How to Set Up Bill Approvals in Xero (And Where Native Workflows Fall Short)

Step-by-step guide to setting up bill approvals in Xero, what the native workflow covers, and where Australian businesses hit limits.

Joey Hotz · 13 May 2026 · 11 min read · Updated 13 May 2026

TL;DR

Xero has a bill approval workflow controlled through user permissions, but it only supports a single approval step with no threshold-based routing. Any user with Standard or Adviser access can approve any bill regardless of amount. Businesses needing multi-level approvals or spend controls need a dedicated AP workflow tool.

Xero has a bill approval workflow and it works. It’s also thinner than most businesses expect, and you usually find that out 50 invoices deep, when you notice the project manager just approved a AU$75,000 subcontractor payment using the same permissions they use for a AU$200 stationery bill.

Xero gives you one approval step and no threshold rules. Here’s how to set it up, and what to add once one step stops being enough.

How Xero bill approval works

There’s no “approval workflow” feature in Xero in the way most people picture it. No settings page where you configure routing rules or build approval chains. The whole mechanism lives in user permissions and bill statuses. For how approvals fit into the wider job of setting up AP in Xero and MYOB, see our pillar guide.

Step by step, it goes like this.

Step 1: Set up user roles correctly

The approval workflow starts in Settings > Users. Xero has three user role levels that matter for bill approval:

  • Invoice Only (Draft): Can create bills, but every bill they enter lands in the Awaiting Approval queue. They cannot approve or pay bills. This is the role for AP officers or staff who enter invoices.
  • Standard: Can create, view, and approve bills. A Standard user can move a bill from Awaiting Approval to Awaiting Payment. They cannot process payments.
  • Adviser: Full access. Can create, approve, and pay bills. Can also bypass the Awaiting Approval queue entirely by creating a bill and approving it in the same action.

The critical setup decision: the person entering bills should hold the Invoice Only role. The person approving bills should hold Standard access. Payment access should sit with a third person or be restricted to Adviser-level users who are not the same people entering or approving bills.

This separation is your basic segregation of duties. If one person can enter, approve, and pay a bill, the approval step is decorative. For more on structuring authority levels, see our guide on delegation of authority for Australian SMBs.

Step 2: Enter a bill for approval

When an Invoice Only user creates a bill in Xero under Business > Bills to pay > New Bill, they fill in the supplier, amounts, account codes, and tax treatment, then click Save. If you need to check the GST component on a line before entering it, our GST calculator adds or removes the 10% instantly. The bill goes into Awaiting Approval status automatically. There is no “submit for approval” button. The status assignment is driven by the user’s role, not by a setting they select.

Step 3: Approve the bill

The approver (Standard or Adviser user) goes to Business > Bills to pay and filters by the Awaiting Approval tab. They open each bill, review the details, and click Approve. The bill moves to Awaiting Payment.

That’s the entire workflow. Bills are approved one at a time, there’s no batch option, and notifications don’t go beyond Xero’s standard activity feed. You can’t leave an approval comment or log a rejection reason, and the record you’re left with says “User X approved this bill on this date.”

What Xero’s native bill approval does

So what you get is this. Bills entered by Invoice Only users have to be approved before they can be paid, one authorised user approves each bill individually, approved bills move to Awaiting Payment where a separate person can pay them, and the bill history shows who approved it and when.

For a business with one AP officer, one approver and 20 invoices a month from known suppliers, that’s genuinely fine. The approver sees every bill, the volume is low enough to read each one properly, and the supplier list barely moves.

What does Xero’s native bill approval not do?

Past that point the gaps start to matter. Xero’s approval workflow won’t:

Enforce approval thresholds. A Standard user approves a AU$500 bill and a AU$150,000 bill with the same click. You can’t configure rules like “invoices above AU$10,000 require the CFO” or “invoices above AU$50,000 require dual approval”. Your approval matrix lives in a document and Xero has never read it.

Route bills to different approvers. Every bill in the Awaiting Approval queue is visible to every user with Standard or Adviser access. Nothing routes by supplier, category, cost centre, tracking category or entity. Either the AP officer chases the right person for each bill, or approvers work out which ones are theirs.

Support multi-level approval chains. One person approves, and that’s the only shape available. Sequential approval (operations manager, then CFO), parallel approval across two department heads, and conditional escalation all sit outside the native workflow.

Validate supplier bank details. If a supplier’s bank account number changes between invoices, Xero won’t say anything. The bill turns up on the same screen as every other bill. Payment redirection fraud, which the ACCC reported cost Australian businesses AU$152.6 million in 2024, works by changing bank details on an invoice that otherwise looks legitimate. The approval step does nothing to catch it.

Catch near-miss duplicate invoices. Xero will flag an exact duplicate, where the contact, reference and amount all match a bill you already have. What gets through is the near-miss: the same invoice resubmitted with a new reference number, or the same job billed twice at slightly different amounts. Those land in the approval queue looking like ordinary bills, and the approver has to spot them.

Match invoices against purchase orders. If a PO was raised in Xero, the approver opens it in another tab and compares it line by line against the bill. There’s no matching, no variance flagging and no exception routing to pick up the difference.

Produce a controls-grade audit trail. Xero records that approval happened. It doesn’t record what was checked, whether the amount sat inside the approver’s authority, whether anyone noted an exception, or what the supplier’s bank details were at the time. That’s a problem when the ATO or an external auditor asks. Xero can tell you who clicked approve. It can’t tell you what they looked at first.

What Xero does vs what you probably need

What it doesXero nativeWhat most industrial businesses need
Basic approve/rejectYesYes
Approval thresholds by dollar valueNoYes, enforced rather than advisory
Multi-level approval routingNoYes, sequential and parallel
Routing by supplier, category, or entityNoYes
Vendor bank detail validationNoYes, flagged for review before approval
Duplicate detection before approvalExact matches onlyYes, including near-matches at intake
PO matchingNoYes, two-way at line level
Audit trail with control evidencePartial: who approved, whenFull: what was checked, authority level, exceptions
Mobile approvalVia Xero app (limited)Yes, with full context on mobile
Batch operationsNoYes

Sole trader or a two-person operation? The left column is plenty. Once you’ve got several approvers, invoices ranging from AU$200 to AU$200,000, and suppliers who occasionally change bank details, the left column leaves you exposed.

The workarounds businesses use (and why they break)

Before buying a dedicated tool, most businesses try to bridge the gaps by hand. Three come up over and over.

Email chains for routing. The AP officer emails specific invoices to specific approvers based on the internal policy. The approver reads the email, logs into Xero, finds the bill, approves it. Fine at low volume. At 40 invoices a week the email thread becomes the bottleneck: approvers miss emails, bills sit in the queue, and month-end turns into a scramble.

Spreadsheet threshold tracking. The AP officer keeps a spreadsheet logging each bill, the amount, and who should sign off under the delegation-of-authority policy. It’s a real control, right up until the person maintaining it takes leave, or it falls two days behind the actual queue.

Verbal approvals. The site manager walks past the finance desk and says “yeah, approve that one.” Nothing gets written down, so when an auditor asks later there’s nothing to show them.

All three work for a while and none of them scale. More to the point, none of them leave evidence that the control was applied, which is the thing you need when something goes wrong.

The ATO expects businesses to maintain records that demonstrate who authorised expenditure and at what level. A delegation-of-authority policy that exists only in a PDF and is enforced only by memory does not meet that standard once invoice volumes and approval complexity grow.

When to move beyond Xero’s native approval

The signals are consistent across businesses:

  • A second approver is needed and there is no way to route bills to the right person
  • Invoice volume passes 30-40 per week and manual routing becomes unreliable
  • A duplicate invoice gets through and is paid before anyone notices
  • A supplier changes bank details and no one flags it before payment
  • An auditor asks how approval thresholds are enforced and the answer is “the AP officer knows the policy”
  • The business adds a second Xero organisation and needs consistent controls across both

Any one of these is enough. Most businesses hit two or three before they act.

How Pulsify extends Xero’s bill approval workflow

Pulsify sits upstream of Xero. Invoices land in Pulsify first, where they’re captured, coded, validated and routed through an approval workflow you configure. The bill only syncs to Xero once it’s approved, arriving as an authorised entry ready for payment. Xero stays your ledger and keeps doing the recording, reconciliation, BAS and reporting.

Routing and thresholds are the main thing you’re buying. You set dollar-value thresholds per role: project manager up to AU$10,000, financial controller up to AU$50,000, anything above that escalating to a director on its own. An approval attempt past someone’s limit gets blocked, with no override sitting next to it. On top of that you can build sequential chains, parallel approval, dual sign-off above a set figure, and routing by supplier, category, cost centre or entity, so the rules in your delegation-of-authority policy are the rules the system runs.

Then there are the checks that happen before anyone sees the bill. Every incoming invoice is compared against the supplier’s bank details on file, and a changed BSB or account number raises a flag on the invoice before it reaches the approval queue, so the approver sees the change highlighted and decides what to do about it. Invoices are checked against existing records at intake too, with exact matches and near-matches flagged and held for review. If a PO was raised, Pulsify matches the invoice against it at line-item level and flags the variances instead of leaving someone to eyeball two tabs.

The audit trail is the part auditors care about. Every action gets recorded: who captured the invoice, how it was coded, which validation checks ran, who approved it, when, and what their delegation limit was at the time. It’s immutable and exportable.

Coding accuracy comes from the sync. Pulsify pulls your chart of accounts, tracking categories, tax rates and supplier list out of Xero, so the coding starts from your real data rather than a guess, and approved invoices publish back as bills without anyone re-keying them or shuffling a CSV around.

For a detailed comparison of how Pulsify stacks up against other approval workflow tools for Xero, see our comparison of the best invoice approval workflow software for Xero.

See how Pulsify works, read up on approval workflows, or start a free trial.


Sources: Xero Central - Add and approve a bill · ATO - Record-keeping requirements for business · ACCC - Targeting scams report


Further reading: Best Invoice Approval Workflow Software for Xero · Invoice Automation: Data Entry vs Controls · Invoice Approval Software: Native vs Dedicated Tools

Automate your AP

30-day free trial. Connect Xero or MYOB in minutes.

Frequently asked questions

How do I turn on bill approvals in Xero?
Xero's bill approval workflow is controlled through user permissions, not a single toggle. To require approval before a bill is authorised, assign the person entering bills the Invoice Only role (with Draft permissions). Bills they create will land in the Awaiting Approval queue. A user with Standard or Adviser access then approves each bill individually. There is no separate approval settings page to enable.
Can Xero route bills to different approvers based on dollar amount?
No. Xero does not support approval routing by dollar value. Any user with Standard or Adviser access can approve any bill regardless of amount. If your business requires different approvers for different spend levels, you need a dedicated AP workflow tool that enforces threshold-based routing outside Xero.
Does Xero support multi-level bill approval workflows?
No. Xero provides a single approval step. A bill moves from Awaiting Approval to Awaiting Payment when one authorised user approves it. There is no option for sequential or parallel approval chains, dual sign-off requirements, or escalation rules within Xero's native workflow.
What is the difference between Xero's Awaiting Approval and Awaiting Payment statuses?
Awaiting Approval means a bill has been entered but not yet authorised. Awaiting Payment means the bill has been approved and is ready to be paid. The approval step sits between these two statuses. Only users with Standard or Adviser permissions can move a bill from Awaiting Approval to Awaiting Payment.
When should a Xero user add a dedicated bill approval workflow tool?
Once more than one person needs to approve bills, or different invoice amounts should route to different approvers, you have already passed what Xero's native workflow can do. The other common triggers are needing vendor bank detail validation before approval, duplicate invoices getting through, and an auditor flagging the approval process as a control gap.

Ready to automate your AP?

Go beyond capture and basic workflows. Pulsify codes, validates, routes, and syncs every invoice automatically.