One point of standing first. The binding text of the Polish VAT Act is the Polish one, published in the Dziennik Ustaw. This page is a working guide for a reader who does not read Polish; where a rule matters, check the instrument, and where the two diverge the Polish text governs.
Why are KSeF permissions not enough?
The KSeF permission model answers the question of who may issue invoices on behalf of an entity. It does not answer the question of which invoices. An integration that has been granted the right to issue holds that right for a PLN 200 document and for a PLN 200,000 document, for a counterparty of fifteen years' standing and for one that appeared in the database this morning.
There is a related property worth stating plainly, because it is a common source of confusion in vendor material: KSeF certificates are carriers of identity and hold no permissions — permissions are managed separately. Holding a certificate is therefore a means of authentication, not a form of access control. A group that has mapped its Polish certificates and considers the access question closed has answered a different question.
Differentiating operations by risk has to be built in your own layer. Nobody supplies it as standard, and no part of the statutory scheme requires it — which is precisely why it goes unbuilt until something goes wrong.
How do you set an approval threshold for invoices?
A value threshold is the most obvious dimension and the least sufficient on its own. In practice a combination of four dimensions works.
Amount
Setting the figure by intuition normally fails in one of two ways: the threshold is so low that it blocks half the flow and gets raised within a month to a harmless level, or so high that it catches nothing. The method that works is to take the distribution of invoice values over the last twelve months and set the threshold so that it captures a few per cent of documents representing a significant share of value. Control then applies to a handful of cases a day, and to real money.
For a group there is a second-order point here. Set the threshold in Polish zloty, per entity. A group limit expressed in euro, sterling or dollars and converted at whatever rate the finance system happens to hold will change what it captures as the exchange rate moves, without anyone deciding that it should. That drift is invisible in the control's own reporting, because the control never sees the currency it was originally written in.
Counterparty
A new counterparty, a counterparty whose bank account details have changed, a counterparty outside the markets you normally sell into. This dimension catches the cases a value threshold will never see, because the amount is entirely normal.
Operation type
Corrections, duplicates, an invoice issued in one of the offline modes, a document with an unusual structure. Exceptional operations deserve a higher level of control precisely because they are rare — automation is least well tested exactly where it is least exercised.
Process behaviour
The most valuable dimension and the most often omitted. Not this invoice is large
but this process issued forty invoices in ten minutes when it normally issues four an hour
. A rate anomaly surfaces a data defect several dozen documents before anyone inspecting individual invoices would find it.
What are the three levels of response?
Control does not have to mean stopping. Three levels give a reasonable compromise between safety and throughput:
| Level | Behaviour | When to use it |
|---|---|---|
| Pass and record | Operation performed, full entry in the audit trail | The overwhelming majority of documents |
| Pass and flag | Operation performed, notification raised for review | Deviations without high risk: a new counterparty at a low value |
| Hold for approval | Operation not performed until a person decides | Value threshold exceeded, corrections above the threshold, rate anomalies |
The middle level is the one that saves the implementation. Without it, every deviation lands in an approval queue, the queue grows, people start approving in bulk, and the control stops existing while continuing to work on paper.
What has to be recorded once an invoice is approved?
An approval without a record has no evidential value. The minimum set that belongs in the audit trail:
- Who approved — a named individual, not a role and not a service account.
- What exactly they saw — the data presented for the decision. If the approver saw only the amount and the number while the problem was in the line items, you need to know that.
- When, precisely enough to bind the decision to the operation.
- Which policy, in which version, triggered the approval requirement.
- The decision, with a reason where it was a rejection.
The second item is what separates a useful record from a decorative one. Jan Kowalski approved at 14:32
says nothing about whether the approval was informed.
Where this collides with a group delegation-of-authority matrix
Most multinationals express approval limits by role: a country finance manager up to one figure, a regional controller above it. That construction is exactly what a KSeF record cannot use. Two things have to be reconciled. The policy may be expressed by role, but the record must name the individual who exercised it, and it must be possible to show which role that individual held on the date in question rather than today. And the delegation has to be attributable to the Polish taxpayer, because the obligation under art. 106ga and any penalty under art. 106ni attach to that entity and not to the group.
A third consideration is language. An inspection is conducted in Polish. An approval record whose policy names, field labels and rejection reasons exist only in English is usable, but it will be read by someone reconstructing your control from a schema they have never seen. Bilingual field definitions and a written description of the control in Polish cost very little in advance and a great deal in the middle of an inspection.
What changes when the operation is initiated by an AI agent?
An agent operating inside a finance process introduces two changes that have to be reflected in the design of thresholds.
First, the agent's scope of action is broader than the scope of a single operation. A deterministic process issues an invoice because it was instructed to issue an invoice. An agent may issue an invoice as a step towards a goal stated more generally — and then the question is not only whether this invoice is permitted, but whether this agent should be issuing invoices in this context at all.
Second, an agent cannot be both the executor and the controller. If the decision about whether an operation requires approval is taken by the same model that initiates the operation, the control does not exist. The threshold has to be enforced in a layer the agent passes through and can neither bypass nor reconfigure. The general form of that argument is set out in approving AI actions before execution, and the recording requirements in audit trail requirements for AI agents.
There is a KSeF-specific consequence. An agent's behaviour cannot be reproduced by re-running it later, so the contemporaneous record is the only evidence that will ever exist — and because the invoice it produced cannot be deleted, there is no version of this problem that can be fixed after the fact.
Which entities does this apply to, and from when?
The obligation attaches to the Polish taxpayer. Art. 106ga ust. 2 of the VAT Act excludes a taxpayer with neither a seat nor a fixed establishment in Poland, and a taxpayer without a Polish seat whose fixed establishment in Poland does not participate in the supply for which the invoice is issued; a Polish VAT registration is not by itself a fixed establishment. The Ministry of Finance published objaśnienia podatkowe on that determination on 28 January 2026, and the test is set out in KSeF penalties from 1 January 2027.
Within that population there is no small-entity carve-out to design around. Every in-scope taxpayer has been obliged to issue through KSeF since 1 February 2026 for the largest and 1 April 2026 for everyone else, and there is no deferral for micro-entrepreneurs: the bill that would have excluded them until 31 December 2027, Sejm druk nr 2321 of 13 February 2026, stalled after its first reading on 13 March 2026 and was never enacted, although it is still cited as binding law in advisory material. The register of corrections keeps that point current.
The date that changes the economics is 1 January 2027, when the penalties in art. 106ni begin to be applied — up to 100% of the tax shown on an invoice issued outside KSeF, or up to 18.7% of the total amount due where none is shown. Those are ceilings, and art. 189d of the Kodeks postępowania administracyjnego obliges the authority to calibrate by reference to the gravity and circumstances of the breach, its frequency and the party's previous conduct. An approval record is one of the few artefacts that speaks directly to all four. The cost model for KSeF automation sets out how that expected value compares with the running cost of the control layer.
What are the common implementation mistakes?
- The threshold as a constant in code. Changing it requires a deployment, so nobody does it, so the threshold is out of date. Thresholds are configuration with a change history, not constants.
- No override path. A control without an emergency procedure will be bypassed informally — by being switched off for the duration of a month-end close. Better a designed override with a raised level of recording than an undocumented disabling.
- Approval after submission. More common than it sounds: the system sends the invoice and asks for acceptance in parallel. That is monitoring with the word approval written on it, and with KSeF it is not recoverable, because the document already has its numer KSeF.
- One threshold for the whole organisation. A threshold that makes sense for a sales division is meaningless for a division issuing three invoices a month at ten times the value. In a group, add the entity dimension: one policy per Polish taxpayer, enforced with tenant isolation so a shared platform cannot apply one entity's threshold to another entity's invoices.
The general pattern behind all four is covered in approval checkpoints in automated workflows.
In practice
BarzelVault applies policy and approval thresholds ahead of execution and issues signed audit receipts, recording the decision together with what the approver was actually shown. BarzelOps runs the cross-system workflow with durable state, approval checkpoints and tenant isolation, so a threshold set for one Polish entity is enforced only against that entity's operations.
Frequently asked questions
Do the KSeF rules require human approval?
No. It is an internal control arising from risk management, not a legal requirement. Its value appears when a penalty is being calibrated and when due care has to be demonstrated.
Can an accepted invoice be deleted?
No. It receives a numer KSeF and can only be corrected. That is why the control has to sit before submission.
How do you set the value threshold?
From the distribution of invoice values over the last twelve months, so that it captures a few per cent of documents representing a significant share of value — and in Polish zloty, per entity.
Are KSeF permissions sufficient as a control?
No. They determine who may issue, but do not differentiate operations by amount, counterparty or document type. Certificates carry identity, not permissions.
How does pre-execution control differ from monitoring?
Monitoring detects an event after the fact. Pre-execution control means the impermissible operation is never performed. With KSeF that matters because the document cannot be removed.
Will thresholds slow invoicing down?
With a well-chosen threshold, control applies to a few per cent of documents. The bottleneck only appears where the threshold is set too low, or where the intermediate pass-and-flag level is missing.
Where this leads
Everything in this article follows from one sentence of system behaviour: acceptance is final, and correction is the only remedy. That makes KSeF unusual among the controls a group finance function designs, because the normal reflex — detect, investigate, reverse — is unavailable at the last step. For a multinational the work is mostly organisational rather than technical: express the policy per Polish taxpayer and in zloty, name individuals rather than roles, keep the record readable to a Polish inspector, and place enforcement somewhere the executing process cannot reach. None of it is required by the statute. All of it is what you will be asked for from 1 January 2027.
In practice
The control has to run before the invoice becomes irreversible.
An accepted structured invoice can be corrected but never deleted, and from the penalty date every defect has a price. Barzel puts the approval threshold, the duplicate check and the signed record in front of submission, so the process can be defended on the day an auditor or the tax authority asks.
95 days leftKSeF penalties apply from 1 January 2027
BarzelVault
The AI action firewall: decide what an agent may do before it does it.
- Approval thresholds and policy checks enforced before execution; human approvals that expire and escalate.
- Cryptographically signed audit receipts: trigger, inputs, policy version, approver, outcome.
- Credential isolation, spend and action limits, and an emergency kill switch.
Free tier: 10,000 calls a monthPaid plans from $199 a monthLive on MCPize
BarzelOps
Governed workflow automation across the systems that run the business.
- Durable, idempotent execution: a timeout is retried once, never filed twice.
- Human approval checkpoints that pause the workflow and resume it.
- Isolation per entity or client, signed evidence receipts and a portable manifest; HubSpot, Xero, Gmail, Google Drive and Slack.
Free tier: 100 calls a dayPaid plans from $19 a monthLive on MCPize
Enterprise: written quote by email within two business days. No sales call.
Related
- KSeF penalties from 1 January 2027
- offline24, awaria and niedostępność: three states, three obligations
- What KSeF automation actually costs
- The KSeF audit trail: documenting an automated operation
- Workflow automation with governance
- AI governance
- Glossary of regulatory and technical terms
Sources
- Ministerstwo Finansów, technical documentation: certyfikaty-KSeF.md, uprawnienia.md — github.com/CIRFMF/ksef-docs.
- Ministerstwo Finansów, Podręcznik KSeF 2.0, część II — wystawianie i otrzymywanie faktur w KSeF (permissions; legal position as at 1 February 2026).
- Kodeks postępowania administracyjnego, art. 189d.
- Ustawa o podatku od towarów i usług (Polish VAT Act), art. 106ga, art. 106ni.
- Ustawa z dnia 5 sierpnia 2025 r. o zmianie ustawy o podatku od towarów i usług oraz niektórych innych ustaw, Dz.U. 2025 poz. 1203.
- Ministerstwo Finansów, Objaśnienia podatkowe z 28 stycznia 2026 r. on determining a fixed establishment in Poland for the purposes of issuing invoices through KSeF.
- Ministerstwo Finansów, Zakres obowiązkowego KSeF — scope and the 1 February and 1 April 2026 dates.
- Sejm RP, druk nr 2321 — private members bill of 13 February 2026, first reading 13 March 2026, not enacted.
This article is a working guide for English-speaking readers and does not constitute tax or legal advice. The binding text is the Polish one.