Microsoft recommends an internal mailbox so a person sees the invoice first.
  • Opening that mailbox in Outlook. A read email can be an invoice the agent never sees, and nothing reports it.
  • Sharing one mailbox between agents. Microsoft warns it causes ownership conflicts.
  • Assuming approval routing is included. It is on the unsupported list.
  • Evaluating configuration before document fit. If the PDFs cannot get through, no setting rescues it.

Frequently Asked Questions

Find answers to common questions about the topics covered in this article.

Still have questions?

Get in touch with our team for personalized assistance.

Contact Us

Still have a question this did not answer?

The person who wrote this article answers these. Describe your setup and what you are stuck on — you will get a straight answer, including where we think the approach is wrong.