

Your approval matrix probably has a dollar amount on it. Under $50,000, a manager signs off. Over that, it goes to the general counsel. That number is easy to write down and easy to defend to an auditor, which is exactly why almost everyone starts there.
It also breaks down fast once your volume goes up. A $48,000 renewal with a liability cap that got quietly widened sails through on the manager's signature. A $52,000 order form with zero changes from your own template sits in the general counsel's queue for a week because it crossed a line on a spreadsheet. The number tells you nothing about which one actually needs a lawyer's eyes.
A dollar threshold is a stand-in for risk, and it's a weak one. Contract value correlates with risk sometimes, and misses it plenty of other times. A low-value agreement with a new data processing clause or an unfamiliar indemnity structure can carry more exposure than a bigger deal that uses your own paper word for word.
ACC's write-up on contract approvals gets at the real question underneath the dollar figure: who should approve the contract before it's signed. That's a roles question, not a math problem. The piece notes that the executive team is the one that decides who approves what, written into a delegation of authority policy that hands specific powers to pre-defined roles for specific contract categories, and that the policy should name roles rather than individuals, since people change jobs and the matrix shouldn't need a rewrite every time someone gets promoted.
Keep the dollar tier. It still matters for things like budget authority and signature limits. But add a second axis: the specific playbook categories your team actually negotiates on, indemnity, data terms, liability caps, exclusivity, termination rights, and assign each one to whoever actually owns that risk, regardless of contract size.
That means a $10,000 vendor agreement with a data processing addendum routes to whoever owns privacy review, and a $2 million renewal that matches your paper word for word doesn't need anyone above the desk that normally handles it. A contract approval matrix works by categorizing agreements based on their financial value, risk profile, and strategic impact, and setting clear thresholds so a contract gets scrutiny in line with its importance. Risk profile is doing at least as much work in that idea as financial value, maybe more.
Write the categories the same way you'd write playbook entries: specific enough that a new hire can apply them without asking someone what "significant deviation" means. "Any indemnity cap below our standard floor" routes one place. "Any change to payment terms past net 45" routes somewhere else. A category called "unusual risk" gives a reviewer nothing to check against, and it'll get applied inconsistently by whoever happens to be reading the file that day.
A matrix that isn't reviewed goes stale the way you'd expect: someone leaves, a new contract type shows up that nobody assigned a home to, and reviewers start guessing or defaulting everything back to the general counsel, which rebuilds the exact bottleneck the matrix was supposed to remove. ACC's guidance on this suggests checking in regularly with the people using the matrix to confirm whether it's still fit for purpose or needs amending, and keeping a record of approvals, dates, and approver comments so there's something for an auditor to look at later.
Put a name on that review, not a department. "Legal ops reviews the matrix" means nobody does it on a schedule. "Priya reviews the matrix every quarter" means someone does.
None of this is a job for software. Deciding who should have authority over a liability clause is a judgment call about your organization, and it belongs to whoever runs legal and the business owners who carry the risk. What software can do is apply the matrix once you've written it down: read an incoming contract against your playbook, flag which categories it touches, and route the file toward the right queue instead of the default one. That's the mechanical, repetitive part, and it's a reasonable thing to hand to goHeather's AI contract review workflow, with the same skepticism you'd apply to any tool that touches something this close to signature authority. Check its routing against a batch of files you already know the answer for before you trust it on the ones you don't.
You don't need fifteen risk categories on day one. Take the five or six clause types that generate the most back-and-forth in your organization right now, assign each one to a role, and leave the dollar tiers in place underneath as a backstop. Add categories as new contract types show up, and cut any category nobody has actually hit in the last quarter.
Try goHeather free and see how it tags an incoming contract against categories you define.
This is legal information, not legal advice; consult a lawyer for legal advice.
Jeff Dutton is a lawyer who advises on technology, corporate, privacy, commercial, employment and real estate law.
Jeff founded his own small law firm, Dutton Law, in 2016 (and merged it with a larger firm in 2019). Before that, Jeff was a prosecutor and a commercial law lawyer at a national boutique law firm.
Jeffrey is a frequent lecturer on legal matters and has been published in newspapers and trade journals. In addition, Jeff was the editor and co-author of a leading employment law text for lawyers for many years.
Education:
Western University, BA (2009)
University of Ottawa, Faculty of Law, JD (2012)

Get the latest contract tips, updates, and exclusive content straight to your inbox. Subscribe now and never miss out on what's new in contract law or at goHeather!
Our AI sifts through each clause, identifying potential risks. This enables us to provide quick yet comprehensive contract reviews, equipping you with the legal information you need to make informed decisions.