On a phone call, a refund could be marked approved before anyone at your business had looked at it. It needed the refund to be at or under the approve limit you had set, and it happened even on accounts set to review refunds by hand — and even where the written refund policy said not to approve without proof. The caller was told the refund had been approved and the amount, and the order was updated to match.
What went wrong. The switch labelled “create refund logs automatically” was also being read as permission to approve them. That switch says, in its own description, that your receptionist records a refund for your team to approve and never moves money itself. That is what it should always have meant.
What happens now. Recording a refund and approving one are separate permissions. Approving on the call is off unless you deliberately switch it on, and there is a new setting for it in your Policy Centre with the consequences spelled out. Your own refund policy comes first either way: if it says refunds need proof, a manager, or a case-by-case look, requests are logged for your team and never approved on the call, whatever the switches say.
If you want to check your own account, open Policy Centre and look at “approve refunds without a person checking”. It is off unless you turn it on.