For the complete documentation index, see llms.txt. This page is also available as Markdown.

Roles & Access

Access to Dedicated Client Vaults is split into two layers: what your team can do in the Tesseract dashboard, and who can move funds on-chain. They are deliberately separate β€” no dashboard role can move funds.

Dashboard roles

When your organisation is onboarded you can invite team members and assign each a role. Roles are ready-made permission sets (individual permissions can also be fine-tuned per user):

Role
What it can do

Viewer

Read-only across the dashboard β€” clients, KYC status, wallets, vaults and reports.

Whitelisting Manager

Everything a Viewer can, plus verify and whitelist wallets for on-chain access.

Admin

Full access, including managing team members (inviting, suspending, adjusting permissions). Provisioned at onboarding.

It all ends at wallet whitelisting

The most any dashboard role can do to affect on-chain activity is whitelist a wallet β€” the job of the Whitelisting Manager. Whitelisting only approves a wallet to interact with vaults; it moves no funds.

Deposits and withdrawals are authorised solely by the whitelisted wallet itself β€” no dashboard role, and no one else, can move funds on your behalf. Tesseract's discretionary management rebalances within your chosen strategy under separate, tightly scoped controls and can never withdraw to an external address; funds only ever move back to your own whitelisted wallet.

Because on-chain control comes down to one wallet, the security of your vault funds is the security of the wallet you whitelist. We recommend whitelisting a wallet that already carries your organisation's custody and approval controls β€” an MPC wallet (e.g. Fireblocks) or an on-chain multisig / smart account (e.g. Safe) β€” so vault interaction reuses your existing security practices (multiple approvers, signing thresholds, transaction policies, audit trails) with no separate approval layer to maintain.


See also: Prerequisites: KYC & Whitelisting Β· FAQ.

Last updated

Was this helpful?