We digitised our own approval workflow
Leave, time off, claims, extension of work and incident reports used to move on paper and in WhatsApp. Here is how we rebuilt them into one inbox — and what an approval has to survive before anyone can trust it.
Story curated by Muhammad Syazz · Junior Developer — Published 25 September 2026, 9:00 AM MYT · 3 min read
Every company has the same quiet bottleneck. Someone fills in a form, walks it to a manager, and waits. The manager is on site, or on leave, or the form is in a bag in a car. Payroll closes on the 25th regardless.
We build the workforce platform our clients run their operations on — so we ran our own approvals on it first. Five request types, one inbox, and one rule: a request is never stuck on a person who is not there.
What was actually broken
The forms were not the problem. The routing was.
A form is only as fast as the person holding it
A leave form on a desk is invisible. Nobody knows whether it is approved, rejected, or under a pile of other paper.
WhatsApp is not an audit trail
“Approved 👍” in a group chat is not something you can show a payroll auditor six months later.
The bottleneck is always absence
The one manager who can approve is the one on site, on leave, or on a plane. Everything behind them stops.
Nobody could answer “where is it?”
The most common question about any request was its status — and the only way to answer was to go and ask someone.
So we stopped moving paper faster and gave every request a route instead of a recipient.
Five requests, one inbox
We mapped every paper form in the company onto one of five request types. Each one knows where it goes without anyone deciding.
Leave
Annual, medical, emergency and unpaid — the balance is checked before the request is even submitted.
Time off and extension of work
Short absences and overtime, tied to the same schedule that clock-in already reads from.
Claims
Expenses with the receipt attached at the moment of claiming, instead of reconstructed at month end.
Reports
Incidents raised from the field, routed by post and site rather than by whoever happens to be reachable.
From the app we use ourselves
Screens from the workforce platform our own team submits and approves on.
The hard parts
An approval looks like a button. It is a financial and legal act, and it has to behave like one.
An approval is a signature
Tapping approve releases money or takes someone off a shift. Face ID, fingerprint or device PIN sits in front of approving, rejecting and delegating, so the person who approved is provably the person holding the phone.
Absence cannot stop the queue
Approvers delegate. The delegation is recorded as its own act, with the same biometric confirmation, so the trail shows who approved and under whose authority.
Not everyone reads English
A Malaysian workforce reads English, Malay, Mandarin, Tamil and Nepali. An approval flow nobody understands is an approval flow nobody trusts, so the app shipped in all five.
The web needed the phone
Sensitive actions started on a desktop are confirmed on the registered handset. The phone approves sign-ins and protected actions, rather than a code sent by SMS that anyone can read over a shoulder.
What we measure now
The metric we care about is not how many approvals happened. It is how many are waiting.
Pending is the number that matters
A healthy inbox reads zero. Anything else means somebody is waiting on somebody.
Every request carries its own history
Raised, routed, approved or rejected, by whom and when — attached to the request itself, not to a chat thread.
Push, instead of chasing
Attendance, approvals and updates arrive as notifications, so nobody refreshes a screen to find out where something got to.
Payroll reads the same record
Approved leave and claims land in the pay run directly, so the number on the payslip and the number in the request are the same number.
Where it landed
We use it every working day, and the same platform now runs approvals for the clients we built it for. The forms did not get shorter. They just stopped sitting on desks — and the question changed from “who has my form?” to nothing at all, because there is nothing to ask.
Built with
Native iOS and Android, a Node.js and Feathers backend, MySQL for the record and Redis for live state — the same stack behind our fleet and ERP platforms.
Let's start with a FREE RFP Analysis session
Sensitive information shared during RFP sessions is protected under NDA.