Approval delegation and out-of-office rules: a practical design guide
Design approval delegation rules that keep requests moving during absences without weakening authority, evidence, or separation of duties.

Approval delegation should give one qualified substitute temporary authority to act for an unavailable approver within a defined scope and time window. The delegate should not inherit broader authority, create a new approval path, or erase who originally owned the decision.
A safe rule answers seven questions before the absence starts: who owns the approval, who may substitute, which decisions the rule covers, when it starts and ends, what happens to pending work, how the record attributes each action, and how ownership returns.
Source review: August 27, 2026. This guide provides a workflow-design method, not legal, audit, security, HR, or compliance advice. Your policy and control owners should set the actual authority rules.
Delegation substitutes an approver without changing the authority chain
Approval delegation lets a qualified person act for the original approver during a limited absence. The original role still defines the authority. The delegate supplies temporary coverage.
Keep four mechanisms separate:
- Delegation: A substitute acts for the original approver within the same authority boundary.
- Reassignment: The workflow transfers ownership to another person or role, which may change the later approval path.
- Escalation: The workflow adds attention or moves work upward after a defined condition, such as overdue time or elevated risk.
- Group coverage: Any eligible member of a named group may claim or complete the task under a shared rule.
Oracle's current procurement guidance illustrates the distinction. Delegation substitutes one reviewer while the original hierarchy continues. Reassignment substitutes the new reviewer's hierarchy. Microsoft documents separate delegation rules for out-of-office status, timeout, or both. These are different controls, even when each one prevents a request from sitting untouched.
Use escalation rules when the problem starts after work stalls. Use delegation when the owner cannot act during a known or confirmed absence.
Write a seven-part delegation contract
Do not reduce the rule to “send Priya's approvals to Mateo.” Write a contract that an operator, auditor, and future workflow owner can test.
- Primary owner: Name the person, role, or position that normally owns the approval.
- Eligible delegate: Require the substitute to hold the necessary role, access, training, separation, and subject knowledge.
- Scope: List the decision classes, departments, value limits, regions, systems, and exclusions that the delegate may cover.
- Effective window: Record the start, end, time zone, activation owner, and early-cancellation rule.
- Request handling: State whether the rule covers new requests, already-pending requests, or both.
- Decision attribution: Preserve the original owner, acting delegate, reason for delegation, decision, timestamp, evidence version, and route version.
- Expiry and return: Stop new routing at the end, define what happens to unfinished delegated work, and confirm ownership restoration.
Treat scope and time as independent controls. A delegate may cover purchase approvals below $25,000 for one week, but not security exceptions, employee decisions, or requests from the delegate's own cost center.
Handle new and already-pending requests separately
An out-of-office rule can affect two queues. New requests arrive after the absence starts. In-flight requests already sit with the primary approver.
Choose one rule for each queue:
- New requests: Route directly to the delegate when the request enters the covered stage during the active window.
- Pending requests: Transfer only covered tasks, preserve their original assignment event, and record the transfer reason and time.
- Partially reviewed requests: Decide whether the delegate may continue from the existing evidence or must confirm that the evidence has not changed.
- High-risk requests: Keep them with a named alternate role or escalate them under a separate policy instead of applying the ordinary delegate.
Avoid bulk reassignment without a scope check. A primary approver may hold requests from several decision classes, but the delegate may qualify for only some of them.
When the absence ends, do not pull a task away while the delegate actively reviews it. Use a clear cutoff. For example, let the delegate finish tasks that reached them during the window, while new tasks return to the primary owner after the end time.
Never let delegation expand decision authority
The delegate should pass the same authority test as the original approver for every covered request. A manager's assistant may manage a calendar but still lack authority to approve a contract, grant production access, accept a privacy risk, or commit budget.
Check these conditions before routing:
- The delegate holds the required role or explicit temporary authorization.
- The request falls within the delegate's value, region, department, and decision limits.
- The delegate can access the request and every piece of evidence needed to decide.
- The delegation does not collapse required separation of duties.
- The delegate did not request, prepare, or materially benefit from the item when policy prohibits self-approval.
- Any specialist review remains in the route.
NIST SP 800-53 AC-5 tells organizations to identify duties that require separation and define access authorizations that support that separation. Delegation should preserve those boundaries. It should never become a quiet way around them.
Stop loops and uncontrolled delegate chains
Delegate chains create ambiguity quickly. Priya delegates to Mateo. Mateo delegates to Lin. Lin's rule points back to Priya. The request can cycle, disappear into a queue, or reach someone the policy never approved.
Use these guardrails:
- Set a maximum depth: Prefer one delegate hop. Route a second absence to a named group or escalation owner.
- Reject cycles: Block any rule that points to the primary owner or another person already in the active chain.
- Resolve conflicts deterministically: Define which rule wins when personal, role, team, and emergency coverage overlap.
- Use one active rule per scope: Do not let two delegates hold the same exclusive authority at the same time unless the completion policy permits it.
- Expire automatically: Stop the rule at the recorded end time and notify the primary owner and delegate.
If the workflow cannot evaluate the chain safely, route the request to a controlled coverage queue. A visible exception beats an invisible loop.
Keep delegation and escalation as separate controls
Delegation answers “who may act while the owner cannot?” Escalation answers “what should happen when the current owner does not act within the expected time?”
A request can use both. The workflow may route a new task to the delegate during an approved absence. If the delegate misses the service target, a separate escalation rule can remind them, notify an operations owner, or transfer the task under the escalation policy.
Do not use a timeout as proof of absence. A reviewer may remain available but need more evidence. An out-of-office flag may also stay active after an early return. Keep the trigger, evidence, and owner distinct for each control.
A software-purchase approval shows the contract in practice
Consider a software-purchase request that needs a department manager, Finance above $10,000, and Security when the vendor handles company data.
The department manager schedules leave from Monday at 09:00 Eastern Time through Friday at 17:00. The approved delegate is another manager in the same business unit. The rule covers department approval up to $25,000. It excludes the delegate's own requests, policy exceptions, and any request that grants privileged access.
During the window:
- A $6,000 renewal routes to the delegate for department approval.
- A $14,000 tool routes to the delegate, then continues to Finance.
- A $9,000 tool that handles customer data routes to the delegate and keeps the Security review.
- The delegate's own request routes to the named alternate manager.
- A $40,000 purchase follows the higher-authority route because delegation cannot raise the delegate's limit.
The audit record keeps the primary manager, delegate, effective rule, route reason, acting identity, decision, evidence version, and timestamp. On Friday at 17:00, new requests return to the primary manager. The delegate finishes any covered task already under active review.
Translate the contract into Formaloo with explicit boundaries
Formaloo's current approval workflow guidance uses a request Form, admin-only Status and Assignee fields, Advanced logic, On submit and On update actions, and Table or Kanban Data Blocks for review. Current Assignee guidance explains how rules assign a form submission to a person or team and control what each assignee sees.
Use those documented building blocks to represent:
- the primary approver and active Assignee;
- delegation status, delegate, start, end, scope, and reason as controlled fields;
- request facts that determine whether the delegation applies;
- an On submit or On update rule that assigns a covered request to the approved person or team;
- a Table or Kanban view for delegated, expiring, excluded, and exception work.
Current Formaloo Help Center sources do not document a native out-of-office calendar trigger or dedicated delegation object. Time passing alone does not appear as a documented On update event. Use a controlled manual review or an approved scheduled service to update the relevant field at the start and end of the window, then let the verified assignment rule respond to that change. Confirm plan access, permissions, and the integration design for your workspace.
Keep the detailed authority conditions in your routing specification, preserve acting identities in the audit record, and send uncovered cases into the named exception path.
If you want to map absence coverage into a working enterprise approval workflow, Book a demo.
Test ten cases before the rule goes live
- A covered new request arrives one minute after the start.
- An excluded request arrives during the active window.
- A pending request transfers with its original evidence intact.
- The delegate submits their own request.
- The delegate lacks access to one attachment or field.
- The delegate's value limit sits below the request amount.
- The delegate also becomes unavailable.
- Two active rules point to different substitutes for the same scope.
- A request arrives one minute after the rule expires.
- The primary owner returns early and cancels the remaining window.
For each test, record the trigger, expected owner, actual owner, authority result, notification, audit events, final state, and corrective action. Test access as the delegate, not only as an administrator.
Monitor delegation as an operating control
Track enough data to see whether the rule protects continuity or hides a staffing problem:
- delegated request volume by owner, delegate, scope, and business unit;
- requests that entered exception handling because no eligible delegate existed;
- self-approval and separation-of-duties blocks;
- delegate-chain conflicts and expired rules;
- cycle time and overdue rate for delegated versus ordinary work;
- decisions reversed or returned after the primary owner came back.
Review standing delegates periodically. Remove access when roles change, test long absences before they start, and inspect repeated emergency delegation. If one person's leave stops an essential workflow, the organization has a coverage-design problem, not a calendar problem.
Use this delegation checklist
- The rule names the primary owner and one qualified substitute.
- The scope states covered and excluded decision classes.
- The start, end, time zone, cancellation, and expiry behavior are explicit.
- New and pending requests have separate handling rules.
- The delegate cannot exceed the original authority boundary.
- Self-approval and separation-of-duties controls still apply.
- The workflow blocks loops and uncontrolled chains.
- The record preserves original ownership and acting identity.
- Uncovered work reaches a visible exception or escalation owner.
- The workflow returns ownership predictably when the absence ends.
Good delegation keeps work moving without making authority vague. Give the substitute enough access and scope to decide, keep every boundary visible, and end the rule when the original owner returns.
Sources
- Formaloo Help Center: How to build an approval workflow in Formaloo
- Formaloo Help Center: How to add advanced logic to your form
- Formaloo Help Center: What is On update logic and how it works
- Formaloo Help Center: How to assign form submissions to a person or team
- Microsoft Learn: Setup out of office and delegation
- Microsoft Learn: Configure preset approvals
- Oracle: How to reassign or delegate specific approval tasks
- NIST SP 800-53 Revision 5.1
Sources and product guidance reviewed on August 27, 2026.
.png)







