Policies

    Edit policies safely

    How a policy change takes effect, what happens to payments already in flight, and how to avoid loosening controls by accident.

    Version 1.1 · Last updated

    When you would do this

    Any time you are about to change a rule that governs money movement. Read this first if you are loosening anything.

    Only an Admin can edit policies. Everyone else can view them, but the controls are read-only.

    How a change takes effect

    A policy change is not a setting that saves when you click, and one Admin cannot apply it alone.

    1. An Admin edits the controls and selects Publish Changes.
    2. The change is queued as a governance item in Operation › Signing.
    3. It requires your full signing quorum, exactly like a payment. A single signature is never enough, even for an Admin.
    4. Once the quorum is met and signed, it takes effect.

    Until the quorum signs it, nothing has changed. If you publish a change and walk away, your old rules are still running.

    What happens to payments already in flight

    Policies are evaluated when a payment request is created, against the rules in force at that moment.

    That means:

    • Payments already in the signing queue keep the rules they were created under. Tightening a policy does not retrospectively block them, and loosening one does not release them.
    • A payment created after the change takes effect uses the new rules.
    • A payment that is stuck because of a rule will not be released by changing that rule. Cancel it and create it again under the new policy.

    The rules that applied are stored with each transaction and appear in its evidence pack, so an auditor sees the rules of the day, not today's rules.

    Loosening a control safely

    1. Change one thing at a time. If several controls move at once and something goes wrong, you will not know which one did it.
    2. Read the Policy Summary panel before publishing. It restates your settings in plain language and is the easiest place to spot a control you did not mean to touch.
    3. Write down why, outside the platform, so the next person understands the intent.
    4. Watch the next few days of payments. If flags disappear entirely, you have probably gone too far.

    Policies are organisation-wide

    A policy applies to your whole organisation and every vault in it. There is no per-vault policy to detach — loosening a control loosens it everywhere, and tightening one tightens it everywhere. There is no way to exempt a single vault from the rules, and there is no way to work around a blocked payment by removing a policy from one wallet. If a payment is stuck, cancel it and recreate it under the current policy.

    What to expect

    Every policy change is recorded in the audit log with who made it, who signed it, and when. This is one of the first things an auditor looks at.

    Common problems and what they mean

    Your change is not applying. It is unsigned in the signing queue.

    A stuck payment did not unstick after you changed the rule. Expected. Cancel and recreate it.

    You cannot publish. You are not an Admin.

    You published something you regret. Publish a corrective change and sign it. You cannot delete the record of the first one.