What Is a Delegation of Authority Matrix?

Turn this article into takeaways for your work.

Each assistant summarizes the article only for you and suggests best practices for your work.

A delegation of authority (DoA) matrix is a documented schedule of who is allowed to approve what, up to which monetary or risk limit. It's usually a table: decision types down the side, roles across the top, and a threshold in each cell. It's also called an authority matrix or an approval matrix.

In a founder-led company, the founder approves almost everything by default, because nobody ever wrote down who else could. A DoA matrix replaces that habit with a written rule. Small decisions move to the people closest to them, large ones stay with the founder or the board, and everyone can see where the line is.

What a DoA matrix actually contains

Strip away the formatting and a DoA matrix answers four questions for every kind of decision the company makes:

  1. What is the decision? A purchase, a contract signature, a hire, a discount, a payment, a legal commitment.
  2. Who may approve it? A named role, not a named person, so the matrix survives turnover.
  3. Up to what limit? Usually a monetary threshold, sometimes a risk category (any contract with unlimited liability goes up a level, whatever its price).
  4. What happens above the limit? The decision escalates to the next level, and eventually to the founder, the board, or the owners.

The most useful matrices also say who can sub-delegate (pass their authority to someone below them), for how long, and how that gets recorded.

Where it comes from: internal control

The DoA matrix isn't a startup invention. It's a standard tool of internal control, and the usual reference point is the COSO Internal Control-Integrated Framework, whose 2013 edition is meant to help organizations design and implement internal control as their business and operating environments change.

A university internal audit office summarizing that framework, McGill's internal audit page, lists its five components: control environment, risk assessment, control activities, information and communication, and monitoring activities. The DoA matrix sits in the third one. McGill describes control activities as the actions set up through policies and procedures to make sure management's directives are carried out, and it gives "authorizations and approvals" as a typical example.

The same page makes the point that matters for founders: responsibilities for authorizing transactions, recording them, and handling the related asset should be divided among different people. That's segregation of duties. A matrix that lets the person who requests a payment also approve it, and also release it, defeats the purpose.

You don't need a formal COSO program to benefit from this. The principle is simple: no single person should be able to commit the company's money from request to payment without a second pair of eyes.

Board-reserved matters versus management authority

A DoA matrix usually has two layers.

Matters reserved for the board (or the owners). These are decisions the owners keep for themselves: approving the annual budget, raising debt or equity, large acquisitions or disposals, changing the company's structure, appointing or removing senior executives, and anything outside the ordinary course of business. In a private company without a formal board, these often sit with the founder and any co-owners.

Authority delegated to management. Everything else is delegated downward in tiers: the CEO, then the executive team, then department heads, then team leads, each with a lower limit than the level above.

Public bodies show this structure clearly because they publish it. The University of Vermont's contract approval policy says contracts may be signed only under a resolution of the trustees, a valid delegation from the President or the Board, or a purchase made under its purchasing policy. It also requires the Board to approve "certain matters" set out in its delegation resolution. The University of Illinois System's contract approval authority rules are tiered by amount: unit heads approve all contracts in their area, a dean or director signs off from $100,000, a vice-president-level officer from $200,000, and the President and University Counsel from $250,000.

Your company isn't a university, and those numbers aren't yours. But the shape is worth copying: a default rule, tiers by amount, and a top tier that stays with the people who ultimately answer for the organization.

Typical categories in a matrix

Most DoA matrices cover the same handful of areas.

Category Example decisions Common control
Capital expenditure Equipment, software platforms, property, vehicles Tiered by amount, plus budget check
Operating spend Subscriptions, vendors, travel, marketing Tiered by amount, often per transaction and per year
Contracts Customer agreements, supplier agreements, leases, NDAs Tiered by value and by risk terms (liability, exclusivity, length)
Hiring and pay New hires, salary changes, bonuses, terminations Approved budget plus HR and the next level up
Pricing and discounts Standard discounts, special terms, free periods Discount bands tied to role
Payments and treasury Releasing payments, opening bank accounts, signing cheques Two approvers above a limit, separate from the requester
Legal and compliance Litigation, regulatory filings, settlements, IP Founder or board, with legal advice

Notice that some categories use a monetary threshold and others use a risk trigger. A small contract that grants a customer exclusivity can be more dangerous than a large one that doesn't. Good matrices have both kinds of rules.

How thresholds work

A threshold is the maximum value a role can approve alone. Three details make thresholds work in practice.

Define what the number measures. Is it per transaction, per contract, per year, or total commitment over the contract's life? A $9,000 monthly subscription is not a $9,000 decision. Splitting a purchase into smaller pieces to stay under a limit is the classic way matrices get gamed, so many policies measure total value, not each invoice.

Make the tiers cumulative. The person above you can approve everything you can, plus more. Nothing should require two approvers on the same tier unless you want it to.

Add a second signature at the top. The University of Illinois rules above bring in both the President and University Counsel at the highest tier. Companies often do the same: above a certain amount, the CEO plus the finance lead must both approve.

Sub-delegation

Sub-delegation is when an approver passes some of their authority to someone else, for example when they're traveling. It's where DoA matrices most often leak, so the good ones control it.

The University of Vermont policy is a clear example. Its delegations must be in writing, renewed annually, and specify the scope, terms, limits, monetary authority, and duration. Its sub-delegations need the same written record, which has to reach the University Controller and General Counsel within two business days. The Illinois rules similarly require delegation to be documented, and let individual universities lower the thresholds or forbid delegating a given approval at all.

A workable version for a company: delegation is allowed one level only, in writing, with an end date, and never for the approval of your own expenses.

DoA matrix, RACI, and org chart

These three are often confused, and a company usually needs all of them.

Delegation of authority matrix RACI matrix Org chart
Question it answers Who may approve this, up to what limit? Who does what on this task or project? Who reports to whom?
Unit A decision type, with a limit A task or deliverable A person or role
Key feature Thresholds and escalation Responsible, Accountable, Consulted, Informed Reporting lines
Lifespan Standing policy, reviewed yearly Per project or process Updated when structure changes
Typical owner CEO, CFO, board Project or process owner HR

The difference between a DoA matrix and a RACI matrix is that RACI assigns involvement in the work and has no money limits, while a DoA matrix assigns the right to commit the company. Someone can be Accountable for a project in RACI and still have to escalate a $40,000 vendor contract under the DoA. An org chart shows reporting lines, but a manager's place on the chart doesn't tell you what they can sign.

A sample matrix (illustrative only)

Here's a hypothetical example to show the layout. The roles and amounts below are placeholders, not recommendations. Set every threshold to fit your company's size, margins, cash position, and risk appetite. A figure that suits a company with 20 people will be wrong for one with 400.

Decision Team lead Department head CFO / COO CEO / founder Board / owners
Operating purchase, per item Up to A Up to B Up to C Up to D Above D
Capital expenditure (budgeted) No Up to B Up to C Up to D Above D
Capital expenditure (unbudgeted) No No Recommend Up to C Above C
Customer contract, standard terms No Up to B Up to C Above C Strategic or non-standard
Customer contract, non-standard liability No No Recommend Approve Above agreed limit
Discounts off list price Up to X% Up to Y% Up to Z% Above Z% No
New hire within approved budget No Approve Approve Senior roles Executive roles
Release a payment Request only Request only Approve, second signer Approve, second signer No
Borrowing, guarantees, equity issue No No No Recommend Approve

Letters A to D and X to Z stand for numbers the company must choose, with A < B < C < D. The pattern matters more than any number: limits rise with seniority, requesters never release their own payments, and the largest or most unusual decisions go to the owners.

Why founder-led firms need one

The reason shows up in a pattern that Greiner's growth model describes. Growth through direction ends in a crisis of autonomy, where people closer to customers and operations want to decide for themselves. In a founder-led company, that crisis tends to look like a queue outside the founder's door: purchases, discounts, hires, and contracts all waiting for one signature.

A DoA matrix is one of the most direct fixes. It does three things for a founder:

  • It removes the bottleneck. Routine decisions stop waiting for the founder, so the founder's attention goes to the decisions that need it.
  • It makes delegation feel safe. A founder who worries about losing control can say exactly how much they're giving up, and no more.
  • It protects the business if the founder is absent. When there's a written rule for who can sign in the founder's place, an illness or a long trip doesn't freeze payments. This is closely tied to key-person risk.

It also helps the people below the founder. A manager who knows their limit can act without asking permission each time. Building a management team below the founder works much better when those managers have clear, written authority, because a title with no signing power is just a label. For the wider picture of how a founder-run firm becomes an organization that doesn't depend on one person, see professionalizing a business.

How to build one

You can draft a first version in a week.

  1. List recurring decisions. Go through the last three months of requests the founder approved. Group them into the categories above.
  2. Pick tiers. Usually three or four levels is enough for a company with a team below 100 people. More tiers add bureaucracy faster than they add control.
  3. Set thresholds from real data. Look at the size distribution of past approvals. Set the lower tiers so that most routine items fall under them, and the founder sees the minority that really matters.
  4. Add risk triggers. Whatever the amount, escalate anything with unusual legal terms, new categories of spend, or related-party dealings.
  5. Separate request, approval, and payment. Apply the segregation principle above.
  6. Write sub-delegation rules and an exceptions process. Who can cover for whom, and how an urgent exception is recorded afterward.
  7. Publish and review it. Put it where people can find it, tie it to your approval workflow, and review it at least once a year or when the company's size changes substantially.

If your sales team needs discount and contract approvals handled in a deal, internal approvals in deal closing shows how that part of the matrix runs in practice. And delegation as a skill covers the human side: a matrix sets the limits, but managers still have to be willing to use them.

Common mistakes

  • Thresholds copied from another company. The numbers have to reflect your own cash and risk.
  • Naming people instead of roles. The matrix is out of date the day someone leaves.
  • No one enforces it. If the finance team pays invoices that bypass the matrix, it's decoration.
  • Too many exceptions. If the founder overrides it weekly, people learn it isn't real.
  • A matrix with no review date. Authority drifts as the company grows.

Key Facts

Key Facts: Delegation of Authority Matrix

  • A DoA matrix is a documented schedule of who can approve which decisions, up to which limit, with escalation above it.
  • COSO's Internal Control-Integrated Framework (2013 edition) is guidance for designing and implementing internal control, per COSO.
  • Authorizations and approvals are cited as control activities, one of COSO's five components, in McGill's internal audit summary.
  • The University of Illinois System tiers contract approval at $100,000, $200,000, and $250,000 (University of Illinois System).
  • The University of Vermont requires written, annually renewed delegations, and sub-delegations reported within two business days (UVM policy).
  • A DoA matrix assigns approval rights, a RACI matrix assigns roles in the work, and an org chart shows reporting lines.

About the author

Brian Tr

Brian Tr

Co-Founder & COO

Brian Tr is Co-Founder and COO of Rework, with 12+ years in B2B go-to-market and operations. Brian scaled Rework from 0 to 10,000+ B2B customers across CRM and productivity tools. Brian writes for founders and owner-CEOs: startup fundamentals, founder-led and family businesses, partnerships, and how SaaS, marketplace, AI and EdTech companies grow.