Ask a finance lead whether their business approves changes to supplier bank details and you'll get a fast yes. Ask the same question of a group running sixty companies and the honest answer arrives slower: in some of them. That pause is the whole problem. It isn't a software problem, and it certainly isn't a competence problem. It's what happens when an approval workflow gets bought once and configured sixty times.
ApprovalMax makes this point well in its own buyer's guide, and it's worth conceding quickly. A tool that connects to your accounting platform has solved a technical problem, not a financial one. Data flows in. Nothing checks it on the way. No rules, no routing, no approver, no record of who agreed to what before it landed in the ledger.
A real approval layer is a different proposition: bills, purchase orders, expense claims, vendor changes and journals routed through rules-based chains, with only the approved result syncing back. The guide also names something most vendors skip: bypass detection, which alerts you when a document misses the workflow entirely or gets edited after approval. Documenting what was approved is easy. Noticing when nobody asked is the harder feature, and the more valuable one.
That distinction is correct. It's also, for most property groups I work with, already settled. They bought the approval tool years ago. The gap is somewhere else.
Here's the scene from inside the books. A group runs sixty companies: a propco holding each asset, an opco trading, a manco running the management function. Entity 1 was set up carefully, back when there was time. Bills route to the financial controller, then up to the FD above a threshold. It works exactly as the policy says it does.
Entity 47 was incorporated two years later, in the fortnight before a deal completed. Someone needed it transacting by Friday. It has the same licence and the same login, and no workflow to speak of. Nobody decided that. It just never got finished, and it has been quietly not-finished ever since.
Both entities "have ApprovalMax". Only one of them is controlled. The group's policy document says both are.
This is why the buyer's-guide question (which tool covers the most document types) doesn't help a group much. Coverage is a property of a configuration, not of a licence. You can own every feature on the comparison table and still run thirty entities where none of them are switched on.
Bypass detection has the same shape. An alert is scoped to the organisation it fires in. It tells you something skipped the workflow there. It says nothing about the estate. Nobody is watching sixty entities at once. They're watching the handful they remember to open, which are reliably the busy ones: the entities where a stray transaction is least likely to matter and most likely to be spotted anyway.
Invoice approval is where everyone starts, because invoices are what finance sees all day. In a property group it's also the cheapest risk on the board.
Two document types carry considerably more, and both tend to sit outside the workflow.
Vendor and bank-detail changes. A group paying main contractors and suppliers moves large sums to a small number of accounts. Changing where that money lands is a two-minute edit to a contact record. It is the highest-value thing an attacker can do inside your finance system, and it is usually waved through on an email from someone who sounds right. A tool that only "connects to Xero" has no opinion on this at all. A tool that approves bills but leaves vendor onboarding to the inbox hasn't closed the gap. It has moved it somewhere less visible.
Journal entries. In a single trading company a journal is a bookkeeping event. In a sixty-entity group it's a transfer between two balance sheets. Intercompany recharges, accruals, revenue recognition adjustments: real money moving between real companies, posted by whoever holds the keys, and in most groups approved by nobody. The audit trail records it perfectly. It simply never asked permission.
Expenses and purchase orders across sites sit in the same category. Routine, distributed, and rarely the thing anyone got round to configuring on entity 47.
The useful exercise isn't a tool comparison. It's a grid: every entity down one axis, every document type across the other, and an honest mark in each cell for whether a rule actually fires.
Most groups have never seen this view of themselves. When they do, two things show up consistently. First, the coverage is patchy in a pattern nobody chose: it tracks the order the entities were incorporated and who happened to set each one up. Second, the worst gaps sit in the entities that transact least. A dormant propco raising one bill a quarter never justified a workflow, so it never got one, and that single quarterly bill goes through unchecked.
Then set the routing by what each entity is for, rather than cloning one template across all sixty. An asset-holding SPV needs almost nothing, but it needs that nothing deliberately. The trading opco needs the full chain. The manco sits somewhere between. Uniform configuration is the same mistake as no configuration. It's just tidier.
On the cost of leaving this manual: Ardent Partners put manual invoice processing at $10.89 per invoice in 2025, against $2.78 for automated teams. The saving is real, and it's the second reason to do this. The first is being able to answer the bank-details question without pausing.
Cloudfox built and configured the finance stack — Xero, ApprovalMax, Syft — across Dandi's sixty-company group. Amy Winter, their Group Finance Director, put it this way: "Managing the finance function across 60 companies requires software that's been set up correctly from the start. Cloudfox built the whole stack and configured it around how our group actually operates rather than a generic template."
The phrase that matters there is the last one. A generic template applied sixty times isn't control. It's sixty copies of a guess. Control is knowing what each entity is for and setting the rules to match, which is a structural question about your group rather than a procurement question about your software. We implement ApprovalMax for PBSA and BTR groups, so weigh the recommendation accordingly. The argument holds whatever you've already bought: the tool is rarely the reason a group is exposed. The unfinished configuration on entity 47 is.
If you can't currently say which of your entities enforce vendor-change approval without opening each one in turn, that's where to start. Send me a message and we'll map it properly: entities down the side, document types across the top, and an honest look at where the rules actually hold. It takes one pass, and the gaps are almost never where people expect them.