Your Altitude workspace is self-custodial: your team, not Altitude or a bank, authorizes every action. That means who can approve, how many approvals each action needs, and how each account is protected aren't just settings: they are the security model.
This article is the checklist for keeping that setup safe. It starts with a short primer on how approvals work, then the at-a-glance review, and the sections after that carry the detail behind each check.
How approvals work
A proposal is any action that runs through the approval flow, such as a payment or a settings change. It is Active while it collects approvals, then Ready once it reaches the Approval Threshold. Payment proposals wait in your Inbox; member and permission changes appear at the top of Settings → Members. See Approvals.
Members can hold any combination of three permissions:
Propose – create proposals.
Approve – vote on proposals. The Approval Threshold counts only members with this permission, not the full members list.
Submit – execute a proposal once it reaches the Approval Threshold.
Read Only – members with none of the three assigned can view the workspace, nothing more.
Run a regular review
Run this review when you first configure your workspace, then quarterly, and whenever anyone joins, changes roles, or leaves. Check that:
Members current. The members list matches your team, there are no stale invitations, and permissions match each person's role. See "Give each member the right access" below.
Threshold safe. At least two approvals are required, and there is at least one more approver than the threshold. Running solo or with only two approvers? See "Set a safe Approval Threshold" and "If you're running the workspace alone" below.
Accounts hardened. Every passkey is reachable, and every recovery email is accessible and on a different domain from their work email. See "Protect every account" below.
Notifications on. Security notifications are on for every approver. See "Keep security notifications on" below.
Nothing unexplained. No proposals you don't recognize in the Inbox or at the top of Settings → Members. See "If something looks wrong" below.
Every payment verified. You approve because you have checked, not because a team member already has. See "Verify every payment before you approve" below.
If every item checks out, you're done until next quarter.
Give each member the right access
Every person on your team should have their own account. Shared logins remove personal authentication and the record of who did what.
Give each person only the access their role requires. Where team size allows, separate duties so a payment is never approved only by the person who created it.
To review access, go to Settings → Members and check each row:
Does everyone on the list still work with you, in the same role?
Does anyone hold more permissions than their role requires?
Are there stale invitations to remove?
To change or remove someone's access:
Go to Settings → Members.
Select the member.
To change their permissions, select Edit Permissions, then Propose. To remove them from the workspace, select Delete instead.
Both changes are proposals that follow your Approval Threshold. To invite a new member, remove a pending invitation, or read more on member management, see Members.
Note: Submitting a permission change cancels all other proposals with an Active or Ready status, including fund transfers. This is by design, for security. Re-create anything still needed afterwards.
Set a safe Approval Threshold
The Approval Threshold is the number of approvals a proposal needs before it can be submitted. Two rules hold at any team size:
Require at least two approvals. A single-approval threshold lets any one member move funds alone.
Keep at least one more approver than the threshold. At 3/3, one member who can no longer sign means the rest can never reach the threshold again, not even to lower it.
Here's how that plays out at common team sizes:
Members with Approve | Setting | What it protects against | What can still go wrong |
1 | 1/1 | Nothing – one account authorizes everything | The threshold can't protect you yet – treat it as temporary and see "If you're running the workspace alone" below |
2 | 2/2 | Unilateral payments | One lost account blocks the workspace. Confirm both members' recovery setups, and treat 2/2 as a temporary stop on the way to 2/3 |
3 | 2/3 | Unilateral payments, with a third approver for continuity | Little, while every account stays protected – this is the recommended baseline |
5 | 3/5 | The same pattern at scale | Outgrowing the setting – raise the threshold as approvers and balances grow |
For team sizes the table doesn't list, apply the same two rules. As approvers and balances grow, raise the threshold with them.
To review or change your threshold:
Go to Settings → Security.
Select Edit on the Approval threshold card.
Set the new threshold, then select Propose. The change is created as a proposal. See Account settings.
Note: Submitting a threshold change cancels all other proposals with an Active or Ready status, including fund transfers. This is by design, for security. Re-create anything still needed afterwards.
If you're running the workspace alone
With a 1/1 threshold, the approval flow can't protect you yet: one account authorizes everything. Treat it as a temporary setup state – a 2/3 threshold is what you want to work towards.
You can still run a one-person workspace carefully, but there's no second pair of eyes. Every safeguard lives in your account setup, so harden each piece:
Make your passkey resilient. Store it with a provider you can reach from more than one device, or on a hardware security key like a YubiKey – a key that holds your sign-in passkey, not a crypto hardware wallet. Losing your only signing credential means losing access to the workspace.
Don't let one device hold everything. If your passkey, primary email, and recovery email all live on the same phone, that phone is your whole treasury.
Add a second approver as balances grow – a co-founder, advisor, or counsel who holds only the Approve permission – and move to 2/2. Aim for 2/3 as soon as a third approver joins.
Beyond that, apply every check in "Protect every account" below – with no co-approvers, your credentials are the entire security model.
Protect every account
Each account is protected by three credentials:
Primary key – your passkey, used to sign in. Store it on your device, in a supported password manager, or on a hardware security key like a YubiKey.
Primary email (2FA) – receives the 6-digit two-factor authentication codes that confirm sensitive actions.
Recovery email – a backup used to regain access. Use a personal address on a different domain from your company email: if your company email is ever compromised or lost, a recovery address on the same domain goes down with it.
Have every member confirm four things:
Their account is on the enterprise security model. Older accounts are prompted to upgrade at sign-in, and older workspaces complete a one-time upgrade from Settings → Security. See Enterprise security on your Altitude account and workspace.
Their passkey is stored with a supported provider and reachable from every device they use for Altitude. See Passkeys in Altitude.
Their recovery email is still accessible, and still on a different domain from their work email.
The email accounts behind two-factor authentication and recovery have strong authentication of their own, on locked and up-to-date devices.
Warning: Watch for shared dependencies. If several accounts recover through the same inbox, device, or person, that shared point is a single point of failure for the whole workspace.
Verify every payment before you approve
Before approving a payment, confirm the recipient, amount, asset, network, and the business purpose behind it. Approve because you have checked, not because a team member already has.
Take extra care when a payment falls outside normal patterns: a new recipient, an unusual amount, an urgent request, or changed payment instructions. Verify with the requester through a channel you already trust, such as a call to a number you already have. Replying to the request itself only confirms with whoever sent it.
For payments to a wallet address, three habits matter most:
Match the network. Confirm which network the recipient expects. Ethereum, Base, Avalanche, and Tempo share the same address format, so a payment on the wrong network can go through and be lost. Crypto transfers cannot be reversed once executed. See Send stablecoins.
Compare the full address against the address the recipient originally gave you, not just the first and last characters. Lookalike scams are designed to match those.
Test new destinations. Send a small amount first, confirm receipt with the recipient over that same trusted channel, then send the rest.
If a proposal doesn't check out, reject it and tell your other approvers. A majority of approvers can cancel a proposal even after it reaches Ready. See Approvals.
Keep security notifications on
Notifications are the earliest signal that something unexpected is happening. Each member controls their own settings, so have everyone, especially approvers, keep these on in Settings → Notifications:
Outgoing transactions – sent when a transfer is initiated, approved, and executed.
Member added or removed – sent when the team roster changes.
Permissions changed – sent when a member's permissions are proposed or updated.
If a notification doesn't match something you expected, review the proposal before anyone approves it. Payment proposals appear in your Inbox, and member or permission changes appear at the top of Settings → Members. See Notifications.
If something looks wrong
These steps are ordered to stop money leaving fastest – and at any point, contact support at [email protected]. Don't wait until the other steps are done.
Alert your other approvers through a channel you already trust, so nothing else gets approved while you investigate.
Stop the proposal. Reject it, or coordinate with other approvers to cancel it if it has already reached Ready. Then check recent transactions for anything you don't recognize. See Approvals.
Freeze affected cards. Card admins can freeze any card in the workspace. If a card may be compromised, ask an admin to terminate it and issue a new one. See Freeze your card.
Contain the account. Propose removing the compromised member's permissions. Submitting that change cancels every Active or Ready proposal, including any the attacker created. If you can't reach the threshold without the compromised account, contact support – this lockout is what the one-spare-approver rule exists to prevent. Afterwards, restore a safe setup: removing one approver from 2/3 leaves 2/2, so add a replacement.
Re-secure before restoring access. Secure the email accounts and set up a new passkey first. A member who lost their passkey can regain access with their recovery email. See Passkeys in Altitude.
