{"templateId":"markdown","sharedDataIds":{"sidebar":"sidebar-user-guide/sidebars.yaml"},"props":{"metadata":{"markdoc":{"tagList":[]},"redocly_category":"User Guide","type":"markdown"},"seo":{"title":"Safe Transactions in Policies","llmstxt":{"hide":false,"sections":[{"title":"Table of contents","includeFiles":["**/*"],"excludeFiles":[]}],"excludeFiles":[]}},"dynamicMarkdocComponents":[],"compilationErrors":[],"ast":{"$$mdtype":"Tag","name":"article","attributes":{},"children":[{"$$mdtype":"Tag","name":"Heading","attributes":{"level":1,"id":"safe-transactions-in-policies","__idx":0},"children":["Safe Transactions in Policies"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["This page explains how Safe transactions are matched against policy rules."]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["For more on Fordefi policies, see ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/user-guide/policies"},"children":["Set Policies"]},"."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["For information on adding a Safe{Wallet} to Fordefi, see"," ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/user-guide/vaults/connect-safe-wallet"},"children":["Connect a Safe{Wallet}"]},"."]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"how-policy-evaluation-works-for-safe-transactions","__idx":1},"children":["How policy evaluation works for Safe transactions"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Fordefi's policy engine evaluates"," ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/user-guide/manage-transactions/safe-transactions"},"children":["Safe transactions"]}," using their"," ","decoded semantics, treating the Safe  as a first-class transaction origin."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["When Fordefi signs a Safe transaction (",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["SafeTx"]},") and a Safe has been added"," ","for the Safe contract:"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["The ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["origin"]}," in the policy engine is the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Safe{Wallet}"]},", not the Fordefi"," ","signer vault. Logically, the user is signing on behalf of the Safe."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Policies run against the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["decoded Safe action"]}," — for example, ",{"$$mdtype":"Tag","name":"em","attributes":{},"children":["Transfer"]},","," ",{"$$mdtype":"Tag","name":"em","attributes":{},"children":["Allowance"]},", or ",{"$$mdtype":"Tag","name":"em","attributes":{},"children":["Contract call"]}," — not against ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["execTransaction"]}," (",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["CALL"]}," /"," ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["DELEGATECALL"]},") or \"message signature\"."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["The semantic meaning of the operation is leading. If a Safe action represents"," ","a transfer, Fordefi evaluates it as a transfer policy, even though it is"," ","technically a signed message."]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["This means existing Fordefi policy rules apply to Safe transactions without any"," ","new policy concepts."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"supported-policy-categories","__idx":2},"children":["Supported policy categories"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["You can use the existing policy framework with Safe transactions. Rules can"," ","match on:"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Initiator"]},": Who proposed the Safe transaction."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Origin"]},": The Safe vault."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Recipient"]},": The address the Safe is interacting with."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Transaction type"]},": Transfer, contract call, allowance, or message"," ","signature."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Asset"]},": The token (or native currency) involved."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Transaction amount"]}]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["For details on each category, see"," ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/user-guide/policies/policy-rules-conditions-and-actions"},"children":["Policy Rules: Conditions and Actions"]},"."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"when-no-safewallet-is-configured","__idx":3},"children":["When no Safe{Wallet} is configured"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["If a Safe contract has not been added as a Safe vault to your organization, the"," ","policy engine cannot detect the Safe origin. In that case:"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["The transaction is evaluated, as if the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Fordefi signer vault"]}," is the origin."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["The semantic action is not decoded; the operation is treated as a generic"," ","message signature."]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["To get full Safe-aware policy evaluation,"," ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/user-guide/vaults/connect-safe-wallet"},"children":["add the Safe{Wallet} as a vault"]},"."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"periodic-amount-considerations","__idx":4},"children":["Periodic Amount considerations"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Fordefi signs a Safe message at the moment a Safe signer requests it, even"," ","though the resulting Safe transaction may never execute on chain — for example,"," ","if other Safe signers reject it. Periodic Amount policy rules count signed"," ","amounts at sign time, so a signed-but-not-executed Safe transaction can still"," ","consume Periodic Amount allowance even though no assets moved."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["If this matters for your operation, monitor executed Safe transactions through"," ","transaction history alongside the Periodic Amount limit."]}]},"headings":[{"value":"Safe Transactions in Policies","id":"safe-transactions-in-policies","depth":1},{"value":"How policy evaluation works for Safe transactions","id":"how-policy-evaluation-works-for-safe-transactions","depth":2},{"value":"Supported policy categories","id":"supported-policy-categories","depth":2},{"value":"When no Safe{Wallet} is configured","id":"when-no-safewallet-is-configured","depth":2},{"value":"Periodic Amount considerations","id":"periodic-amount-considerations","depth":2}],"frontmatter":{"seo":{"title":"Safe Transactions in Policies"}},"lastModified":"2026-07-07T13:48:24.000Z","pagePropGetterError":{"message":"","name":""}},"slug":"/user-guide/policies/safe-policies","userData":{"isAuthenticated":false,"teams":["anonymous"]},"isPublic":true}