We have authorization rules setup at PR level but when an RFQ is created from the PR, we lose any authorization capability. Regardless of the value agreed, you are then able to generate a PO without authorization. Only the approval step is required but this isn't based on value.
In this flow, does the auth have to take place at PO level rather than PR level? Unless theres a setting Im missing, would a CRIM be the solution here?