
SSP Enterprise: Multisig Vaults for Teams
How organisations, vaults, roles and proposals fit together in SSP Enterprise — and which of them actually stop a transaction rather than just shaping it.
How teams share custody without handing it to one person: organisations, M-of-N vaults, roles that are separate from signing power, policies that shape proposals, and the threshold that decides what actually settles.
6 parts

How organisations, vaults, roles and proposals fit together in SSP Enterprise — and which of them actually stop a transaction rather than just shaping it.

Organisation roles are records; the signer set is an address. The full permission matrix, why admins cannot touch admins, and what requires re-signing.

The five-step wizard, why two of those steps are permanent, what pending setup means, and the four checks to run before any money arrives.

Whitelists, time locks and approval rules shape what gets proposed. Only the signature threshold is enforced by the chain. A three-layer threat model, stated honestly.

Thirteen operations need re-signing, not a session cookie. Why the server writes the challenge, what it is bound to, and why failed attempts are logged too.

A preview of a transaction's effects, fourteen warning checks, address-poisoning detection — and why none of it is allowed to block your signature.