Approve from your inbox
Zero logins. One tap. Enterprise-grade audit trail.
Company
Medius
Year
2026
Role
Designer
Scope
Email UI
Mobile
Security
The problem
Most approvers had no reason to open Medius except to approve. The friction — login, navigation, context switch — was enough to delay decisions by hours. Some approvers batch-approved without reviewing details just to clear the queue.
- Context switch to a full web app for a 15-second decision.
- Delayed approvals blocked downstream purchasing workflows.
- Batch-approving without review created audit and compliance risk.
The approach
The actionable email card had to feel as casual as a one-tap reply — while satisfying enterprise security requirements. Security was treated as a design layer from day one, not added at the end.
- Cards tied to Azure AD / Entra for identity — forwarded emails are rejected by the back-end.
- Every action audit-logged with channel = "Actionable email".
- Designed for mail clients: Outlook, Apple Mail, Gmail — all tested.
Key design decisions
Surface the decision context, not the form
The card shows the purchase requisition summary, requester, line items with budget status, and the decision buttons — nothing else. Approvers see exactly what they need to act, without having to navigate into the platform.
Rejection requires a comment
Approving is one tap. Rejecting opens an inline text field — required before the action submits. This creates accountability without friction: the path of least resistance is still a considered decision.
Security as invisible infrastructure
Token-based action links expire after 48 hours. Forwarded emails produce a "This approval link was already used or expired" message. The compliance team reviewed every state; none required a visible UI element.
Outcome
Approvers can now approve or reject purchase requisitions without opening the platform. The interface feels as casual as a one-tap reply; the audit trail satisfies enterprise compliance.
0
Logins required to approve
3
Mail clients supported
100%
Actions audit-logged