1 · How approval works
In production the authority comes from a mandate: your backend says which customer, which actions and how much. Refunds up to auto_allow_up_to_minor are executed straight away; above it — but within the maximum — they become REVIEW and wait for a person. Anything outside the mandate is DENY.
2 · Create a mandate per conversation
When a ticket opens, a node (or your backend) registers the mandate with your backend key. The facts come from your systems — the logged-in customer and their payments — never from the model:
POST https://colvo.app/v1/mandates
Authorization: Bearer <backend key>
{ "project_id": "…", "source_request_id": "ticket_4711",
"subject": { "customer_id": "cus_01", "payment_ids": ["pi_01"] },
"actions": ["refund.create"],
"limits": { "currency": "eur", "max_amount_minor": 20000,
"auto_allow_up_to_minor": 5000, "max_operations": 1 },
"expires_at": "2026-10-06T12:00:00Z" }Pass the returned mandate_id to the HTTP Request node that proposes. Not sure about the numbers? The mandate builder writes this body for you.
3 · Get told when someone must decide
COLVO emails every owner and editor when a refund waits for approval. For Slack, open Settings → Alert channels, add a Slack webhook and subscribe it to approval.requested (and approval.reminder, approval.expired if you like).
The reviewer approves or rejects on the Approvals page, signed in, against the exact refund they were shown. Undecided approvals expire after 24 hours (or the mandate’s expiry, if sooner) and nothing is sent.
4 · Tell the customer the truth
Branch on decision after the HTTP Request node:
ALLOW— “Your refund of €40 is on its way.”REVIEW— “A colleague will confirm your refund shortly.”DENYorHOLD— “I can’t do that here; I’ve passed it to the team.”