1

Start from a preset, then set your tiers

Company size:
Currency:
2

Who approves what — click any cell to change it

← Swipe the table to see every tier →

Approvers sign in the order shown, left to right. Auto means no human: the invoice matched its purchase order within tolerance and is released without a second opinion.

3

Rules a spreadsheet can't enforce

4

Route a document through it

    5

    Take it with you

    The JSON is the same matrix in a shape an AI agent can route against — tiers, chains, and rules, with no prose to interpret. The share link carries thresholds and roles only.

    How this works. Presets are starting points drawn from published delegation-of-authority schedules and common practice for companies of that size, not a recommendation for yours — the right thresholds are the ones where each approver still reads what they sign. Routing applies the rules in a fixed order: contract value over the term, then split-purchase aggregation, then the tier, then new-vendor, the AI agent limit, and segregation of duties. Nothing you enter leaves the browser; analytics counts the visit and which preset you started from.

    Built and maintained by Alec Zakhary.

    What an approval matrix is

    An approval matrix is a table that answers one question for every document that costs money: who has to say yes before this is paid or signed? Rows are document or transaction types — invoices, purchase requests, contracts. Columns are amount tiers. Each cell names the approvers, in order. A delegation of authority (DoA) matrix is the same idea written as policy: which roles the board has authorised to commit the company, up to what amount. The DoA is the law; the approval matrix is how it runs day to day. Almost every company past a few dozen people has one — nearly 90% of the companies EY and the Society for Corporate Governance surveyed have a DoA policy. The weak spot is not having one. It is enforcing it and keeping it current.

    How to set the thresholds

    There is no standard, but public institutions publish theirs, and they cluster. Two real examples:

    OrganisationTiers
    Oregon State University, purchasingDepartment up to $5,000 · business centre $5,000.01–$25,000 · central procurement above $25,000
    William & Mary, contract signatureProcurement specialist up to $50,000 · director of sourcing up to $250,000 · AVP supply chain up to $500,000

    Our three presets follow the same logic at different scales: the first tier is what a budget owner can sign without anyone noticing it's gone, the last tier is where the money is large enough that two senior people should both read it. Three tests for your own numbers:

    1. Count the volume per tier. Export twelve months of bills and bucket them. If 80% of invoices land in the top two tiers, your thresholds are too low and your CFO is rubber-stamping. Approvers who see more than a few dozen items a week stop reading them.
    2. Check who actually signs today. The matrix should describe reality plus one fix, not an ideal nobody follows. A matrix people route around is worse than none: it creates the paper trail of control without the control.
    3. Set the agent or auto tier last. Whatever you let through without a person — PO-matched invoices, or an AI agent — should sit entirely inside your lowest human tier.

    The five rules a spreadsheet can't enforce

    Every template that ranks for this search is a grid you fill in. The grid is the easy part. What makes a matrix hold is a handful of rules that operate across cells, and a spreadsheet can state them but never apply them:

    RuleWhat goes wrong without it
    Segregation of dutiesThe person who requests a purchase approves it. UCLA's control guidance puts it plainly: the requester should not be the approver, and at least two people should see every transaction. The first test in any audit.
    Split-purchase aggregationA 40,000 purchase becomes two 20,000 orders that never reach the next tier. US federal rules forbid it outright (FAR 13.003(c)(2)), and state auditors flag it as bid splitting. The fix is to evaluate spend per vendor per period, not per document.
    Total contract valueA three-year SaaS deal at 30,000 a year is approved as a 30,000 decision when it is a 90,000 commitment — and usually auto-renews into a fourth year.
    New-vendor reviewThe first invoice from an unknown payee, or from a known vendor with new bank details, is where payment fraud lands. It needs finance eyes regardless of the amount.
    Renewal ownershipApproval is the last time anyone reads the renewal clause. If nobody is named as owner and the notice deadline isn't recorded then, the contract renews by default.

    Two more that belong in the written policy even though no tool can check them: a backup approver for every role (approvers go on leave, and some leave the company while still on the chain), and an escalation deadline — what happens to an item nobody has touched in five working days.

    How accounting tools implement approvals

    Once you have the matrix, you will enter it somewhere. What the common tools can hold, as of September 2026:

    ToolAmount tiersMulti-stepNotes
    QuickBooks OnlineYesYesBill approval workflows with conditions on amount and vendor — on the Advanced tier and Bill Pay add-ons, not every plan.
    XeroNo (built in)No (built in)Approval is a single step governed by user role; amount-based, multi-level routing comes from add-ons such as ApprovalMax.
    NetSuiteYesYesPer-employee approval limits; a bill climbs the supervisor chain until it reaches someone whose limit covers it.
    BILLYesYesApproval policies with ordered approvers; changing a policy doesn't re-route bills already in flight.
    RampYesYesMulti-step chains with conditions by amount and department, and a separate payment-release step that keeps approving a bill and paying it in different hands.
    CoupaYesYesApproval chains layered on the management hierarchy; PO-backed invoices can skip approval unless they break tolerance.

    Notice what none of them do on their own: add up split purchases across documents, or tier a contract by its full term. Those rules live in people's heads — which is why they are the ones that fail.

    When an AI agent sits on the matrix

    The question most teams are now asking is whether an agent can approve invoices. The honest answer: it can approve the ones your matrix already releases without a human — and it can do the checking for everyone else. That is why the tool above treats the agent as a limit inside the auto tier, not as a new approver. An agent on the matrix should:

    1. approve only PO-matched invoices, from a known vendor, within a stated tolerance, for a period not billed before — and only below a limit that sits inside the tier where no person signs today;
    2. route everything else to the approver this matrix names, with its reasoning attached: which checks passed, which failed, what it could not resolve;
    3. never be the only control on a new vendor or changed bank details, whatever the amount.

    That is also why the export has a JSON option. An agent can't follow a PDF policy reliably; it can follow tiers, chains, and rules expressed as data, and cite the rule it applied. The request_approval call in the example is one of the seven tools in the reference toolset a document system should expose to agents. Firms like PwC recommend keeping a human at the helm for consequential decisions — the matrix is where you write down which decisions those are.

    Frequently asked questions

    What is an approval matrix?

    A table that says who must approve each type of spending document at each amount — for example, invoices up to 5,000 approved by the budget owner, 5,001–25,000 by the department head, and above 100,000 by the department head and the CFO. It turns a delegation-of-authority policy into routing rules people and software can follow.

    What is the difference between an approval matrix and a delegation of authority?

    A delegation of authority is the governance document: the board authorises roles to commit the company up to set limits. The approval matrix is the operational version of it: which documents route to which approvers, in what order, at which amounts. The DoA says the CFO may sign up to 500,000; the matrix says which invoices actually go to the CFO.

    What invoice approval thresholds should a small business use?

    A common starting point for a company under 50 people: the budget owner approves up to about 1,000, adds a finance check up to 10,000, the founder or CEO signs up to 50,000, and anything larger needs two signatures. Then check it against a year of bills — if most invoices land in the top tiers, the limits are too low and approvals become rubber stamps.

    Can the person who requests a purchase also approve it?

    No. Segregation of duties means the requester, the approver, and the person who pays should be different people wherever the team is large enough. When a requester would otherwise be on their own approval chain, the step goes to the next person up — which is what the generator does when you set "Requested by".

    How do you stop people splitting purchases to stay under a threshold?

    Evaluate spend per vendor over a rolling window — 30 days is typical — rather than per document, and pick the tier from the total. Spreadsheets and most approval tools can't do this on their own; it needs whatever routes the approval to look up recent spend with the same vendor.

    Can AI approve invoices automatically?

    Yes, within limits you set: PO-matched invoices from known vendors, within a small tolerance of the PO, for a period not already billed, and below an amount that your matrix already lets through without a person. Everything outside those limits should go to the named approver with the agent's reasoning attached. A new vendor or changed bank details should always reach a human.

    How do I make an approval matrix in Excel?

    Build it here, then use Download CSV — it opens directly in Excel with one row per document type and tier, plus the rules underneath. For Google Sheets, use Copy for Google Sheets and paste into cell A1. Keep in mind that a spreadsheet records the matrix but can't enforce it: split purchases and self-approval have to be checked by whoever routes the document.

    A matrix on paper is a suggestion. In the inbox it's a rule.

    This page builds the matrix. The real version reads every invoice and contract that lands in your invoices@ or contracts@ mailbox, works out the amount, the vendor, and whether a PO exists, and sends it to the right approver on this matrix — with split purchases added up, the requester taken off their own approval, and the renewal deadline already on someone's calendar.

    Private beta, rolling invites. We'll email you about access — this tool stays free either way, and we won't send you anything else.

    What an agent extracts from an invoice Duplicate invoice payments