No single person should be able to move money out alone — it's the most effective fraud control a small nonprofit can adopt, and the one auditors and insurers ask about first. With two-person approval on, every check, debit card purchase, and ACH payment waits for a second set of eyes before it posts.
Availability: Core plan and up.
Turning it on
Two steps, and it's live:
- Be on a plan that includes it (Core or Pro).
- Add at least one user besides the bookkeeper to the Approver group — Settings → Users → edit the user → check Approver under Permission Groups. (See Users and Permissions.)
That's it. From then on, outgoing payments entered in the register post as pending and are automatically sent to every approver. The person who entered a payment can never approve it — that rule is hardcoded and can't be turned off.
Deposits and transfers between your own accounts don't need approval — only money leaving the organization.
What the approver experiences
Every approver gets an email — "Action Required: Approve a Check" — with the date, payee, and description, plus a Review & Approve button. Approvers with a cell number who've opted into texts get an SMS too.
The link opens a secure page (no login needed — the link itself is unique to the approver and single-purpose) showing the full entry: date, payee, check number, the account/fund lines, and the attached receipt or invoice right on the page. Two buttons:
- Approve — the entry posts immediately.
- Reject — requires a reason, which goes back to the bookkeeper.
The approver's IP address and device are recorded with the action — the page says so, and the entry's audit trail shows it forever.
Approvers also have an Approvals item in their left menu (with a pending count badge) listing everything waiting on them plus their recent history.
What happens next
- First response wins. All approvers are notified; the first to act decides, and the other requests are cancelled.
- Approved → the entry posts, and a queued check becomes printable.
- Rejected → the entry is automatically voided and the submitter is emailed the reason. The submitter opens the entry and uses Amend & Resubmit — a corrected copy is created and goes straight back out for approval, with the original kept, clearly marked, for the audit trail.
Nobody has to chase anyone: approvers get an automatic reminder every 24 hours while a request is pending, and the bookkeeper can Resend Reminder from the entry (at most once every 4 hours).
- No response for 7 days → the request expires. The emailed links stop working, the entry shows an Approval Expired badge, and the bookkeeper can send it out again with Request Approval on the entry page. An expired entry still can't post or print until someone approves it.
The audit trail
Every entry's page has a 2-Person Approval block showing each request: who was notified and when, who acted, the outcome, the rejection reason if any, and the IP/device it came from. That block is what you show the auditor.
Good to know
- There's an on/off switch on Settings → Internal Controls — on by default whenever your plan includes the feature. Turning it off warns you first and emails every administrator, so approval can't be quietly disabled.
- Checks waiting for approval can't be printed and don't appear in the print queue until approved — see Printing Checks.
- Pending entries appear in the register with a clock icon and are already included in your financial statements; the Checkbook Register report shows posted entries only, with Pending flagged. See A Guide to Your Financial Reports.
- If the only Approver is the person entering payments, there's effectively nobody to approve — entries post normally and the entry page tells you to add another user to the Approver group. Two people minimum, really.
- Approval pairs naturally with the other guardrails in Internal Controls.
Comments
0 comments
Please sign in to leave a comment.