Skip to content

Approvals Hub

Where to find it: Work & Decisions, then Approvals Hub (/approvals).

The Approvals Hub is the decision centre: every governed decision awaiting action, across every module, in one view.


Workbench or Approvals Hub?

They overlap deliberately, and they answer different questions.

WorkbenchApprovals Hub
QuestionWhat is waiting for me to do?What decisions are outstanding?
ScopeAll your work — reviews, own work, attestations, offersGoverned decisions
AudienceEveryoneApprovers and governance functions
Organised byBucket, by what kind of obligation it isDecision, by what needs deciding

An approver typically lives in the Approvals Hub. Everyone else lives in the Workbench.


What appears

Governed decisions from across the platform:

ModuleDecisions
ComplianceObligation submissions, requirement demonstrations, compliance validation
ApplicabilityApplicability decision approvals
ControlsMapping approvals, assessment reviews, design adequacy reviews, expected evidence acceptance
RiskRisk acceptance, exception approvals, action plan approvals and verifications
PolicyPublication approvals
AuditPlan approvals, engagement sign-off
InspectionsResponse package sign-off
ResilienceBIA, plan and exercise sign-off
IncidentsClosure review
Third-partyEngagement decisions

Each item shows what is being decided, who submitted it, when, and a deep link to the record.


Segregation is applied before you see it

Decisions you are not permitted to make do not appear.

  • Your own submissions are excluded from your queue.
  • Decisions whose stage is bound to a role you do not hold are excluded.

You cannot see an approval you would be blocked from making. This avoids the common frustration of a queue full of items that error on click.


Working an approval queue

Read what is being asked. A mapping approval, a policy publication and an incident closure are different decisions requiring different scrutiny. The hub shows what kind each is.

Open the record. The hub shows enough to triage. It does not show enough to decide. Every item deep-links to the record.

Return rather than reject where the work is salvageable. A return with a specific comment gets the right outcome. A rejection restarts the chain.

Write the reason. The reason is read by the submitter now and by an auditor later. "Rejected" is not a reason.

Watch the age. An approval open for two weeks is blocking a person, and often a chain of people behind them.

A chain that never returns anything is not a control

If your approval queue has a 100% first-time approval rate, either your submitters are exceptional or the review is a formality. The policy publication example shows what a good return looks like — it caught a materiality threshold error that would have propagated into an entire reassessment programme.


Escalation

Some chains support escalation from a review stage to an executive or committee stage. Where available, escalation is a distinct action from approval and rejection, and it moves the decision up rather than concluding it.

Requires work.escalate or the escalation transition on the stage.


Permissions

ActionPermission
View work and decisionswork.read
Approve a workflow transitionworkflow.approve, plus the stage's role binding
Administrative workflow overrideworkflow.override
Module-specific approvalsThe relevant module permission — mapping.review, exception.approve, risk.accept, policy stage roles, and so on

Example

A Chief Risk Officer's Approvals Hub.

ItemTypeSubmittedAge
EXC-2026-0031 MFA exception, legacy trading platformException approvalIT Security Ops Manager6 days
RSK-2026-0022 acceptance, legacy settlement platformRisk acceptanceHead of Operations2 days
ENG-2026-0041 core hostingEngagement decisionTechnology Sourcing Analyst4 days
INC-2026-0014 closureIncident closure reviewHead of Payments Operations1 day
BIA-2026-0003 Retail PaymentsBIA approvalHead of Payments Operations9 days

What is not in the queue: three risk acceptances the CRO's own team submitted where the CRO is named as the requester, and two mapping approvals bound to the Compliance Manager role.

The nine-day BIA is the one to worry about. It is blocking the continuity plan approval behind it, which is blocking the exercise schedule behind that. A single stalled approval near the front of a chain delays everything downstream of it, and the age column is the only signal that shows it.


Troubleshooting

"An approval I expected is not in my queue." Either you submitted it, or the stage is bound to a role you do not hold.

"I can see it but cannot approve it." This should not happen — segregation is applied before display. If it does, check whether you hold the module permission as well as the stage role.

"Approving did not change the business state." In a multi-stage chain, intermediate approvals advance the stage. Only the terminal stage updates the business state.

"I need to approve something I submitted." Segregation of duties blocks this. Where your governance model genuinely requires a break-glass path, see Segregation of Duties.


OrviQ Enterprise Governance, Risk & Compliance Platform