Roles & Permissions
Capabilities, restrictions, approval requirements, and risk implications for Torq roles.
Torq uses roles because credit operations are not one job. Depositing, borrowing, submitting valuation data, changing oracle policy, managing a vault, and recovering a stressed market require different authority.
Role authority is checked through function registry entries, page surface registry entries, role function catalogs, role field catalogs, permission contracts, and timelock routes.
Role design in context
Aave-style pool usage is often explained from the point of view of a supplier, borrower, liquidator, or governance participant. Morpho Vault V2 documents owner, curator, allocator, and sentinel-style separation. Torq extends the role model into a full operating workspace map: protocol manager, asset manager, asset issuer, NAV reporter, investor, lender, borrower, liquidator, partner, guardian, council, operations SRE, release manager, vault owner, allocator, and projector responsibilities are all tracked as product roles.
Product safety model
Controlled credit workflows need visible permissions and completion
role + wallet + entity
NAV + Live-Feed + oracle status
wallet plan + action review
indexed state + workspace refresh
Role inventory
| Role | Capabilities | Restrictions | Approval requirements | Risk implications |
|---|---|---|---|---|
protocol_manager | Operates Protocol Manager inventory, assets, issuers, reporters, oracles, IRMs, markets, roles, settings, faucet, and incident fields. | Does not bypass contract ownership, timelock, entity scope, or permission checks. | Direct, timelock, or governed route depending on action. | Highest operational blast radius; wrong changes can affect global fields. |
guardian | Handles safety actions, emergency state, critical-role recovery, freezes, and selected risk fields. | Cannot freely manage unrelated business settings. | Often direct for protective actions; timelock or scoped route for sensitive changes. | Misuse can block risk-increasing actions or change emergency posture. |
council | Participates in governance transitions such as selected IRM or oracle transitions. | Limited to governed action families. | Governed or timelocked execution. | Incorrect approvals can change market behavior. |
asset_manager | Operates vault programs, assets, oracles, markets, IRMs, partners, roles, profile, AI allocator support, and price adapters. | Scope is tied to managed entities; not global protocol admin by label alone. | Direct, scoped, or timelocked route depending on target action. | Fields credit program configuration and partner exposure. |
curator | Compatibility role mapped to active Asset Manager surfaces where supported. | Legacy label; active runtime reasoning uses V2 asset-manager/vault-control paths. | Same as equivalent active asset-manager route. | Confusion risk if treated as legacy runtime authority. |
vault_owner | Owns or accepts vault-level authority where configured. | Cannot control unrelated vaults or global protocol settings. | Vault-scoped route, acceptance flow, or timelock depending on action. | Fields sensitive vault configuration. |
vault_pending_owner | Can accept pending vault ownership where staged. | Cannot act as owner before acceptance. | Acceptance action path. | Prevents accidental or unauthorized owner transfer completion. |
vault_manager | Operates vault-management fields where configured. | Restricted to assigned vault surfaces. | Entity-scoped permissions. | Mistakes affect one vault program rather than the whole protocol. |
allocator | Allocates or toggles market capacity where allowed. | Cannot grant itself policy authority. | Vault or market-scoped permission. | Incorrect allocation can create unintended credit exposure. |
asset_issuer | Submits assets, tracks controlled assets, NAV reports, roles, messages, and incident context. | Submission does not equal protocol listing or vault authority. | Metadata action path or scoped approval for supported actions. | Bad metadata can mislead review if not checked. |
nav_reporter | Submits valuation reports and maintains covered asset/report context. | Reporting authority is not general governance authority. | Signature, cadence, quorum, signer, and freshness checks where configured. | Bad or stale NAV can affect action availability. |
oracle_bootstrap_actor | Performs bounded oracle setup or bootstrap tasks. | Restricted to setup/preflight scope. | Configured bootstrap permissions. | Incorrect oracle setup can affect valuation fields. |
investor | Reviews portfolio state, vaults, partner paths, messages, and supported investor routes. | Cannot force liquidity, bypass queues, or treat a visible route as investment authority. | Wallet and vault-state checks where action is available. | Faces vault, tranche, queue, valuation, and facility exposure risk. |
borrower | Deposits collateral, borrows, repays, and withdraws collateral through market detail. | Cannot borrow without valid route, collateral, oracle state, and market/vault conditions. | Wallet execution with route and risk checks. | Unsafe borrow or withdrawal can trigger liquidation. |
lender | Deposits, reviews positions, requests redemption, and monitors vault exposure. | Cannot force liquidity or bypass queues. | Wallet approval and vault state checks. | Faces vault, tranche, queue, and credit exposure risk. |
liquidator | Executes liquidation or recovery action paths where valid. | Cannot liquidate healthy or protected positions. | Market, borrower, oracle, close-factor, and freeze checks. | Incorrect liquidation handling can affect recovery fairness. |
partner | Coordinates partner access, messages, applications, and channel context where configured. | Does not control source vault authority or valuation policy. | Partner-scoped approval or metadata route depending on action. | Misstated partner authority can create distribution and attribution risk. |
operations_sre | Reviews incident, operational, and governed-action state where surfaced. | Does not become protocol admin or bypass wallet/timelock authority. | Operations-scoped review route and configured incident permissions. | Weak operations review can hide degraded-state or response gaps. |
release_manager | Reviews release readiness, evidence, and deployment-related state where surfaced. | Does not turn advisory evidence into release certification by label alone. | Release-scoped review route and governed evidence checks. | Premature readiness labeling can create false assurance. |
indexer_projector | Produces application truth from observed events. | Not a user-facing financial authority role. | Operational service authorization and deployment fields. | Bugs can show stale or wrong product state. |
A Torq role is not just a label on a page. It is tied to a wallet, an entity, a function family, a result surface, and sometimes a timelock. If any part does not match, the action can be blocked.
Permission model
| Permission layer | Plain meaning | Example |
|---|---|---|
| Role | The job the user is allowed to perform. | asset_manager, borrower, nav_reporter. |
| Entity scope | The object the role can touch. | One vault, one asset issuer, one market, one workspace. |
| Function family | The action family being attempted. | borrowerBorrow, vaultDeploy, permissionTemplateAndGrantSave. |
| Route owner | The source that decides direct, metadata-only, wallet, or timelock path. | Function registry and action matrix owners. |
| Result surface | Where the user verifies the action after execution. | Vault detail, market detail, Protocol Manager settings. |
Approval requirements
| Approval path | Meaning |
|---|---|
| Metadata-only | Persisted database/API update; no wallet transaction by itself. |
| Direct wallet write | User signs one or more required transactions. |
| Direct or timelock | Direct execution if authority allows; otherwise queue and execute through timelock. |
| Timelock | A sensitive change is queued, waits the configured delay, then executes. |
| Blocked | Missing permission, stale state, unsupported route, invalid input, or unsafe condition. |
For reviewers
The role list is grounded in apps/web/config/roleFunctionCatalog.json,
apps/web/config/roleFieldCatalog.json, apps/web/config/functionRegistry.json, and the active V2
permission contracts listed in the contract inventory.