Forge template
Custody policy console
Allow-list, labels instead of keys, and a simulated broadcast. No signer.
Start from a reviewed template, not a random repository.
Adapters in this template
- Allow-list
Running in a demo
An instruction to a destination that is not allow-listed is held. Destinations are labels.
- Destination label
Running in a demo
The destination field is a demo label. There is no key field.
- Emergency hold
Running in a demo
Policy hold stops an instruction until an approver releases or rejects it. Broadcast is only a simulation after approval.
- Hard cap
Running in a demo
A synthetic amount above the hard cap cannot be submitted. The cap is demo units.
- Role access
Running in a demo
Each desk has named roles. A restricted field is hidden from the role that should not see it.
- Audit log
Running in a demo
Each transition appends an event the auditor can read. The digest is a label, not a cryptographic hash.
- State machine
Running in a demo
A record only moves along the transitions defined for its desk.
- Demo fence
Running in a demo
Every running desk states that it is synthetic, local, and not for production.
Held out
These stay on the external registry. They are not composed into the template and they are not copied.
- Account pattern, reference only
Reference only · not composed
Read the account-abstraction pattern on the component page. That page records GPL-3.0. Forge does not copy the repository.
- Wallet session, reference only
Reference only · not composed
A public wallet-session repository can still be the wrong thing to copy. The component page records a custom community licence, not an OSI grant.
Not in the box
- Private repository
- Push or pull request to an upstream project
- GitHub Codespaces
- Dev Container
- Docker Compose file
- Ephemeral preview URL
- SBOM
- Pinned commit
- OpenSSF score
- Secret scan
- Vulnerability scan
- Source-derived code pack
