Software Requirements Specification — Acme Invoicing Portal
| Field | Value |
|---|---|
| Document Reference | SRS-INVOICING-2026-001 |
| Project | Acme Invoicing Portal |
| Client / Organisation | Acme Logistics Ltd |
| Date | 7 May 2026 |
| Version | 1.0 |
| Classification | Client-Facing |
| Status | Draft |
Introduction
Purpose
This Software Requirements Specification (SRS) defines the functional and non-functional requirements for the Acme Invoicing Portal — a self-service web application that replaces Acme Logistics' current manual invoicing process. It is intended for the engineering team, the Acme product sponsor, and the QA partner conducting User Acceptance Testing.
Scope
The system shall provide invoice creation, approval, dispatch, and reconciliation for Acme's 200+ B2B customers. Out of scope: payment collection (handled by Stripe), customer onboarding (handled by the existing Salesforce CRM), and historical invoice migration prior to 1 January 2026.
Overall Description
User Classes
- Finance Operator — creates and dispatches invoices; needs bulk-edit and CSV export.
- Approver — reviews invoices flagged above £10,000; needs an inbox view and one-click approve / reject.
- Customer Admin — external user; views their invoices, downloads PDFs, raises queries.
Functional Requirements
| ID | Requirement |
|---|---|
| FR-01 | The system shall allow Finance Operators to draft, save, and dispatch an invoice within a single screen. |
| FR-02 | Invoices over £10,000 shall be routed to an Approver before dispatch; dispatch is blocked until approval. |
| FR-03 | Customers shall receive a branded email with a unique link to view and download their invoice as PDF. |
| FR-04 | The system shall reconcile inbound payments against outstanding invoices nightly via the Stripe webhook. |
Non-Functional Requirements
[!note] The targets below are derived from Acme's existing portal SLA; revisit if the customer base scales beyond 1,000 active users.
- Performance. P95 page load < 2.0s; P95 invoice-generation API < 800ms.
- Reliability. 99.9% monthly uptime SLA; recovery point objective (RPO) ≤ 5 minutes.
- Security. OWASP ASVS Level 2; all data encrypted at rest (AES-256) and in transit (TLS 1.3); RBAC with least-privilege; quarterly penetration test.
- Accessibility. WCAG 2.1 Level AA on all customer-facing screens.