Solutions · Treasury operations

Run company funds with the controls of a finance team

For any company holding digital assets: a reserve that never moves without several people agreeing, a small float for daily operations, and a record of every decision.

Three tiers of funds

TierWalletHoldsWho can move it
ReservetreasuryMost of the fundsTwo or three named approvers, saved addresses only
Operating floatoperationalA few days of outflowsAPI within limits; a person above them
GasoperationalNetwork coins for feesThe gas station, under a daily cap

Approval groups

  1. Finance (2 of 3): CFO, controller, treasury lead. Approves anything from the reserve.
  2. Operations (1 of 4): approves float payouts above the automatic limit.
  3. Default group: approves changes to policies and groups themselves. Make it at least 2 people, so nobody can loosen the rules alone.

Each approval is confirmed with the approver's passkey and bound to the exact amount and destination: changing either after approval invalidates it. When a transfer comes from an API key, the member who created that key can't approve it: someone else has to.

Policies

RuleEffectWhy
wallet.type == 'treasury' && !withdrawal.is_whitelistedBlockThe reserve only pays saved, cooled-down addresses.
wallet.type == 'treasury'Require approval (Finance, 2)Every reserve movement has two signatures.
context.day_of_week == 'Saturday' || context.day_of_week == 'Sunday'Require approval (Finance, 2)No unattended weekend outflows.
workspace.network_outflow_24h > 100000Require approval (Finance, 2)A daily ceiling per network.

Use Block for things that must never happen, and Require approval for things that need a second look. The policy editor checks each expression as you type, and the strictest matching rule wins.

Using DeFi and other contracts

If treasury funds go into a lending pool, vault or payment contract, add the contract in Security → Contracts with only the functions you need. Each call then needs your Finance group unless a rule names it, for example call.contract_label == 'Aave pool' && call.function == 'supply'. Avoid allowing approve broadly: it lets the approved address spend your tokens later.

Address book

Save exchange accounts, OTC desks and vendors in Security → Address book. A new address has a cooldown (24 hours by default, set in Settings) before it counts as saved. That gives you time to notice a change you didn't make. Adding an address is itself recorded in the audit log.

Monitoring

  • Alerts (Automation → Alerts) to email, Slack, Telegram, Discord or a webhook: large deposits, any treasury transfer, failed transfers, a balance under a level.
  • Analytics: inflow, outflow, internal moves and network fees by day, asset and category.
  • Audit log: every sign-in, approval, policy change, key creation and wallet change, with who did it and from where. Export it for your auditors.

Access hygiene

  • Every member signs in with a passkey; at least two passkeys each (laptop and phone)
  • Custom roles that give people only what they use
  • API keys scoped to wallets, IP-restricted and set to expire
  • Quarterly review of members, keys and saved addresses
  • A written procedure for when an approver leaves or loses a device