Map real control, not stated control
Governance tokens, multisignature wallets, administrators, upgrade keys, delegates, foundations, and service providers can each hold meaningful influence. Documenting these paths reveals concentration and key-person risk.
- Identify privileged roles and keys
- Review quorum, delegation, and emergency powers
- Test segregation of duties
Treat dependencies as part of the system
Oracles, bridges, custodians, front ends, cloud services, and external protocols extend the risk boundary. Their failure modes should appear in threat models, continuity plans, and monitoring.
- Tier dependencies by criticality
- Define fallback and shutdown conditions
- Monitor changes in external assumptions
Pre-assign incident authority
Response is slower when nobody knows who may pause a contract, communicate with users, engage investigators, or authorize recovery actions. Governance should define these rights before an event.
- Create scenario-specific playbooks
- Run tabletop exercises
- Preserve decision and transaction evidence