Skip to content
Satnam SatoshiIn service of humanityFind your place ↗
Menu

Sikh Bitcoin · Expert · Lesson 2 of 21

Design a custody architecture

Separate routine use, authorization and observation.

About 14 minutes with practice. You only need something to take notes with. No real wallet details or payments are part of this lesson.

Course contents · Lesson 2 of 21
  1. Threat model before tools
  2. Design a custody architecture
  3. Entropy, mnemonics and passphrase tradeoffs
  4. Hardware signing and trusted displays
  5. Multisig and independent control
  6. Recovery and continuity across people
  7. Coin control and privacy tradeoffs
  8. Lightning operations and recovery
  9. Payment operations and reconciliation
  10. Native bitcoin and wrapped claims
  11. USDC, reserves and redemption
  12. Identify a Morpho market precisely
  13. Oracles, prices and measurement risk
  14. LTV, liquidation and nonlinear losses
  15. Variable rates and growing debt
  16. Vaults, allocation and exit liquidity
  17. Arc, Base and cross-chain dependencies
  18. Allowances, signing and simulation
  19. Treasury accounting and restricted funds
  20. Incident response with clear human authority
  21. Capstone: a defensible treasury design

What you will learn

  • Map the different functions of a custody system.
  • Avoid confusing watch-only access with operational safety.

Divide responsibilities by purpose

An architecture can separate payment preparation, signing, observation and reconciliation. A watch-only system may generate addresses or inspect balances without holding spending keys. An offline signer can authorize a transaction prepared elsewhere. These separations help, but the interfaces between them still need verification of the intended policy and outputs.

Minimize authority where possible

A research agent usually needs public or redacted observations, not credentials that can transact. A bookkeeper may need receipts, not every private wallet detail. A signer needs a clear proposal and independent display, not a command to approve everything a coordinator creates. Access should match the job and be revocable without destroying the only recovery path.

Document what remains dependent

A diagram with cold storage at the center may still depend on one coordinator, one cloud account or one person who understands recovery. Name those dependencies and test alternatives. Do not assume a native Bitcoin multisig and an EVM smart-contract wallet have identical guarantees just because both use multiple approvals. This exercise describes architecture choices; it does not authorize establishing custody or moving community funds.

Practice on paper

Assign prepare, sign, reconcile and read-only research roles in a fictional four-person team. Which roles must an agent not silently acquire?

Reveal the worked answer

An agent may assist preparation or research within a brief. It must not acquire signing, custody or spending authority because its draft was accepted. Human approval and reconciliation remain separately assigned responsibilities.

Check your understanding

Choose an answer in your head or on paper, then reveal the explanation. Retry whenever you like. Answers are not submitted or scored; completion marks are your own learning notes.

1. Does watch-only mean the data is harmless to disclose?

  • Yes
  • No
Reveal answer 1

No. It can reveal sensitive financial history.

2. Does an offline signer eliminate the need to inspect outputs?

  • Yes
  • No
Reveal answer 2

No. It can still authorize a maliciously prepared transaction.

Take this with you

Separate capability, ownership and human authorization in the design.

Your learning, at your pace

Read every lesson freely. Optional progress tracking needs JavaScript and browser storage; it does not require an account or wallet.