Concepts
Lookout and watcher
A guardian who never looks is just a delay. These make sure you look.
Why you need one
The waiting room protects you only if somebody is watching it. A veto needs a human decision ("is that me?") or a rule ("is that an address I know?"). Marmot ships both a web lookout and a terminal watcher.
The web lookout
Open the Lookout, paste the vault address. It reads the chain directly from your browser (the public RPC allows it), shows every announcement in a sentence, and refreshes every 6 seconds. When a new one appears it plays a whistle, flashes the tab title and, if you pressed "Alert me", sends a desktop notification. Each live announcement has a "Whistle" button.
For a passkey guardian, the button asks your device for the passkey, checks the signature in the page, then offers to send it with your wallet, or to copy the calldata or a CLI command. For a wallet guardian it builds the veto transaction for that wallet.
The terminal watcher
node cli/marmot.mjs watch <vault> [--interval 5] [--notify-url URL]
[--auto-veto --allow 0xA,0xB]
On start it examines everything already waiting (announcements made while it was off), then follows new events. For each announcement it prints a line with a risk label, and posts JSON to --notify-url if you gave one. The JSON carries both a text field (Slack-style webhooks) and a content field (Discord webhooks), so either accepts it as is.
QUEUED #4 [MONEY] Send 1.0 ETH to 0x0F54...1074 (ready 2026-10-10T15:18:19.000Z)
PENDING #5 [UNLIMITED APPROVAL] Let 0x91aa...30c2 spend UNLIMITED USDC
QUEUED #6 [CONTROL CHANGE] Hand the vault to a new owner 0x4faE...432E
Auto-veto
With --auto-veto and a guardian wallet key in MARMOT_PRIVATE_KEY, the watcher refuses every announcement that is not a plain send (ETH or token) to an address on your --allow list. That means every approval, call, setting and owner change is refused automatically, and so is any send to an unknown address.
It checks that the announcement is still live before sending the veto, so replaying history never fires a stale transaction. A passkey guardian cannot auto-veto: a passkey needs a person. Use the notification to wake yourself up.
An auto-veto key lives on a machine that is online. It can only refuse, never move money, so the worst a thief can do with it is annoy you. Even so, treat it like a password.
Risk labels
| Label | Means |
|---|---|
| MONEY | Sends ETH or tokens out, or an ordinary call |
| UNLIMITED APPROVAL | An approve with an effectively unlimited amount. Once run, the spender can drain that token without the vault. |
| CONTROL CHANGE | Changes who controls the vault (new owner or new guardian), or shortens the wait below an hour |
| SETTING | Changes the wait to an hour or more |
Keeping it running
On a spare machine or a small server, run the watcher under any process manager (pm2, systemd, a Windows scheduled task). Keep the --notify-url webhook private. Check that you really get the alert: announce a tiny test withdrawal and see how long the notification takes.