Approval Is Not Verification
Workflows fail because they promise a check nobody can perform. Naming the smaller thing the approver can honestly do makes the control real.
Standard four-stage workflow
No review possible
Submitted
Submitted Friday
Approved
Approved Monday
Time taken
3 stages passed
Employee, manager, finance, payroll · No stage held independent knowledge of the hours.
A great deal of effort goes into workflows that ask managers to confirm something they are structurally unable to confirm. The manager did not watch the week. They have no independent record of it. In a hybrid or field organisation they may not have seen the person at all.
The approval issue in “Approval Is Not Verification” becomes easier to diagnose when the record shows both the submitted hours and the operational context around them. A team evaluating how employees cheat time trackers for how employees cheat time trackers should define what an approver must actually check, how a disputed entry is returned and which activity signals are context rather than proof that the work occurred.
Asking them to verify the hours is asking for a lie, and they supply one, by pressing Approve. The workflow then reports that verification occurred. Everyone involved knows it did not, and the knowledge is carried silently until something goes wrong and the absence becomes a finding.
For a separate benchmark relevant to “Approval Is Not Verification”, consult the NIST Privacy Framework. Use it to test record quality, approvals, retention, employee rights and exception handling against the real workflow rather than treating a software report as self-explanatory evidence.
The smaller claim that is actually available
An approver can honestly assert a narrow set of things, and the narrow set is worth more than the broad one because it is true.
They can confirm that the person was assigned to that work in that period, which they know from the rota or the project allocation. They can confirm that the pattern is consistent with what they expected, and flag it where it is not. They can confirm that the cost codes used are codes the person was entitled to use. And they can confirm that nothing in the submission contradicts anything they independently know — an absence they authorised, a site visit they arranged, a day the person was with them.
That is a real control. It catches miscoding, it catches hours on a project the person left two months ago, it catches the week submitted for somebody who was on leave. It does not catch a person who worked seven hours and wrote eight, and no approval workflow ever has.
Why the broad promise is worse than useless
A control that claims more than it delivers displaces the controls that would have worked. If approval is believed to verify hours, nobody builds the reconciliation that would actually detect inflation — comparing recorded hours against access logs, against delivery, against the client's own record of attendance, against the rota.
It also fails loudly when tested. An auditor who asks the approver how they verified the hours, and receives the honest answer, has found a control failure. The same auditor told in advance that the approval confirms assignment and coding, with reconciliation handled separately, finds a control that works as described. The second organisation is not better behaved than the first. It has simply written down what it does.
Writing the smaller claim into the system
Put it on the screen. The approval dialogue in most products takes a configurable line of text, and almost everybody leaves it as "Approve this timesheet?" Replacing that with the specific claim — you are confirming the assignment and the coding are correct and that nothing here contradicts what you know — takes ten minutes and changes what the approver believes they are doing.
Put it in the policy, and put the same words in the induction for new managers. Then put it in the audit trail, so the record of approval carries the definition that was in force at the time. Definitions change; a record that says "approved" without saying what approval meant that year is much weaker three years later than one that stored the text.
What has to exist alongside it
Naming the limit creates an obligation to cover what the limit excludes. If approval does not verify hours, something has to, or the organisation has decided it does not need to, and that decision should be deliberate and written rather than accidental.
For most organisations the answer is sampling plus reconciliation. A small sample of weeks checked properly against an independent source, quarterly, finds systematic problems at a cost a universal check could never reach. Reconciliation against whatever other record exists — badge data, vehicle telematics, client sign-in sheets, delivery records — catches the gross cases continuously. Neither requires the manager to pretend.
The conversation this makes possible
Managers given an honest definition of their role in the workflow generally engage with it, because it is achievable. The common objection to timesheet approval is not that it is tedious; it is that it is fake, and people resent being made party to something fake.
The organisations where approval functions are, without exception, the ones that asked for less. They asked for a specific, bounded confirmation that the approver was in a position to give, they built something else to cover the rest, and they stopped describing the result as verification.