Ten amount tiers, named approvers, enforced at the MPC signature
Below the threshold, transfers flow; above it, every listed approver must confirm and a single rejection kills the request. A transfer that fails policy is never signed — anywhere, by anyone.
Share the Trust, Guard the Keys
Spending limits enforced by a front end are advisory. Vaultody evaluates your rules before the signing ceremony runs: a transaction request that does not clear its policy is never signed, so there is no privileged screen, no override button and no support path that moves funds anyway.
A rule scopes one or more vaults, an amount band (10 predefined tiers from $0–10k to $10M+), a rolling time window and a named approver list. With no rule configured there is still no unguarded state — every transaction requires one owner approval by default.
API key creation, webhook changes, team changes, backups, policy edits themselves — all approval-gated through the same engine. Nobody quietly widens their own mandate, including automation.
What the engine evaluates, and what it deliberately does not.
Get answers to commonly asked questions.
A rule requires all of its listed approvers — deliberate unanimity. Configure smaller approver lists per tier for lighter flows; one rejection always stops the transfer.
Humans on the mobile co-signer — a real key share behind biometrics — or your automated signers for flows you have predefined, both inside the rule.
1 on Entry, 3 on Standard, 5 on Business, custom on Enterprise.

Your mandate, enforced where it cannot be talked around.