Home › Features › Policy Engine
Features · rules enforced at signing

Rules that sign — or refuse to

Ten amount tiers, named approvers, enforced at the MPC signature

Below the threshold, transfers flow; above it, every listed approver must confirm and a single rejection kills the request. A transfer that fails policy is never signed — anywhere, by anyone.

Share the Trust, Guard the Keys

Create accountLive on testnet in an afternoon
Compare PlansIncluded in a plan, not an add-on
The problem

A control that lives in the UI is a control an admin can walk around

Spending limits enforced by a front end are advisory. Vaultody evaluates your rules before the signing ceremony runs: a transaction request that does not clear its policy is never signed, so there is no privileged screen, no override button and no support path that moves funds anyway.

  • Amount bands, not one limitTiers from small transfers to $10M+, each with its own approver set and quorum.
  • Every listed approver, or nothingAbove the threshold each named approver must confirm, and a single rejection ends the request.
  • The rules are themselves governedEditing a policy is an approval-gated action, so relaxing a control leaves the same evidence trail as spending money.

How it works

Anatomy of a rule

A rule scopes one or more vaults, an amount band (10 predefined tiers from $0–10k to $10M+), a rolling time window and a named approver list. With no rule configured there is still no unguarded state — every transaction requires one owner approval by default.

  • Per-vault regimes: reserves strict, float fast
  • Rolling windows catch salami-slicing, not just single big transfers
  • Unanimity by design: every listed approver confirms
rule · operations vault · $50k–$250k
M
Maria Dimitrova
CFO
approver
J
James Chen
CEO
approver
W
Window
rolling 24h aggregate
enforced

Twenty-six actions beyond money

API key creation, webhook changes, team changes, backups, policy edits themselves — all approval-gated through the same engine. Nobody quietly widens their own mandate, including automation.

  • Policy edits require approval — rules govern the rules
  • Automated signers operate strictly inside the rules
  • Every evaluation lands in the append-only audit trail
gated actions — excerpt
CREATE_API_KEY → approval required UPDATE_WEBHOOK → approval required ADD_TEAM_MEMBER → approval required UPDATE_TX_POLICY → approval required CREATE_BACKUP → approval required # …26 action types in total

Availability by plan

Entry1 policy+ implicit owner default
Standard3 policiesper-vault regimes
Business5 policiesfull segregation
Enterprisecustomnegotiated
Specification

Policy specification

What the engine evaluates, and what it deliberately does not.

ScopeRules are set per vault, so reserves and operating float can live under different regimes.
DimensionsAmount band, named approvers, required quorum and the rolling window the band is measured over.
Beyond transfers26 sensitive action types are approval-gated — team members, API keys, webhooks, contacts, automation rules, device changes.
Approver vs signerAn approver authorises a request; a signer contributes a share to the signature. Different acts, often different people — a policy rule counts approvers, never signatures. Both happen in the mobile app.
Enforcement pointThe governance layer, before signing. The signer itself holds no spend policy — there is nothing there to misconfigure.
Rule capacityOne governance rule on Entry, three on Standard, five on Business, negotiated on Enterprise. Automation rules are separate: none on Entry, three on Standard, five on Business.
EligibilityWho may approve a given request comes from that request's approver roles, not from a global permission — a role alone does not unlock approval.
Not availableDestination allow-lists and transaction simulation are not part of the product today.

Frequently asked questions

Get answers to commonly asked questions.

Is it M-of-N approval?

A rule requires all of its listed approvers — deliberate unanimity. Configure smaller approver lists per tier for lighter flows; one rejection always stops the transfer.

Who approves in practice?

Humans on the mobile co-signer — a real key share behind biometrics — or your automated signers for flows you have predefined, both inside the rule.

How many policies do plans include?

1 on Entry, 3 on Standard, 5 on Business, custom on Enterprise.

Share the Trust Guard the Keys

Your mandate, enforced where it cannot be talked around.