Review journeys before they go live, with an automatic risk assessment and a recorded decision.
Approvals is the gate between a finished journey and a live one. Anyone can build, but only an Admin or Manager can approve, and nothing publishes without a decision being recorded.
The queue lists journeys awaiting review. Each entry carries a risk level Xenia assigns automatically, and you can filter by risk or search by name.
The risk note is written out, not just a badge. A high-risk journey with no safety rules is described as such, and reviewers are told to verify audience scope and frequency caps before approving. A high-risk journey that does have guardrails says how many.
Risk is a prompt for attention, not a verdict. It is derived from the journey's shape, so a small journey aimed at your entire customer base still deserves a careful read.
The briefing is the author's statement of what the journey does and who it targets. If it does not tell you the audience, the channel, and the intent, send it back for that reason alone.
Reviewing takes you into the builder with the journey loaded, so you can inspect nodes, rules, and copy rather than approving a summary.
Who enrols, how many, how often, and what stops it. Confirm waits are sane, rules exclude who they should, and any recovery journey checks whether the thing it is recovering already happened.
Approve, or reject with a comment. Both are recorded against your reviewer role.
A reviewer reads intent and scope. Whether the journey actually executes is what Simulation proves. Expect a journey to have been simulated before it reaches you, and ask if the author cannot say what the paths did.
Approving requires the Admin or Manager role. Other roles can see the queue but the decision actions are unavailable, rather than failing after the fact.
Approval is a human check on top of automatic enforcement, not instead of it. Even an approved journey cannot send to someone without marketing consent, and per-person, per-channel frequency caps still apply at send time. A reviewer's job is the judgment those rules cannot make: whether this message, to these people, at this moment, is the right thing to send.