From quote to order in a B2B portal: approvals and changes
The customer approved the quote, but has the supplier accepted the order? Define who approves what, which changes require review and what confirmation proves.
What does “approved” mean in your operation?
A distributor receives a request for 10 units. The buyer needs their manager’s approval; sales must review commercial terms and the warehouse must check availability. If every screen says “approved,” nobody can tell what remains. Another button will not resolve the ambiguity: each state needs an owner, condition and evidence.
| State | What it establishes | What still needs verification |
|---|---|---|
| Draft request or quote | The customer entered an intention and its lines | Current offer, required approvals and supplier acceptance |
| Buyer approved | An authorized person accepted a specific version for their company and location | Seller acceptance and commercial conditions |
| Under supplier review | The supplier received the request for a decision | Commercial outcome, availability and order recording |
| Confirmed order | The designated system accepted the order and returned its reference | Reservation, preparation, delivery and payment under their own records |
| Partial preparation or delivery | Actual quantities have been prepared or delivered | The remaining quantity and its agreed resolution |
| Payment pending or applied | The payment record identifies its state | Approval or a screenshot does not replace payment confirmation |
The customer’s purchase order may have its own reference too. Link it to the quote and supplier order: a shared number does not make them the same document. The customer portal guide helps decide whether you need this channel; here we define transaction acceptance.
Commercial products also distinguish these stages. Shopify supports B2B orders submitted as drafts for review; a draft submitted for approval still needs completion to become an order. Business Central describes acceptance and conversion of a quote, preserving the originating quote reference in the resulting document. First check whether your existing system can represent the stages you need.
Who requests, who approves and who accepts?
Write down both sides of the permission matrix: the buying company and your company. Someone allowed to request goods should not automatically be able to approve terms, view another branch’s purchases or increase their credit limit. Adapt this example to your actual responsibilities and rules:
| Role | Permitted action in this example | Boundary to test |
|---|---|---|
| Customer requester | Prepare and submit requests for their assigned location | Cannot approve for the manager or consult another customer |
| Customer approver | Accept the offer version within their assigned scope | Cannot change price lists, release seller holds or expand their own permissions |
| Supplier commercial owner | Accept or revise terms and review a hold under the commercial policy | Cannot silently alter an accepted offer without recording the change and obtaining required approval |
| Supplier operational owner | Record their assigned reservation, preparation or delivery actions | Cannot mark partial delivery complete or change commercial authorization |
Access may also depend on location. Shopify distinguishes ordering-only contacts and location admins, with different access to order history and addresses. These native roles do not establish that your internal approval chain is included: test the exact requirement in the configuration, extension or development you choose.
The server must check company, location, document and action for every request. OWASP recommends validating permission on each request. Hiding a button is insufficient: try changing the quote identifier and downloading another customer’s attachment. When a contact is revoked, their next action must be rejected even if an old session or link remains open. Preserve attributed history without preserving access.
What happens when the quote, price or validity changes?
An approval must identify the reference, version, company and location, products, units, quantities and terms that were displayed. Agree which changes are material: quantity, price, timing, address or supply method may require new approval. Preserve the history instead of silently replacing the content beneath a previous approval.
| Chosen commercial rule | Behavior to agree | Useful test |
|---|---|---|
| Honor the valid quote | Maintain the expressly quoted price during its validity and under its conditions | A catalog change does not secretly alter the price of that offer |
| Revalidate and requote | Present a revised offer when a condition requires a price review | The customer sees the difference and approves the new version before confirmation |
| Expired offer | Review or issue a current offer under the written rule | An old link does not extend validity or automatically confirm an order |
Having a catalog does not determine the rule. Shopify documents locked and unlocked draft-order prices: locking can retain the quoted price; unlocking can update it. The test must explain which choice applies to your flow. A catalog price decrease also needs an explicit rule: locked pricing does not mean every subsequent change applies automatically.
In the tests, COT-100 v1 requests 10 units. If the offer changes to v2 for 12 units, approval of v1 does not accept 12. In a different independent case, the catalog changes from LISTA-A-v1 to LISTA-A-v2, while an unexpired, expressly locked offer retains LISTA-A-v1. Changing an offer and changing a catalog are different decisions.
What should credit and stock checks establish before confirmation?
A commercial credit hold is a condition of your sales policy. Define its trigger, who reviews it and the evidence recorded for an exception. The buyer may consult their own status or request review; they must not release the hold by changing a portal field. Releasing a hold does not establish payment or remove the checks for price, version and availability.
Distinguish trade credit, credit balance, prepaid balance and applied payment: their rules differ. For follow-up after the sale, see the collections-system guide. This test covers when to accept an order rather than recommending a credit facility.
If the customer requests 10 units and 8 are available for immediate supply, explain the 2 pending. Agree partial supply, revise quantity or hold the request; never silently change it to 8 or promise 10 immediately. An order for 10 with agreed partial supply still totals 10 ordered: 8 ready and 2 pending. That does not establish reservation or delivery of all 10.
Decide when stock is reserved, at which location and what happens when two customers compete for the same availability. Viewing stock does not reserve it. The system recording inventory movements must validate reservation under its rules; the inventory-between-warehouses guide explains available, reserved, blocked and in-transit quantities.
Eight tests before inviting customers to the portal
| Case | Input or condition | Required outcome |
|---|---|---|
| B01 — Valid confirmation | Unexpired v1; buyer and supplier approval; no hold; availability/reservation condition checked | One confirmed ORD-100 linked to COT-100 v1; ordered quantity 10 |
| B02 — Stale approval | v1 requested 10; v2 requests 12; approval of v1 is submitted | Zero confirmed orders; show the revision and request approval of v2 |
| B03 — Quoted price | Catalog LISTA-A-v2; unexpired v1 offer expressly honors locked quoted pricing; all other conditions pass | One order; retain the offer’s LISTA-A-v1. A requoting policy needs a different outcome and test |
| B04 — Another customer | Customer B attempts to read, approve or download A-1’s COT-100 | Access denied; zero confirmed orders and no company A prices or documents disclosed |
| B05 — Buyer approval only | The buyer accepts v1; the supplier has not accepted it | Zero confirmed orders; show supplier acceptance pending |
| B06 — Commercial hold | Version and approvals are ready, but the commercial credit hold is active | Zero confirmed orders; authorized owner reviews the hold, with no customer release |
| B07 — Agreed partial supply | 10 ordered, 8 immediately available; buyer and supplier accept 8 now and 2 pending; all other conditions pass | One order for 10; show 8 ready and 2 pending, without claiming delivery or full availability |
| B08 — Repeated confirmation | op-COT100-v1 is repeated after ORD-100 was recorded | One ORD-100; return or reconcile the same result instead of creating another order |
Download the B2B quote-to-order CSV and the portal test instructions. The CSV is an example for team review, not an order importer or a configuration ready for production.
Include three more exceptions in your review: an expired offer, a revoked contact and an uncertain response. If the supplier system times out or loses its response, the confirmed-order count is still unknown: keep it pending instead of assuming zero or one. Reconcile the real outcome first. The connect-your-ERP guide explains retries and references without duplicate operations.
What message does the customer see when something remains pending?
Show the actual stage and next step. “Request received: COT-100 v1, awaiting supplier acceptance” differs from “Order confirmed: ORD-100, 8 ready and 2 pending.” Identify who reviews the exception and which contact channel remains available. A success screen must correspond to the recorded outcome, not merely to the browser finishing its submission.
Agree which event sends each notification and how retries avoid repeating it. If the offer changes, the notice should lead to the current version with access checked. If part of the order has already been supplied, cancellation cannot erase what happened: follow the agreed rule for pending quantities, reservations and actual deliveries.
Configure the platform, extend it or build a portal?
Apply the same tests to all three choices. If your ERP or commerce platform already handles companies, quotes and orders under the required rules, start with configuration. An extension may address a boundary with another system; a custom portal makes sense when the required process cannot fit those alternatives viably.
| Alternative | What to check | When to stop the decision |
|---|---|---|
| Existing configuration | Correct company/location, permissions, pricing, review, validity and states using your examples | An essential rule is unavailable or only simulated with an ambiguous status |
| Extension or integration | Supported access, authority for each field and actual order acceptance in the designated system | No permitted access, reconciliation or owner for an exception |
| Custom portal | Written rules, available data, maintenance and permission/transaction acceptance tests | The team has not agreed who can accept or what each status means |
Check the actual account and plan. Shopify’s current B2B feature matrix distinguishes plan capabilities such as direct company catalog assignments and advanced payment options. Being able to create companies does not establish support for your specific price or approval policy. Business Central documentation shows native quote-to-order conversion; it does not itself establish a connection to your portal.
What should you bring to a scope review?
- A representative quote with versions, units, terms and validity; use authorized or fictional data.
- A company, location and user matrix: who requests, approves, accepts, reviews credit and records quantities.
- Price and change rules, reservation timing and what the customer does when supply is partial.
- The system confirming the order, related references and the owner reviewing unknown outcomes.
- B01–B08 plus expiry, revocation and cancellation exceptions as written acceptance criteria.
The CelMex Unlockers case shows orders, balances and digital-service supplier connections. It supports work at that scope; it does not establish this synthetic wholesale approval, physical-stock or trade-credit policy. A proposal starts from your rules and data rather than attributing this example to a customer.
Review the customer portal service and use the scope worksheet. If the transaction must be recorded in an existing system, include the ERP and integration review. A useful first stage has one concrete flow and a test your team can accept.
Primary sources reviewed on 5 October 2026. Product and plan capabilities can change; verify the edition, configuration and account access before choosing a solution. The matrices and cases are review criteria, not guarantees of security, integration or commercial results.
Frequently asked questions
It depends on the written flow. Buyer approval accepts an offer version; supplier approval and recording in the designated system confirm supplier acceptance. The portal must distinguish the stages and show the actual reference without inferring payment, reservation or delivery from approval.
Define the commercial rule. An unexpired offer with expressly locked pricing can retain it; a revalidation policy may require a revised quote and another approval. Never hide a change beneath an earlier approval. Verify the available behavior in your platform and plan.
Show the immediately available and pending quantities. Customer and supplier must agree partial supply, revision or waiting before confirmation. In the example, 10 ordered remain 8 ready and 2 pending, rather than 10 delivered.
Identify the authorized operation and link its result to the quote and version. If ORD-100 already exists, a retry should retrieve or reconcile that result. If the response is unknown, verify the real state before creating again.
Sources
- Creating B2B orders using draft ordersShopify
- Creating and managing B2B company contacts using customersShopify
- Shopify B2B features by planShopify
- Make sales quotes — Business CentralMicrosoft
- Authorization Cheat SheetOWASP
Last updated: