Approva · Quickstart
Approva Quickstart, as shipped in the download
The QUICKSTART.txt in the download — the same steps your delivery email carries.
APPROVA — QUICKSTART
====================
Purchase approvals with segregation of duties — self-hosted PHP + MySQL/SQLite.
REQUIREMENTS
------------
- PHP 8.1+ with extensions: pdo, pdo_sqlite (or pdo_mysql), mbstring, openssl, curl, json
- MySQL 5.7+ OR SQLite 3 (SQLite requires no extra setup — the default)
- A web server (Apache with mod_rewrite — the shipped .htaccess does the routing — or Nginx with try_files)
- No Composer packages, no Node, no build step, no external services.
SHARED HOSTING / CPANEL (RECOMMENDED FOR MOST BUYERS)
------------------------------------------------------
1. Upload the contents of the `app/` folder to your web root (e.g. public_html/)
or a subdirectory (e.g. public_html/approva/).
2. Make sure this directory is writable by PHP (it holds the SQLite file, uploads and backups):
data/
Via cPanel File Manager: right-click -> Permissions -> set to 755 or 775.
(If data/ is missing, Approva creates it on first run.)
3. Visit https://yourdomain.com/install/ in your browser.
4. Fill in the installer:
- Database: choose MySQL (host, database name, user, password) or SQLite (no setup;
the file is data/approva.sqlite)
- Organisation name and currency (ISO code, e.g. USD)
- PO number prefix (the purchase orders it issues are numbered from it)
- Second-approver threshold, and an optional third-approver threshold — amounts in your currency
- Timezone
- Your name, email and password (the first admin)
5. The installer writes config.php and sends you to the login page.
FIRST STEPS (what to do in the first ten minutes)
-------------------------------------------------
1. Settings: add your vendors and cost centres — a request is raised against them.
2. Invite people and give each a role: requester, approver or admin. An approver can never approve their own request; that rule is the product.
3. Raise a test request above the second-approver threshold and watch it need two decisions. The rule that applied is frozen on the record at submission, so changing thresholds later never rewrites history.
4. Approvers going on leave delegate to a colleague for a date window (Delegation screens) — the delegation cannot be used on their own request.
5. A fully approved request becomes a numbered purchase order with one click; it prints as a PDF. Approva approves and issues POs — it never pays anyone.
The manual (docs/MANUAL.md in this download, or the product page on the store) covers every
screen and every rule above, each with the line of source it comes from.
VPS / SELF-HOSTED
-----------------
Requirements same as above. Apache example:
<VirtualHost *:80>
DocumentRoot /var/www/approva/app
<Directory /var/www/approva/app>
AllowOverride All
Require all granted
</Directory>
</VirtualHost>
Run the web installer as above. Demo data on a FRESH install only (it wipes what is there):
php bin/demo.php
DOCKER (QUICK TEST)
-------------------
The app/ folder ships a Dockerfile (Apache + PHP 8.3, mod_rewrite on):
docker build -t approva .
docker run --rm -p 8080:80 -v approva-data:/var/www/html/data approva
Then visit http://localhost:8080/install/
POST-INSTALL SECURITY CHECKLIST
--------------------------------
[ ] config.php, data/ and the *.sqlite file are blocked by the shipped .htaccess (Apache).
On Nginx, deny /data/, /src/, /bin/, /tests/, /controllers/, /views/ and config.php yourself.
[ ] Open https://yourdomain.com/data/ once — it must answer 403, never a listing.
[ ] Use HTTPS in production.
[ ] Keep PHP updated.
[ ] If you ran bin/demo.php, change or delete the demo accounts before going live.
[ ] Back up data/ (Settings -> Backups writes to data/backups/).
NOTES
-----
* Money is integer cents; amounts compare exactly against the thresholds.
* The decision e-mail tells the requester what happened; nothing is ordered or paid by the software.
* REST API with an OpenAPI spec, signed webhooks and an MCP endpoint for agents: see API.md — an agent faces the same approval rules a person does.
← Back to Approva · Manual · API · Test run