Platform · Approvals & Authorization

Route every approval. Govern every action.

Design multi-step approval flows with the Approval Matrix, and decide exactly who can view, create, edit, approve or delete each record with the Authorization Matrix — down to the field and the row, mapped to your org hierarchy.

Sequential, parallel & conditional routing · field-level + row-level access · full audit trail
app.processo.io · approval-matrix

Discount Approved

+ Add Level Save
Account Name × Deal Name × Deal Stage × Discount % × +
1
Level 1Sales App… · 2 rules
#1 Rule 1

Deals.Stage in "Discount Requested" AND deal.owner_role is "SALES_REP"

#2 Rule 2

Deals.Stage in "Discount Requested" AND deal.discount_pct > "15"

No. of approvers
1
Roles
SALES_MANAGER
Level 1 saved2 rules · Discount Approved
Routes by Deal Stageauto-escalates to SALES_MANAGER
Two matrices, one source of truth

Approvals decide what happens. Authorization decides who can.

Processo separates routing from access so both stay simple to reason about. The Approval Matrix moves a record through the right people in the right order; the Authorization Matrix controls who can ever touch it — and how much of it they see.

Approval Matrix

Define the steps a record must clear before it's final. Each step names an approver — by role, by hierarchy, or by a specific user — and can run one after another, all at once, or only when a condition is met.

SequentialParallelConditionalThresholds

Authorization Matrix

Map every role to what it can do per entity — View, Create, Edit, Approve, Delete — then refine down to individual fields and individual rows. Permissions inherit your user hierarchy, so managers see their team's records automatically.

Per-entityField-levelRow-levelPII / ePHI aware
Multi-step routing

Build the approval flow your process actually follows

Chain as many steps as you need. A workflow trigger submits the record; Processo routes it to each approver, sends the notification, records the decision, and only advances when the step is cleared.

Step 0

Submitted

Requester raises PO #4821 for $480,000 — over the $100k threshold.

Workflow trigger
Step 1

Manager

Routed to the requester's reporting manager via the hierarchy.

Approved · 2h
Step 2

Finance

Conditional step — triggered only because the amount exceeds $100k.

Approved · 4h
Done

Approved

PO is locked, vendor is notified, and the ledger entry is created.

Status → Approved

Sequential

One approver after another. The record advances only when the current step says yes; a rejection sends it back with a reason.

Parallel

Several approvers at once. Require all to sign off, or any single approval — perfect for cross-functional reviews.

Conditional

Steps that fire only when the data demands it — an amount over a threshold, a flagged region, a high-risk category.

Field-level access

Hide or mask the fields a role shouldn't see

The same record can look different to different people. Mark a field as hidden or masked for a role, and Processo enforces it everywhere — forms, tables, pages, queries and exports — never just in the UI.

Hide or mask

Show full value, a masked value (••• 4821), or nothing at all — set per role, per field.

PII & ePHI aware

Fields flagged as PII or ePHI are masked by default and only exposed to roles you explicitly clear.

Read vs. edit per field

A role can read a field but not change it — or edit it only while the record is in a given status.

record · employee profile

Employee · Emily Carter

Viewing as · Requester
NameEmily Carter
DepartmentOperations
Email PIIe••••@acme.co
Phone PII+1 (•••) •••-••21
Annual salary Hidden for this role
Bank account PII Hidden for this role
Data-level (row) access

Everyone sees only the records that are theirs

Row-level rules scope what data a user can reach. Tie access to the user hierarchy and the rest follows automatically — reps see their own deals, managers see their whole team, regional heads see their region.

  • Own records — a user only sees rows they created or are assigned to.
  • Team & hierarchy — managers inherit visibility of everyone reporting up to them.
  • Attribute scopes — restrict by region, branch, organization or any field on the record.
  • Multi-tenant safe — organizations stay isolated; no row ever leaks across tenants.
authorization · data-access scope

Row visibility — Purchase Orders

mapped to hierarchy
UserScopeRows visible
JordanRequesterOwn only12
MeganManagerTeam (8 users)96
RyanRegional headWest region340
SaraFinanceAll · approve1,204
DrewAuditorAll · read-only1,204
Worked example

A purchase order over the limit

One PO record, governed end-to-end — routing, permissions, masking and audit, all configured without code.

PO #4821 · Procurement process · $480,000
1

A Requester creates the PO. The Authorization Matrix lets them Create and View, and Edit only their own drafts — never approve.

2

On submit, a workflow trigger kicks off the Approval Matrix. Step 1 routes to the requester's Manager through the hierarchy.

3

Because the amount is over $100,000, a conditional Step 2 adds Finance sign-off. Under the threshold, this step is skipped entirely.

4

The vendor's bank details are flagged PII — visible to Finance, masked for everyone else, even on exports and saved queries.

5

Once both steps approve, the status flips to Approved, the record locks, and a WhatsApp + email notification fires to the vendor.

6

Every decision — who, when, what comment — is captured in the audit trail. The Auditor role can read it all but change nothing.

Works with

Part of the bigger governance picture

Approvals and authorization plug straight into the rest of Processo.

Govern with confidence

Set up approvals and access in an afternoon — no code, no risk.

Start from a prebuilt process or a blank canvas, then layer in your Approval Matrix and Authorization Matrix. Field-level masking, row-level scope and a full audit trail come standard.

Start building free See pricing