Policies FAQs
Who can create policies for all wallets or wallets by type?
Enterprise admins can create policies of all wallets and wallets by type, but require approval from 1 other enterprise admin.
View the Roles and Permissions Matrix for more information
Where do I set how many approvals are required for new policies and policy changes?
Currently, in the wallet settings
What happens if I try to update a policy but I have fewer admins than the required # of approvals?
Automatically rejected. This is what happens today as well.
Additionally, there’s logic in the wallet settings for required # of approvals, so you can ensure the number you set is n - 1. To reach this edge case you must remove wallet admins from the wallet below that original threshold.
What happens if there’s only 1 admin on the wallet?
This admin is able to build any policies they want on the wallet and there will be no approvals required.
What changes to a policy require approval?
Any changes to a policy requires approval. E.g.,
Name change
Scope change
Touchpoint change
Condition change
Action change
Are V1 wallets supported in the new Policy Engine?
No, you continue to manage policies in the V1 wallet policies page
Not even All Wallets policies cover V1 wallets
What about in-progress policy changes?
BitGo only allows 1 in-progress change at a time
Example:
userA requests to unlock policyX
policyX is now unlocked for 48 hours
userA changes the spending limit of policyX from $50k to $100k
userA submits and this goes to approval
now while policyX is unlocked userB thinks they can also make a change, so they open the policy but are shown a message along the lines - “this policy has already been edited” and cannot make changes until the existing pending approval is approved/rejected
If the change userA made is rejected and there is still remaining time before it gets locked, userB can now open policyX and submit changes, which then go to pending approval again
Can I build many policies that cover the same wallet?
Yes, you can create any number of policies that cover a given wallet
What happens when a single transaction triggers multiple policies?
The actions associated with each policy all apply
BitGo aggregates and deduplicates. For example:
Policy1 Actions: Get 2 approvals from userA, userB, userC, userD
Policy2 Actions: Get 1 approval from userC, userE, userF
Both policies need to be fully satisfied in order to let the transaction through.
Scenarios:
☑️userA, userB, and userE approve
☑️userA, userC approve (userC satisfies ½ of Policy1 and all of Policy2)
✖️userC, userE, userF approve (did not satisfy Policy1)
What is the order of actions?
Currently, the only action that takes place after the other actions is the final approval
Otherwise, all actions are handled at the same time - users are notified at the same time, any action can be resolved at the same time, etc.
What happens to my whitelist?
Whitelists continue to exist in each wallet and at the enterprise level. However, you can customize the behavior of what happens when withdrawing to non-whitelisted addresses. For example:
Scope: All Wallets
Touchpoint: withdrawal
Condition: destination - non-whitelisted address
Action: Deny (or require approval.)
What happens if the pending approval for a policy change is not approved before the unlock period ends?
The pending approval will continue to exist and approvers can still approve or reject the policy change. If approved, the policy update takes effect.
This is different from today where a user must unlock the policy again just to approve the changes.
Is the API for the new Policy Engine available to me?
Yes
Was this article helpful?
That’s Great!
Thank you for your feedback
Sorry! We couldn't be helpful
Thank you for your feedback
Feedback sent
We appreciate your effort and will try to fix the article