Skip to contentHODL ConsultingHODL ConsultingFR
Menu

Company wallets: organising access, approvals and supporting records

Published 03/01/2025 · Updated 08/09/2026 · Houssen Issouf Aly, French chartered accountant

Crypto-assets · Companies · Directors

Practical guidance for companies and directors. Revised on 7 September 2026.

Original article: 2025-01-03 · Houssen Issouf Aly · HODL Consulting

Company wallets: organising access, approvals and supporting records

Define responsibilities before selecting a wallet

A company wallet belongs within an operating process: someone prepares the transaction, another person checks it, authorised signers approve it and the accounting team reconciles the movement with supporting records. Choosing a brand does not establish that chain of responsibility.

Start with the use cases: customer receipts, supplier payments, treasury holdings or protocol interactions. Separating uses can help control, but adding wallets without an inventory can create omissions. The process should remain understandable when a director or employee is unavailable.

Maintain an inventory without storing secrets in it

For each account or address, record the legal owner, network, purpose, expected assets, authorised people, associated tools and last review date. Include the source of transaction history, account-opening evidence and links with bank accounts.

An address used on several networks still requires records for each network. Separate company, personal and third-party holdings even when the same individual operates them.

  • Ownership: which entity or person owns the assets?
  • Responsibilities: who prepares, approves, signs, reconciles and covers absences?
  • Records: which exports are available, how often are they collected, and who archives them?
  • Reviews: new and closed wallets, changed purposes and departing staff.

Do not put private keys or recovery phrases in the inventory shared with the accounting firm. Secret backup and recovery arrangements require a separate, appropriate process tested with competent people.

Check the rules actually configured

Authentication protects account access. Transaction approval also depends on the wallet and its permissions. French official cybersecurity guidance recommends two-factor authentication where available. Application permissions and signer rights still require review.

Safe’s confirmation threshold specifies how many signers must confirm a transaction. Its setup documentation makes the configuration dependent on the use case. Its spending-limit feature can allow certain transfers without the usual signer confirmations. Review modules and exceptions as well as the displayed threshold.

A technical threshold does not establish legal authority or internal spending policy. Check who can replace signers, add permissions and change settings. These examples illustrate questions to ask, not a universal product recommendation.

Use a six-step payment process

  1. Prepare: identify the invoice, paying entity, recipient and due date.
  2. Verify: check recipient, network, asset, amount and fees; handle changed payment details under the agreed procedure.
  3. Approve: confirm the expenditure against the budget and delegated authority.
  4. Sign: inspect the proposed transaction before authorising execution.
  5. Record: retain the transaction reference, outcome and exceptions.
  6. Reconcile: connect the payment with its invoice, fees and valuation evidence.

Fictional example: a €2,400 supplier invoice is prepared and approved by different people. Required signatures follow the actual configuration. After execution, accounting receives the invoice, payment evidence and fee records. €2,400 is an illustrative amount, not a recommended approval limit.

Plan for absences, staff changes and incidents

A staff departure should trigger a review of accounts, delegated authority, API keys, devices and signer roles. Check that removing access does not unexpectedly prevent necessary operations. Sensitive configuration changes deserve a defined approval process too.

Keep an incident plan identifying contacts, ways to suspend activity where available, records to preserve and relevant specialists. An internal form cannot make an irreversible transaction recoverable. Exercises should test the team’s ability to respond without exposing secrets.

At period end, reconcile quantities by asset and network. Separate payments, conversion, fees and transfers between wallets owned by the same company. An internal movement should not automatically be classified as new revenue.

Questions to discuss with the firm

Does the accountant need control of the wallet?

Reconciliation uses exports, documents and read-only access where required. It does not require authority to transfer funds.

Is there a perfect configuration?

No. Exposure, use cases, available people and recovery arrangements determine the assessment. Technology does not remove human risk or the need to review permissions.

Where should we start?

Bring the inventory and a complete example transaction. Our accounting support structures the records and reconciliations. Read the fractional CFO guide for the planning workflow and the freelance payments guide for the connection with invoices.

Continue reading