What is the operator playbook for a CRO inheriting a Salesforce-based discount approval workflow that everyone bypasses via exception emails in 2027?
Quality
Certified

Do not rip out the workflow. Spend 30 days pulling approval cycle times, the discount distribution, and the exception-email count, then choose between two paths: subtract friction from the existing process, or rebuild a two-axis authority matrix in Flow. Quick wins buy capital; the redesign earns trust back.
The two paths a CRO can take with an inherited bypass problem
When you inherit a Salesforce discount approval workflow that the field routes around via exception email, there are exactly two coherent operator responses, and they lead to different builds, different timelines, and different political fights. Naming them explicitly matters because most new CROs blur them together, start a redesign, discover halfway through that they actually needed the other path, and end up with a half-built matrix nobody trusts.
Path A is subtraction. You keep the existing approval architecture and remove friction from it until the official process is faster than the exception email. That means auto-approving the bottom discount band outright, deleting redundant approval steps, attaching a hard service-level agreement to every remaining step with automated escalation, and fixing whatever routing bugs the audit surfaces — the approval that fires to a manager who left the company, the two rules that both trigger on the same condition and deadlock. Path A does not touch the authority bands. It does not change who can approve what. It changes only how long the official process takes and how predictable it is. It is reversible in an afternoon, requires no change management beyond an email to the field, and can be live inside three or four weeks of your start date.

Path B is reconstruction. You accept that the inherited authority structure is itself wrong — usually because it is flat (one threshold, one approver tier) or because it is keyed only to discount percentage with no deal-size axis — and you rebuild it. That means designing a tiered matrix, translating it into Flow-based approval orchestration, locking the discounting surface so a rep cannot change net price anywhere the approval logic does not evaluate, building a structured exception path that captures non-standard payment terms and multi-year ramps rather than only percentage, and running a staged rollout with manager enablement. Path B is a 90-to-180-day project. It consumes real RevOps engineering time, it redistributes approval authority (which means somebody loses power), and it cannot be reversed cheaply once the field has been retrained.
The trap is treating these as sequential by default. They are not automatically sequential — Path A is sometimes the whole answer. If the audit shows a rigorous, well-tiered matrix that is simply slow, subtraction fixes the bypass problem completely and reconstruction would be destructive theater. Conversely, if the audit shows a flat structure where a manager rubber-stamps everything from a routine twelve percent to a strategic fifty-five percent, subtraction just makes a broken control fast. You would be speeding up a process that was never controlling anything.

There is also a third possibility the audit must be honest enough to surface: the workflow is not the problem at all. Discount chaos can be a pricing problem, a packaging problem, or a compensation problem wearing a workflow costume. If a rep is paid on gross bookings with no margin component, that rep is economically indifferent to discounting, and no approval architecture fully overcomes it. The diagnostic tell is a discount distribution that is uniformly deep across the entire quarter with no pile-up at any threshold number — that is not reps working around a control, that is reps who have no reason to hold price. Both Path A and Path B are wasted motion in that world.
What the exception-email trail actually tells you
The exception-email log is the hardest artifact to collect and the single most diagnostic one, because it lives in inboxes rather than in Salesforce — which is precisely the point. Ask the deal desk, the RevOps lead, and every approving vice president to forward you every thread from the last two quarters containing an approval that never went through the system. Then count them, categorize them, and compute one ratio: out-of-system approvals divided by total meaningful approvals.

That ratio is your severity score, and it maps cleanly onto the two paths. Under roughly ten percent, the workflow is basically alive and the exceptions are genuine edge cases — you have a tuning problem, not a bypass problem. Somewhere in the ten-to-thirty percent range, the workflow is degrading and Path A subtraction usually restores it. Above roughly forty percent, the Salesforce workflow is a fiction the organization maintains for audit theater, and no amount of speeding it up will recover trust — that is Path B territory, because the field has already concluded the system does not govern anything real.
Now read the content of the emails, not just the volume. Categorize each thread by what the requester actually needed, and you will typically find four buckets. Depth exceptions — the rep needs a discount above their band. Speed exceptions — the discount was within policy, but the rep could not wait for the queue, so they got a verbal yes and backfilled the record days later, or never. Term exceptions — the concession was not a percentage at all: waived annual-up-front, quarterly billing, net-ninety payment terms, an unusual ramp on a multi-year commitment, a custom service-level agreement, non-standard cancellation rights. Bug exceptions — the rep tried the system, it routed somewhere broken, and the email was a workaround for a defect.

The mix determines the fix, and this is where most operators get it wrong. If the majority of exception emails are speed exceptions and bug exceptions, the bypass is a latency and defect problem — Path A. If the majority are depth exceptions, the authority bands are miscalibrated against how the business actually sells, which is Path B. And if a large share are term exceptions, you have discovered something important: your workflow governs only discount percentage while a meaningful fraction of the value your organization gives away leaves through a channel the approval logic never sees. Fixing percentage governance alone would fix half the problem and let you believe you had fixed all of it.
One more read. Sort the exception threads by approver. If they cluster on one or two regional vice presidents, you have a person-shaped problem — an individual who has become the informal approval authority and whose calendar is the real bottleneck. If they are spread evenly across every approver, the system itself has lost legitimacy and everyone has independently concluded the same thing. Concentrated exceptions can be handled with a conversation. Distributed exceptions require rebuilding.

How to decide between subtraction and reconstruction
The decision is not a judgment call once you have the audit data — it is a decision tree with four inputs, each of which you can measure in the first thirty days.
Input one: the exception ratio, as described above. Under thirty percent leans Path A; over forty percent leans Path B.

Input two: the shape of the discount histogram. Plot average discount per closed-won deal across the trailing four quarters. A healthy distribution is left-anchored and roughly log-normal: the mode sits well below the average approved discount, most deals cluster in a modest band, a thin right tail holds genuinely strategic deals, and critically there is no pile-up at any specific number. An unhealthy one shows threshold pile-up — a fat bar sitting immediately under the number where the next approval tier kicks in, and a near-empty gap just above it. If the manager band tops out at twenty percent, you will see a wall of deals at nineteen and twenty and almost nothing between twenty-one and twenty-five. Reps are not negotiating to twenty; they are anchoring to twenty because it is the most they can extract without escalation friction. Threshold pile-up means the band is doing behavioral work but the wrong kind, and it argues for Path B recalibration. A distribution with no pile-up but a high, low-variance mean argues that the control has no deterrent value at all and the problem may be compensation rather than workflow.
Input three: the cycle-time distribution. Pull elapsed business hours from approval-submitted to approval-final for every request in the trailing two quarters, and look at the shape rather than the average — the average lies. You want median, seventy-fifth percentile, ninetieth percentile, and the tail of requests that sat a week or more. A six-hour median with a five-day ninetieth percentile is the classic bypass generator, because trust is binary: reps do not use a process that fails ten percent of the time ninety percent of the time. They route around it every time, because they cannot predict which deal will be the one that sits. If the ninetieth percentile is the problem and the median is fine, Path A subtraction fixes it directly.

Input four: whether the authority structure has a deal-size axis. Almost no inherited matrix does, and it is the most consequential missing dimension. A thirty percent discount on a twenty-thousand-dollar deal and a thirty percent discount on a two-million-dollar deal are not the same decision — the dollar value of the concession differs by a hundred times, the precedent risk differs, the strategic stakes differ. A percentage-only matrix is simultaneously too strict for small deals and far too loose for large ones. If the axis is missing and the organization has meaningful deal-size variance, no amount of subtraction fixes it. That is Path B, unconditionally.
mermaid flowchart TD A[Week 1: Pull six artifacts] --> B[Week 4: Read distribution and exception mix] B --> C[Week 4-8: Ship subtractions] C --> C1[Auto-approve bottom band] C --> C2[Publish approval SLA] C --> C3[Delete redundant steps] C --> C4[Fix routing defects] C1 --> D[Week 6-12: Design two-axis matrix] C2 --> D C3 --> D C4 --> D D --> E[Negotiate bands with RVPs and finance] E --> F[Week 10-16: Build in sandbox] F --> G[Replay 2 quarters of historical deals] G -->|Routing mismatches| F G -->|Clean| H[Enable managers first] H --> I[Pilot one segment or region] I -->|Cycle time holds| J[Expand org-wide] I -->|Cycle time degrades| F J --> K[Quarterly discount review forever] </invoke>

Weeks sixteen onward: roll out, managers first. First-line managers are the load-bearing layer of any sales process change — a confident manager carries the rollout, a skeptical one quietly tells their team to keep emailing exceptions. Run them through the matrix, the flow, the service-level agreements, and the exception path before a single rep sees it, and give them the answers to the questions their reps will ask. Then pilot one segment or region, validate that cycle time behaves as designed, fix what breaks, and expand. The pilot produces the proof points that make the wider rollout credible.
The message, throughout, is velocity — not control. The field does not care about margin discipline; that is your problem and finance's. What the field cares about is deal speed, so the rollout framing is "submit a clean request and you get an answer in four hours, guaranteed, instead of the lottery you have today." That framing only works if it is true, which is why the subtraction phase runs first and why the fast-lane-for-clean-deals, scrutiny-for-exceptions split is a design requirement rather than a nicety. You are not making every deal slower to control the risky few; you are sorting deals by risk and matching process intensity to risk. Presented correctly, the one-page matrix is a gift: it tells every rep exactly what they can approve themselves, exactly how fast the next tier responds, and exactly how to handle a non-standard deal — more clarity than the inherited ad-hoc system ever offered.

Then govern, or it drifts back within a year. A standing quarterly review re-pulls the same six artifacts and asks fixed questions: is threshold pile-up creeping back, is any rep or region drifting, are cycle times holding, what categories of exception recur often enough that they should be promoted into the standard offering, is the matrix still tuned given changes in deal size or competitive pressure. And keep the compensation plan in view. Discount behavior is driven more by comp than by any approval architecture — a rep paid on gross bookings with no margin component or discount clawback is economically indifferent, and you have built a better fence around a field where the animals have no reason to stay in. You usually cannot change comp mid-year and should not try, but the redesign should be built so that the next comp cycle reinforces it rather than fights it.
Related questions
Should a new CRO stand up a deal desk during the redesign?
If approval routing is a real job in volume terms and there is meaningful non-standard-terms complexity, yes — a dedicated owner clears queues faster and applies the matrix more consistently than fifteen regional vice presidents interpreting it. Below that threshold, a part-time owner inside RevOps is sufficient.
What if the CEO personally approves strategic discounts outside any workflow?
You cannot put the chief executive in a matrix, so channel rather than block. Get agreement that even executive-blessed deals get logged with their strategic rationale, and get an explicit definition of "strategic" plus a rough annual volume, so it stays an exception rather than becoming a parallel discount regime.
How do you handle two workflows after a merger?
Run the audit twice, then reconcile. Stabilize both sides with subtraction quick wins before attempting to unify, and expect the hard part to be change management for whichever side loses its familiar process — the Salesforce build is comparatively easy.
Is over-governance ever the inherited problem?
Frequently. A rigorous, multi-tiered, slow workflow with a large shadow exception economy needs mostly subtraction: auto-approve thresholds, deleted steps, hard service-level agreements, a real fast lane. The bands may be fine; the routing speed is what failed.
FAQ
How long should the diagnostic phase actually take before I touch anything?
Roughly thirty days, and the discipline is to genuinely touch nothing during it. The reason is not caution for its own sake — it is that the diagnosis routinely changes the redesign. Operators who pull the data often discover the bottleneck is a step finance owns that nobody told the field about, or a routing defect sending regional-tier deals to a manager who left. None of that is visible from the leadership chair in week one.
Where exactly should the auto-approve threshold sit?
Let the data set it rather than picking a round number. Pull the historical approval rate and modification rate by discount band. Wherever approval rates run near-universal and modifications are effectively nil, that band is pure latency and belongs on auto-approve, logged but not gated. On many organizations that lands in the low single digits to around ten percent, but the correct boundary is a function of your gross margin structure, not a benchmark you borrow.
Why does deal size matter more than discount percentage?
Because percentage is a ratio and concessions are paid in dollars. Identical percentages on deals two orders of magnitude apart represent completely different giveaways, different precedent risk, and different strategic stakes, yet a percentage-only matrix routes them identically. That is how an inherited structure ends up escalating trivial dollar amounts while letting a manager wave through a very large concession because the percentage looked ordinary.
What if fixing the workflow does not reduce exception emails?
Then the design was not the problem and the rollout was. Persistent out-of-system approvals after a redesign mean the field still does not believe the new path will be fast or will say yes. Go back to the cycle-time data by tier, find where requests are actually sitting, and check whether managers were properly enabled before reps were asked to change behavior.
Should the exception path capture more than discount depth?
Yes, and this is the most commonly missed piece. Exception-email culture conflates deep discounts with waived up-front payment, quarterly billing, extended payment terms, unusual multi-year ramps, custom service levels, and non-standard cancellation rights. A structured exception path that records only percentage governs a fraction of what the organization actually concedes, while creating the impression of full coverage.
Can I change compensation at the same time as the workflow?
Generally not mid-year, and attempting it usually costs more credibility than it gains. Design the workflow in the first half-year with the next comp cycle explicitly in view, so that when the plan is rewritten it reinforces the matrix — through a margin component, net-of-discount crediting, or discount clawbacks — rather than working against it.
Sources
- https://help.salesforce.com/s/articleView?id=platform.approvals_overview.htm&type=5
- https://help.salesforce.com/s/articleView?id=sf.cpq_approvals_parent.htm&type=5
- https://architect.salesforce.com/well-architected
- https://trailhead.salesforce.com/content/learn/modules/approval-processes
- https://hbr.org/2010/09/how-to-stop-customers-from-fixating-on-price
- https://www.mckinsey.com/capabilities/growth-marketing-and-sales/our-insights/the-power-of-pricing
- https://www.bain.com/insights/is-your-sales-organization-leaving-money-on-the-table/
- https://developer.salesforce.com/docs/atlas.en-us.salesforce_app_limits_cheatsheet.meta/salesforce_app_limits_cheatsheet/salesforce_app_limits_platform_flows.htm
- https://www.gartner.com/en/sales/topics/revenue-operations
Related on PULSE
- How to design a sales compensation plan that protects gross margin
- What a deal desk actually owns and when to stand one up
- How to read a discount distribution for threshold anchoring
- Salesforce CPQ approval rules versus native Flow approvals
- The first 90 days for a CRO inheriting a broken forecast process
- How to run a quarterly pricing and discount governance review
This page will be disappearing soon. Save it to your device for $1 — or read it free while it is here.
@Kory-White- · if Venmo asks, the last 4 of my number are 2012
This page is gone.
This one is off the shelf now. $1 keeps it on your phone for good — the whole page, pictures and diagrams included.










