Back to Blog
Best Practice

Invoice authorization in Exact Online: setting up approval flows

G
Glimps
The Glimps team
6 July 2026 9 min read

Invoice authorization means someone with the right responsibility approves a purchase invoice before it is paid. In Exact Online this often stalls on email rounds, missing context, and stand-ins pulled in during holidays. This article shows how to set up authorization so it stays fast, auditable and scalable, and how to send only genuine exceptions to people.

What is invoice authorization and why does it stall?

Authorization, or fiatteren in Dutch, is a synonym for approval: an authorized person confirms an invoice is correct and may be paid. In practice finance teams use both terms interchangeably. Where approval is often the formal word, authorization emphasizes the act itself: someone puts their sign-off on the invoice. For the broader approach, see the page on approving invoices in Exact Online.

The idea is simple; the execution less so. Authorization stalls for a few recognizable reasons:

  • Email rounds. An invoice is forwarded as a PDF, someone replies "approved", and that email then has to be fed back into the administration by hand. The posting and the approval live in two places.
  • Missing context. The approver sees an amount but not the order, the delivery, or the earlier agreement. Without context, approving becomes guessing or chasing.
  • Holiday stand-ins. The regular budget owner is away and nobody knows who may step in. The invoice sits until the payment term expires.
  • No escalation. When an invoice stalls, nothing happens automatically. It only surfaces when a reminder arrives.

Designing approval routes

Good authorization starts with a clear route: who may approve what, and on what basis? The strongest setups combine several dimensions instead of putting everything on one person.

  • By amount. The classic threshold. Up to €1,000 a team lead may authorize, above that the manager, and beyond a limit the board. This covers financial risk.
  • By cost center. The budget owner of the relevant department authorizes, so costs land with whoever is responsible for them.
  • By entity. With multiple administrations in Exact Online, you route invoices to the right entity and its matching approver.
  • By budget owner. Tie approval to the person managing the budget, not to a role that shifts per invoice.
  • By project. In project-driven organizations, the project lead authorizes the costs charged to their project.

In practice you combine these: a €4,000 invoice on cost center Marketing goes to the marketing budget owner, and because the amount exceeds the team threshold, also to the manager. How you configure these routes technically is covered under workflows.

Practical tip Keep the number of routes limited. Ten clear rules work better than fifty exceptions nobody can explain anymore. Start with amount and cost center, and only add complexity when you truly need it.

Authorizing before or after posting

An important choice: do you have invoices authorized before they are posted, or after? Both work, each with its own trade-offs.

Authorize before posting. Nothing enters the books before it is approved. Upside: your ledger contains only approved invoices, and errors are caught early. Downside: outstanding commitments are less visible while invoices sit in the approval stage, which can blur your view of payables.

Authorize after posting. The invoice is posted first and only then released for payment. Upside: your payables position is complete immediately and the month-end close is cleaner. Downside: a posting exists that has not yet been approved, so you need a tight payment block to ensure nothing is paid before sign-off.

For most SMB teams, authorizing after posting with a hard payment block works best, because your commitments are fully visible. Just make sure the block is watertight: a posted but unauthorized invoice must never end up in a payment batch.

Audit trail and internal control

Authorization is not only a practical step, it is internal control. A good setup records who approved what, when, and why. That matters for your accountant, for segregation of duties, and for preventing fraud.

Watch these points:

  • Segregation of duties. Whoever enters an invoice must not authorize it themselves. Whoever authorizes must not also release payment without a second check.
  • Recorded trail. Every approval must be traceable to a person, a moment, and the version of the invoice that was approved. An emailed "approved" rarely qualifies.
  • Four-eyes for high amounts. Above a threshold, one sign-off is not enough. Define when a second approver is mandatory.
  • Immutability. After authorization the invoice must not quietly change. If the amount or supplier changes, the approval should lapse.

Authorization combined with PO matching

The biggest gain lies in combining authorization with PO matching. When an invoice automatically matches an approved purchase order and a goods receipt, the approval has effectively already happened at the moment of ordering. Whoever placed the order already approved the commitment.

The principle: if the invoice matches within tolerance on price, quantity and order, no human needs to look at it. Only the exceptions go to an approver: a price difference, a missing receipt, an invoice without an order. This shifts authorization from "review every invoice" to "review only deviations". That is exactly where the volume problem disappears: with a thousand invoices you want maybe fifty to genuinely pass a person, not a thousand.

Core idea Authorization should not be the default but the exception. If an invoice matches cleanly against an approved order, ordering is approving. Only what deviates deserves human attention.

Practical setup steps

Here is how to set up authorization in a structured way, whether you stay in Exact Online or add a layer like Glimps on top:

  1. Map your approvers. Who is the budget owner per cost center, entity and project? Record that before building routes.
  2. Set your thresholds. Which amount may which role authorize, and where is four-eyes mandatory?
  3. Choose before or after posting. And configure the matching payment block if you authorize after posting.
  4. Arrange cover. Record a stand-in for every approver, so a holiday never costs a payment term.
  5. Add PO matching where you can. That shrinks the number of invoices that need authorizing at all.
  6. Measure lead time. Track how long invoices stay in the approval stage and where they get stuck.

Common mistakes

  • Authorizing by email. No audit trail, no link to the posting, and approvals that vanish into inboxes.
  • Too broad an authorization matrix. If everyone may authorize everything, there is effectively no control.
  • No escalation. An invoice left sitting should automatically trigger a reminder or escalation after a number of days.
  • Forgetting stand-ins. The most common cause of delay is simply that the approver is away and nobody may step in.
  • Authorizing everything. Without matching, you send invoices to people that could have been handled automatically.

Frequently asked questions

What is the difference between authorization and approval?

In practice, nothing. Authorization (fiatteren) and approval are synonyms for signing off an invoice before it is paid. Authorization emphasizes the act, approval is often the formal term. The page on approving invoices covers the broader explanation.

Can you authorize invoices in Exact Online?

Exact Online supports approval steps, but many teams want finer-grained routes by amount, cost center, entity and budget owner, plus an audit trail and escalation. For that they add a workflow layer.

Should I authorize before or after posting?

Both work. Before posting keeps your ledger clean; after posting makes your payables position complete immediately, provided you set a hard payment block on unauthorized invoices.

How do I stop authorization stalling during holidays?

Record a fixed stand-in for every approver and make sure routes escalate automatically when an approval sits too long.

How do I avoid every invoice needing a human?

Combine authorization with PO matching. Invoices matching within tolerance on order and receipt do not need separate authorization. Only the exceptions go to an approver.

Is authorizing by email enough for my accountant?

Usually not. An email saying "approved" offers no reliable, traceable record of who approved what and when. A structured approval flow with recorded steps is better for your internal control.

Conclusion

Authorization is not a formality but one of the places where invoice processing stalls most often. The fix is not stricter email rounds, but clear routes, context on the invoice, arranged cover, and an audit trail your accountant trusts. Add PO matching and authorization turns from a daily burden into an exception process: only what deviates still reaches a person.

Read how to set up approving invoices in Exact Online, explore the workflows, or see how Glimps invoice processing combines authorization and matching.

Share this article

Ready to transform your finance team? Start today.

Join the growing number of finance teams using Glimps to automate their AP workflow.

Book a call