Delegation of Authority Policy: Drafting Approval Thresholds
Josh BertiniPublished
When Chuck Kable became general counsel at Innovative Renal Care, the first thing he did was ask who was spending the company's money and on whose say-so. That question, asked across every department instead of one litigation file, is the one a delegation of authority policy exists to answer.
At the point that I came in, I wanted to see the invoices. How much are they billing us per month? What's involved in these? What's the strategy here? Why do we have three law firms involved? These kinds of questions.
Kable shared the story on CZ and Friends, GC AI's podcast hosted by CEO and former general counsel Cecilia Ziniti.
When a new GC, CLO, or in-house lawyer cannot answer “who approved this,” the usual cause is a missing document: nobody wrote down who is allowed to commit the company, to what, and up to what dollar amount. A delegation of authority policy, often shortened to a DOA policy, puts that in one place, and drafting the approval thresholds is the part that lands on legal's desk.
A working delegation of authority policy has seven parts. The sections below walk through each one and hand you the model language to copy:
- The four approval levels (Inform, Request, Confirm, Approve)
- An approval threshold matrix by role and dollar amount
- Board-reserved matters
- Sub-delegation rules
- Three controls: segregation of duties, an aggregation rule, and a written exception path
- A consequences section for unauthorized commitments
- A review cadence
Once the policy exists, someone still has to check every incoming contract against it: GC AI, the legal AI platform built for in-house counsel, reads the contract inside Microsoft Word and flags which approval threshold applies before anyone signs.
The Three Questions a Delegation of Authority Policy Answers
A delegation of authority policy is a single governance document that defines who in an organization can approve specific decisions, commit funds, and sign contracts, mapped to role and dollar threshold. Nearly 90% of companies have one, according to a 2025 EY and Society for Corporate Governance survey of more than 200 governance professionals, though keeping it trained, enforced, and current is where most teams struggle.
The policy answers three questions for every category of decision:
- Who can approve it? A named role, so the matrix survives turnover.
- Up to what amount? A dollar threshold that escalates approval as the commitment grows.
- What sign-off is required above that? The next role in the chain, up to the board.
The Association of Corporate Counsel recommends in-house counsel administer the policy and its revisions, since legal already fields the question “am I allowed to sign this?” several times a week.
Owning the document turns those one-off questions into a standard everyone can read, and it pairs well with training the team on the approval workflow through resources like GC AI's free AI courses for legal professionals.
When legal owns the delegation of authority policy, 'am I allowed to sign this?' has one answer the whole company can point to.
The Four Approval Levels
Before you assign dollar amounts, define what “approval” means. The ACC framework uses four levels, and naming them removes the ambiguity that leaves a contract sitting in someone's inbox for a week:
- Inform (I): The role gets written notice. No approval is required, and the work proceeds.
- Request (R): The role can initiate or request the action but cannot greenlight it alone.
- Confirm (C): The role gives a conditional or mid-level acknowledgement before final approval.
- Approve (A): The role holds final decision authority and can commit the company.
A clean policy assigns one or more of these levels to each role for each decision type. A line manager might hold Approve authority on a $5,000 software purchase, Confirm on a $50,000 vendor contract, and Inform on anything above that, where the threshold escalates to the VP and then the CFO.
Define what approval means before you attach a dollar figure to it, and the matrix stops being a guessing game about who can say yes.
Approval Thresholds by Role and Dollar Amount
Approval thresholds are dollar ceilings that route a decision to the right level of sign-off as the commitment grows. The structure is a ladder: small spend stays with the manager closest to the work, and each step up adds a more senior approver. The numbers below are a starting model for a mid-market company. Calibrate them to your revenue, risk tolerance, and how fast the business moves.
| Decision Type | Manager / Director | VP or Function Head | C-Suite (CFO/CEO) | Board |
|---|---|---|---|---|
| Vendor and procurement contracts | Up to $25,000 | $25,001 to $250,000 | $250,001 to $1M | Above $1M |
| Capital expenditure | Up to $50,000 | $50,001 to $500,000 | $500,001 to $2M | Above $2M |
| Customer and revenue contracts | Standard terms only | Non-standard terms | Above $500,000 ACV | Strategic or multi-year |
| Hiring and compensation | Within approved headcount | New roles in budget | Executive offers | C-suite hires |
| Litigation and settlements | None | Up to $100,000 | $100,001 to $500,000 | Above $500,000 |
| Real estate and leases | None | None | Up to lease threshold | Long-term or material leases |
Two drafting notes save you a redraft later. First, set thresholds on total contract value over the full term, including renewal options, so a three-year deal cannot slip under a one-year ceiling. Second, add an aggregation rule so approval authority cannot be split: five $24,000 purchase orders to a single vendor sum to $120,000 and climb to the VP tier together. The controls section below gives you the clause language for both.
Price the Litigation Row Like a GC
The litigation and settlement rows deserve their own calibration pass, because they are the thresholds where a wrong number costs the most. On the same episode, Kable priced the decision the way every GC prices a case:
[I]t's gonna cost me, you know, a million dollars to get from here today to trial.
He settled that case at a mediation that ran until midnight. The settlement authority that let him architect the deal at the table was set long before the mediation started, and that is what the litigation row decides: how much your team can commit at 11pm without stopping a mediation to convene the board. Price your realistic path to trial the way Kable did, then set the band so the GC has room to close inside it.
What Needs Board, Executive, or Manager Sign-Off
The cleanest way to set the top of the ladder is to start from the board and work down. Some decisions belong to the board no matter the dollar amount, because the governance risk, the precedent, or the materiality outweighs the spend.
Board-Level Decisions
Reserve board approval for decisions that change the company's risk profile or commit it well beyond ordinary operations. Typical board-reserved items include any transaction above the highest dollar threshold, mergers and acquisitions, equity issuance and financing rounds, executive compensation for C-suite roles, dividend declarations, material litigation or settlements, and anything that touches the company's charter or bylaws. A real example sits in the public record: a delegation of authority policy filed with the SEC reserves major commitments for board sign-off while delegating day-to-day authority down the chain.
Executive Sign-Off
The C-suite owns the band between the function heads and the board: large vendor and capital commitments, non-standard customer contracts above a meaningful ACV, executive hiring, and settlements that are material but below the board line. This is where a CFO co-sign on spend and a GC co-sign on legal risk usually live.
Manager and Director Sign-Off
Managers and directors handle the volume: standard-form contracts, in-budget purchases, hiring within approved headcount, and routine renewals. The goal here is speed. If a salesperson cannot close a standard deal without three approvals, the policy is creating the bottleneck it was meant to remove. Push routine, low-risk decisions as far down the chain as your risk tolerance allows, and keep the heavy sign-off for the decisions that earn it.
Write the Controls Into the Policy
A threshold matrix is only as good as the controls that enforce it. Three controls do most of the work, and each one is a short clause you can lift straight into your draft.
- Segregation of duties. The person who requests a commitment should have a separate approver on anything above a nominal floor. Pair Request authority with a distinct Approve role.
- The aggregation rule. Sum related commitments to the same vendor or for the same project over a rolling 12-month window so split transactions cannot dodge a threshold.
- An exception path. Real life produces urgent, off-matrix decisions. Define who can grant a documented exception, in writing, with a time limit, so the exception does not quietly become the new rule.
Here is the aggregation clause, ready to adapt:
Related commitments to the same counterparty or for the same project are aggregated over a rolling twelve-month period for threshold purposes. No employee may divide a commitment into smaller parts to avoid an approval threshold.
The exception clause follows the same copy-and-adapt pattern:
An exception to this Policy may be granted only in writing by the CFO and General Counsel jointly, must state its scope and expiration date, and must be reported to the Audit Committee at its next meeting. The Legal Department maintains a log of all exceptions and reviews it quarterly.
Sub-delegation rounds out the enforcement layer. Authority holders go on leave and deals keep moving, so let an approver hand authority to a named direct report in writing, for a defined period, capped at the delegator's own threshold, with a copy filed with legal. The clause is one sentence:
Sub-delegations must be in writing and state the scope, the dollar limit, and the end date, and sub-delegated authority may not be re-delegated.
This is also where automated review comes in. A delegation of authority policy lives or dies on whether the people committing the company apply it to the contract in front of them. With GC AI for Word, an in-house lawyer can run a contract against the company's standard positions and surface the dollar value, the term length, and the non-standard clauses that determine which approval threshold applies, without leaving the document.
Alexis Palmer, Senior Managing Counsel at Snyk, described the gut-check that makes this work:
I can see whether a trademark issue is going to be thorny or straightforward. GC AI gives me a really nice gut check so I know if I can knock it out in 30 minutes or need to carve out more time.
A threshold policy automates that triage instinct at scale. Palmer also bakes her standards into reusable prompts so the rest of her team applies the same review when she is out: “Having saved prompts means anyone on my team can run the same review I would. If I'm on PTO, I know they'll get a similar result and apply their own judgment from there.” A delegation of authority policy is that same idea written for the whole company, and Playbooks let legal encode the approval logic so contract review flags the threshold before the document ever reaches the wrong signer. Watch Playbooks apply a team's standard positions to a live contract in the Playbooks demo. We teach the fuller method in how to build a contract playbook.
GC AI is an enterprise-grade legal AI platform purpose-built for in-house teams, used by 2,200+ legal departments across 50+ countries as of October 2026, including the teams at Liquid Death, Snyk, Tipalti, and Columbia Sportswear, plus 300+ public companies.
You can see how it compares in our guide to the best legal AI tools for in-house counsel. In a December 2025 ROI study of more than 100 active customers, those teams reported saving an average of 14 hours per week, much of it on the contract triage that feeds an approval matrix.
The policy protects the company only at the moment someone checks a real contract against it.
When Someone Signs Outside the Policy
A contract signed outside a delegation of authority policy can still bind the company. Under the doctrine of apparent authority, applied in a fact-specific, jurisdiction-dependent way, courts can hold the company to a deal when the counterparty reasonably believed the signer could commit it, and the company can also ratify an unauthorized commitment after the fact by accepting its benefits. The policy is an internal control; the counterparty across the table has never seen it.
So the consequences section does three jobs. It states that a commitment made outside the policy is unauthorized. It requires immediate reporting to legal, because the company's options narrow the longer an unauthorized deal runs. And it preserves the company's choice to ratify or unwind. Here is language to adapt:
A commitment made outside this Policy is not authorized by the Company. Employees must report any unauthorized commitment to the Legal Department immediately, and the Company may in its discretion ratify or unwind it. Employees who exceed their delegated authority are subject to disciplinary action.
Two audiences will read this section closely. If you are at a public company, your auditors test approval controls as part of internal controls over financial reporting, and a matrix nobody follows shows up in that testing. And in any acquisition, the diligence request list asks for the delegation of authority policy along with evidence the company follows it.
Write the consequences section on the assumption that the contract may bind the company anyway; the policy's job is to surface the breach while you can still do something about it.
Set a Review Cadence
A delegation of authority policy goes stale faster than most governance documents because the business it governs keeps changing. Set a fixed review cadence and write it into the policy itself.
- Annual full review. Once a year, legal walks the matrix with finance and the function heads to recalibrate thresholds against the current budget, headcount, and risk appetite.
- Event-triggered review. A financing round, an acquisition, a new business line, or a reorganization changes who should hold authority. Trigger a review on any of these events as well as on the calendar.
- Quarterly exception audit. Pull the exceptions granted that quarter. A rising count of exceptions in one category is the signal that a threshold is set wrong and the policy is fighting the business.
Document the owner, the version, and the effective date on the policy so anyone can see when it was last current. Date the policy and name its owner, and the team treats the matrix as the rule.
Assemble Your Delegation of Authority Policy
Everything above assembles into a ten-section working document, in this order: purpose, scope, the four approval levels, general principles (role-based authority, total contract value, aggregation, segregation of duties, no self-dealing), the approval matrix, board-reserved matters, sub-delegation, exceptions, unauthorized commitments, and review. Write each section from the model language in this guide, drop in your own dollar amounts, and circulate the draft to finance and the function heads for calibration.
To pressure-test your draft, run a handful of your real contracts and purchase orders through it and confirm each one routes to the approver you would expect. The gaps you find in that test are the gaps a new GC would have found six months in, the way Chuck Kable did, except you will have found them first.
Build the Policy, Then Let It Run Itself
A delegation of authority policy stops being a PDF the day every contract routes to the right approver on its own. Write the ten sections, calibrate the dollar ladder with finance, name the board-reserved items, drop in the aggregation and exception clauses, and put the review date on the calendar. Start this week and you can have a calibrated draft in front of finance before the next contract gets stuck waiting for an answer nobody wrote down.






