Key Policy Controller
Compiles custody mandates into transaction, signer, quorum, destination, and velocity policy.
Evaluates proposed operations against approved rules and produces a machine-readable decision, while key material stays sealed inside the HSM or MPC boundary, out of its reach.
Authority
Monitor and intervene
Team role
Provides independent challenge
Handoffs
Named collaborators
The role
What it owns and where its authority ends
Desk
Custody, Keys & Resilience
Desk workflow
Validate mandate, assemble policy, collect independent approvals, execute through HSM or MPC, and reconcile signed results.
Collaboration
Separates preparation from review
Decision boundary
Monitors continuously and intervenes only within stated limits.
Systems and capabilities involved
Custody policy engine
HSM/MPC policy interface
Policy metadata only; no key material
Mandate and authority registry
Key ceremony approval
Handoffs
What this role gives and receives
Capabilities offered
Evaluate a custody operation
Returns deterministic policy results, missing approvals, and an expiring execution mandate.
- Receives:
- Signed operation intent and custody context
- Returns:
- Allow, deny, or escalate decision with policy trace
Delegates
Obtain a normalized intent and independent operational checks. Trigger: A custody action requests policy evaluation Returns: Canonical operation intent, simulations, and approval set.
External handoff
Custody risk officer
External handoff
Mandate owners
Context
What the role needs to do the work
- Current work
- The matter in flight: its assets, events, policy results, approvals, and unresolved facts
- Prior interactions
- Prior cases on the same asset or counterparty, exceptions, and reviewer outcomes
- Policies and reference
- Firm asset, chain, entity, jurisdiction, risk, control, and reporting taxonomies
- Working method
- The desk's own approved runbooks and escalation paths
Illustrative workflow
How the work moves
Starting point
Operations requests a large transfer to a newly whitelisted address
- 01
Verify signed intent and mandate
- 02
Apply destination, amount, and quorum rules
- 03
Check cooling-off period
- 04
Issue deny or expiring execution authorization
Result
Cryptographically bound policy decision and approval checklist
Checks and boundaries
What must be tested or reviewed
- 01Cannot access, log, or reconstruct secret shares or private keys
- 02Denies stale mandates, insufficient quorum, and destination-policy mismatch
- 03Policy decisions replay exactly from signed inputs and versioned rules
Human authority
- Named custodians approve every key ceremony, key-share change, recovery action, and exceptional value movement
Keep exploring