Skip to content
Signed, Not Read

Home / The signature

Nine Seconds: Reading the Approval Timestamps

Every workflow records when a timesheet was submitted and when it was approved. The interval between them is the cheapest audit available and nobody runs it.

The signature · Procedure

One approver, one Monday morning

No review possible

Submitted

09:12:04

Approved

09:12:13

Time taken

9 seconds

Approved by operations manager · Thirty-one weeks approved between 09:12 and 09:19.

Two columns exist in every timesheet system ever shipped: submitted_at and approved_at. Subtract one from the other and you have the time the approver spent with the record. It is the only direct measurement of whether the control is a control, it requires no new software, and in most organisations nobody has ever looked at it.

The approval issue in “Nine Seconds: Reading the Approval Timestamps” becomes easier to diagnose when the record shows both the submitted hours and the operational context around them. A team evaluating this reference page for does microsoft teams track your activity should define what an approver must actually check, how a disputed entry is returned and which activity signals are context rather than proof that the work occurred.

The result is usually brutal. A distribution of approval intervals, plotted for a quarter, tends to have a very tall spike in the first ten seconds and a long thin tail. The spike is bulk approval. The tail is the handful of people actually reading.

For a separate benchmark relevant to “Nine Seconds: Reading the Approval Timestamps”, consult the CISA insider-risk mitigation resources. Use it to test record quality, approvals, retention, employee rights and exception handling against the real workflow rather than treating a software report as self-explanatory evidence.

Running it

The query is three lines against whatever the timesheet system exports. Pull submission and approval timestamps for every record in a period, compute the interval, group by approver. If the export does not include both timestamps, ask the vendor; they exist in the audit table even when they are absent from the standard report, and a support ticket will usually produce them.

Plot the distribution rather than the average. An average of four minutes can be forty weeks at two seconds and one at three hours, and the average conceals exactly the thing you are looking for. What you want is the shape: how many approvals happened faster than a human can read a week of entries, which is somewhere around fifteen seconds for a simple sheet and considerably longer for one with project codes.

What the intervals mean

Under five seconds, no review of any kind took place. The approver did not open the detail; they acted on the row in a list. This is not necessarily wrong — see below — but it is not review, and the record should not be described as reviewed.

Five to thirty seconds is a glance at a total. Enough to notice 97 hours in a week, not enough to notice a Tuesday coded to the wrong project. Thirty seconds to a few minutes is a genuine read of a simple sheet. Beyond that you are usually looking at a timesheet somebody had to think about, which is the behaviour the whole workflow is nominally designed to produce.

The other signal is clustering. Thirty approvals inside one minute is a batch action regardless of what the individual intervals say, and batching is visible in the data even when the interface does not offer a select-all.

Where fast approval is legitimate

Speed is not automatically a failure. A supervisor who was on site all week, who already knows what everybody did, and who is confirming a sheet generated from a clock system, can reasonably approve in four seconds. Their knowledge came from the week, not from the screen.

The distinction is whether the approver had independent knowledge. That is a question about the work, not about the software, and the timestamp cannot answer it. What the timestamp does is tell you where to ask. An approver with a median interval of three seconds and a span of eleven people they see daily is plausible. The same interval from a manager who covers four sites and has eighty reports is not, and the conversation that follows is a useful one in both cases.

What to do with the finding

Do not circulate a league table of approvers by speed. It converts a diagnostic into a performance metric, and the immediate response is that everybody leaves the tab open for two minutes before pressing the button, after which the measurement is destroyed and nothing else has changed.

Use it privately, to size the problem and to find the structural causes. An approver whose intervals are all sub-second has too many reports, or no visibility of the work, or both, and those are fixable. A department whose distribution is healthy is evidence that the design can work, and worth copying. The number to report upward is the proportion of hours — not timesheets, hours, weighted by cost — approved in under fifteen seconds, because that figure says how much of the payroll and the billing rests on a control nobody exercised.

Keeping the measurement honest

Re-run it quarterly, and re-run it after any change to spans of control, approval delegation or the submission deadline. All three move the distribution, usually in ways nobody predicted.

And record the figure alongside the completion rate rather than instead of it. A workflow that is 100% complete and 80% sub-fifteen-second is telling you something precise about itself, and the two numbers together are far harder to misread than either alone.