Understanding transaction policies
Each organization manages a list of transaction policies. When a transaction is initiated, it undergoes a matching process against the ordered policies in the list. If a matching policy is identified, the corresponding approval action will be automatically executed. Transaction policies are managed by Cobo Portalโs backend system. They offer:- Flexibility: Easy to modify and update as needed
- Compatibility: Works with multiple wallet types
- Immediate effect: Changes take effect instantly without blockchain transactions
To simplify the initial setup process, Cobo Portal pre-configures a set of default transaction policies for new organizations, designed to provide foundational security. You can adjust these default policies according to your organizationโs specific needs.
Policy matching and precedence
When a transaction is initiated, Cobo Portal evaluates it against your ordered list of transaction policies to decide which approval action applies.How a policy is matched
A policy is matched when the transaction meets all of the policyโs criteria. Depending on the policy type, these criteria can include:- Wallet scope: The transaction must originate from a wallet included in the policyโs applicable wallets.
- Initiators: The team member or API key that initiated the transaction.
- Source and destination addresses: The receiving address, or whether it is included in a specified address list.
- Contract interaction: For contract call policies, the contract address, method, and parameters.
- Amount and spending limits: The transaction amount, per-transaction limit, or accumulated amount within a time window.
- Token types: The tokens involved in the transaction.
How precedence is applied
Policies are evaluated in priority order, from the top of the list downward. Once a transaction matches a policy, that policyโs approval action is applied and no lower-priority policies are evaluated for that transaction.Why a transaction may not trigger an expected policy
If a transaction does not trigger the policy you expected, check the following:- Scope mismatch: The wallet, initiator, address, token, or amount does not meet the policyโs conditions, so the policy does not match.
- A higher-priority policy matched first: Another policy higher in the list already matched the transaction, so evaluation stopped before reaching the policy you expected.
- A condition is not met: A policy requires all of its conditions to be satisfied. If any single condition is not met, the policy does not match.
Accessing Transaction Policies
Transaction Policies is accessible directly from the left sidebar navigation in Cobo Portal. Click Transaction Policies in the left sidebar to open the Transaction Policies page.Page layout
The Transaction Policies page includes the following elements:- Two tabs: Transaction Policies and Address Lists, allowing you to switch between managing policies and managing address lists.
- Manage Emergency Policy button: Quickly access the emergency policy settings.
- Adjust Priorities and Create Policy buttons: Reorder existing policies or create new ones.
- Policy list table: Displays all configured policies with the following columns:
- Priority: The order in which policies are evaluated against transactions.
- Type: The policy type (e.g., Token Transfer, Contract Call, Message Signing).
- Name: The name assigned to the policy.
- Wallets: The wallets the policy applies to.
- Conditions: The conditions that trigger the policy.
- Action: The approval action configured for the policy (e.g., Auto Approval, Auto Rejection, Approval Quorum).
- Status: Whether the policy is active or inactive.
- Operations: Available actions such as editing or deleting the policy.
- Search: Search for policies by policy name.
- Filter: Filter policies to narrow down the displayed list.
Setting up transaction policies
Prerequisite: Please assign the Operator role to the designated team members who will set up transaction policies.
Transaction policies are an important security measure for your organization. It is recommended to strictly configure these policies, especially for large withdrawal scenarios, to avoid high-risk situations such as having no transaction policies, having transactions that are not covered by a transaction policy, automatically approving all transactions, or allowing the same role to both withdraw and approve transactions.
