Platform
Automation & Intelligence

Approval Workflows

Configurable approvals and four-eyes sign-off everywhere

A shared approval engine used across the platform — configurable routing, delegation, four-eyes sign-off and segregation of duties — so decisions are approved by the right roles and every approval is recorded as evidence. Approvals are the moments a firm decides something matters: onboarding a higher-risk customer, closing an alert, publishing a policy, accepting a vendor. When those decisions live in email chains and verbal nods, no one can prove who agreed to what, or that the person who did the work wasn't the person who signed it off. OnyxOne Approval Workflows makes every consequential decision a routed, recorded step, so approval becomes a controlled process the firm can configure once and rely on everywhere.

At a glance

How it works, visually

Where this sits in the platformSchematic
Data sources & inputsCustomers · vendors · transactions · documents · your systems of recordIngestion & screeningOnboarding · sanctions, PEP & adverse-media screening · capture & normalisationRisk, case & monitoring enginesRisk scoringCase & investigationOngoing monitoringControls, evidence & policyControls library · testing · evidence capture · policy mappingReporting & analyticsDashboards · regulatory returns · executive & board reportingIntegrations & audit trailAPIs & connectors · append-only, timestamped audit trailOne layered platform — every layer feeds the next, and every action lands in the audit trail.

The layered platform architecture — this module operates across ingestion, the engines and the audit trail.

The challenge

The problems this module solves

The operational realities that make this hard for compliance and risk teams today.

Approvals happen in email, chat and hallways

A decision that needs sign-off is confirmed by a reply, a thumbs-up or a conversation, with no durable record. When someone later asks who approved it and on what basis, the answer has to be reconstructed from inboxes, and often the evidence simply isn't there.

The wrong people approve the wrong things

Without enforced routing, an approval lands with whoever is available rather than the role that is actually accountable. A decision that policy says needs senior or independent sign-off gets waved through by someone without the authority to give it.

No separation between doing and approving

The analyst who assessed a case also closes it; the person who drafted a policy also publishes it. Where segregation of duties should apply, nothing enforces it, so the four-eyes control the firm claims to operate exists on paper but not in practice.

Approvals stall with no visibility

A request sits in an approver's queue while they are on leave, and everything waiting on it quietly halts. Nobody can see where a decision is stuck, and the first sign of a bottleneck is the work that should have moved but didn't.

Every module reinvents its own approval

Each part of the programme builds its own bespoke sign-off, so routing, delegation and evidence work differently in cases, policies, onboarding and vendors. The firm maintains a dozen inconsistent approval mechanisms and can't govern any of them centrally.

The approach

How OnyxOne addresses it

Every approval is a recorded step

Requests, decisions, comments and outcomes are captured as structured records rather than messages. For any approved decision the firm can show who requested it, who approved it, when and on what basis — evidence produced automatically instead of reconstructed later.

Routing to the accountable role

Approvals are routed by configurable rules to the role that policy makes accountable — by risk tier, value, type or business unit — so a decision reaches the right approver every time rather than whoever happens to be nearby.

Four-eyes and segregation of duties enforced

The engine can require independent sign-off and prevent the person who did the work from approving it, so segregation of duties is enforced by the system rather than trusted to convention. The control the firm describes is the control it actually operates.

Delegation and escalation keep decisions moving

Approvers can delegate within policy while on leave, and requests that sit too long escalate automatically. Work no longer stalls silently in an absent approver's queue, and bottlenecks surface before they hold up the programme.

One engine, used everywhere

A single approval engine serves onboarding, cases, policies, vendors and change alike, so routing, delegation, four-eyes and evidence behave consistently across the platform and can be governed from one place instead of a dozen bespoke mechanisms.

Capabilities

What's in the module

Turn on what you need and add more as your programme scales.

Configurable routing rules

Route approvals by risk tier, value, type, jurisdiction or business unit to the role that policy makes accountable.

Four-eyes sign-off

Require a second, independent approval on decisions where a single sign-off is not enough.

Segregation of duties

Prevent the person who performed an action from approving it, enforcing separation the firm can prove.

Multi-step and parallel approval

Chain sequential approvers or gather parallel sign-offs where a decision needs several roles to agree.

Delegation

Let approvers delegate authority within policy for a defined period, with the delegation itself recorded.

Automatic escalation

Escalate requests that exceed a target time to a nominated role so decisions do not stall unseen.

Conditional thresholds

Trigger heavier approval — more approvers or a more senior role — only when a request crosses a defined threshold.

Decision rationale capture

Record the reasoning behind an approve, reject or return-for-more-information decision as durable evidence.

Reusable approval templates

Define an approval flow once and reuse it wherever the same decision type occurs across the platform.

Immutable approval trail

Write every request, routing, decision and delegation to an append-only audit record.

Dashboards

The views your team works from

Purpose-built dashboards and views, each answering a question a specific role needs to act on.

An executive viewIllustrative
ILLUSTRATIVE EXAMPLEOPEN CASES128SLA ADHERENCE96%SCREENING ALERTS1.2kOVERDUE REVIEWS14Cases by categoryAMLKYCFraudSanctionsConductOtherRisk mixby tierHighMediumLow

A representative layout of the KPI tiles and charts these dashboards present. Figures shown are illustrative examples, not real data.

Approval queue

Every pending request by decision type and approver, with ageing so nothing sits unseen.

My approvals

A focused view for each approver of the requests awaiting their decision and those they have delegated.

Bottleneck view

Where approvals are stalling across the platform, highlighting queues and roles that are holding work up.

Four-eyes & SoD monitor

Confirmation that segregation-of-duties and four-eyes rules are being applied, flagging any exceptions for review.

Approval evidence view

The end-to-end record for any decision — request, routing, approvals and rationale — assembled as audit-ready evidence.

Automation

What the platform automates

Rules, workflows, alerts and scheduling that run the routine so your team works the exceptions.

Rule-based routing

Requests are routed automatically to the accountable role by configurable rules, without manual assignment.

Delegation handling

When a primary approver has delegated, requests route to the delegate for the delegation's defined period automatically.

Escalation on delay

A request exceeding its target time escalates to a nominated role automatically so the decision keeps moving.

Threshold-triggered approval

Crossing a defined threshold automatically invokes heavier approval — more approvers or a more senior role.

Reminder scheduling

Approvers are reminded of pending requests on a schedule before they fall overdue.

AI assistance

Where AI helps the analyst

Assistive, decision-support features that speed up the work on the record. Suggestions are always reviewable, and a person stays in control of every decision.

Request summarisation

Drafts a concise summary of what an approver is being asked to decide from the underlying record, for the approver to read and verify before deciding.

Routing suggestion

Suggests the appropriate approval route for a novel request based on similar past ones, which a person confirms — it never overrides the configured rules.

Bottleneck highlighting

Points out where approvals are backing up so the function can rebalance, without taking any action on approvals itself.

The workflow

The enterprise workflow

A defined, end-to-end process with clear ownership at every stage.

The workflow, step by stepSchematic
01Define the flowAn approval flow is configured for a decision type — its steps, the accountableroles, thresholds and any four-eyes or segregation rules.02Raise a requestA decision that needs sign-off is submitted into the flow, from any module, with thecontext the approver needs to judge it.03Route to the approverThe engine routes the request by rule to the accountable role, applying delegationwhere the primary approver is unavailable.04Decide with rationaleThe approver approves, rejects or returns the request for more information,recording the reasoning behind the decision.05Escalate if stalledA request that exceeds its target time escalates automatically so the decision movesrather than sitting unseen in a queue.06Record & releaseThe outcome is written to the audit trail and the originating work proceeds, blockeduntil the required approvals are in place.

Every result, decision and override is captured against the record it belongs to.

01

Define the flow

An approval flow is configured for a decision type — its steps, the accountable roles, thresholds and any four-eyes or segregation rules.

02

Raise a request

A decision that needs sign-off is submitted into the flow, from any module, with the context the approver needs to judge it.

03

Route to the approver

The engine routes the request by rule to the accountable role, applying delegation where the primary approver is unavailable.

04

Decide with rationale

The approver approves, rejects or returns the request for more information, recording the reasoning behind the decision.

05

Escalate if stalled

A request that exceeds its target time escalates automatically so the decision moves rather than sitting unseen in a queue.

06

Record & release

The outcome is written to the audit trail and the originating work proceeds, blocked until the required approvals are in place.

The value

What your team gains

Evidenced

Every approval provable

Structured records of who approved what, when and why mean sign-off is evidence produced automatically, not a reconstruction from email chains.

Accountable

The right role signs off

Rule-based routing sends each decision to the role policy makes accountable, so authority matches the decision rather than availability.

Enforced

Four-eyes that actually holds

Segregation of duties enforced by the engine means the four-eyes control the firm describes is the control it genuinely operates.

Moving

Decisions that don't stall

Delegation and automatic escalation keep approvals flowing, so work no longer halts silently in an absent approver's queue.

One consistent engine

A single approval engine across onboarding, cases, policies and vendors replaces a dozen bespoke mechanisms with one the firm can govern centrally.

Audit-ready by default

Because approvals are recorded as they happen, demonstrating controlled decision-making to an auditor is a report, not a scramble.

Built for

Industries it serves

BankingFinancial ServicesFintechInsuranceInvestment FirmsAsset ManagementLendingCorporate & Trust Service ProvidersRegulated Enterprises
Integrations

Works with your existing systems

Described as capabilities — OnyxOne connects to the systems your deployment requires, configured per implementation.

Platform modules
  • Provides the shared approval step for onboarding, cases, policies, vendors and regulatory change across the platform
Identity & directory
  • Draws roles and reporting lines from your existing identity and directory services so routing reflects real accountability
Collaboration & notification
  • Delivers approval requests, reminders and escalations through your existing email and messaging channels
Governance
  • Applies the delegation and segregation-of-duties model defined in governance so authority stays consistent
Audit & reporting
  • Feeds the approval trail into audit and reporting so sign-off evidence sits alongside the rest of the programme record
Assurance

Security, compliance & reporting

Security & data handling

  • Approval requests, decisions and rationale are encrypted in transit and at rest, with access governed by role-based permissions.
  • Segregation of duties is enforced by the engine, preventing the same person from performing and approving an action where policy requires separation.
  • Delegated authority is time-bound, scoped and recorded, so a delegation cannot silently outlive its purpose.
  • Approvers see only the requests and context they are entitled to under need-to-know restrictions.
  • Every request, routing decision, approval, rejection and delegation is written to an append-only audit trail.
  • Retention of approval records is configurable to your regulatory and evidential obligations.

Compliance support

  • Supports four-eyes and segregation-of-duties expectations across governance and compliance processes
  • Provides the recorded sign-off evidence supervisors and auditors expect for consequential decisions
  • Underpins delegation-of-authority and approval-hierarchy requirements in a control framework
  • Evidences that decisions were approved by roles with the appropriate authority
  • Supplies a dated, end-to-end audit trail of how each decision was approved

Reports & exports

  • Approval-status reports by decision type, queue and approver
  • Pending and overdue approval reports with ageing
  • Segregation-of-duties and four-eyes compliance reports
  • Delegation and escalation activity reports
  • Decision-outcome reports with approve, reject and return rates
  • Approval audit-trail and evidence packs per decision
Best practice

How to get the most from it

Route to accountability, not availability

Configure routing around the role policy makes accountable for each decision. An approval that lands with whoever is free undermines the whole point of requiring one.

Enforce four-eyes in the engine

Where a decision needs independent sign-off, let the system prevent self-approval rather than trusting people to remember. A four-eyes control that relies on convention is not a control.

Set escalation before things stall

Give every approval a target time and an escalation path. Requests without one sit in queues until someone chases, and the programme waits on them.

Reuse flows, don't rebuild them

Define an approval flow once and reuse it across modules. Bespoke sign-off in every corner of the platform is impossible to govern and inconsistent by design.

FAQ

Questions, answered

How are approvals routed to the right person?

Configurable rules route each request by risk tier, value, type, jurisdiction or business unit to the role policy makes accountable, drawing on your identity and directory services so routing reflects real reporting lines. A decision reaches the right approver rather than whoever happens to be available.

Can you enforce four-eyes and segregation of duties?

Yes. The engine can require a second, independent approval and prevent the person who performed an action from approving it, so segregation of duties is enforced by the system rather than trusted to convention. The four-eyes control the firm describes is the one it actually operates.

What happens when an approver is on leave?

Approvers can delegate their authority within policy for a defined period, with the delegation recorded, and any request that exceeds its target time escalates automatically. Work no longer stalls silently in an absent approver's queue.

Is this one engine or a separate one per module?

One. A single approval engine serves onboarding, cases, policies, vendors and regulatory change alike, so routing, delegation, four-eyes and evidence behave consistently everywhere and can be governed centrally instead of as a dozen bespoke mechanisms.

What evidence does an approval leave behind?

Every request, routing decision, approval, rejection, return and delegation is written to an append-only audit trail, including the rationale the approver recorded. For any approved decision the firm can show who approved it, when and on what basis without reconstructing it from email.

See Approval Workflows in your programme

Book a walkthrough and we'll show how this module fits your policy, workflows and obligations — then scope an implementation.