Who this is for. Super Admins configuring an Agent Co-worker. See the Roles and Access.
Contact Management is a capability group on the AP Helpdesk tab of Define capabilities. It tells the agent how to classify the FROM address on every inbound email, and holds the contact lists that drive that classification.
Every inbound email is classified by its FROM address into one of four sender types. The classification is not a label. It is the authorization boundary. It decides what records the agent may reach and how autonomously it may act, and it is half of every processing rule.
Figure 1. Contact Management on the AP Helpdesk tab of Define capabilities.
The product describes it as telling the agent how to classify the FROM address on every inbound email, as External (vendors), Internal (your team), System (no-reply platforms), or Unknown, and managing the contact lists that drive that classification. Each sender type sets the authorization scope for the action rules on the next step.
This is the most security-relevant configuration in the product. A mistake here does not produce an error. It produces a reply that discloses more than intended, or less, and neither is obvious from the queue.
The four sender types
Every address the agent reads resolves to one of four types, and the type decides what a reply to it may contain. Where a sender matches decides what the agent may access on their behalf; when the access looks wrong, check the Matched through column first.
Figure 2. The four sender types and the access each one grants.
Table 1. Sender types, what they authorize, and where each list is kept
| Type | Matched through | What the agent may reveal | Contact list |
|---|---|---|---|
| External Sender | The sender matches your vendor directory, a vendor, or someone from a vendor’s organization. | Acts only on records tied to the matched vendor when processing and responding. A vendor asking about another vendor’s invoice gets nothing. | View External Contacts, with a count |
| Internal Sender | Your Internal Contacts config: specific contacts, and optionally domains for broader coverage. | Broad access across vendor records and internal AP data, because a colleague may legitimately be asking about any vendor. This is the broadest scope. | Manage Internal Contacts, with a count |
| System Sender | Your System Sender list: configured addresses, domains, or wildcard subdomains. | Treated as a trusted automated source: a vendor ERP, AR or billing platform, e-invoicing network, payment processor, or your own internal systems. Eligible for processing beyond basic triage, including task creation. In AP Helpdesk a System Sender address can also be linked to one or more vendor records, so automated mail from a billing platform can be associated with the right supplier. | Manage System Senders, with a count |
| Unknown Sender | Nothing: matches no vendor, teammate, or trusted system. | Handled with the strictest caution. The Agent Co-worker does not surface supplier record details in responses. | None |
Sender type is the authorization boundary. An email that lands as Unknown gets a cautious reply with no supplier detail in it. Where a reply carried less detail than expected, the sender’s classification is the first thing to read.
Unknown is a working state. A vendor writing from an address that is not on their vendor record classifies as Unknown, and the agent will answer without supplier detail. The reply is bounded by the classification. Add the address to the vendor record rather than loosening the rules.
How the product defines each type
The wizard shows a one-line definition against each sender type. These are the definitions the classifier applies.
Table 2. Sender type definitions
| Type | Definition shown in the product |
|---|---|
| External | Vendors, suppliers, or customers matched by contact or domain. |
| Internal | Listed in Internal Contacts or matched by internal domain. |
| System | Trusted platform / no-reply system address. |
| Unknown | Sender could not be classified. |
Each type also shows a sender count and a message count, so you can see how much traffic sits behind a type before you widen what it is allowed to do.
How classification works
Classification is deterministic, not a judgment call. The FROM address of every inbound email is matched against your configured contact lists, either on the full email address or on the email address domain. The result is one of four sender types.
Because it is deterministic, the same address always classifies the same way. Where a sender is classified incorrectly, the cause is the contact lists rather than the message content.
Classification is applied before anything else. Everything downstream operates inside the scope it establishes.
Alongside the sender type, two further values are recorded:
Match type: whether the match was on the specific contact or on the domain.
Status: for External senders only, whether the matched vendor is Enrolled or Unenrolled for AP Helpdesk processing. Internal and System matches carry no status; Unknown senders have neither match nor status.
Classification is an authorization decision
Sender type is not a label for reporting. It is the permission boundary the Agent Co-worker operates inside for that message. That boundary comes from the match, not from the autonomy level.
A vendor is entitled to information about their own invoices and nothing else. A colleague in AP may legitimately ask about any vendor. A billing platform sending an automated notification is neither. Someone the system does not recognize should not receive supplier record details at all. Sender type encodes those distinctions so the Agent Co-worker applies them consistently on every message.
Which sender types carry most risk
Internal grants the widest access of the three matched types. Every address enrolled as an Internal Contact, and every address on a Relaxed Matching domain, can prompt the Agent Co-worker to look across your whole vendor base. Keep that list limited to people who do AP work, and treat a Relaxed Matching domain as granting the same access to everyone on it.
System is the type most often left incomplete. Automated senders that are not configured land as Unknown, so routine platform notifications get maximum-caution handling and create little value.
The setting that carries real risk
Relaxed Matching classifies senders as Internal by email domain rather than by individual address. Review any domain addition deliberately rather than as routine maintenance.
Public and consumer email domains cannot be added. Adding one would classify anyone with such an address as an Internal sender, granting them the broadest access scope in the product.
Enrollment is a separate gate
Matching a sender and enrolling their vendor are two different things, and both must be true for full processing. A vendor can be matched without being enrolled, and the difference is large.
Table 3. Matched against enrolled
| State | Handling |
|---|---|
| Matched and enrolled | Full processing: intent detection, extracted values, generated drafts, attachments, labels, auto-assignment. |
| Matched but unenrolled | A basic review task at most. No intent detection, no draft. |
| Unmatched | Unknown. No record access at all. |
Enrollment changes apply to future email only. Enrolling a vendor does not reprocess what has already arrived.
Why unmatched senders limit automation
Sender identity is the foundational gate. Without a match there is no authorization scope and no record access, so the Agent Co-worker cannot act autonomously regardless of how the rest of the configuration is set. No rule can compensate for it.
Adding a genuine business sender to the appropriate contact list does more for automation than any other single configuration change. The Unknown group in the mailbox is worth reviewing periodically for exactly this reason. It is where automation is being lost.
Where classification is managed
Three of the four types are managed from the Contact Management capability group, which carries one link each: View External Contacts, Manage Internal Contacts, and Manage System Senders. Unknown has no list. It is what remains when nothing else matches.
Configure contact management second
The AP Helpdesk capability settings decide how vendor email is classified, what the agent may reveal to whom, and how replies are composed. One setting here matters more than the rest, and it is not the autonomy level.
Table 4. Order
| # | Setting | Why here |
|---|---|---|
| 1 | Autonomy level | Determines which of the remaining sections exist. |
| 2 | Contact management | Sets the authorization scope every later section operates inside. |
| 3+ | The rest | In the order presented. |
Tuning categories, guidance, or rules before the boundary is set means tuning behavior the boundary will later override.
Navigate to Contact Management
On the Define capabilities step, select the AP Helpdesk tab.
In the left navigation, select Contact Management.
Work through the lists in this order
Review External Contacts first. This list comes from your vendor directory and needs no configuration, but reviewing the count confirms your vendor data synchronized as expected. If it looks wrong, the problem is upstream in the system of record.
Set up Internal Contacts next. Decide whether to enroll people individually or allow-list a domain. This is where over-granting causes the most risk, because Internal classification carries the widest access.
Populate System Senders third. Every automated platform you leave out lands as Unknown, which limits what the Agent Co-worker can do with routine notifications.
Review the Unknown Sender Email Addresses table last, at the foot of the Manage System Senders panel. It shows addresses that have already written to you without matching anything, with message counts, which makes it the fastest way to find platforms you have missed.
Where else these settings appear
Email categories and processing rules are also reachable from Settings. Contact management is configured in the wizard, as described above.
Change a sender’s classification
Reclassification happens by editing the contact lists, not by writing a rule. No rule may direct the Agent Co-worker to treat an Unknown sender as a matched sender type; that boundary holds regardless of how a rule is worded.
The routes are: add the address or domain to the Internal Contacts configuration, add it to the System Sender list, correct the vendor record in the system of record so the vendor directory matches it, or use Helpdesk Contact Management from the message itself, described below.
Indirect mail processing
Process Indirect Mail sits at the foot of the Contact Management capability group. It decides whether the agent works mail that reached the connected mailbox without being addressed to it directly. The area contains one setting.
Relaxed Pre-Check
The setting is Relaxed Pre-Check. The product describes it as:
Figure 3. Process Indirect Mail, with the Relaxed Pre-Check setting.
When Relaxed Pre-Check is enabled, emails received by connected mailbox, wherein the email TO is not the mailbox address, are processed as if mailbox address was the email TO. This includes emails received by way of Cc, Bcc, Alias, and Redirect.
Table 5. What the setting covers
| Arrival route | Worked with Relaxed Pre-Check off | Worked with it on |
|---|---|---|
| Addressed directly to the mailbox | Yes | Yes |
| Cc | No | Yes |
| Bcc | No | Yes |
| Alias | No | Yes |
| Redirect | No | Yes |
This is worth ruling out early where mail is arriving but producing no work. If vendors copy the AP mailbox rather than addressing it, or mail reaches it through an alias or a forwarding rule, none of it is worked until Relaxed Pre-Check is enabled, and nothing in the queue indicates the mail arrived at all.
Enable Relaxed Pre-Check
In the left navigation, select Contact Management.
Under Process Indirect Mail, select or clear Relaxed Pre-Check.
Select Next to continue to the next capability section.
When to enable it
Enable it when genuine AP work reaches the mailbox indirectly and is currently being missed. Common signs:
Vendors reply to buyers or requisitioners and copy the AP mailbox.
Your AP address is an alias for another mailbox, or mail is redirected into it.
Colleagues forward vendor threads in rather than composing a new message.
What to consider before enabling it
The setting widens the volume the Agent Co-worker processes, so expect more classified email and potentially more tasks. Two things limit the risk:
Authorization is unchanged. Sender classification still runs on every message, so a Cc’d email from an unknown address is still treated as an Unknown sender.
Your rules still apply. Anything that must not happen autonomously remains gated by the rules you wrote.
What does change is that internal threads copied to AP become eligible for processing, which can produce tasks your team did not previously see.
The setting is all-or-nothing for the mailbox. It cannot be applied to Cc but not Bcc, or to some aliases but not others.
What this depends on rather than configures
The connected mailbox. Everything here operates on mail arriving there.
Vendor contacts on vendor records. External sender matching resolves against these. A vendor without contacts matches as Unknown.
Vendor master synchronization. A vendor absent from the directory cannot be matched at all, and their email is treated as Unknown.
Where the agent does not resolve a vendor, check the connection sync before checking configuration. The connection sync runs every four hours by default, and vendor master is not one of the record types offered for the hourly refresh, so a vendor added in the system of record can take up to four hours to appear here.
Helpdesk Contact Management
A sender can be classified from the message itself, without opening the wizard. An icon sits beside the sender address on a task and on a message in the Mailbox. Its tooltip reads Add Helpdesk Contact where the sender is not yet configured, Manage Helpdesk Contact where they are, and Blocked Helpdesk Contact where they are on the blocked list. Selecting it opens Helpdesk Contact Management.
The dialog shows the sender address and an ADD TO list. Each entry the sender already belongs to offers Remove instead.
Table 6. Where a sender can be added
Entry |
What it does |
|---|---|
System Sender List |
Sets the sender as a trusted source of platform communication. A consumer address such as gmail.com or outlook.com is refused, and the entry says so. Where the System sender type is not enabled on the agent, the entry says that instead. |
Vendor Contacts |
Adds the address as a point of contact for one or more vendors. |
Internal Contacts |
Authorizes the address as a team member for processing. |
Blocked Sender List |
Suppresses processing of the sender’s email and removes it from the Inbox. |
Adding to the Blocked Sender List stops the agent processing that sender and takes their mail out of the Inbox view. It is the one entry here that removes work rather than enabling it.
Related information
For the System Sender list and its controls, see System Senders.
For the categories that complete end to end, see Standard Email Categories.
For the decisions to settle before you configure capabilities, see Before You Start.