Concepts
Vault and roles
Who can do what, and, more importantly, what nobody can do.
The vault
One vault is one contract, deployed for one owner. It holds ETH and any ERC-20 or NFT sent to it. The factory that deploys it has no power over it afterwards: no fee, no owner, no registry you must use.
Owner
A single address. It can be a normal account, or a smart account (a Safe, an ERC-4337 account): the vault only checks that msg.sender is the owner, so any contract that can call it can be one. The owner can announce things and cancel their own announcements. They cannot execute early, cannot veto, and cannot change anything instantly.
Guardian
One of three kinds, decided at creation and changeable only by an announcement:
| Kind | How it refuses | Gas for the guardian |
|---|---|---|
| Passkey (P-256) | Signs with Face ID / fingerprint / PIN. Anyone submits the signature (vetoWithSig). | None |
| Wallet (EOA) | Calls veto directly, or signs an EIP-712 message anyone can submit. | Only if it calls directly |
| Contract (ERC-1271) | A Safe or smart account that validates a signature. Handled by the same vetoWithSig. | None |
The guardian has exactly two powers: refuse one announcement, refuse everything pending (panic). Look at the contract: no function lets the guardian send, approve, call, change the owner or change a setting.
Anyone
Two public actions: execute(id) once an announcement is ripe, and submitting a guardian signature. Because both are open, nothing depends on a particular server or relayer. If one stops, you submit it yourself.
Who can do what
| Action | Owner | Guardian | Anyone |
|---|---|---|---|
| Deposit | yes | yes | yes |
| Announce (send, call, setting) | yes | no | no |
| Cancel an announcement | yes (any pending) | no | no |
| Refuse an announcement | no | yes | only by carrying the guardian's signature |
| Kill everything pending (panic) | no | yes | only by carrying the guardian's signature |
| Execute a ripe announcement | yes | yes | yes |
| Change delay, guardian or owner instantly | no | no | no |
What nobody can do
- Skip the wait. There is no emergency path, no admin override.
- Move funds by whistling. A veto and a panic only change the status of announcements.
- Upgrade the contract, pause it or take a fee.
- Target the vault itself with a
queueCall: the owner cannot make the vault call its own functions.