Business Accounts are in early access. See the overview for the model.
What you set up
A business account with one wallet, a manager who administers as anadmin member, and one end-user signer bound by signer-layer deny rules.
Prerequisites: Business Accounts access, which is in early access, and step-up authentication for the caller who adds signers.
1
Create the account and wallet
The manager signs up, creates the business account, and creates the wallet the end user will sign with. As creator, the manager becomes the owner and the wallet’s first signer. That first signer matters later, because only someone already signing on a wallet can add new signers to it.
2
Add the manager as admin
The account’s creator is already the owner, so this step applies when a different operator administers the account. The manager administers but does not need to sign beyond the initial setup.
3
Add the end user as signer
Adding a signer requires step-up authentication and a caller who is already an active signer on the wallet; the creator qualifies from the previous step. Best practice also puts governance on
addSignerToWallet so signer additions need approvals; see Governance.4
Set signer-layer deny rules
Scope Because rules must pass every layer, the manager can also set broader account or wallet rules underneath. See Policies.
createPolicy to the end user’s share set so the deny list applies only to their signing, not to the manager’s administration or any other signer. Deny known-bad or off-limits destinations; add blockExport to keep the key from leaving the wallet.Things to know
- A
shareSetIdrotates when wallet shares refresh. Re-read it before each policy update rather than storing it; a stale value is rejected with a stale-share-set error. See Policies. - You cannot remove the last active signer on a wallet. Add a replacement signer before removing the current one.
- Members and signers are independent: the manager signs here only because they created the wallet, not because
admingrants signing, and the end user’s signer access grants no admin rights.