Solutions · Treasury operations
Run company funds with the controls of a finance team
For any company holding digital assets: a reserve that never moves without several people agreeing, a small float for daily operations, and a record of every decision.
Three tiers of funds
| Tier | Wallet | Holds | Who can move it |
|---|---|---|---|
| Reserve | treasury | Most of the funds | Two or three named approvers, saved addresses only |
| Operating float | operational | A few days of outflows | API within limits; a person above them |
| Gas | operational | Network coins for fees | The gas station, under a daily cap |
Approval groups
- Finance (2 of 3): CFO, controller, treasury lead. Approves anything from the reserve.
- Operations (1 of 4): approves float payouts above the automatic limit.
- Default group: approves changes to policies and groups themselves. Make it at least 2 people, so nobody can loosen the rules alone.
Each approval is confirmed with the approver's passkey and bound to the exact amount and destination: changing either after approval invalidates it. When a transfer comes from an API key, the member who created that key can't approve it: someone else has to.
Policies
| Rule | Effect | Why |
|---|---|---|
wallet.type == 'treasury' && !withdrawal.is_whitelisted | Block | The reserve only pays saved, cooled-down addresses. |
wallet.type == 'treasury' | Require approval (Finance, 2) | Every reserve movement has two signatures. |
context.day_of_week == 'Saturday' || context.day_of_week == 'Sunday' | Require approval (Finance, 2) | No unattended weekend outflows. |
workspace.network_outflow_24h > 100000 | Require approval (Finance, 2) | A daily ceiling per network. |
Use Block for things that must never happen, and Require approval for things that need a second look. The policy editor checks each expression as you type, and the strictest matching rule wins.
Using DeFi and other contracts
If treasury funds go into a lending pool, vault or payment contract, add the contract in Security → Contracts with only the functions you need. Each call then needs your Finance group unless a rule names it, for example call.contract_label == 'Aave pool' && call.function == 'supply'. Avoid allowing approve broadly: it lets the approved address spend your tokens later.
Address book
Save exchange accounts, OTC desks and vendors in Security → Address book. A new address has a cooldown (24 hours by default, set in Settings) before it counts as saved. That gives you time to notice a change you didn't make. Adding an address is itself recorded in the audit log.
Monitoring
- Alerts (Automation → Alerts) to email, Slack, Telegram, Discord or a webhook: large deposits, any treasury transfer, failed transfers, a balance under a level.
- Analytics: inflow, outflow, internal moves and network fees by day, asset and category.
- Audit log: every sign-in, approval, policy change, key creation and wallet change, with who did it and from where. Export it for your auditors.
Access hygiene
- Every member signs in with a passkey; at least two passkeys each (laptop and phone)
- Custom roles that give people only what they use
- API keys scoped to wallets, IP-restricted and set to expire
- Quarterly review of members, keys and saved addresses
- A written procedure for when an approver leaves or loses a device