Role-based access
Owners, admins, managers, analysts, reviewers, and viewers have different permissions.
Approvals
An analyst prepares the run. A reviewer checks exceptions. A manager approves. Role-based access decides who can do each step. Audit history records who acted. This is an internal control workflow, not a certified regulatory attestation.
If the person who ran the match can also silently accept every exception, the control is weak. Maker/checker separates preparation from approval and keeps a history of who did what.
How it works
Step 1
Analyst runs the job and works the exception queue.
Step 2
Reviewer inspects remaining items and comments.
Step 3
A user with approval permission records the approval.
Step 4
Certified or approved results stay in history. Source files stay unchanged.
What this workflow is designed to do with uploaded files.
Owners, admins, managers, analysts, reviewers, and viewers have different permissions.
Preparation and approval are separate actions by authenticated users.
Approval actions are recorded. There is no AI approver.
Approvers see the same structured exceptions the analyst saw.
Analyst prepares the March vendor rec. Reviewer checks the five open items. Manager approves the run. The audit history shows three people and three actions — not one person clicking through their own work.
Sample preview
Roles are examples of the permission model, not job titles you must hire.
Step 1
Runs the reconciliation, maps columns, and works obvious exceptions.
Step 2
Inspects remaining items, comments, and can send items back.
Step 3
Records approval. The action is stored in audit history.
Approvals add control. They do not mean AuditExport is certified for a specific regulation. We do not claim SOC 2, ISO, or statutory sign-off by using this workflow.
Continue with the workflows that usually sit next to this one.
No. Approval is always a human user. AI does not approve exceptions.
No. Maker/checker is a control pattern. We have not certified regulatory compliance on this page.
Users whose role includes approval permission. The server re-checks the action.
Start a workspace, invite a reviewer, and keep approval in the product — not in a forwarded spreadsheet.