RACI for Requirements Sign-Off: Who Actually Approves
A sign-off matrix on a published returns case: one business rule walked through every role that can approve it, and what to write when nobody can be named.
Numbers in this note carry source tags ([POLICY], [THREADS n=10], [MINE]). What the tags mean.
There is one cell in my rule register I could not fill, and it is the one that decides whether the rule can ever change. BR-11 says partial refunds are permitted only above 40 EUR of order value. The figure is published, worded as a hard rule in the returns policy and in two help centre articles [POLICY]. Who set it, and whose yes would make a different figure real, is nowhere I could reach.
The case under this piece is the one I publish on this site: returns and refunds at a mid-size online retailer, assembled from the published policy, the help centre and ten complaint threads anybody can open. I had no client and no access. Nobody inside that company has been asked a question by me or on my behalf, which is why the matrix below carries roles and no names, and why several of its approval cells are unfilled on purpose.
A RACI matrix is a table with work or decisions in the rows, roles in the columns, and one of four letters in each cell: R for whoever does the work, A for the single role whose approval makes it count, C for whoever must be asked first, I for whoever is told afterwards. Almost everything published about it is a template for project tasks. This is the narrower use that bites: who approves a requirement, and who approves the rule underneath it.
In short
- Sign-off rows are artifacts at a version, never activities. The question that stops a requirements document is whose yes makes one sentence in it true.
- One A per row. Where no person can be named, the cell still carries the role, an open question id, a due date and the default that applies if the date passes.
- Every role in the chain can be absent, and each absence fails differently: a rule approved and never built, a policy page that stops matching the system, a decision unmade at the loading dock.
- The matrix creates no authority. It shows where authority is missing, while asking for it is still cheap.
Why do sign-off rows have to be decisions rather than activities?
The RACI that ships with a project plan puts activities in the rows: gather requirements, migrate data, run UAT. That tells you who is busy this month. It says nothing about the sentence in your register somebody will quote back at you in eighteen months.
Sign-off rows are artifacts and the decisions taken on them: this rule statement, this rationale, this criterion, this exclusion, this baseline. The difference appears the moment you fill in letters. "Write the business rules" has an obvious R and a woolly A. "BR-11 as written" has a precise A, and mine is a cell I cannot fill, which is worth knowing in April rather than in build.
The matrix, filled in, with no names in it
Columns come from the stakeholder map in the same case, seven rows written as decision rights rather than job titles. [OPEN] beside an A means the role is identified and the person is not.
| What is being approved | BA (me) | Finance lead | Head of Customer Care | E-commerce PO | Goods-in lead | Legal | Approval expires when |
|---|---|---|---|---|---|---|---|
BR-11 as written: partial refunds above 40 EUR only [POLICY] |
R | A [OPEN, OQ-03] |
C | I | I | - | Per-transaction fee changes |
The rationale under BR-11, marked as my inference [MINE] |
R, A | C, confirm or kill | I | - | - | - | Cost data appears |
BR-07 status: five working days, promise or target [HELP] |
R | I | A [OPEN, OQ-02] |
I | C | - | The published wording changes |
| REQ-014 criterion 3, what the form does at the threshold | R | C | A [OPEN] |
C | I | - | BR-11 changes |
REQ-016 criterion 1, 90 day photo retention [MINE, OPEN, OQ-01] |
R | - | I | C | - | A | Statute changes |
Scope exclusion: non-delivery and lost parcels, with the reason [MINE] |
R, A | - | C | I | C | - | Anyone asks why they are absent |
| Whether partial refunds are wanted in release 1 (OQ-05) | C | C | A [OPEN] |
C | - | - | 30 April 2026 passes |
| Whether release 1 has room for them | C | I | C | A [OPEN] |
- | - | The release plan moves |
| Baseline of the register at v1.2, 9 April 2026 | R, A [MINE] |
I | I | I | I | I | The next change request |
One A per row, including the rows where the A is me. Where nobody could be named the letter still goes against the role. A blank cell would have been the easier lie.
Read the A column on its own. Six of the nine rows have an unclaimed A: a role identified, a person missing. This case can be written, reviewed and pulled apart, and nobody except me can baseline it.
Four unclaimed cells are the same absent person. My register tracks the gap at rule level, as OQ-02 and OQ-03, never at role level, so the Customer Care rows carry an open tag with no id behind it. Fifteen minutes of filling in letters found a hole four other artifacts walked past.
The chain: one rule, every role it has to pass
Here is the route BR-11 travels before anyone can rely on it, and what happens at each link when the role is absent.
1. The analyst, who writes it down (R)
In v1.1 my register carried the rule as one line: the number, nothing else. A business analyst reading it on 6 April 2026 asked "Why 40 EUR? Who set that?", and the answer ran to a page. The R belongs to whoever can give that answer in one breath, with the source, the status, the reasoning and the review trigger.
Absent: the figure survives as a law of nature, quoted for years and designed around, because nothing is written down to argue with.
2. Finance, whose yes makes the number real (A)
The threshold governs how much money leaves without a person looking at it, and the map gives the finance lead a veto over exactly that. I cannot name them, and typing in a job title to make the table look finished would have been the one line here a single phone call could take apart.
Absent: OQ-03, due before the register is baselined, with the default in the row: both rules stay with the A unclaimed, and neither threshold moves until it is claimed. Freezing the number is what an unclaimed A buys.
3. Customer Care, who lives with the wording (C)
The threshold is quoted at customers in the policy and in two help centre articles, and Customer Care owns the published promise. So they are C on the rule and A on anything that changes how it reads to a customer, which is why they hold criterion 3 of REQ-014 and the finance lead does not.
Absent: the system and the policy page stop agreeing, and the first customer to quote the page back at an agent runs the test for us.
4. The product owner, who owns the slot (A, one row down)
Approving a rule and making room to build the thing that enforces it are two decisions belonging to two people. This is where a two-name A cell shows up: "partial refunds in release 1" reads like one decision and is two. Split, it gives one A each, whether they are wanted (Customer Care) and whether there is room (product owner).
Absent: a rule approved and never built. The register says v1.2, agreed; the form still hides nothing and refuses nothing; and the gap stays invisible until an order under the threshold is offered a partial refund the policy forbids.
5. Goods-in, informed at best, able to undo it anyway (I)
The goods-in lead holds no approval right I can find. That role also receives the parcel, judges whether its condition matches the claim, and decides whether it is restocked or scrapped. On this matrix it is an I, and in the process it decides in practice. Finding a row like that is most of the reason to build a matrix rather than photograph the org chart.
Absent: the decision is unmade at the dock, after the money has gone. That is why REQ-017 exists, and why my one-page summary asks for whoever holds that role to be in the room before anything ships.
6. The frontline agent, who applies the rule all week (C, one row over)
No public source contains a written test for whether photographic evidence is "enough" [WALKTHROUGH], so the judgement sits with whoever picks up the case. On BR-11 the agent is an I. On BR-04, the fourteen day damage reporting window, the agent is the C I would fight hardest to keep.
Absent: the rule is enforced at a slightly different threshold by everyone applying it, and the first report to measure the variation gets read as a data quality problem.
7. Legal, absent here and able to stop the release anyway (A elsewhere)
Legal has no view on a refund threshold. They hold an absolute A one row down, on retention of the uploaded photographs, where the ninety day figure is mine and still open [MINE, OPEN, OQ-01]. A chain belongs to an artifact rather than a project, which is how a role can be irrelevant to eight rows and decisive on the ninth.
Absent: the answer is identical whenever it arrives. Asked early it costs an email. Asked after build it costs the build.
8. The customer, who has no column at all
The map gives the customer no right inside the company and one outside it. Four of the ten complaint threads I read were a customer escalating in public [THREADS n=10], which counts the threads I chose and measures nothing about the ones I did not read. Their veto arrives through a chargeback, a statutory claim or a review, months after sign-off.
Absent: they can be absent from the table and never from the process, and that is what makes the escalation look like bad luck.
What do you write when you cannot name the approver?
This is the normal condition on a case built from outside a company, on any project in week two, and on more mature projects than people admit. An unclaimed A worth writing has four parts.
The role, as a decision right. "Finance" approves nothing. "Whoever signs off refund policy in finance" is an approver with a missing name, which is a different thing to hand to the first colleague who does have access.
An id, so the gap lands in the open questions register instead of a table nobody opens twice.
A due date pinned to an event, because a date tied to an event survives a slipped plan: before the register is baselined, before build starts.
A default resolution. OQ-02 asks whether five working days is a promise or a target. If 30 April passes unanswered, it gets published as a target and the escalation hangs off my own window, which is mine to guarantee. Write the unattractive default; it is what gets an answer out of an organisation, and what protects the work when no answer comes.
The objection is fair and I have taken it more than once: a role with nobody behind it approves nothing, so the cell does less than I claim for it. What it does do is hold the position open, so the first person with real access fills it from a human being rather than from a guess.
Five ways a sign-off matrix stops working
Two A cells in one row. "We approve it jointly" resolves in practice to nobody having baselined it, and it surfaces the day somebody wants the decision reversed. When you cannot name one A, the row is cut wrong rather than the organisation being unusual, so split it. Where the two names disagree on substance, that belongs on a conflict card instead of in this table.
Everybody consulted. A C belongs to a role whose absence would make the decision wrong, rather than to one that would have liked to know. Ten C on a rule means it gets approved late and changed afterwards anyway, by the people consulted last.
Names in the columns instead of decision rights. One reorganisation and the matrix becomes a work of history. My case has the opposite problem and the same fix: decision rights in the columns, names in a list that changes without anybody reopening the table.
Approved once, then never re-read. Approval attaches to a version and expires with it. A change request that edits a rule statement expires the approval on every row tracing to it, and working out which rows those are is what a traceability matrix does in a quarter of an hour.
Treating A as seniority. The A follows the rule rather than the pay grade. Legal outranks nobody here and holds an absolute A on retention; the Head of Customer Care chairs the meeting and still does not own a money rule. The question that settles these arguments is not who is senior, but who will be asked to explain the decision in twelve months when it is quoted back at the company.
The empty matrix, hints left in
| What is being approved | [Role 1, as a decision right] | [Role 2] | [Role 3] | Approval expires when |
|---|---|---|---|---|
| [BR-nn as written, at a version. Never "write the rules"] | [R. Whoever can defend the source and the reasoning] | [A. One per row. A name, or the role plus an open id] | [C, only where absence makes the decision wrong] | [The review trigger for that rule] |
| [The rationale, and whose it is. An inference of yours is its own row] | [R, A where the reasoning is yours] | [C, to confirm or kill] | [I] | [Evidence appears that settles it] |
| [AC-nn-nn. One criterion. Criteria are where sign-off bites] | [R] | [A] | [C] | [The rule it implements changes] |
| [The scope exclusion, with its reason. Exclusions get approved too] | [R] | [A] | [C] | [Anyone asks why it is missing] |
| [The baseline, version and date. The only row saying what "approved" refers to] | [R] | [A, or the role plus OQ-nn] | [I] | [The next change request] |
Fill the A column first, top to bottom, then go back and put a name against every letter in it. The rows where you cannot are the output. On an engagement each one is a meeting request with its agenda already written. Where the stakeholder map those columns came from sits among the other five artifacts is a separate piece; decision rights are checks 04 and 06 of the standard I hold myself to, free to run against your own case.
BR-11 still has an unclaimed A. It has carried one since 9 April, with a date and a default beside it, and the register says so on its face rather than in a footnote.
Read next
Acceptance Criteria That Survive a Sprint Review
What an acceptance criterion actually is, six weak ones shown as they arrived and as they went out, and the three object
From Change Request to Impact Analysis in One Page
A one-line change request and the six fields of an impact analysis, filled in one at a time: what belongs in each field,
Get the Proof Pack
Six blank templates and one worked case. Free, one email. The scorecard is a separate file and needs none.
Send it to meAll field notes · The portfolio guide · More in Requirements That Survive Review