Skip to main content

Spend governance approvals

/governance-approvals manages approval policies, governed requests, and emergency overrides. It is separate from virtual-key requests on the general Approvals page.

Open the page and understand scope​

Select Spend Governance in the sidebar's Administration group or open /governance-approvals. All signed-in roles can open the page, but the returned requests and available actions are permission-checked.

  • ADMIN can manage policies, review eligible requests, and revoke active overrides.
  • ADMIN_VIEWER and USER_VIEWER are read-only.
  • Other writable users can submit requests, cancel their own pending requests, and approve or reject only when the policy resolves them as an eligible reviewer.

The page shows policy configuration for platform admins, then the policy list, request form, request queue with SLA state, and—only for platform admins—the emergency-override register.

Policies​

Platform admins can create policies for:

  • budget increases
  • high-cost models
  • high-cost agents
  • emergency overrides

A policy can be global or scoped, and can define a USD threshold, owner, manager, or explicit approvers, an SLA, and escalation users. Only active policies participate in routing.

Requests and decisions​

Writable users can submit a governed request with a subject, reason, requested amount when applicable, and expiry. Emergency overrides require an expiry. Eligible reviewers can approve or reject pending requests; requesters can cancel their own pending requests. Escalation users become eligible after the configured SLA.

Approving an emergency-override request creates the override. Overrides cannot be granted directly around the approval path. Platform admins can review active, expired, and revoked overrides and revoke an active override.

Use a clear reason and the shortest practical expiry. Policy, decision, and override mutations are auditable.

This workflow turns observed spend risk into a recorded human decision without granting every requester direct administrative access. See FinOps relationship and data flow.