Select your platform and then browse by platform category

Who are you and what section are you in?

Learn about Restrict Admin Overrides in Workflows

Available for the following HR Classic plans: Free, Standard, Premium, Platinum
Available for the following user access levels: Manager, Admin

The Restrict Admin Overrides toggle button lets you enforce mandatory approvals for specific workflows. When toggled on, admins cannot skip steps, ensuring compliance. This setting is locked once published for stability. If no approver is found with this toggled on, the workflow owner is notified. Admins explicitly assigned as approvers can still approve.

Restrict admin overrides

If toggled OFF:

  • Admins can override approval steps as needed.
  • However, in the case where the default workflow (OFF) and another custom workflow (ON) are published at the same time, any leave request that matches both workflows will have admin overrides restricted (even when it is off for the default workflow).

If toggled ON:

  • Admins are strictly prevented from overriding any approval steps within that workflow.
  • Employment Hero will fully enforce the designed approval path with no bypass allowed.
What does Restrict Admin Overrides do?

Restrict Admin Overrides is a setting you can turn on for a workflow to stop administrators from bypassing its approval steps. It's designed for workflows where every request — even one submitted by an admin — needs to go through the proper approval chain (for example, workflows tied to compliance requirements).

The setting is off by default for every workflow, and needs to be turned on manually in your Workflow Settings for each workflow you want it applied to. Once a workflow has been published, this setting is locked — to change it, you'll need to unpublish the workflow, update the setting, and republish it.

What actually happens when the setting is turned on?

When Restrict Admin Overrides is turned on for a workflow:

  • Admins can't bypass any approval step, whether they try via the main app or the API.
  • If no valid approver can be found for a step, the request is not automatically passed to an admin or owner to approve — instead, it's held, and the person who created the request gets an email letting them know.
  • The request will show a message explaining that it's governed by a workflow that restricts admin overrides.
  • The one exception: if an admin has been specifically set up as an approver within that workflow, they can still approve in that capacity — the restriction only stops admins from using their admin-level bypass, not from approving where they're a designated approver.

When the setting is turned off (the default), admins can override approval steps as needed, and if no valid approver is found, the request automatically falls back to an admin or owner.

Does this apply to every workflow, including the default ones?

Restrict Admin Overrides only applies to custom workflows you've set up — it isn't available on default workflows, which always allow admin overrides.

If a request triggers both a custom workflow (with the setting on) and a default workflow at the same time, the restriction still applies to the whole request. Similarly, if a request triggers more than one custom workflow and any one of them has the setting on, the restriction applies across the whole request — the stricter rule always wins.

If a request doesn't trigger any workflow at all, there's no restriction to enforce, so an admin override is allowed.

Does Restrict Admin Overrides apply when an admin submits a request for themselves?
Yes. Across all request types — Leave, Expenses, and Employee File Changes — if an administrator creates a request for their own account, Restrict Admin Overrides applies as expected. The request still goes through the normal approval process.
Does Restrict Admin Overrides apply when an admin creates a request on behalf of another employee?

It depends on the request type:

Request type Admin submits for themselves Admin submits on behalf of an employee
Leave Restrict Admin Overrides applies Restrict Admin Overrides does not apply — the request is automatically approved
Expenses Applies Applies
Employee File Change Applies Applies

For Expenses and Employee File Changes, the behaviour is consistent no matter who the request is for. Leave is the exception — see below for why.

Why is Leave different?

When an administrator submits a leave request on their own behalf, it's processed through the same approval system used for Expenses and Employee File Changes, so Restrict Admin Overrides is checked and applied.

When an administrator submits a leave request on behalf of an employee, it's automatically approved through a separate, legacy process rather than the standard approval system. Because this request never goes through the standard approval process, there's no point at which Restrict Admin Overrides is checked — so it doesn't apply, and the leave is approved automatically.

We know this differs from what many customers expect, and we're calling it out clearly here so there are no surprises.

What should I do if I don't want admin-submitted leave (on behalf of employees) to be auto-approved?

This isn't currently supported — there's no setting that extends Restrict Admin Overrides to cover this specific scenario today. If this is something you'd like to see supported, we'd encourage you to submit a Feature Request so it can be considered and prioritised.

How do admin overrides interact with two-level leave approvals?

Where an admin override is permitted, it only skips the approval step that's currently pending — it doesn't undo steps that have already been completed. So if a leave request needs approval from two people and both are still pending, an override skips both. If the first approver has already approved, an override only skips the second (remaining) approval.

Known limitations with Restrict Admin Overrides
In some rare cases where multiple workflows are triggered by the same event and have conflicting admin override settings (e.g. one has "Restrict Admin Overrides" enabled and another does not), Employment Hero may behave inconsistently due to the non-deterministic order in which messages are processed. This can result in an admin approval being created, even when it should have been blocked.
What if a workflow is unpublished after a request has already been submitted with Restrict Admin Overrides?

Restrict Admin Overrides is evaluated at the time a request is triggered, not at the time an admin attempts to override.

Once a request is created, it inherits the toggle setting from the workflow version that was active at that moment.

This enforcement state is persisted for the lifetime of the request, even if the workflow is later unpublished or the toggle is changed.

This ensures:

  • Consistent enforcement for each request.
  • No retroactive changes to approval rules
  • Clear audit trails and compliance alignment
In which features can I Restrict Admin Overrides?
The Restrict Admin Overrides feature exists across Leave, Expense, and Employee File Change workflows, with any workflow-specific differences called out where applicable.
Does Restrict Admin Overrides apply when an admin submits a request for themselves?
Yes. Across all request types — Leave, Expenses, and Employee File Changes — if an administrator creates a request for their own account, Restrict Admin Overrides applies as expected. The request still goes through the normal approval process.
Does Restrict Admin Overrides apply when an admin creates a request on behalf of another employee?

It depends on the request type:

Request type Admin submits for themselves Admin submits on behalf of an employee
Leave Restrict Admin Overrides applies Restrict Admin Overrides does not apply — the request is automatically approved
Expenses Applies Applies
Employee File Change Applies Applies

For Expenses and Employee File Changes, the behaviour is consistent no matter who the request is for. Leave is the exception — see below for why.

Why is Leave different?

When an administrator submits a leave request on their own behalf, it's processed through the same approval system used for Expenses and Employee File Changes, so Restrict Admin Overrides is checked and applied.

When an administrator submits a leave request on behalf of an employee, it's automatically approved through a separate, legacy process rather than the standard approval system. Because this request never goes through the standard approval process, there's no point at which Restrict Admin Overrides is checked — so it doesn't apply, and the leave is approved automatically.

We know this differs from what many customers expect, and we're calling it out clearly here so there are no surprises.

Explore related content

Was this article helpful?
0 out of 0 found this helpful