Finances
Approvals (four-eyes mode)
How to enable approval of sensitive money actions: refunds, balance adjustments and debt write-offs execute only after the owner approves.
Updated:
Approval mode is “four eyes” for sensitive money operations: a staff member’s action doesn’t execute immediately — it becomes a request the owner has to approve. One person initiates, another confirms — so mistakes and abuse get caught before any money actually moves.
The mode is off by default and available from the Studio plan.
How to enable it
- Open Settings → Approvals (the “Finance” group).
- Switch the mode on.
- Choose who may approve: owner + administrators, or owner only.
- Set the request lifetime: 24, 48, 72 hours or a week. If a request isn’t reviewed in time, it expires — and the action can simply be requested again.
- Tick which actions require approval.
By default only the owner can change these settings (the permission can be delegated to a trusted person separately) — a supervised administrator cannot switch the control off for themselves.
Which actions can be guarded
- Refunding a student.
- Manually adjusting a lesson balance.
- Writing off (annulling) invoice debt.
- Cancelling an invoice.
- Marking a teacher payout as paid — single and bulk.
- Recording a manual bank payment (off by default).
What the team sees
When a supervised staff member performs a guarded action, it doesn’t go through immediately: an explanation appears saying an approval request has been created. Repeating the same action doesn’t spawn duplicates — the system recognises an identical request.
How approving works
The owner (or an administrator, if allowed) sees requests in the Approvals section — with three tabs: “Pending”, “My requests”, “History”. The pending count shows as a badge in the menu. A rejection can carry a reason comment.
You can also approve or reject straight from Telegram — with buttons under the notification, no sign-in required.
Three important guarantees:
- The requester can never approve their own request — even an administrator with full permissions.
- An approved action runs as new: with every usual validation against fresh data. If something changed while the request waited (say, the invoice got paid), the system honestly refuses instead of executing a stale action.
- Every step is in the history: who requested, who decided and when, and with what outcome.