Who can do what - delegating the Convert console
How the install grants the Convert keys from keys your roles already hold, why the three manage keys are granted to nobody, which keys let a delegate move the house's money or decide what happened on a chain, and the role layout that keeps those apart.
Instant Convert follows the platform's <verb>.convert.<section> pattern:
access opens a screen, view reads it, edit changes terms or moves the
house's inventory, and manage settles something only a person can decide. Every
key and the route or screen that demands it is in the
permissions reference.
What the install grants
The permission seeder that ships with Instant Convert derives grants from keys you already chose by hand, never from a role's name, so an install that renamed or split its roles is not silently left out:
| Keys | Granted to every role that holds |
|---|---|
access.convert, view.convert, every view.convert.*, access.convert.settings |
view.transaction |
every edit.convert.* |
both edit.deposit and edit.withdraw |
manage.convert.send, manage.convert.hedge, manage.convert.rebalance |
nobody |
- Read follows
view.transaction. Every Convert screen reads customer converts and the house's balances: the same ledger the transaction log shows, seen from the other side. - Edit needs both money witnesses. Enabling an asset, funding or defunding the house, setting floors and caps, changing the fee and spread and starting a house movement each move or price the platform's own inventory against customer money. A role that already decides customer money in both directions holds more than this; a role that decides only one does not acquire the other sideways through a console it has never seen.
- Manage is granted to nobody. Approving, confirming or reversing a Send, resolving a hedge or a movement in review, and unfreezing a currency each declare, on the operator's word, what happened on a chain or at a venue, and a wrong answer pays twice or not at all. No existing key has that weight to derive from.
The seeder only adds missing pairs. It never revokes, never widens a role beyond what its witnesses already say, and running it again changes nothing. Super Admin holds everything by name and needs no rows.
Keys that can cost money in the wrong hands
| Key | Why it matters |
|---|---|
manage.convert.send |
Reversing a payout that later lands pays the user twice from the house. The engine demands the chain's proof, but approve and confirm are still judgements. |
manage.convert.hedge |
Marking a hedge failed that did execute leaves a position unbooked and hedged twice. Unfreezing and reopening quoting put a currency back in play. |
manage.convert.rebalance |
Marking a movement failed, or writing a credit off, decides where the house's coins are. |
edit.convert.inventory |
Funds and defunds the house from the Super Admin wallet, sets each currency's floor and target (a lower floor lets the house pay out further), and turns Convert & Send on or off per chain, with the house's on-chain floor and target there. |
edit.convert.settings |
The fee, the spread, the guards and the limits. Also runs Sweep now on the P&L page. The nine protected keys still need a Super Admin. |
edit.convert.asset |
Opens a currency to converts, or widens its size limits. |
edit.convert.rebalance |
Starts a house movement by hand: the house's own coins leave the exchange for a chain, or a chain for the exchange. Every switch, band floor and venue limit of the automatic cycle still applies. |
manage.pool.backing |
The core Instant Convert house page: defund, and settle Sends, hedges and movements while the addon is off. Always with a second factor; the kill switches also need Super Admin. |
A layout that keeps them apart
- Support reads:
access.convert,view.convert*. They can see a user's convert, its quote and its payout, and answer the ticket. - Treasury funds, prices and moves the house's coins: add
edit.convert.asset,edit.convert.inventory,edit.convert.rebalanceandedit.convert.settings. - Operations settles the queues: add
manage.convert.send,manage.convert.hedgeandmanage.convert.rebalance, to the few people who will actually check an explorer or a venue before they click. - Super Admin keeps the kill switches, the exposure and hedge caps, drain mode and the profit sweep.
Alerts about stuck payouts go only to accounts whose role is named Admin or
Super Admin (Super Admin alone on a demo install): an Admin who holds
view.convert.send or manage.convert.send, and every Super Admin. The install
gives view.convert.send to every role that holds view.transaction, so such an
Admin role is alerted without further grants. A role you create, such as the
Operations role above, is never alerted whatever keys it holds, so whoever
settles the queues there should watch Sends and the dashboard's Needs
attention card.