Skip to content
Digital Assets agents
Industry & NetworksDigital AssetsCustody, Keys & Resilience

Custody Recovery & Continuity Agent

Maintains and rehearses recovery paths for key shares, providers, chains, and critical operators.

Runs non-secret tabletop and sandbox exercises, validates dependency and contact freshness, and assembles a tightly scoped recovery ceremony when activation is approved.

Authority

Prepare

Team role

Coordinates the work

Handoffs

Named collaborators

The role

What it owns and where its authority ends

Desk

Custody, Keys & Resilience

Desk workflow

Validate mandate, assemble policy, collect independent approvals, execute through HSM or MPC, and reconcile signed results.

Collaboration

Coordinates specialist contributions

Decision boundary

Assembles the work product; approval remains elsewhere.

Systems and capabilities involved

  • Recovery runbook vault

    Metadata and procedures; never secret shares

  • Provider health feeds

  • Sandbox ceremony simulator

  • Crisis and custodian command

Handoffs

What this role gives and receives

Capabilities offered

Prepare custody recovery

Builds an approved, scoped recovery plan from current dependencies and tested procedures.

Receives:
Incident facts, affected vaults, and continuity objective
Returns:
Recovery plan, quorum roster, rollback conditions, and evidence log

Delegates

Key Policy Controller

Validate that the proposed recovery path meets current mandate and quorum rules. Trigger: A rehearsal or live recovery plan is assembled Returns: Policy trace and unresolved approval requirements.

Delegates

technology resilience specialist

Test non-key infrastructure, connectivity, and fallback dependencies. Trigger: The recovery plan depends on degraded technology Returns: Dependency readiness and failure-mode results.

External handoff

Crisis command

External handoff

Provider monitoring

External handoff

Business continuity management

Context

What the role needs to do the work

Current work
The matter in flight: its assets, events, policy results, approvals, and unresolved facts
Prior interactions
Prior cases on the same asset or counterparty, exceptions, and reviewer outcomes
Policies and reference
Firm asset, chain, entity, jurisdiction, risk, control, and reporting taxonomies
Working method
The desk's own approved runbooks and escalation paths

Illustrative workflow

How the work moves

Starting point

Primary MPC provider becomes unavailable during market stress

  1. 01

    Confirm incident scope

  2. 02

    Select rehearsed fallback path

  3. 03

    Validate policy and quorum

  4. 04

    Prepare command decision package

Result

Time-bounded recovery ceremony plan with readiness gaps and abort criteria

Checks and boundaries

What must be tested or reviewed

  1. 01Exercises use no production secret material or unauthorized signing power
  2. 02Detects stale signers, unreachable providers, and circular dependencies
  3. 03Recovery plans include stop, rollback, and evidence-capture conditions

Human authority

  • Crisis commander and authorized custodians activate recovery and conduct any real key ceremony

Keep exploring