Approval Workflows
Configurable approvals and four-eyes sign-off everywhere
A shared approval engine used across the platform — configurable routing, delegation, four-eyes sign-off and segregation of duties — so decisions are approved by the right roles and every approval is recorded as evidence. Approvals are the moments a firm decides something matters: onboarding a higher-risk customer, closing an alert, publishing a policy, accepting a vendor. When those decisions live in email chains and verbal nods, no one can prove who agreed to what, or that the person who did the work wasn't the person who signed it off. OnyxOne Approval Workflows makes every consequential decision a routed, recorded step, so approval becomes a controlled process the firm can configure once and rely on everywhere.
How it works, visually
The layered platform architecture — this module operates across ingestion, the engines and the audit trail.
The problems this module solves
The operational realities that make this hard for compliance and risk teams today.
Approvals happen in email, chat and hallways
A decision that needs sign-off is confirmed by a reply, a thumbs-up or a conversation, with no durable record. When someone later asks who approved it and on what basis, the answer has to be reconstructed from inboxes, and often the evidence simply isn't there.
The wrong people approve the wrong things
Without enforced routing, an approval lands with whoever is available rather than the role that is actually accountable. A decision that policy says needs senior or independent sign-off gets waved through by someone without the authority to give it.
No separation between doing and approving
The analyst who assessed a case also closes it; the person who drafted a policy also publishes it. Where segregation of duties should apply, nothing enforces it, so the four-eyes control the firm claims to operate exists on paper but not in practice.
Approvals stall with no visibility
A request sits in an approver's queue while they are on leave, and everything waiting on it quietly halts. Nobody can see where a decision is stuck, and the first sign of a bottleneck is the work that should have moved but didn't.
Every module reinvents its own approval
Each part of the programme builds its own bespoke sign-off, so routing, delegation and evidence work differently in cases, policies, onboarding and vendors. The firm maintains a dozen inconsistent approval mechanisms and can't govern any of them centrally.
How OnyxOne addresses it
Every approval is a recorded step
Requests, decisions, comments and outcomes are captured as structured records rather than messages. For any approved decision the firm can show who requested it, who approved it, when and on what basis — evidence produced automatically instead of reconstructed later.
Routing to the accountable role
Approvals are routed by configurable rules to the role that policy makes accountable — by risk tier, value, type or business unit — so a decision reaches the right approver every time rather than whoever happens to be nearby.
Four-eyes and segregation of duties enforced
The engine can require independent sign-off and prevent the person who did the work from approving it, so segregation of duties is enforced by the system rather than trusted to convention. The control the firm describes is the control it actually operates.
Delegation and escalation keep decisions moving
Approvers can delegate within policy while on leave, and requests that sit too long escalate automatically. Work no longer stalls silently in an absent approver's queue, and bottlenecks surface before they hold up the programme.
One engine, used everywhere
A single approval engine serves onboarding, cases, policies, vendors and change alike, so routing, delegation, four-eyes and evidence behave consistently across the platform and can be governed from one place instead of a dozen bespoke mechanisms.
What's in the module
Turn on what you need and add more as your programme scales.
Configurable routing rules
Route approvals by risk tier, value, type, jurisdiction or business unit to the role that policy makes accountable.
Four-eyes sign-off
Require a second, independent approval on decisions where a single sign-off is not enough.
Segregation of duties
Prevent the person who performed an action from approving it, enforcing separation the firm can prove.
Multi-step and parallel approval
Chain sequential approvers or gather parallel sign-offs where a decision needs several roles to agree.
Delegation
Let approvers delegate authority within policy for a defined period, with the delegation itself recorded.
Automatic escalation
Escalate requests that exceed a target time to a nominated role so decisions do not stall unseen.
Conditional thresholds
Trigger heavier approval — more approvers or a more senior role — only when a request crosses a defined threshold.
Decision rationale capture
Record the reasoning behind an approve, reject or return-for-more-information decision as durable evidence.
Reusable approval templates
Define an approval flow once and reuse it wherever the same decision type occurs across the platform.
Immutable approval trail
Write every request, routing, decision and delegation to an append-only audit record.
The views your team works from
Purpose-built dashboards and views, each answering a question a specific role needs to act on.
A representative layout of the KPI tiles and charts these dashboards present. Figures shown are illustrative examples, not real data.
Approval queue
Every pending request by decision type and approver, with ageing so nothing sits unseen.
My approvals
A focused view for each approver of the requests awaiting their decision and those they have delegated.
Bottleneck view
Where approvals are stalling across the platform, highlighting queues and roles that are holding work up.
Four-eyes & SoD monitor
Confirmation that segregation-of-duties and four-eyes rules are being applied, flagging any exceptions for review.
Approval evidence view
The end-to-end record for any decision — request, routing, approvals and rationale — assembled as audit-ready evidence.
What the platform automates
Rules, workflows, alerts and scheduling that run the routine so your team works the exceptions.
Rule-based routing
Requests are routed automatically to the accountable role by configurable rules, without manual assignment.
Delegation handling
When a primary approver has delegated, requests route to the delegate for the delegation's defined period automatically.
Escalation on delay
A request exceeding its target time escalates to a nominated role automatically so the decision keeps moving.
Threshold-triggered approval
Crossing a defined threshold automatically invokes heavier approval — more approvers or a more senior role.
Reminder scheduling
Approvers are reminded of pending requests on a schedule before they fall overdue.
Where AI helps the analyst
Assistive, decision-support features that speed up the work on the record. Suggestions are always reviewable, and a person stays in control of every decision.
Request summarisation
Drafts a concise summary of what an approver is being asked to decide from the underlying record, for the approver to read and verify before deciding.
Routing suggestion
Suggests the appropriate approval route for a novel request based on similar past ones, which a person confirms — it never overrides the configured rules.
Bottleneck highlighting
Points out where approvals are backing up so the function can rebalance, without taking any action on approvals itself.
The enterprise workflow
A defined, end-to-end process with clear ownership at every stage.
Every result, decision and override is captured against the record it belongs to.
Define the flow
An approval flow is configured for a decision type — its steps, the accountable roles, thresholds and any four-eyes or segregation rules.
Raise a request
A decision that needs sign-off is submitted into the flow, from any module, with the context the approver needs to judge it.
Route to the approver
The engine routes the request by rule to the accountable role, applying delegation where the primary approver is unavailable.
Decide with rationale
The approver approves, rejects or returns the request for more information, recording the reasoning behind the decision.
Escalate if stalled
A request that exceeds its target time escalates automatically so the decision moves rather than sitting unseen in a queue.
Record & release
The outcome is written to the audit trail and the originating work proceeds, blocked until the required approvals are in place.
What your team gains
Every approval provable
Structured records of who approved what, when and why mean sign-off is evidence produced automatically, not a reconstruction from email chains.
The right role signs off
Rule-based routing sends each decision to the role policy makes accountable, so authority matches the decision rather than availability.
Four-eyes that actually holds
Segregation of duties enforced by the engine means the four-eyes control the firm describes is the control it genuinely operates.
Decisions that don't stall
Delegation and automatic escalation keep approvals flowing, so work no longer halts silently in an absent approver's queue.
One consistent engine
A single approval engine across onboarding, cases, policies and vendors replaces a dozen bespoke mechanisms with one the firm can govern centrally.
Audit-ready by default
Because approvals are recorded as they happen, demonstrating controlled decision-making to an auditor is a report, not a scramble.
Industries it serves
Works with your existing systems
Described as capabilities — OnyxOne connects to the systems your deployment requires, configured per implementation.
- Provides the shared approval step for onboarding, cases, policies, vendors and regulatory change across the platform
- Draws roles and reporting lines from your existing identity and directory services so routing reflects real accountability
- Delivers approval requests, reminders and escalations through your existing email and messaging channels
- Applies the delegation and segregation-of-duties model defined in governance so authority stays consistent
- Feeds the approval trail into audit and reporting so sign-off evidence sits alongside the rest of the programme record
Security, compliance & reporting
Security & data handling
- Approval requests, decisions and rationale are encrypted in transit and at rest, with access governed by role-based permissions.
- Segregation of duties is enforced by the engine, preventing the same person from performing and approving an action where policy requires separation.
- Delegated authority is time-bound, scoped and recorded, so a delegation cannot silently outlive its purpose.
- Approvers see only the requests and context they are entitled to under need-to-know restrictions.
- Every request, routing decision, approval, rejection and delegation is written to an append-only audit trail.
- Retention of approval records is configurable to your regulatory and evidential obligations.
Compliance support
- Supports four-eyes and segregation-of-duties expectations across governance and compliance processes
- Provides the recorded sign-off evidence supervisors and auditors expect for consequential decisions
- Underpins delegation-of-authority and approval-hierarchy requirements in a control framework
- Evidences that decisions were approved by roles with the appropriate authority
- Supplies a dated, end-to-end audit trail of how each decision was approved
Reports & exports
- Approval-status reports by decision type, queue and approver
- Pending and overdue approval reports with ageing
- Segregation-of-duties and four-eyes compliance reports
- Delegation and escalation activity reports
- Decision-outcome reports with approve, reject and return rates
- Approval audit-trail and evidence packs per decision
How to get the most from it
Route to accountability, not availability
Configure routing around the role policy makes accountable for each decision. An approval that lands with whoever is free undermines the whole point of requiring one.
Enforce four-eyes in the engine
Where a decision needs independent sign-off, let the system prevent self-approval rather than trusting people to remember. A four-eyes control that relies on convention is not a control.
Set escalation before things stall
Give every approval a target time and an escalation path. Requests without one sit in queues until someone chases, and the programme waits on them.
Reuse flows, don't rebuild them
Define an approval flow once and reuse it across modules. Bespoke sign-off in every corner of the platform is impossible to govern and inconsistent by design.
Questions, answered
How are approvals routed to the right person?
Configurable rules route each request by risk tier, value, type, jurisdiction or business unit to the role policy makes accountable, drawing on your identity and directory services so routing reflects real reporting lines. A decision reaches the right approver rather than whoever happens to be available.
Can you enforce four-eyes and segregation of duties?
Yes. The engine can require a second, independent approval and prevent the person who performed an action from approving it, so segregation of duties is enforced by the system rather than trusted to convention. The four-eyes control the firm describes is the one it actually operates.
What happens when an approver is on leave?
Approvers can delegate their authority within policy for a defined period, with the delegation recorded, and any request that exceeds its target time escalates automatically. Work no longer stalls silently in an absent approver's queue.
Is this one engine or a separate one per module?
One. A single approval engine serves onboarding, cases, policies, vendors and regulatory change alike, so routing, delegation, four-eyes and evidence behave consistently everywhere and can be governed centrally instead of as a dozen bespoke mechanisms.
What evidence does an approval leave behind?
Every request, routing decision, approval, rejection, return and delegation is written to an append-only audit trail, including the rationale the approver recorded. For any approved decision the firm can show who approved it, when and on what basis without reconstructing it from email.
Related modules
See Approval Workflows in your programme
Book a walkthrough and we'll show how this module fits your policy, workflows and obligations — then scope an implementation.