Approval Limits and Controls: Thresholds, Who Approves What, and How It Is Recorded
Back to blog
product·September 11, 2026·4 min read·By Yehonatan Saadia

Approval Limits and Controls: Thresholds, Who Approves What, and How It Is Recorded

When every approval reaches one person, that person is the bottleneck. How to set thresholds, what stays with the owner, and how to keep control without delaying everything.

Key takeaways

  • Personal approval of everything is the most common bottleneck in a small business.
  • A written threshold replaces a conversation and returns hours to both sides.
  • What requires approval should be defined by risk, not by habit.
  • An approval that is always granted is not a control but a ceremony.

In many small businesses everything goes to one person for approval - so everything waits for them. The fix is not abandoning control but moving it from a case-by-case decision into a rule: what can be approved without asking, up to what amount, under what conditions.

What actually needs approval

AreaWhat is usually rightThe risk being managed
PurchasingA threshold by amount, plus every new supplierUnnecessary spend
DiscountsA percentage threshold by roleMargin erosion
Credits and returnsA threshold, with exceptions approvedFinancial loss and precedent
Unusual payment termsAlwaysCash flow
Timeline commitments to customersBy scopeReputation
Access to systems and dataAlwaysInformation and security

Row four is often forgotten and is among the most significant: agreeing long payment terms is a cash-flow decision made in a sales conversation, sometimes without anyone noticing.

How to set a threshold

Not by instinct. Three questions decide it: what amount is one where an error is still tolerable; how often this happens per month; and how much time the approval itself costs. When the approval costs more than the risk, the threshold is too low.

In practice, most businesses find that most approvals concern small amounts, and that the bulk of the time goes precisely on those. Raising the threshold slightly - so most cases need no approval - returns most of the time and leaves control exactly where it is needed. The logic of a human bottleneck is covered in finding the bottleneck in your process.

What must stay with the owner

  • A new supplier - because it is an ongoing commitment rather than a one-off spend.
  • An unusual price for a regular customer - because it becomes a precedent.
  • A legal commitment - a contract, a guarantee, unusual terms.
  • Hiring and salary commitments.
  • Anything above the high threshold you defined.

What has no reason to stay: approving office supplies, approving a small credit, approving a discount of a few per cent. Those are precisely the cases where approval costs more than the amount.

Recording - what is enough

No system is needed. What is needed is three things per exceptional approval: who approved, when, and on what exactly. A message in the work channel is sufficient, provided it is linked to the order or customer rather than sitting in a private conversation.

What matters is that the record is somewhere findable in six months. An approval given verbally and never recorded is a source of argument: the rep remembers it was approved, the manager remembers hesitating, and there is no way to settle it - which is exactly the problem described in task handoffs without drops.

How to tell the system is working

Three signals. How many approvals a week - if the number did not fall after you set thresholds, the thresholds are too low. How long people wait for approval - the metric the team feels. And how many approvals were refused - if the answer is zero over two months, that approval is ceremonial and can be removed.

The third matters most and almost nobody measures it. An approval granted 100% of the time prevents nothing; it only adds waiting, and sometimes creates a false sense that somebody genuinely checked.

What happens when the approver is unavailable

This is the failure that makes good thresholds worthless. With no defined deputy, one person's day off stops orders, credits and quotations.

The fix is one rule: every authority has a named deputy, and the substitution triggers automatically after a defined time - if no approval within X hours, the deputy may approve. It sounds risky and is usually safer than the current state, in which people improvise anyway when the approver is away.

How do you define this in an hour?

No policy document required. One page with four columns is enough: type of decision, who may decide, up to what limit, and what must be recorded. Five to eight rows cover most day-to-day decisions in a small business.

The fast way to build it is not to plan ahead but to look back: review the last fortnight and list everything that actually required approval. That list is almost always short, and usually three kinds of decision explain most of the requests - and thresholds for all three can be written in ten minutes.

Once the page exists, put it somewhere visible rather than emailing it. An authority you have to search for in order to know it exists will be ignored, and people will go back to asking - which is exactly what you were trying to prevent.

What happens when you grant authority and nobody uses it

This happens more often than expected, and it is a habit problem rather than a trust one. A team used to asking keeps asking, even when entitled to decide - mainly because prior approval protects them if something goes wrong.

What changes that is not the permission but the reaction: when somebody decides within the threshold and the outcome is imperfect, the reaction determines whether they will decide again. A reaction that asks whether the decision was reasonable given what was known - rather than whether the outcome was good - is what produces a team that decides.

It also helps to say it explicitly, once: "if you decided within the threshold, that was the right decision even if the outcome was poor". One sentence like that, said before the first such case rather than after it, saves months of people coming back to ask about everything.

Sources

#authority#approvals#controls#management#process#איסוף נתונים

Frequently asked questions

What size of business is this relevant for?

From three people. Even in a very small business, if the owner approves every discount and every purchase, they are the bottleneck - so setting thresholds is one of the first things that returns time to them, even with a small team.

How do you delegate without losing control?

By combining a threshold with a record: the rep may decide up to a limit, and every such decision is recorded and visible. Control moves from "before" to "after", and it is usually more effective - because it rests on what actually happened rather than on an estimate beforehand.

What if somebody exceeds their authority?

Establish whether it came from a misunderstanding, customer pressure, or a threshold that is unrealistic. The third is more common than expected, and when it is the cause the fix belongs to the threshold rather than the person.

How often should thresholds be updated?

Annually, or when prices change materially. A threshold set three years ago no longer matches the same transaction, and in most cases it is too low - which puts everyone straight back into the approvals they were trying to avoid.

Keep reading

Related service

MVP Development

Turn an idea into a validated product in weeks, not months.

Learn more

About the author

Yehonatan Saadia

Freelance automation, web & MVP developer

I'm Yehonatan Saadia, a senior developer who builds business automation, custom websites, and MVPs for small and mid-sized companies across the US, Europe, and Israel. These guides come from real client work, not theory.

Work with me

Have a project like this?

Tell me what you're trying to automate or build and I'll tell you the fastest reliable way to ship it.