Blog · Back office · 27 September 2026 · 12 min
Spend approval rules after your raise: three numbers and two names
This is a spend policy you can fill in over a coffee. It is written for a company of 11 to 50 people that raised in the last few months, where nobody is a full-time finance person yet.
The money landed. Within a month there are more cards, more vendors and more people who can say "just pay it". Until now the approval policy was one person: you. It worked because everyone could reach you and because the amounts were small enough that a wrong one stung but did not matter.
That stops being true in the same quarter the round closes. Not because anyone is dishonest, but because the founder becomes the queue. Payments wait for a chat reply from an airport. A new vendor gets paid on the details in the email that brought the invoice. The bookkeeper finds the $9,000 prepayment in week six, when it is already a fact.
The policy below needs no software: a page in your wiki and three people who read it is enough.
A spend policy is three numbers and two names
Most of the value is in deciding very little.
- A floor. Below it, the person who owns the budget line pays and nobody signs. Interrupting a founder for a $60 subscription costs more than the subscription.
- A ceiling. Above it, two people sign, and one of them is the founder or the finance lead. This is where a wrong payment moves runway by an amount you would notice.
- An irreversible line. A wire abroad, a crypto transfer, a deposit, a prepayment to a vendor you have never paid: none of these can be pulled back. They get the two-signature treatment even when the amount is under the ceiling.
And two names.
- The backup approver. The person who signs up to the ceiling when the founder is unreachable. Named now, in writing, not in the chat thread on the day.
- The person who can say no. Somebody who can reject or withdraw any payment even when they cannot sign it, so nothing sits in a queue waiting for someone who has left. Usually the founder.
Everything else in the policy is a refinement of these five things.
Example thresholds (illustrative, not a benchmark)
The numbers below are an example for a company spending in the region of $150,000 a month. Do not copy them. Take your own monthly burn and ask two questions: what is the amount I never want to be interrupted for, and what is the amount that would visibly move our runway. Those are your floor and your ceiling.
| Band | Example range | Who signs | Typical contents |
|---|---|---|---|
| 1. Routine | under $500 | nobody; the budget owner pays | subscriptions, small tools, travel within policy |
| 2. Standard | $500 to $5,000 | one approver: the manager of the budget line | contractors' monthly invoices, one-off vendor work |
| 3. Significant | $5,000 to $25,000 | two signatures, one of them founder or finance lead | annual software, equipment, monthly agency fees, deposits |
| 4. Material | above $25,000 | two signatures, and the board is told in the monthly update | anything that moves runway; check whether your board consent threshold already covers it |
| Irreversible, any amount | transfers to new bank details, crypto sends, deposits, prepayments to a new vendor | as band 3 regardless of amount | you cannot recall it, so a second pair of eyes is cheaper than the mistake |
A sanity check on the ceiling: a band 4 payment should be a number where losing it once would show up in the next board deck. For many companies at this size that lands somewhere between one and two weeks of burn. Again, an example, not a rule.
The same amount is not the same risk
Amount is one axis. Spend type is the other. Two payments of $4,000 can deserve different treatment.
| Spend type | What makes it different | Suggested handling |
|---|---|---|
| Payroll and regular contractors | approved once at hiring, then recurring | the run is checked on its total, not line by line; two signatures if the total is above the ceiling |
| Software and subscriptions | small, recurring, paid by card | a card with a limit per holder, not an approval queue |
| One-off vendor work | known vendor, known scope | the amount bands above |
| First payment to a new vendor | you have never paid them; details unverified | one signature at any amount; verify the bank details by a channel you already had |
| Changed bank details of an existing vendor | the classic "we have a new bank account" fraud | treat as a new vendor: hold the payment until a second person confirms the details by phone |
| Wires abroad, crypto sends, deposits, prepayments | irreversible | two signatures regardless of amount |
| Taxes, government fees, rent | late is expensive; amounts known in advance | approve the schedule once, not each payment |
| Expense claims | money a person already spent | one approver who is not the claimant; paid in a batch |
| Refunds and customer credits | money going back out | one approver from outside sales |
Who approves what: three roles, not one
Split the act of paying into three parts.
- The proposer writes the payment: payee, amount, account, what for. Anyone with a budget line can propose.
- The approver signs. The rule that matters most: nobody signs their own proposal. A quorum counts other people. A two-signature rule where the proposer is one of the two is a one-signature rule with extra steps.
- The releaser presses the button that moves the money, or makes the transfer in the bank. This can be the approver. Keeping it separate means a payment approved by two people is not stuck because the person who wrote it is away.
For large or irreversible payments, "two of three named people" survives holidays better than "the founder plus one". Count your eligible signers before you write the rule: a rule that asks for two signatures in a company where only one person may sign stops payroll on the first Friday.
Write the roster as names, not titles. "Head of Ops" is a title that can be empty for a month.
When the founder is on vacation
The honest test of a spend policy: can the month's payroll and the rent go out while you are unreachable for five working days? If the answer is no, you do not have a policy, you have a person.
Three things to do before you leave. They take twenty minutes.
- Name the backup approver in the policy, not in the chat. They sign bands 2 and 3 in your absence. Band 4 and anything irreversible waits, or goes to the co-founder. Do not lower the bar for the top band because you are away; that is exactly when the "urgent" wire arrives.
- Empty the queue or hand it over. Anything waiting on you is signed before you go or explicitly moved to the backup. A payment nobody can act on for a week makes a vendor call your team, and the team will find a workaround. Workarounds are how policies die.
- Check who can release, not just who can sign. If only you can make the bank transfer, the backup's approval changes nothing. Give the releasing right to a second person for the period, or set the transfers up before you go.
While you are away, every request should name the backup approver and say where the money is going: the account or wallet, not just the amount. Signing "$8,400 to Studio Norte, account ending 4471" from a phone is fine. Signing "$8,400" is not.
New vendors and first payments
The classic version of invoice fraud is an email saying the vendor's bank account has changed. The policy for new and changed payees is short because it has to be followed on a busy Friday.
- The first payment to a new payee collects a signature at any amount. Even $300. The first payment is when the details get checked, and the check is one phone call to a number you already had, never a reply to the email that brought the invoice.
- Changed details are a new vendor. The payment is held until a second person confirms the new account by phone. The person who proposed the payment does not confirm it.
- Keep a trusted list. Once a vendor has been paid and verified, they go on it, and repeat payments to trusted payees below the ceiling go without a signature round. Adding to the list is an owner-level decision. Taking somebody off it is not.
- Nobody creates a payee and pays them in the same breath. At least one other person sits between "add the vendor" and "pay the vendor".
Card limits and approvals are different controls
A common first mistake is to treat them as one thing. They stop money at different moments.
An approval stops a payment before it leaves. A card limit cannot: by the time the charge reaches you, the merchant has the money. What a card limit does is cap the damage per holder and per period.
- Small recurring spend (tools, ads, travel) goes on cards with a ceiling per holder. A $40 subscription does not belong in a two-signature queue.
- Transfers, invoices and anything above the floor go through approvals. A $12,000 vendor prepayment does not belong on a card.
- The two numbers do not add up. A person with a $2,000 card and a $5,000 monthly payment allowance can spend $7,000. If you mean to cap a person overall, set both, and say so.
- Freeze beats cancel. A frozen card is unfrozen when the person is back; a cancelled one means a new card and a week of re-entering it into services.
What to show the board monthly
One page, the same shape every month, so the board reads the numbers and not the layout.
- Total out versus plan, and the runway that results.
- Top ten payees by amount, with new ones marked.
- Exceptions from the rules: what went out with fewer signatures than its band asked for, what went out above the floor without matching any rule, and any change to the rules themselves during the month. An empty list is a real answer, and the most valuable line on the page.
- How many payments are waiting right now, and how long a payment waited from proposal to last signature. If this grows, the policy has a bottleneck, and it is usually a person.
- Changes to who may sign or release, with dates.
No narrative. If a board member wants the story behind a line, the line is the invitation.
Common failure modes
- The policy is a person. One signer, no backup. Fine until the first flight.
- Splitting. A $9,000 invoice paid as three $3,000 "instalments" to stay under the two-signature band. Measure the threshold per payee per day and per bill, not per transaction.
- "Off" that nobody defined. A rule you mute to "turn off" the second signature may still block the payments it would have matched, or may quietly let them through. Decide what off means, and prefer deleting a rule you no longer want.
- Rules written before the team. "Needs two" with one eligible signer. Write it down, but do not switch it on until the second signer exists.
- Approving an amount, not a destination. The notice must name the payee and the rail: account, wallet, network. A signature given for "$8,400" is a signature for anything.
- Gaps between bands. One rule stops at $1,000, the next starts at $2,000, and the $1,500 payment goes out unsigned because it matched nothing. Bands must touch.
- The policy lives in a document. If the rule is not where the payment is made, it is advice, and advice loses to Friday afternoon.
- The batch is forty decisions. A payroll of forty rows is one decision on one total. Sign it once; look at the rows you would not recognise.
Fill-in template
Copy this, replace the examples, and put it where payments are made.
Standing decisions
| Decision | Your answer |
|---|---|
| Floor (nobody signs below) | $____ |
| Ceiling (two signatures above) | $____ |
| Board-informed line | $____ |
| Backup approver (name) | ________ |
| Second releaser (name) | ________ |
| Who can reject or withdraw any payment | ________ |
| Who may add a payee to the trusted list | ________ |
| Who reviews exceptions monthly | ________ |
| Next review of this policy | YYYY‑MM‑DD |
Bands
| Band | From | To | Spend type | Proposer | Signatures (how many, by whom) | Backup signer | Releaser | Notes |
|---|---|---|---|---|---|---|---|---|
| 1 | $0 | $____ | routine | budget owner | 0 | n/a | budget owner | on a card where possible |
| 2 | $____ | $____ | standard | anyone with a budget line | 1: the budget line's manager | ________ | ________ | |
| 3 | $____ | $____ | significant | anyone with a budget line | 2: one of them founder or finance lead | ________ | ________ | never the proposer |
| 4 | $____ | no ceiling | material | founder or finance lead | 2, and the board is told monthly | ________ | ________ | waits while the founder is away |
| I | any | any | irreversible: new bank details, crypto sends, deposits, prepayments to new vendors | anyone with a budget line | as band 3 | ________ | ________ | confirm details by phone first |
Card ceilings
| Holder | Limit per month | What it is for | Who can raise it |
|---|---|---|---|
| ________ | $____ | ________ | ________ |
If you want the rules enforced rather than remembered
Everything above works on a wiki page. The one thing a page cannot do is refuse a payment.
Orla keeps approval rules in the same shape as this template. A rule is a USD threshold and a number of co-signer signatures, set in Team & access for a business space. It can hold several rules, each with an amount band, an account scope, a named list of who may sign and whose spending it governs; rules are checked top to bottom and the first match applies, and a payment that falls in a gap between two bands is refused and told which rules it fell between. Whoever proposes a payment cannot sign it, the owner can always reject one, and a rule that asks for more signatures than it has eligible signers says so with the numbers. Releasing a payment is its own permission, so an approved payout is never stuck because the person who wrote it is away, and approvers still waiting are nudged once a day. A payee you have paid before who turns up with new bank details holds the payment, even with every signature on it, until another person who can sign confirms the new details. Working alone, you confirm you checked them by phone. A threshold is measured per payee per day and on a batch total, so slicing does not walk past it. Cards are a separate control: a card has its own ceiling from a prepaid balance, and the two numbers do not add up. One rule with a threshold, a signature count and the address-book switch is on every plan; bands, named approvers and per-person monthly allowances are on the Scale and Enterprise plans.
Nothing moves without a person's signature. Agents and automations propose, the rule decides what waits, and you still sign.
Asked next
The questions that follow this one
How do you set spend approval thresholds after a funding round?
From your own burn, not from a benchmark. The floor is the amount you never want to be interrupted for, and the ceiling is the amount that would visibly move your runway. Below the floor the budget owner pays alone; above the ceiling two people sign, one of them the founder or the finance lead.
Who approves payments when the founder is on vacation?
A backup approver, named in the written policy before the trip, who signs up to the ceiling. The top band and anything irreversible waits or goes to the co-founder. Check who can release money as well as who can sign: if only the founder can make the bank transfer, the backup's approval changes nothing.
What is the difference between a card limit and a payment approval?
An approval stops a payment before it leaves. A card limit cannot, because by the time the charge reaches you the merchant has the money; it caps the damage per holder and per period. The two numbers do not add up, so set both if you mean to cap a person overall.
What should you do when a vendor says their bank details changed?
Treat them as a new vendor. Hold the payment until a second person, not the one who proposed it, confirms the new account by phone on a number you already had, never by replying to the email that brought the invoice.
What spending should a startup show its board every month?
One page in the same shape each month: total out against plan and the runway that results, the top ten payees with new ones marked, the exceptions from the rules, what is waiting and how long payments waited for signatures, and any change to who may sign or release.
Read next
Where this goes on
Next
More from back office
Month-end close checklist for a small business, with crypto in the mix
The month-end close process for a small business, in order: statements, categories, receipts, bills, invoices, crypto lots, rates, codes, then a sealed month.
Back officeSep 26, 2026Supplier bill approvals for a small team: a threshold, two signatures and an audit trail
Supplier bill approvals for a small team: where to set the threshold, why the second signature cannot be the proposer's, and what an audit trail must contain.
Back officeSee it on your own books
Thirty minutes: we connect an account, drop a real bill in, and close a month together.