Institutional Vault Overview
Institutional Vault streamlines crypto operations and treasury management for institutional banks, stock brokers, and large institutional companies. The most reliable blockchain infrastructure backs it. With a single integration, the Institutional Vault assists the institution in managing its digital assets.
You can also check out our video guide on how to onboard the Institutional Vault here:
Blockdaemon Institutional Vault Demo
1. Institutional Vault Features
Institutional Vault offers five important features that make it suited for numerous industries, including traditional Web2 companies, crypto-accepting payment companies and custodians, and Web3 or crypto foundations.
2. Institutional Vault Policies
Institutional Vault applies a set of principles to a specific set of operations, including both transaction and staking operations. The policy framework guides the decision-making process to determine whether an operation should be approved, rejected, or completed.
2.1. Three Types of Policies
Institutional Vault divides the policies into three categories based on the wallet configuration:
2.1.1. Administration Policy
Administration Policy is a collection of rules governing all wallet operations. This policy specifies the behaviour of a wallet for every operation performed on it. This policy is only modifiable by users with the Admin role. This policy addresses user management, group management, and the modification of the transfer policy.
2.1.2. Transfer Policy
A transfer policy is a list of rules for making transfers or transactions. It is only modifiable via the administration policy.
2.1.3. Staking Policy
A staking policy serves as a guidebook for how staking functions in the Institutional Vault. This policy provides clear directions and settings for overseeing the asset staking process, ensuring its smooth and secure operation.
3. User Management
User Management refers to the process of defining and controlling access within the Institutional Vault system. It involves categorizing users into different types and assigning them roles.
3.1. User Types
User types categorize users based on access and interaction with the wallet:
- Users (Human Users): A non-administrator with general access. They can access features but cannot modify policies or settings. Each user must belong to at least one group. If not explicitly assigned, they default to the "all-approvers" group.
- System Users: Programmatic users created for automated access. They are managed by admins, can have roles, and use API keys for authentication in API requests.
3.2. Roles
Roles define what a user can do within the wallet system. Regardless of whether the user is a human or system user, roles define the specific actions or permissions granted to that user. Available roles are:
| Roles | Description |
|---|---|
| MarketOps | A role for users who need more permissions than a standard user but fewer than an admin. They manage trading operations, transfers, and asset monitoring. |
| Viewer | A read-only role that allows users to view transaction history and export data without making any changes to the system. |
| Admin | The highest level of access. Admin users have full control over the wallet system, including creating and managing groups, assigning roles, and configuring wallet policies. |
4. Approval Process User Role
Institutional Vault is a secure platform that allows users to manage their cryptocurrencies easily. The platform includes features such as transaction intents, policies, and approval rules, which help ensure transaction security and integrity. The approver and the confirmer are two distinct roles in the transaction approval process.
4.1. Approver
The approver is any user granted permission to approve transactions through the approval app. These users are typically part of a group quorum defined by the wallet's policy and related rules. The approver is responsible for evaluating the transaction request and deciding whether or not to approve it. This role is critical for preventing fraud and unauthorized access to user funds.
4.2. Confirmer
The confirmer is typically the user who initiated the transaction intent and is responsible for initiating the confirmation process by sending a confirmation request to the approval app.
By separating the confirmer and approver roles and requiring multiple approvals for certain transactions, Institutional Vault ensures that all transactions are securely executed.
5. Supported Protocols and Networks
Institutional Vault supports the following protocols and networks:
| Protocols | Networks |
|---|---|
| EVM-compatible chains | Any EVM-compatible network |
| Base | Mainnet/Sepolia |
| Bitcoin | Mainnet/Testnet |
| Canton | Mainnet/Testnet |
| Ethereum | Mainnet/Hoodi/Sepolia |
| Kaia | Mainnet/Kairos |
| Polygon | Mainnet/Amoy |
| Polkadot | Mainnet/Westend |
| Solana | Mainnet/Testnet/Devnet |
6. Supported Confidential Computing Configurations
| Provider | Technology | Signed Software Images | Remote Attestation for Secret Release | Supported |
|---|---|---|---|---|
| AWS | Nitro Enclaves | Yes | AWS KMS | Yes |
| Azure | ACI Confidential Containers (AMD SEV-SNP) | Yes | Premium Azure Key Vault (HSM) | Yes |
For how MPC key shares are protected inside TEEs, including attestation, encryption at rest and in transit, and comparison with physical HSMs, see MPC and TEE Security Architecture.
Contact for Assistance
Please contact us via email or support chat if you encounter an issue, bug, or need assistance. Don't forget to include any relevant details about the problem.