Flow LedgerOperations notes / 2026

Control / Field brief

Remove Approval Layers Without Removing Control

A useful approval changes the risk of a decision. A repeated approval often changes only the waiting time.

A three-part loop labeled prepare, review, and resolve
Working diagram. Start with the decision, then add the system.

Approval chains grow for understandable reasons. A problem occurs, a leader wants more oversight, and another review is added. Over time, several people can approve the same request using the same information. The process feels controlled because many names appear in the history, but the added layers can hide who is responsible for the actual decision.

The goal is not to remove review. It is to make each review purposeful. A good approval lowers a specific risk because the reviewer has distinct authority, evidence, or expertise. If two reviewers perform the same check and neither can explain the difference, the second review may add delay without adding control.

Name the risk each approval manages

List every approval and complete one sentence: “This reviewer protects against ___ by checking ___.” Use a concrete risk and a visible test. “Provides oversight” is too broad. “Confirms that the request is within the department budget by comparing the approved allocation and current commitment” is testable.

If the team cannot complete the sentence, investigate why the approval exists. It can be a historical response to a failure that another control now handles. It can also be a substitute for a policy that no one has written.

Compare authority and information

An approver needs the authority to accept or reject the consequence. The approver also needs the information required to make that decision. A senior title does not supply missing context. When leaders routinely approve in seconds, the design can be asking them to endorse a decision already made elsewhere.

Move routine checks to the point where the evidence is created. Let the accountable owner approve the decision that remains. Escalate only cases that cross a clear threshold or need different expertise. This keeps senior attention for the cases where it changes the result.

Use thresholds with care

Financial value is a common approval threshold, but it is not the only source of risk. Data sensitivity, legal effect, customer impact, reversibility, and novelty can matter more. A low-cost change to access permissions can need stronger review than an ordinary high-value renewal already covered by a contract.

Create thresholds from the consequence of a wrong decision. Make them easy to explain and test. Avoid a dense grid in which small input differences produce surprising approval paths. When an exception does not fit, route it to a judgment owner and record the reason.

Replace serial review when decisions are independent

Two reviews can be necessary without being sequential. If security and finance assess different evidence, they can often work in parallel. The workflow should wait for both results, then resolve conflicts through a defined owner. Parallel work reduces elapsed time without removing either control.

Do not run reviews in parallel when one result changes the evidence needed by the other. In that case, the sequence is meaningful and should remain visible.

Test what happens when the approver says no

Some approval steps are ceremonial because rejection has no defined effect. The reviewer can click “reject,” but the requester does not know whether to revise, appeal, or stop. Define the result of each decision. State what information returns to the requester and whether the case can re-enter.

Also test absence and delegation. A workflow that depends on one named person is not controlled when that person is away. Delegation should transfer the role, evidence, and decision boundary. It should not allow silent forwarding to anyone available.

Measure decisions, not clicks

Track approval time, rejection rate, return reasons, overrides, and decisions changed by the review. A near-zero rejection rate does not automatically mean the approval is useless; upstream controls can be strong. But a fast click with no changed outcomes deserves review.

The best approval design makes responsibility easier to see. Each reviewer manages a named risk, receives the needed evidence, has authority to act, and produces a result that changes the path. Anything less can be an expensive pause labeled as control.