Note:
This article combines three related procedures: creating, editing, and publishing a Policy. These steps are typically performed in sequence.
Create a Policy
You can use the Fireblocks Console to create Policies customized to your organization's financial security needs. Before you begin, review the About Policies article. If you have any questions, contact your Customer Success Manager.
Before creating your Policy
- Read Policy examples for helpful templates and use-case guidance.
- Review Policy best practices for important tips and reminders.
- Apply rules to specific users, including API users, and make sure to create and configure each user before creating the rules.
- Set up any source or destination in your workspace that you wish to use in a rule before creating the rule. Review how to create a vault account or link an exchange account before using them as a source or destination. This also applies to Fireblocks P2P Network connections and whitelisted addresses.
- To apply rules to user groups, create the groups on the Manage Groups page of your Fireblocks Console. We recommend that all users in the same group have similar workspace roles.
Please note the following:
- Only the workspace Owner or Admin-level users can create Policy rules.
- Policies can only be edited by one person at any given time.
- The Policy Editor automatically times out after 30 minutes of inactivity.
- If you plan to perform Web3 operations, we recommend creating a DeFi policy.
Active policies
The Policies page in your Console has two sections: Active and Unconfigured policies. Initially, both sections appear under an Overview tab, but each activated Policy creates its own tab at the top of the page.
To add rules to your active Policies:
- In the Fireblocks Console, select Policies in the left navigation panel.
- Under the Active policies section, choose the Policy type (e.g., Transfer), then select Edit policy.
- Select +Add rule to open the Policy Editor, where you can configure rules using the appropriate rule parameters. Each parameter allows you to define specific conditions for when the rule should apply.
- After building your rules, select Add rule. The new rule appears in the Policy Editor. Use the arrows to the left of your rules to reorder them following the first-match principle.
- Review your changes, then select Publish policy to submit your changes to the approval group assigned to Policy changes.
Note:
Saved Policy drafts don't affect your active Policies.
Unconfigured policies
To create a Policy from the Unconfigured section (which displays all Policy types that have not yet been activated):
- In the Fireblocks Console, go to Policies in the left navigation panel.
- Under the Unconfigured policies section, select the Policy type you want to create (e.g., +Add Stake policy).
- Follow steps 3 to 5 above.
Note:
If you see error messages while creating or editing rules, see Policy rule error messages for guidance on resolving them.
Edit a Policy
The Policy Editor, located in the Fireblocks Console, is a tool to manage your organization's Policies. Access it from the Policies option in the left navigation panel. Before getting started, make sure you have reviewed About Policies and the create steps above.
You can use the Fireblocks Console to edit your active Policies by submitting rule changes for approval and publication. Generally, changes to your Policy rules only apply to transactions submitted after the changes are approved. Transactions already in progress will have the Policy rules active at the time of submission applied to them. In some cases, such as with AML screening, the transaction may not reach your Policies instantly, so the new Policy rules would be applied instead.
Additionally, note the following:
- Only your workspace Owner or other Admin-level users can edit your Policies.
- Policies can only be edited by one person at any given time.
- You are automatically timed out of the Policy Editor after 30 minutes of inactivity.
Viewing drafted changes
When editing a Policy, you can review the drafted rule changes. In the top-left corner, you can see if other Admins drafted changes in the same timeframe that may conflict with yours.
- Added rules appear with a green badge.
- Deleted rules are grayed out with diagonal stripes.
- Edited rules include a button to expand the rule to compare the old and new versions. Modified parameters are shaded in gray.
- Moved rules appear in their new position and are deleted from their old position.
Important:
Only one user can edit a Policy at a time. If you don't exit the Policy Editor, your Owner and other Admins will be prevented from editing that specific Policy. To limit this possibility, you will be automatically timed out of the Policy Editor after 30 minutes of inactivity.
Editing a rule
- In the Fireblocks Console, select Policies in the left navigation panel.
- Select the Policy type (e.g., Transfer or Contract Call), then select Edit policy.
- Hover over the rule you want to change, then select More Actions (...) > Edit.
- Change the rule's parameters as necessary, then select Save rule.
- Select Publish policy to submit your changes to the approval group assigned to Policy changes.
Deleting a Policy rule from a Policy draft
Follow the same steps above, but in step 3, select More Actions (...) > Delete.
Note:
To delete all drafted rules, select Discard changes at the top-right when editing the Policy. However, this deletes all drafted changes to the Policy, not just your drafted changes.
Loading a previous Policy as a draft
Once you have implemented multiple versions of your Policy, a new option appears that allows you to load your most recent previously approved Policy as a draft. Loading a previous Policy will open it as a draft in the Policy Editor. Then, your assigned approval group must approve restoring the policy.
Note:
You can only restore your most recent Policy when no pending Policy changes are waiting for approval.
- Under Policies, select the appropriate Policy type, then select Edit policy.
- Select Load previous policy. The previous Policy's details appear. Select Load Policy.
- The previous Policy loads as a draft. Restoring your previous Policy will discard any unsubmitted Policy drafts. If restoring your previous policy returns any error or warning indicators, review them and make edits as needed.
- Publish your restored Policy.
Publish a Policy
After you finish creating, editing, or restoring a Policy, publish it to submit your changes for approval.
- Select Publish policy. You must have at least one edited, added, or removed rule to submit changes.
- A limited summary of the submitted policy details appears.
- Select Publish policy for your specific policy type (e.g., Transfer) to send the Policy to the assigned approval group for approval.
After editing your policy draft, you can publish multiple policies in one click, or publish a single policy at a time:
- Select Publish Policy.
- Select Multi-Publish in one request and then select the policy types you want to publish.
- Select Add.
- Select Publish to publish the policy.
Note:
Administrators can only approve or reject policies that were sent for publication.
Approving a new or edited Policy
Important:
Policy approvers must have the latest version of the Fireblocks mobile app installed to ensure full functionality and access to approval workflows. Additionally, if the policy is approved automatically by an API user, the Cosigner associated with the API user must be updated to the latest version.
After you submit a new or edited Policy, the assigned approval group receives Fireblocks mobile app notifications. Users in the group will also see the Pending approval indicator in the Console.
To approve the new or edited Policy:
- In the Fireblocks Console, go to Policies and select the new or edited Policy. The yellow Pending approval badge indicates there are changes to review.
- Select Review changes. Rules will appear the same as when you are viewing draft changes.
- Select Approve policy.
- Complete the approval process using your Fireblocks mobile app. The Policy becomes active immediately.
If you select Deny changes, you can enter a reason that will be logged in the Audit Log. When Policy changes are denied, the submitter can resubmit Policy changes based on the feedback in the denial notification. When the submitter enters the Policy Editor, their denied changes still appear so they can pick up where they left off. The submitter can't draft more edits until the new request is approved or denied.
Next steps
- Policy best practices — Follow recommendations for effective Policy management
- Policy rule parameters — Reference guide for all available parameters
- Policy examples — Review common use cases