Skip to main content

Security Policies

Control how sensitive workspace changes are protected with security delays and team approvals.

When you manage digital assets as a team, protecting assets goes beyond keeping credentials safe. You need a system that defines roles, controls actions, and ensures no single person can put your assets at risk.

Security policies are that system. Each policy covers one kind of sensitive workspace change and holds it behind a security delay or approval from your team before it takes effect. Only Owners can edit security policies.

1. Where To Find Security Policies

  • Desktop / Web — open Settings (the gear icon in the top bar) → SecuritySecurity policies.

  • Mobile — tap your avatar (top right) → ProfileSecuritySecurity policies.

The page has four blocks: the Policy change rule at the top, the Policies list, Other settings, and a Danger zone.

2. Policy Change Rule

The Policy change rule is the policy that protects all the other policies. It requires a security delay or team approval before any security policy can be changed or disabled — so an attacker who takes over one account cannot simply switch your safeguards off.

Start here. A new workspace is created with this one policy already on — a 48-hour security delay, no approvers — and nothing else: the four policies below and all the locks are off. Older workspaces may have it off; while it is off, the Policies and Other blocks stay read-only.

Press Edit next to it and choose:

  • Security delay — the change is held for 48 hours before it applies.

  • User approval — the change needs approval from the Authorized approvers you pick. Leave it as Owners only to let the Owners approve, or select specific users. Then set how many approvals are needed under Approval required.

Two rules always apply to approvals:

  • At least 2 approvals are required.

  • The request creator counts as the first approver — so "2 approvals" means the author plus one other person. Nobody can approve or reject their own request.

The current setup is shown on the page, for example Owner approval — Requires 2 approvals from 8 owners.

3. Policies

Press Edit on the Policies block. Each policy is independent: you turn it on and give it its own protection method, its own approvers and its own number of approvals. All four are off by default.

⚠️ Each policy can be enabled for the first time without a security delay or team approval, so you can set your workspace up in one sitting. Later changes — disabling a policy, or re-enabling it — may require one, because from then on they are covered by the Policy change rule.

3.1 Protection Methods

Security delay holds the change for 48 hours before it takes effect, giving the team time to notice and react if something looks wrong. It works in a workspace of any size, including a single-user one.

User approval requires explicit approval before the change is applied. You choose the Authorized approvers and the number of required approvals — minimum 2, request creator included. Selecting a user as an approver grants them approver permission for that policy only; it does not change their role. This option needs at least two users with approver permissions in the workspace.

Both methods are available on all plans, on every policy.

3.2 Manage Transaction Limits

Protects adding, removing or editing transaction limits. This is the policy that stops someone from quietly raising a limit or deleting a rule before moving funds.

It protects changes to the rules, not the transactions themselves — whether an individual transaction is delayed or needs approval is decided by the transaction limit rules, which carry their own approvals and delays.

3.3 Manage Address Book

Protects adding, removing or editing records in your address book. Combined with Address book lock (see section 5) it means a new withdrawal destination cannot appear without oversight.

3.4 Manage Owners

Protects adding, removing, upgrading or downgrading Owners. Because Owners have full control of the workspace, this policy is handled more strictly:

  • The methods are Security delay and Owner approval — approval always comes from the Owners, and you cannot pick individual approvers. Owners added later join the approver pool automatically.

  • When your workspace has multiple Owners, only Owners can configure this policy.

3.5 Manage Users

Protects adding, removing, upgrading or downgrading regular users — everyone who is not an Owner. Inviting a user, deactivating one and changing a role all go through this policy. See Users for the roles themselves.

4. Reviewing A Pending Change

While a change is waiting, the affected block on the Security policies page shows a Changes row with its status — Security delay or Awaiting approval — and a Review button.

Review shows exactly what was requested: which policies are being enabled or disabled, how the approver lists and approval counts change, plus who requested it and when.

  • Awaiting approval — authorised approvers can Approve or Reject. The person who requested the change cannot vote on it.

  • Security delay — the change applies automatically when the countdown ends. Until then it can be rejected, which cancels it.

  • The requester can cancel their own pending request at any time.

5. Other Settings

The Other block holds workspace-wide switches. Press Edit to change them. The Policy change rule protects them, but only in the direction that weakens your security. Turning Address book lock, New address withdrawal lock, Enable Bron tag search or Enable API key creation on applies immediately; turning any of them off goes through the delay or approval. Enable AI agent access is the other way round — switching it on is the protected change, switching it off is immediate.

Address book lock — when enabled, funds can only be withdrawn to addresses saved in the address book. Any other destination is blocked.

New address withdrawal lock — prevents withdrawals to newly added addresses for 48 hours, giving the team time to review before assets can move.

Enable Bron tag search — when enabled, other Bron users can find your tag by searching for it and send you funds using your Bron Tag. Turn it off if you do not want your workspace to be discoverable. It is on by default.

Enable API key creation — allows Owners to create new API keys. Turning it off does not break your integrations: existing keys keep working, only new ones are blocked.

Enable AI agent access — allows AI agents to connect to this workspace. Off by default; keep it off unless you deliberately use one.

6. Danger Zone: Reset Security Policies

If your workspace ends up in a state where the approval requirements can no longer be met — for example the approvers are unreachable — Reset security policies is the way out. All security policies are disabled after a 6-month security delay, and no user approval is required.

The long delay is deliberate: this is a last resort, not a shortcut. Only an Owner can request the reset, and any Owner can cancel it at any point during those six months — so your team has half a year to notice and stop it. If you still have working approvers, change the policies normally instead.

7. Recommended Setup

A practical starting point for a team workspace:

  1. Enable the Policy change rule first — it unlocks the rest of the page and is what keeps your policies from being switched off.

  2. Enable Manage transaction limits and Manage address book with User approval.

  3. Enable Manage owners and Manage users — Owner approval for Owner changes, user approval for the rest.

  4. Turn on Address book lock and New address withdrawal lock if all your withdrawal destinations are known in advance.

  5. Leave Enable API key creation and Enable AI agent access off unless you use them.

Do it in one pass: the first time you enable a policy there is no delay and no approval to wait for.

In a single-Owner workspace, use Security delay everywhere — approvals need a second approver.

If you have questions, contact our support team via messenger on the Bron platform or by email support@bron.org.

📅 Questions about how this works for your team? Book a call with our product team

Did this answer your question?