Approvals

One inbox for every signature i3 needs, across eleven subject types owned by six different modules · 17 pending · 4 waiting on you · SLA clocks frozen at request time · Wed 29 July 2026 14:41 GST

2 requests are past their SLA and 1 expired overnight. APR-0046 is a D+60 influencer trial write-off at 30h against a 24h clock, and APR-0043 is an authority exception at 28h. The expired one, APR-0029, went back to module 09 as pending. Expiry is a state, never an approval. Show breached →
Subject
Sort
Request Subject type Subject What the signature commits to Requested by Outstanding signature Tier AED Requested SLA Action
APR-0051 Auto-accept batch AAB-2026-W31 9 cases auto-accepted by rule aar_micro_shrink_v1, 12 units, all negative, all under the per-event cap. Rejecting posts a reversal pair per case. Rrule AYAhmad Yousuf T2 412 29-07 06:00 8h
APR-0050 Ledger correction COR-0034 MIN-CNL-019 at HQ_319, 10 units from STOCK to WRITTEN_OFF. Closes DRF-0134. Appends one row, rechains nothing. AYAhmad Yousuf RKRamesh Kumar T2 1,800 29-07 14:38 0h
APR-0049 Count variance CC-0912 L4 MIN-VAS-022 at CCZ, system 28 against counted 26. Under 5 units so a single signature, and the signer must be outside CCZ. SASara Ahmed AYAhmad Yousuf T2 360 29-07 09:12 5h
APR-0048 Count variance CC-0908 L11 MIN-TRAY-012 at AJM, system 24 against counted 17. 7 units, so dual sign. Fatima has signed as ordinal 1; AY is ordinal 2. KSKhaled S. AYAY · 2 of 2 T3 1,190 29-07 07:40 7h
APR-0047 Write-off · Finance WO-0612 JAE17 at HQ_319, 2 units confirmed_lost after the bay C cycle count. Irreversible, so T3 regardless of value. RKRamesh Kumar FAFinance · 1 of 2 T3 470 29-07 05:22 9h
APR-0046 Trial write-off · D+60 TRW-0088 2 units with @leenagh are 60 days past dispatch with no return scan. Choose gift (revenue recognised) or write-off (loss). The default is neither. Rrule · D+60 sweep FAFinance + Marketing T3 4,120 28-07 09:00 30h
APR-0045 SKU merge MRG-0031 MSK15-B merges into MSK15-BLK. Historical rows keep their original sku_id; the loser is frozen and its balance moves by a compensating pair per location and stock type. AYAhmad Yousuf RKRamesh Kumar T3 6,240 28-07 16:10 23h
APR-0044 Gift finalization GFT-0142 @noor.styles keeps 1 unit of LBA01. Moves INFLUENCER_POOL to gifted and recognises the cost as marketing spend, not shrinkage. MLMarketing lead FAFinance T2 2,050 28-07 18:44 20h
APR-0043 Authority exception AUX-0002 Prefer ops2 over i3 for dispatch AWB at 3PL_ARAMEX for 14 days while the location is registered. Time-boxed and always dual-signed. AYAhmad Yousuf FAFinance + admin T3 0 28-07 11:02 28h
APR-0042 Ledger correction COR-0031 LBA01 and LBA02 paired reclass at MCC, net −1. Two legs sharing one movement_pair_id, summing to zero at commit. AYAhmad Yousuf FZFatima Al-Zaabi T2 155 29-07 11:20 3h
APR-0041 Opening balance OB-BAS-01 BAS opening balance of 418 units across 264 SKUs, from a signed physical count. GATE-0 cannot close for BAS until this is signed. BMBAS manager AYAY + Finance T3 370K 28-07 20:15 18h
APR-0040 Rule promotion RUL-0087 Classifier rule pos_refund_no_restock from shadow to production. 41 shadow hits, 2 false positives stated on the rule row. AYAhmad Yousuf RKRamesh Kumar T2 0 29-07 08:05 6h
APR-0039 Write-off · Finance WO-0609 MIN-TBL-014, 4 units confirmed_lost at TRANSIT after 69h with no receive scan. Closes DRF-0104. RKRamesh Kumar FAFinance · 1 of 2 T3 1,180 29-07 10:30 4h
APR-0038 RTS write-off RTS-0022 LC Straps, 120 units returned to supplier, credit refused. Writes off the stock and closes the supplier claim. Over AED 5,000 so T3. RKRamesh Kumar FAFinance T3 8,400 29-07 12:00 2h
APR-0037 Cost revision CST-0114 PO-2026-118 landed cost up AED 7,400 after freight reconciliation. Posts to cost_ledger only: value moves with zero quantity, so it never touches the quantity ledger. FNFinance analyst FAFinance lead T2 7,400 29-07 13:15 1h
APR-0036 Count variance CC-0905 L2 FYB01 at HQ_319, system 88 against counted 89. Overage of 1 unit, so a rule may sign at T1 but it may never be auto-accepted: found stock is never credited by a threshold. Rstock bot RKRamesh Kumar T1 375 29-07 13:50 1h
APR-0035 HMAC rotation KEY-0009 Rotate the CSD inbound webhook secret. Old key stays valid for 24h so in-flight retries are not lost. Value is zero but the blast radius is not. AYAhmad Yousuf ADadmin T2 0 29-07 14:02 0h
APR-0029 Write-off · Finance WO-0588 Expired unsigned at 168h. The subject went back to module 09 as pending and the requester was notified. Nothing was approved. RKRamesh Kumar none · expired T3 720 22-07 09:40 expired
17 pending · 1 expired shown for context · 8 at T3 needing two different humans J K to move · A approve · R reject · D defer · a signature always opens the two-factor prompt

APR-0051 · auto-accept batch AAB-2026-W31

The weekly batch is one subject with one signature over an explicitly enumerated list. This is what makes an auto-accept threshold safe rather than silent.

8h of 24h used
subject auto_accept_batches · AAB-2026-W31 · version 1
period_start 2026-07-23
period_end 2026-07-29
rule_code aar_micro_shrink_v1 (version 1, left shadow 2026-07-08)
case_count 9
total_qty −12 units (every case negative, per R-13.8)
total_value_aed 412.00
manifest_digest sha256 b41c7f9e…2a08
− state pending
+ state signed
+ signature ordinal 1 · Ahmad Yousuf · ops_manager
on reject 9 reversal pairs posted, one per case, net zero
on expiry state expires · the 9 cases reopen as investigating
CaseSKULocΔAEDExplanationRecurGuard that let it through
DRF-0121MIN-DIF-007HQ_319−258confirmed_shrinkage1under 2u and AED 150, negative, no conflict, recurrence 1
DRF-0118MIN-CNL-002HQ_319−236confirmed_shrinkage1same, budget had room
DRF-0116MIN-DIF-012HQ_319−118confirmed_shrinkage1same
DRF-0115TNS01YAS−147breakage_unticketed2recurrence 2, still under the block threshold of 3
DRF-0112MIN-CNL-031HQ_319−119confirmed_shrinkage1same
DRF-0110FYB01CCZ−138confirmed_shrinkage1same
DRF-0107MIN-MRR-003BAS−2120breakage_unticketed1AED 120, closest to the AED 150 cap in this batch
DRF-0106MIN-CNL-024HQ_325−137confirmed_shrinkage1same
DRF-0103JRY01AJM−139confirmed_shrinkage1same
Batch total−124129 of 9 individually within cap and budgetRefused this week: 6 cases, all named below
6 refusals this week, logged not silent: 3 over the 2-unit cap, 1 over the AED 150 cap, 1 blocked on recurrence ordinal 7, 1 blocked because the case carried immutable gate evidence.

Signatures

Bound to the digest, never to a description

R
aar_micro_shrink_v1 · rule
per-case signature, ordinal 1, 9 times
23-07 to 29-07
signer_role = rule
AY
Ahmad Yousuf · ops_manager
batch signature, ordinal 1 of 1 · outstanding
due 30-07 06:00
2FA required
Tier
T2 policy
Basis
policy · batch review
Reversible
Yes, by reversal pairs
Required role
role >= manager
Subject version
1
Evidence digest
sha256 b41c…2a08
Requester
rule, so no human is excluded
If any case is added to or removed from this batch, subject_version increments and every collected signature is marked invalidated. Signatures are never deleted.

Why a rule may sign at all

Auto-accept changes who signs, never whether anything is written. Every artefact a human closure produces is produced: the case, the evidence, the explanation, the compensating entry, and an approval row whose signer is the named rule version.

A rule signature counts for at most one signature and only at T1. This batch review exists because nine T1 rule signatures in a week should still meet one human once.

The budget matters more than the cap. Every one of these nine was under 2 units and under AED 150. So was every one of the roughly 4,500 units the Mirdif POS mapping bug misrouted.

Defer may not push past expires_at. There is no action here that results in nothing being decided.

Throughput · 14 days

Approved, rejected and expired per day, with median time to first signature as a line. An expiry is a failure of the queue, not an outcome.

median 2h 14m
16-07 · approved 7 16-07 · rejected 2 17-07 · approved 8 17-07 · rejected 1 18-07 · approved 6 19-07 · approved 5 19-07 · rejected 1 20-07 · approved 9 21-07 · approved 7 21-07 · expired 1 22-07 · approved 6 22-07 · rejected 2 23-07 · approved 10 24-07 · approved 8 24-07 · rejected 1 25-07 · approved 5 26-07 · approved 4 27-07 · approved 7 27-07 · expired 1 · WO-0588 28-07 · approved 9 28-07 · rejected 2 29-07 to date · approved 6 29-07 to date · rejected 3 median 3h 40m3h 12m4h 20m4h 55m2h 40m3h 20m3h 55m2h 20m2h 50m4h 40m5h 20m3h 45m2h 30m2h 14m today
16-0718-0720-0722-0724-0726-0728-07
ApprovedRejectedExpiredMedian time to first signatureRejections are healthy. Two expiries in 14 days are not.

SLA bands right now

Four bands, computed from a clock frozen at request time so a later policy change cannot rewrite history

2 breached
ok <4hwarn 4-12hdanger 12-24hcrit >24h 6 requests on track, under 4 hours old 6 requests in the warning band, 4 to 12 hours 3 requests in danger, 12 to 24 hours 2 requests breached, over 24 hours: TRW-0088 at 30h and AUX-0002 at 28h 6632
Bands are per subject type, not global. A write-off has a 168h expiry and a 24h target; a ledger correction has 24h and 24h; an opening balance has 72h. The band shown is against the subject's own target.
Oldest unsigned: TRW-0088 at 30h. Oldest T3 without its first signature: AUX-0002 at 28h.

Active delegations

A delegation is a scoped grant, never an impersonation. Both people appear on the signature.

FromToSubject typesLocationsMax AEDMax tierWindowUsed
FAFinance leadFNFinance analystcost_revisionall10,000T227-07 to 03-082 of unlimited
AYAhmad YousufRKRamesh Kumarledger_correction, count_varianceHQ_319, HQ_3252,000T229-07 to 31-071 used
FZFatima Al-ZaabiSASara Ahmedcount_varianceMCC, CCZ500T128-07 to 05-080 used
KSKhaled S.BMBAS managercount_varianceAJM, BAS500T1expired 26-073 used
AYAhmad YousufRKRamesh Kumarwrite_offall1,000T2revoked 24-070 used
No delegation covers write_off today, deliberately. Until the Finance signer is named, write-offs are the one subject type where only an admin can satisfy the second signature, and that is a segregation-of-duties weakness we should not carry past Phase 3.
A delegate can never exceed the delegator's own ceiling, and a delegate acting for the requester is refused by the same trigger that refuses the requester signing directly.

Signature audit

Who approved what, with the digest they saw

Full log ↗
SignedRequestSignerOn behalf ofDecisionAED signedDigest2FA
29-07 14:12APR-0034Ramesh Kumar-approve375a91c…7fyes
29-07 13:40APR-0033Finance lead-approve2,4803d0e…12yes
29-07 12:55APR-0032Finance analystFinance leadapprove6,10077ab…c2yes
29-07 11:48APR-0031Ahmad Yousuf-reject1,8405c2f…9ayes
29-07 10:22APR-0030Ramesh KumarAhmad Yousufapprove560e40b…31yes
29-07 09:04APR-0028Fatima Al-Zaabi-approve155118f…d3yes
29-07 08:31APR-0027Ahmad Yousuf-reject8909d4a…c1yes
29-07 07:15APR-0026Finance lead-approve4,620c4e1…02yes
29-07 06:02APR-0025Khaled S.-reject240660b…a1yes
28-07 22:10APR-0022Ramesh Kumar-invalidated1,1904f2a…9cyes
28-07 20:44APR-0021Ahmad Yousuf-approve7,400882e…34yes
28-07 18:02APR-0020Finance lead-approve840551c…02yes
28-07 15:31APR-0019Ahmad Yousuf-approve306442d…03yes
28-07 12:18APR-0018Sara AhmedFatima Al-Zaabiapprove180333e…04yes

The highlighted row is an invalidated signature: APR-0022's subject changed after Ramesh signed, from 5 units to 7, which pushed it from T2 to T3. His signature was marked invalid with a reason rather than deleted, and the request went back out for two fresh signatures. That row is why the digest column exists.

Three delegated signatures appear above, each naming both the signer and the person they acted for. A delegated approval that hides the delegator is indistinguishable from an impersonation.

How tier is decided

Value, quantity, reversibility and immutability. Never the matcher's own confidence.

TierSignaturesTriggered by any ofWho may sign
T11, may be a ruleValue at or under AED 150, quantity at or under 2 units, reversible, no immutable authority involved, negative delta onlyrule, or role >= manager
T21 humanValue AED 151 to AED 5,000, quantity 3 to 4 units, reversiblerole >= manager + feature
T32 different humansValue over AED 5,000, quantity 5 units or more, irreversible, an immutable authority is on the losing side, an authority exception, or an opening balancefinance + ops_manager, or admin

v2's conflict page tiers on the matcher's confidence: 90% and above auto-resolves, 50 to 90% takes one approver, under 50% takes two. That lets the component most likely to be wrong choose its own level of scrutiny, and a systematically over-confident matcher then auto-resolves its own errors. i3 keys on value and reversibility and shows confidence as a display column only.

Tier is computed once, at request time, and stored with its basis. A later threshold change cannot retroactively make a past approval look sufficient.

8 of 17 pending requests are T3. Four of those are T3 on irreversibility rather than on value, which is the case v2 has no way to express.

The four rules this queue enforces

1. The requester never signs. Directly or as the beneficiary of a delegation. It is a trigger on the signature table, not a check in the handler, so no code path can forget it.

2. A subject change invalidates prior signatures. subject_version increments and every collected signature is marked invalidated_at with a reason. Nothing is deleted, so the audit still shows that somebody signed the older version.

3. Expiry is a state, never an approval. An unsigned request expires and the subject returns to its owning module's pending state. There is no timeout that grants consent.

4. A delegate never exceeds the delegator. Scope, location, value ceiling, tier ceiling and a window, all recorded, and the signature names both people.

This module owns routing and signatures only. The write-off request itself lives in module 09, the merge in module 03, the count variance in module 10, the gift in module 11. Redefining their tables here would be two writers on one decision, which is the shape of most of the defects i3 exists to fix.

State variants

Six of the eight states this page can render

Pattern library ↗
Loading

SLA chips are the last thing to render, because a wrong band shown for even a moment is worse than a blank one.

Empty

Inbox zero.

Every dual-approval gate is clear. 9 cleared today, median 2h 14m, nothing expired. Next digest 18:00 GST to 7 recipients.

Recently clearedDrift queue
Error

Couldn't load the queue.

The approvals service returned 503. No signature was taken and no clock was reset. SLA clocks keep running, which is why this banner names the oldest pending request from cache.

Error id apr-3f81c2 · oldest pending TRW-0088 at 30h
Service health
Zero-filter

No requests match.

3 filters are hiding all 17 pending requests.

subject: SKU mergelocation: BASvalue over AED 5,000
Permission

You can read the queue but not sign.

Signing needs role >= manager plus the feature for that subject type. Your grant on app i3 is viewer, so every action button is absent rather than disabled.

apps.i3.role = viewer · features = [read]
Request accessWho can do what
Maintenance

Read-only for 25 minutes.

The nightly hash-chain verify is running, so nothing may post. Requests can be read and commented on; signatures are held because a signature that cannot post its subject is a promise, not a decision.

21:00 to 21:25 GST · job chain-verify-0729 · SLA clocks pause for the window
Connected to Drift queue Case detail Correction workbench Conflict inspector Anomaly explorer Damages and write-offs Incidents Stock count Merge and aliases Influencer Return to supplier Opening stock Cost and price Rules Settings Audit log Notifications Reports Dashboard