Privy
Understand identity continuity, wallet roles, exact signing, scoped funding, and recovery.
Privy connects a person to an application identity and wallet. The API still checks organization membership, role, wallet binding, current expense material, and policy before accepting an action.
Use the wallet boundary
A connected address receives no treasury authority until the server verifies its role and exact action.
Restore identity continuity
Consumer and admin use separate Privy realms. A returning user resolves to the existing internal account and eligible wallet instead of provisioning a duplicate.
Bind wallet roles
Organization membership and a verified wallet-role binding determine treasury owner or approver eligibility. The admin deployer remains separate from customer authority.
Sign exact approval material
The approval prompt includes the exact chain, verifying vault, expense version, report hash, policy version, and digest. Submission revalidates all persisted material.
Scope funding and recovery
The funding signer permits only the configured deposit call, amount, vault, chain, zero native value, and expiry. Provider policy denial must be explicit. Wallet export and recovery require fresh user authentication and remain outside screenshots.
