Skip to main content
DoneThat

AI Adoption GuideProcurementApprove

Risk-based approval routing

Agentic AI scores request risk by value, supplier novelty, and policy gaps, then routes to the correct approver tier while skipping unnecessary layers, using tools like Zip or Tonkean.

Procurement processRequestApproveSourceEvaluateSelectOrderReceiveReview

By Don, DoneThat’s AI coach · updated

Skip courtesy layers, never skip the matrix row

The job is to shorten the path to the person the delegation-of-authority matrix already names, and to add reviewers when value, supplier novelty, or policy gaps make the request worth extra eyes. It is not a license to drop that named delegate.

Courtesy layers are the manager, skip-level, and FYI stops copied from last year's org chart. Skip them when they are not on the matrix row for this amount, entity, and category.

The named DoA delegate stays. A low score cannot substitute a cheaper path. A high score cannot replace the delegate with a faster person in the same cost center. DoA compliance enforcement still joins the clicker to the live matrix. Routing chooses the path. The matrix still owns who may bind the company.

This is not low-risk auto-approval. That path skips a human because policy already says so. This path still needs humans. It stops asking humans who are not on the row.

This is not approver delay prediction. Delay prediction watches whether people already on the path will answer in time. Routing decides who belongs on the path.

Zip, Tonkean, Coupa, and SAP Ariba are a class of places the path can run. They are not the control. The control is the published score plus the live matrix row.

Score value, supplier novelty, and policy gaps

Build the score from three inputs you can name. Do not hide a fourth model-confidence factor nobody can replay.

Value. Use the amount DoA is written against, usually the requisition or PO total with the tax treatment your policy names. Band it against the matrix cuts you already publish. Value alone is not risk. A catalog laptop and a new-supplier services SOW at the same amount are not the same request.

Supplier novelty. Preferred or catalog with an active record is low. Paid by this legal entity in the last year is medium. First-time, no vendor master, or an incomplete record is high. Novelty is a join to vendor master and payment history, not a guess.

Policy gaps. Missing artifacts and open exceptions that policy pre-check at intake would have blocked if they were hard rules: no contract, no certificate of insurance, category mismatch, off-catalog when a catalog item exists, exception requested. A pre-check pass is not a zero on this axis. Intake can confirm the supplier list and the threshold. It cannot erase an exception filed after the form went green.

High on any one axis adds a reviewer. High on two or more adds the category or risk reviewer and keeps every DoA row the amount requires. Do not let a blended medium hide a new supplier. Do not let a low value hide a policy exception.

The output is this request, the three factors in plain language, who stays, who drops, and who is added. If you cannot name why a layer was skipped, do not skip it.

Illustrative example: a new-supplier HVAC repair

This is a worked example with made-up names, not a case study with results.

Calder Packaging raises a $47,500 emergency HVAC repair for the west warehouse. Riverton Mechanical has no vendor master in this legal entity and no contract. Marco, the site manager, sits on every facilities PR because the workflow copied his node. The named DoA delegate for maintenance opex at this amount is Aisha, VP Operations. The default path is requester manager, Marco, facilities director, then Aisha.

Value sits inside Aisha's row. Novelty is high: first-time payee, no master. Policy gaps are high: no contract, insurance certificate missing.

Drop the requester manager and Marco. They are courtesy, not on the matrix row. Keep Aisha. Add the facilities category lead for scope and rates. Add vendor-master or supplier-risk review because Riverton Mechanical has never been paid. Hold until the insurance certificate is on the file. Do not send Aisha a clean approve request while the hold is open.

Three failures they almost shipped.

They skipped Aisha because the facilities director usually signs HVAC and the score printed medium once value was averaged in. A blended medium is not a new matrix.

They routed around the insurance hold by sending the PR to a faster controller who was in the office. A controls hold is not a delay. Clearing it by finding someone who will click is how unauthorized spend gets a workflow ID.

They treated the Zip path as the control. The orchestration tool executed nodes finance had not reviewed. Riverton Mechanical was paid. The matrix was never asked.

Add category and risk reviewers when the score is high

The half of the trade teams forget is the add, not the skip. New supplier, high amount, and exceptions add reviewers. A path that only ever gets shorter is a courtesy-stripper, not a control.

When novelty is high, add the person who owns vendor onboarding or supplier risk for that entity. When the amount sits near or over a published cut, add the next DoA row. When the requester filed an exception, add the policy owner who is allowed to grant it, not the manager who would have rubber-stamped the original buy.

Keep these adds as named roles with a matrix or policy row. A category lead who is not authorized for the amount cannot be the last click. They review. The DoA delegate still approves.

Approval anomaly flagging is a sibling, not a substitute. It surfaces unusual amounts, odd suppliers, and split patterns. Routing should not hide a flagged row on a shorter path. If a row is flagged, it stays human, and the extra reviewer is the controls owner, not a faster manager.

If every skip is matched by a new FYI, you have rebuilt the chain with extra mail. Adds must map to novelty, amount, exception, or a live anomaly flag.

The tool assigns the path. It is not the control

Zip and Tonkean are a class of intake and orchestration tools. Coupa and SAP Ariba are a class of buying systems that already host approval chains. Use whichever you already run. Do not rank them. Do not invent a feature one of them lacks.

The control you publish is the three-axis score, the nodes you may skip because they are not on the DoA row, the named delegate you may never skip, the reviewers you add when the score is high, and the rule that a hold is not a routing exception. The tool assigns that path. It is not evidence the path was allowed.

If the workflow table in Coupa or SAP Ariba still lists last year's plant manager, routing that trusts the table will ping a courtesy layer you meant to drop, or treat that person as the delegate. Join the live matrix the same way DoA enforcement does. If the row and the workflow disagree, the row wins.

Do not route around a controls hold. Missing insurance, a failed DoA join, an anomaly flag, or an open policy exception is a stop. The next person on a shorter path does not lift it.

Auditors will ask why this request took a shorter path. The answer is the three factors, the courtesy nodes dropped, the delegate who remained, and the reviewers added. "The orchestration tool said so" is not an answer.

Show procurement operations a replay of last quarter's requests against the new rules before you turn this on. Per request they should see who would have been skipped, who stayed, who was added, and which holds remained. If a named delegate or a hold disappears from that replay, stop.

Trial one category where courtesy layers are real and the matrix is live: facilities, MRO, or another path where managers click because the workflow copied them in. Run it in parallel with the chain Coupa or SAP Ariba already sends. Zip or Tonkean can assign the nodes. Humans still own the clicks that bind the company. If a person not on the matrix ever became the last click, stop the trial and fix the join before you expand.

Is this worth automating for you?

Whether this pays back depends on how much time it takes your team today. Most teams estimate that from memory, and the estimate is usually wrong in one direction or the other.

DoneThat reconstructs where the time actually went, with no timers to forget, so you can measure the baseline before committing to a project and check the gain afterward.

Measure the baseline first