Use case
Institutional wallet policy
Who can move an asset, under what limit, and what happens when a person or a device is gone. A wallet library is not that policy.
A firm holds or instructs movement of digital assets and needs quorum, limits, and a record a risk committee can read.
When shared machinery earns a place
Shared control of keys, especially across entities, is a real problem. Multisig and smart accounts are patterns, not compliance.
When it does not
If you do not hold assets and do not instruct a custodian, you need an approval workflow, not a wallet stack.
Conventional-first
Instruction workflow, dual control, custodian API, your own audit log.
You trust the custodian's controls. You do not operate keys.
Hybrid
Quorum account, spend limits, allow-listed destinations, indexer of your own movements.
LGPL and admin-module risk on some account contracts. Key ceremony is now yours.
On-chain-native
Smart account plus an off-chain approval tool. Still not a licence to custody.
Public policy can leak a firm's controls. Incidents are irreversible.
Patterns
Components
- Safe Smart AccountAmber — conditions, and a legal review before you copy it in
- viemGreen — compatible use if you keep the notices
- AlloyGreen — compatible use if you keep the notices
- PonderGreen — compatible use if you keep the notices
Questions a person still has to answer
- Are you the custodian, the adviser, or the software vendor?
- What is the recovery path?
- Which modules can bypass the quorum?
