Custody Models
One decision core, two custody wrappers. Which one you use changes the deposit mechanics in the same view: most products hide that behind a single Deposit button, and here it is the point, because the two paths are not cosmetically different. One of them destroys the money if used like the other.
| Safe | Vault | |
|---|---|---|
| Container | a canonical Safe per user | an ERC-4626 vault |
| Heron's authority | a scoped session key: venue allowlist, selectors, caps, expiry | cap writes |
| A refusal is | nothing happening, so a log is required | cap = 0, visible on-chain |
| Approval latency | immediate | waits out the timelock |
A scoped session key can expire and can be narrowed, and narrowing is the action a worried user actually wants. A single executor address can only be switched on and off.
See Deposit for the two traps this shape exists to prevent.