Approva
Purchase requests with amount-based sign-off, the rule frozen on the record, and numbered purchase orders.
For finance teams and cost-center owners. Often replaces Precoro, Tradogram or Procurify.
Single license $99 · Extended license $229 · paid once, yours for good
What it does
A request needs one, two or three sign-offs by thresholds you set. Nothing becomes a PO until fully approved.
Per cost center, name the person or people for each level, in order. Only they, or their delegate, can sign it.
The sign-offs a request needs are locked at submission and named on it. A later threshold change never re-decides it.
Each level's people are emailed as the level before is signed. They can add their own Slack, Google Chat, Teams or Discord channel.
One click on a fully approved request makes a sequential, unique PO number and a printable purchase order.
Each cost center can have its own thresholds and a budget per month, quarter or year. Approvers see an over-budget flag.
Record goods received against each PO line, part deliveries included. Email the PO to the vendor from its page, off until you switch it on.
Every request carries an append-only activity log and approval trail. Export it to CSV or JSON at any time.
On final approval or rejection, the requester gets one email through your own SMTP. It is off by default.
An approver hands their approvals to a colleague for a date window. Delegation can never approve the delegator's own request.
A REST API with an OpenAPI spec and signed webhooks. Connect your own agent over MCP, under the same guards a person faces.
Install it from the browser to a phone or tablet home screen. No app store involved.
Also: integer-cent money maths, CSV and JSON export, printable PDFs, file attachments, saved views, two-factor sign-in, backups with a dry-run restore, and dark mode.
Self-hosted without the assembly
The other answer to “self-hosted” is a repository: clone it, read the compose file, provision a database, wire up mail, then keep it patched yourself. That is a fair answer when running infrastructure is already your job, and we would rather say so than pretend otherwise. This is the other kind. It is bought once at $99.00, the full PHP source is in the download, and the web installer finishes on ordinary shared hosting in about two minutes. No Composer, no Node, no build step, nothing to compile, and nothing that phones home.
What Approva deliberately doesn’t do.
- Not an accounting system or ERP; it does not post to a general ledger.
- It does not process payments — Approva approves requests and issues POs; it never moves money or pays vendors.
- No 3-way matching (PO ↔ goods receipt ↔ invoice), no inventory and no encumbrance accounting: budgets flag a request, they never hold money or block one.
- No punchout catalogs or supplier portals — a request describes the purchase in your own words.
- One currency per installation (pick any at install — EUR, GBP, AUD, CAD, CHF and more are formatted natively).
- Single-tenant: one organization per installation.
What renting costs instead
1 month of Precoro costs what Approva costs once.
Read Sep 3, 2026 · source1 month of Tradogram costs what Approva costs once.
Read Sep 3, 2026 · sourceThe full comparison: every rival, what each does better, and who should stay with them →
Replacing one of these? Precoro alternative · Tradogram alternative · Procurify alternative
Release history
For Approva, 4.1 makes two changes that every app gets. What’s new in 4.1 →
For Approva, 4.0 means updates from inside the app: the Updates page checks for a new release with your license key, verifies Ownware's signature, takes a backup and… What’s new in 4.0 →
This release made the approval chain yours: for each cost center you name who signs each level, in order, and each level's people are asked in turn by email, and in… What’s new in 3.2 →
The 3.1 wave gave the catalog a way to reach the other side of the transaction: counterparty email through your own SMTP server, calendar feeds your own calendar…
Approva 3.0 adds an MCP endpoint, so Claude, ChatGPT agents or n8n can list requests, raise them and record approvals through the same guards a person faces — and…
Approva 2.0 adds the 2.0 owner layer.
What’s in the zip
The tree as the zip ships it — the working leftovers the packager deletes are not listed
- .htaccess
- API.md
- Dockerfile
- QUICKSTART.txt
- assets/
- bin/
- config.sample.php
- controllers/
- deploy/
- index.php
- install/
- manifest.json
- offline.html
- router.php
- src/
- sw.js
- tests/
- views/
src/Purchase.php: a real module, the first 24 of 710 lines
Chosen as the largest module in src/ that is not one of the shared cores — this product's own logic, not a file every product carries.
<?php /** * Purchase.php — THE core Approva stands behind (fully covered by tests/run.php, offline). * * Everything money- and workflow-critical lives here and is pure (no network, and only the * DB-collision helpers touch Database, which the test suite stubs). That separation is what * makes the arithmetic and the approval state machine testable in isolation. * * 1. MONEY MATH in integer cents. A line's amount = qty x unit_price, rounded to the nearest * cent (quantities may be fractional). A request's subtotal/total = the sum of its lines. * Same integer-cent discipline used across the Ownware catalog. * * 2. APPROVAL THRESHOLDS. Given a request total and the configured cent thresholds, how many * approval levels are required: below the first threshold -> 1 approver; at or above it -> 2; * each further threshold adds another required approver. * * 3. STATE MACHINE. A request's DISPLAY status is derived, never stored raw: * draft -> pending -> partially_approved -> approved -> po_issued, with 'rejected' as a * terminal halt. Precedence guarantees a rejected request is NEVER shown as approved. * * 4. PO NUMBERS. Sequential, prefixed, zero-padded, unique (collision-checked against the DB). * * 5. EXPORT. RFC-4180 CSV and JSON of the request register. */
Runs on: Two-minute web installer on PHP 8.1+ with MySQL or SQLite; a Dockerfile is also included for containerized deployments. Tested on PHP 8.3. Or run it in Docker: the Dockerfile is in the zip.
Technical owners can install it with one line and their license key: curl -fsSL https://ownware.io/install.sh | sh -s -- approva <your license key>
Nothing is obfuscated or encoded; what you read is what runs. Manual · API · the test run
Which license do I need?
It comes down to how many installations you need. Running your own business on one site is the Single license. A second domain of your own, or sites you build or run for other people, is the Extended license.
- Install it on one domain or subdomain you own or operate
- Change the source however you like for that installation
- Run your own business on it commercially, client work included
- Re-download the current build any time from your buyer portal
- A second site, or an installation you hand to a client as theirs, needs the Extended license
- No reselling, redistributing or sublicensing the source
- Not for offering it to other people as a hosted service
- Everything the Single license grants
- Install it on as many domains as you own or operate — no cap on the number
- Up to ten client installations, one per client project, handed over or hosted for each client; for more, buy another Extended license
- White-label: remove or replace the product name and logo in the screens of client installations
- Still no reselling or redistributing the source itself
- Running it as a multi-tenant service others sign up for needs a SaaS agreement
Every download carries the full terms as LICENSE.txt. The complete wording is on the terms page.
After you buy
The app’s Updates page installs a new release with your license key, with the release’s signature checked and a backup taken first. Your download link always serves the current build. Download again any time from your order page or the buyer portal; there is no renewal fee.
Email support for installation and for defects in the code as delivered: a person reads and answers every message. It does not cover custom development or server administration. What support covers
Refunds are handled by Lemon Squeezy as merchant of record, case by case. EU consumers keep the statutory 14-day right until delivery starts. Refund terms
It keeps running: your server, the full PHP source, no license check that can fail. If no stable release is published for 365 days, the domain limit lifts; after three such years your copy becomes MIT-licensed. The terms have the exact wording: continuity.
Questions
What is Approva?
How do the approval thresholds work?
Is it multi-user? What are the roles?
Does it integrate with QuickBooks, Xero, or SAP?
Can Power Automate or Logic Apps use it?
Does it pay vendors?
Will it run on my shared host?
Can an AI agent really use it — and can it approve things it shouldn't?
What happens when an approver is on holiday?
Covered in these guides
- Supplier and purchase-order software you own
- Self-hosted approval workflow software
- Best self-hosted project management software: six projects, their real prices, and what each needs from your server
- The Back-Office Suite: four kinds of paper, one license
- What's new in Own It 3.1
- Purchase Approvals — The Empty Shelf Between $499 a Month and an ERP Project
Also covered in: What's new in Own It 3.0.
More about Approva
Self-hosted purchase approvals for finance teams and cost-center owners: a request needs one, two or three sign-offs by amount, you can name who signs each one, and the rule that applied is frozen on the record at submission.
The problem it solves
A self-hosted purchase order approval system is a strangely hard thing to buy: procurement SaaS starts at per-user monthly pricing built for enterprises, and the free alternative is email-the-manager-and-hope. Approva is $99 once — amount-based approval chains, numbered POs, plain PHP on shared hosting, and an audit trail finance can actually open.
Someone in your team wants to buy something. Right now that "approval" is a Slack message and a forwarded email, and the first time finance hears about it is when the invoice arrives. Small and mid-sized organizations that have outgrown "email the manager" still lack a repeatable requisition-to-approval-to-purchase-order flow with an audit trail, without buying and configuring a full ERP.
- No threshold-based rule for who must approve a purchase
- No append-only trail of who approved what, when, and why
- Nothing to turn an approved request into a numbered purchase order
Every feature
- Per-cost-center approval rules. Marketing can need two signatures at €250 while the company rule starts at €1,000 — same engine, same audit trail, just a different threshold list per center. Blank means inherit, never "one signature is enough".
- The rule is frozen on the record. Required approvals are locked at submission and named on the request. Tighten a threshold tomorrow and every request already raised keeps the rule it was raised under — an auditor sees the rule that was in force, not today's.
- The requester hears the decision. On final approval or rejection, the person who raised the request gets one email — reference, total, the rule that applied, who decided and their note. Off by default, sent through your own SMTP, and a mail failure never undoes a recorded decision.
- Amount-based approval routing. A request needs one, two or three sign-offs based on thresholds you set — and, if you switch it on, each person who can sign is emailed — and nothing becomes a PO until fully approved.
- Full approval audit trail. Every request carries an append-only activity log and approval trail, exportable to CSV or JSON at any time.
- Numbered PO generation. One click on a fully approved request generates a sequential, unique PO number and a printable purchase order.
- Integer-cent money math. Totals are kept in integer cents throughout, with fractional quantities supported and correctly rounded.
- Two-minute self-hosted install. Installs through a web form on PHP 8.1+ and MySQL or SQLite, with no Composer and no Node; only the optional scheduled backup uses a cron line.
- REST API + signed webhooks. Bearer-key API with the same role guards as the UI, HMAC-signed webhooks on submit/approve/reject/PO, and an OpenAPI spec that imports straight into Power Automate as a custom connector.
- Installable mobile app (PWA). Add it to a phone or tablet home screen straight from the browser — a full-screen app served from your own server, with no app store involved. Business data is not stored offline on the device; what you see is read live.
- Name who signs each step. Per cost center, name the person or people for each level, in order: the Marketing lead, then Finance, then a director. Only they, or their delegate while they are away, can sign that level; a level with nobody named is open to every approver. Each request keeps the steps it was submitted under.
- Budgets, receiving and sending the PO. A budget per cost center (month, quarter or year) with an over-budget flag the approvers see; goods received recorded against each PO line, part deliveries included; and the PO emailed to the vendor from its page, off until you switch it on.
- Approvers are asked, step by step. Each level's people are emailed in turn as the level before is signed, in their own Slack, Google Chat, Teams or Discord channel too if they add one, and an optional morning digest lists everything waiting on each approver.
- Updates from inside the app. The Updates page installs a new release with your license key: Ownware's signature is checked, a backup is taken first, and the app puts the previous version back by itself if the update is interrupted or the database step or start-up check of the new version fails. It never checks by itself.
- Backups by themselves. Automatic backups, an optional copy to S3-compatible storage you own, and a weekly check that the latest backup reads back. The Health page names anything that needs attention.
- Own It 4.0.1 — fixes and an up-to-date manual. For Approva, 4.0.1 fixes an installer that had lost its styling, a rollback that a page opened during an update could stop and a command-line update that ended in an error after putting the previous version back. Its manual, FAQ and QUICKSTART now cover everything 4.0 added, including two Nginx rules that keep the data folder private. Your license covers it: press Check for updates on the Updates page, or download it from your order page.
- Own It 4.0.2 — the installer opens on every host. For Approva, 4.0.2 fixes a fresh install on an Apache host: the one-page setup at /install/ looped back to itself and never opened, and now it opens. Approva's Docker image also gives the web server the whole app folder, so a Docker install can finish and update itself. Your license covers it: press Check for updates on the Updates page, or download it from your order page.
Release notes in full
- Own It 4.1: client installations and your other tools. For Approva, 4.1 makes two changes that every app gets. An Extended license bought from October 4, 2026 covers up to ten client installations, one per client project: hand each one over to the client or host it for them, with the client's logo and colors from the app's branding settings. The API reference now shows how to connect Approva to Zapier, Make or n8n, using its own webhooks and API key. Your license covers the update: press Check for updates on the Updates page, or download it from your order page.
- Own It 4.0: it updates and backs itself up. For Approva, 4.0 means updates from inside the app: the Updates page checks for a new release with your license key, verifies Ownware's signature, takes a backup and puts the previous version back by itself if the update is interrupted or the database step or start-up check of the new version fails. A new install can start with a sample business and remove it in one click; backups run by themselves, with an optional offsite copy and a weekly check that the latest one reads back; and the Health page says whether the install is looking after itself.
- Own It 3.2: the right people sign, in order. This release made the approval chain yours: for each cost center you name who signs each level, in order, and each level's people are asked in turn by email, and in their own Slack, Google Chat, Teams or Discord channel too if they add one. A budget per cost center flags a request that goes over, and goods received are recorded against each PO line. The PO can be emailed to the vendor from its page, off until you switch it on.
- Own It 3.1: it writes to the people you serve. The 3.1 wave gave the catalog a way to reach the other side of the transaction: counterparty email through your own SMTP server, calendar feeds your own calendar subscribes to, attachments filed where the paperwork belongs, and export presets other people's software imports. Each outbound feature ships switched off and runs on your own credentials; a failed send is recorded, and the action that triggered it stands. What this app gained is listed at the top of this section.
- Own It 3.0: works for your AI, not just for you. Approva 3.0 adds an MCP endpoint, so Claude, ChatGPT agents or n8n can list requests, raise them and record approvals through the same guards a person faces — and deliberately cannot cut a purchase order.
- Own It 2.0: API, 2FA, backups, dark mode. Approva 2.0 adds the 2.0 owner layer. Upgrade by replacing the files — the database migrates itself, and it is still the same one-time purchase.
Browse self-hosted: Front-office software · Office & finance software