Operators & Multisigs

Three MPCs hold every privileged role across the protocol. Their powers do not overlap. Their signer sets are operationally required to be distinct. Every privileged write routes through the AccessManager hub, which schedules timelocked actions and enforces role gating on every selector.

Three MPCs, distinct signer sets, all writes through AccessManager.

Three MPCs with distinct signer sets. ADMIN 3/5 (3-day standard, 7-day upgrades, 14-day meta-timelock). RISK_COUNCIL 3/5 (3-day). GUARDIAN 2/5 (instant).
Three MPCs with distinct signer sets. ADMIN 3/5 (3-day standard, 7-day upgrades, 14-day meta-timelock). RISK_COUNCIL 3/5 (3-day). GUARDIAN 2/5 (instant).

ADMIN — 3-of-5 MPC, 3-day timelock (7-day for upgrades)

Powers

Powers it does NOT have

Composition at MVP

Five members from The Trust Company senior representatives, external counsel (Reed Smith partner, Carey Olsen partner), and one technical lead. Distinct from RISK_COUNCIL and GUARDIAN.

Tempo

Standard ADMIN actions scheduled through AccessManager with a 3-day delay. Upgrades carry a 7-day delay. GUARDIAN can cancel during the window. A 14-day meta-timelock gates the delay parameter itself.

RISK_COUNCIL — 3-of-5 MPC, 3-day timelock

Powers

Powers it does NOT have

Composition at MVP

Five members from the off-chain Risk committee. Reed Smith, Carey Olsen, The Trust Company, plus two further committee members. Decentralisation roadmap as in Risk committee.

Tempo

3-day delay. Credit and recovery decisions need to land within a working week. Pre-announced and reversible until execution. GUARDIAN-cancelable.

GUARDIAN — 2-of-5 MPC, instant

Powers

Powers it does NOT have

Composition at MVP

Five members optimised for fast response — security-experienced operators across multiple time zones. Distinct from ADMIN and RISK_COUNCIL. Lower threshold (2-of-5) reflects the defensive-only role: a compromised GUARDIAN can grief but cannot escalate, and restoration is ADMIN’s job.

Tempo

Instant. Every action reviewable on-chain. No single-call “revoke everything” switch — every revocation is a named record with bounded blast radius.

Signer-set rotation

Rotation requires off-chain review and is published in the signer registry. The protocol does not enforce signer-set distinctness on-chain — that is procedural, enforced at construction. A rotation that violated the constraint would not be caught by the contracts; the mitigation is the published registry and the rotation playbook.