ByCustody
Solutions
Security
Resources
Company
Account ManagementByCustody uses role-based access control (RBAC) to help secure your organization's digital assets.
Account ManagementByCustody uses role-based access control (RBAC) to help secure your organization’s digital assets. Each user is assigned a role that determines their level of access. Every role requires a unique Gmail address and an iOS device for authentication.
OwnerThe Owner is the highest-level authority for the workspace. Each workspace has one Owner. Approve new user additions and device pairings. Authorize critical workspace changes, such as policy updates and whitelist approvals.
AdminAdmins manage the workspace under the Owner’s authority. Add and manage Operators, Approvers, and Viewers. Create and manage vaults. Create and update transaction policies.
OperatorOperators initiate day-to-day transactions and act as makers in the maker-checker workflow. Create and submit withdrawal and transfer requests. View vault balances and transaction status.
ApproverApprovers independently review transaction requests. Review pending transaction requests. Approve or reject withdrawal and transfer requests.
Viewer (Optional)Viewers have read-only access for monitoring and auditing. View transaction history and status. Monitor vault balances.
PolicyPolicies define how transactions are processed within a vault. Use them to enforce approval workflows, spending limits, and destination restrictions. Policies are configured at the vault level. Each vault can have its own policy, allowing different rules for different asset pools.
Destination AddressControl where assets can be sent. One-Time: Allow transfers to any address without a whitelist. Custom: Restrict transfers to whitelisted addresses or vaults within the same workspace.
Transaction LimitSet spending limits to control exposure. Maximum amount per day: The maximum total transfer amount allowed within a 24-hour period. Maximum amount per order: The maximum amount allowed per transfer request.
Initiated ByDefine who can initiate transfers. Grant transfer permissions to users with the Operator role. Only designated Operators can create transaction requests under this policy.
Approval (Optional)Configure the multi-approval workflow. Level: Define different approval rules for different transaction amount thresholds. Threshold: The transaction amount (≥) that triggers an approval rule. Action: Allow — no approval required; Approved by — requires approval from designated Approvers. Required quorum: The minimum number of approvals required to execute the transfer.