Custody Recovery & Continuity Agent
Maintains and rehearses recovery paths for key shares, providers, chains, and critical operators.
Runs non-secret tabletop and sandbox exercises, validates dependency and contact freshness, and assembles a tightly scoped recovery ceremony when activation is approved.
Authority
Prepare
Team role
Coordinates the work
Handoffs
Named collaborators
The role
What it owns and where its authority ends
Desk
Custody, Keys & Resilience
Desk workflow
Validate mandate, assemble policy, collect independent approvals, execute through HSM or MPC, and reconcile signed results.
Collaboration
Coordinates specialist contributions
Decision boundary
Assembles the work product; approval remains elsewhere.
Systems and capabilities involved
Recovery runbook vault
Metadata and procedures; never secret shares
Provider health feeds
Sandbox ceremony simulator
Crisis and custodian command
Handoffs
What this role gives and receives
Capabilities offered
Prepare custody recovery
Builds an approved, scoped recovery plan from current dependencies and tested procedures.
- Receives:
- Incident facts, affected vaults, and continuity objective
- Returns:
- Recovery plan, quorum roster, rollback conditions, and evidence log
Delegates
Validate that the proposed recovery path meets current mandate and quorum rules. Trigger: A rehearsal or live recovery plan is assembled Returns: Policy trace and unresolved approval requirements.
Delegates
technology resilience specialist
Test non-key infrastructure, connectivity, and fallback dependencies. Trigger: The recovery plan depends on degraded technology Returns: Dependency readiness and failure-mode results.
Handoff to
External handoff
Crisis command
External handoff
Provider monitoring
External handoff
Business continuity management
Context
What the role needs to do the work
- Current work
- The matter in flight: its assets, events, policy results, approvals, and unresolved facts
- Prior interactions
- Prior cases on the same asset or counterparty, exceptions, and reviewer outcomes
- Policies and reference
- Firm asset, chain, entity, jurisdiction, risk, control, and reporting taxonomies
- Working method
- The desk's own approved runbooks and escalation paths
Illustrative workflow
How the work moves
Starting point
Primary MPC provider becomes unavailable during market stress
- 01
Confirm incident scope
- 02
Select rehearsed fallback path
- 03
Validate policy and quorum
- 04
Prepare command decision package
Result
Time-bounded recovery ceremony plan with readiness gaps and abort criteria
Checks and boundaries
What must be tested or reviewed
- 01Exercises use no production secret material or unauthorized signing power
- 02Detects stale signers, unreachable providers, and circular dependencies
- 03Recovery plans include stop, rollback, and evidence-capture conditions
Human authority
- Crisis commander and authorized custodians activate recovery and conduct any real key ceremony
Keep exploring