The approval tier state machine

Featurekamo-shared-library
Shipped
August 12, 2026 at 1:53 AM UTC
Author
Kamo
Commit
fad32fb

Employee submits -> manager approves -> payroll closes, per the owner's decision. Four rules, enforced in a pure transition table and pinned by 25 tests: 1. A manager CANNOT approve until the employee has submitted. The submission is the employee's own assertion that the hours are theirs and complete; approving without it approves nothing anyone attested to. 2. Manager approval LOCKS the employee out of further edits. 3. A manager MAY act on behalf -- submit or approve -- and that is the only sanctioned route past rule 1. It requires a written reason, and the row records both the manager who clicked and the employee stood in for. 4. Payroll may edit in ANY state including locked, always with a reason. Corrections after close are routine and legally required; forbidding them just moves the edit out of the audit trail. Segregation of duties lives in the transition table, not in role naming: nobody approves their own timecard, and a manager is somebody's employee too. Unapproving cascades from PAYROLL_LOCKED all the way to SUBMITTED, because withdrawing an approval invalidates the lock built on it. Approvals are scoped to a DATE RANGE so a mid-period approval survives a later edit outside its scope instead of silently covering work it never saw.

All changes

Like what you see shipping?

Every one of these updates lands in your workspace automatically. Start free and watch it grow week after week.

Start Free ForeverView Pricing