Thread Transfer
Purchase Order Approval Thresholds: Setting Limits That Do Not Strangle Ops
Requiring an approval for a $40 purchase spends 72% of the purchase price to control it. Build the ladder from your distribution, add the three override rules, and watch for splitting — the clearest sign your threshold is wrong.
Thread Transfer
Operations Systems for SMBs
There are two ways to lose money on purchasing, and most businesses are convinced they are only exposed to one of them. The obvious risk is spend without oversight: someone orders something nobody authorised, at a price nobody negotiated, from a supplier nobody vetted. The less obvious and usually larger risk is oversight without proportion — an approval process so heavy that a $60 consumable waits three days for a signature while a production line idles.
Approval thresholds are the control that balances those two failures. Set them badly and you get both at once: trivial purchases queued behind busy people, and genuinely significant commitments waved through because everyone is exhausted from approving staplers.
The Real Cost of an Approval
Before setting a threshold you have to price the control itself. Every approval consumes: the requester's time raising it, the approver's time reviewing it, the delay cost while work waits, and the switching cost of interrupting the approver's actual job.
A conservative estimate for a small business, per approval event:
| Component | Time | Cost at loaded rates |
|---|---|---|
| Requester raises request | 6 min | $5 |
| Approver reviews and decides | 4 min | $6 |
| Context switch penalty | ~10 min | $14 |
| Chasing (occurs ~30% of the time) | 5 min avg | $4 |
| Total per approval | ~$29 |
That figure alone settles the design question. If an approval costs about $29 to perform, requiring one for a $40 purchase is straightforwardly value-destroying — you are spending 72% of the purchase price to control it, and the maximum recoverable loss is smaller than the control cost. Any threshold below roughly $150 fails a basic cost-benefit test unless the category itself carries risk beyond its price.
The Four Thresholds Most SMBs Need
A ladder with four rungs handles the overwhelming majority of small-business purchasing without becoming a bureaucracy.
| Band | Approver | Target turnaround | Control mechanism |
|---|---|---|---|
| Under $500 | None — auto-approved | Instant | Post-hoc review, budget-capped |
| $500 - $5,000 | Department manager | Same day | Budget check plus single approval |
| $5,000 - $25,000 | Finance | 2 business days | Quote comparison required |
| Above $25,000 | Owner or director | 5 business days | Full business case |
Adjust the numbers for your revenue — a useful anchor is setting the bottom band at roughly 0.01% of annual revenue and the top at 0.5%. The structure matters more than the specific figures.
The auto-approve band is the important one
Most businesses resist the bottom band hardest, and it delivers the most value. Auto-approval is not the absence of control. It is control moved from prevention to detection: a spend cap per requester per month, a restricted supplier list, and a weekly report of everything auto-approved. You catch the same problems, days later, at a fraction of the cost — and nothing waits.
Why Value-Only Thresholds Are Not Enough
Value is a proxy for risk, and an imperfect one. Three categories need routing rules independent of amount.
Recurring commitments
A $200/month subscription is a $7,200 three-year commitment. Judged on the monthly figure it clears the bottom band and gets auto-approved forever. Rule: evaluate any recurring purchase at 24 months of total value.
New suppliers
A first purchase from an unknown supplier carries risks price does not capture — payment fraud, data handling, insurance, dependency. Rule: first order from any new supplier requires approval regardless of value, once. Subsequent orders follow the value ladder.
Restricted categories
Anything touching customer data, requiring an integration, or creating a compliance obligation is a different kind of decision. A $19/month tool that ingests your customer list is a higher-risk purchase than a $4,000 pallet racking order. Rule: category override, always approved by a named person, regardless of value.
How Approval Systems Actually Fail
Nearly every broken purchasing process in a small business fails in one of five identical ways.
1. The single approver bottleneck
One person approves everything. They go on holiday. Purchasing stops, or everyone routes around them and the control becomes fiction. Every rung needs a named delegate and an automatic escalation after a defined period.
2. Approval by email
Email has no state. There is no queue, no ageing, no audit trail that survives a mailbox cleanup, and no way to answer "what is waiting on me right now." Every email-based approval process eventually becomes a chasing process, and chasing is pure waste.
3. Thresholds that never move
The $1,000 threshold set when the business turned over $800K is absurd at $6M. Unreviewed thresholds convert a sensible control into a tax on growth. Review annually against revenue.
4. No budget context at the decision point
An approver looking at a request for $3,000 of packaging cannot decide well without knowing that $2,700 of a $3,000 monthly packaging budget is already committed. Without that context the approval is a rubber stamp with extra steps.
5. Splitting
Where thresholds are painful, humans route around them. A $9,000 purchase becomes three $3,000 purchases. This is the most reliable diagnostic signal available: if you see clusters of requests just below a threshold from the same requester in the same week, your threshold is set too low and your people are telling you so.
That splitting pattern is worth actively monitoring, and it is trivial to detect automatically — which is one reason approval workflows belong in a system rather than in an inbox. OpsMavix builds this as a standard component of an invoice and purchase approval workflow: a mobile-approvable queue, rules by value and category, delegate and escalation logic, live budget context on the request, and a complete audit trail.
Designing Your Ladder in an Afternoon
- Export twelve months of purchases. Every line, with amount, category, supplier, and requester.
- Plot the distribution by value. Almost universally you will find 60-75% of transactions sit under $500 and account for under 8% of spend. That is your auto-approve band, revealed by data rather than nerves.
- Find where the money actually is. Typically 5-10% of transactions carry 70%+ of spend. That is where scrutiny belongs, and where most businesses spend the least attention because those purchases feel routine to the person making them.
- Set four bands so that roughly 70% of transactions auto-approve, 20% get one approval, 8% get finance, and 2% reach the owner.
- Write the three override rules — recurring, new supplier, restricted category.
- Define delegates and escalation timers for every rung. No rung without a named backup.
- Set the review date twelve months out, in the calendar, now.
What to Measure Afterwards
An approval process is a system with a service level, and it should be reported like one.
| Metric | Healthy range | What a bad number means |
|---|---|---|
| Median time to approval | Under 8 working hours | Wrong approver, or no mobile path |
| Auto-approved share of transactions | 60-75% | Bottom threshold set too low |
| Rejection rate | 3-8% | Below 3% means the control is theatre |
| Requests just under a threshold | Flat distribution | Clustering means splitting is happening |
| Approvals sitting over 48h | Under 5% | Escalation is not firing |
The rejection-rate row deserves emphasis. A process that rejects nothing is not preventing bad purchases; it is documenting them slowly. If your rejection rate is near zero, either your thresholds are too high to catch anything, or your approvers are approving without reading — and both are worth knowing.
The Principle Underneath
Approval thresholds are not about trust. Framing them that way guarantees a bad design, because the resulting rules get set by how much you like people rather than by exposure. They are about matching the cost of a control to the size of the risk it manages.
A well-designed ladder makes small purchases frictionless, medium purchases fast and accountable, and large purchases genuinely deliberate. Badly designed, it inverts: small purchases become slow and infuriating, and large ones sail through because everyone is numb.
If purchasing in your business currently runs on email chains and remembering, that is not a discipline problem to be solved with a policy document. It is a missing system. Mapping it is part of what the Operations Leak Audit at opsmavix.com covers — 90 minutes, written findings, and a clear view of whether your controls are protecting margin or quietly consuming it.
Learn more: How it works · Why bundles beat raw thread history