Best Practices for Security Safeguards

Modified on Wed, 15 Jul at 3:50 PM

Best Practices for Security Safeguards

Your security controls should evolve with your business. We recommend: 

  • Review your wallets holistically 

    • What types of wallets do you use (hot, cold, custody, self-custody, etc.)

    • What purposes do your wallets serve (transfers, long-term storage, etc.)

  • Review policies regularly to ensure they align with current operations and risk tolerance. 

    • Define what small, medium and large transactions look like to you

    • Define what you believe or uncommon or risky behaviors

    • Develop a strategy around whitelisting 

    • Are certain policies too sensitive or add too much friction

  • Updating policies and whitelists when teams, workflows or counterparties change. 

    • Use the Admin Console to help manage users and their roles

    • Who should initiate transactions

    • Who should approve transactions

    • Who should manage policies

  • Testing approval policies periodically to confirm they work smoothly during high-volume or urgent withdrawals.

Additional Notes

Allowed

  1. ✅1 condition → 1:many actions

    1. If coin is BTC → require approval from Jack and Elon

  2. ✅Many conditions (evaluated as AND) → 1:many actions

    1. If coin is BTC AND amount is > $100k → require approval from Jack or Elon

  3. ✅Many conditions (evaluated as OR) → 1:many actions

    1. If coin is BTC or ETH → require approval from Jack and Elon

  4. ✅The order in which you add actions, is the order in which they will be sequenced

    1. Require approval from Jack and Elon (Jack must approve before going to Elon)

    2. Require approval from Elon and Jack (Elon must approve before going to Jack)

  5. ✅If you add a policy at the All Wallets level, it will automatically cover all wallets in the enterprise except for the Go Account

  6. ✅Hierarchy

    1. Adding an enterprise-level policy affects all wallets underneath, including exchange connections

    2. Adding a wallet-level policy only affects touchpoints relevant to that wallet

Not Allowed

  1. ❌You can’t combine AND and OR within conditions, i.e., you must choose all AND or all OR

    1. Not allowed: If Coin is BTC AND user is Jack OR amount > $100k

  2. ❌You can’t combine AND and OR within actions, you must choose one or the other

    1. Not allowed: If [condition], require approval from Jack AND Elon OR Zuck

  3. ❌You can’t have condition → action, and condition → action

    1. Not allowed: If coin is BTC → do X, and if amount is greater than $5M → do Y

Was this article helpful?

That’s Great!

Thank you for your feedback

Sorry! We couldn't be helpful

Thank you for your feedback

Let us know how can we improve this article!

Select at least one of the reasons
CAPTCHA verification is required.

Feedback sent

We appreciate your effort and will try to fix the article