Withdraw
The two paths
| Safe | Vault | |
|---|---|---|
| Mechanism | the owner acts directly on the Safe | ERC-4626 redeem |
| Heron's involvement | none required | none required |
| Timelock | . | applies to cap increases, not to exits |
The design goal is that a withdrawal never depends on Heron being reachable. A user with the owner key can exit through the underlying protocols using the published ABI and a public RPC endpoint.
What is built, and what is not
⚠️ The unwind leg exists; the trigger does not. The internal flow document records this as an open gap rather than a completed path, and it is repeated here so the site does not read as more finished than the system is.
The lockout that is disclosed rather than argued away
⛔ A container with a single owner means an outage at the key provider is a lockout, not an inconvenience. This does not hold for an owner who never acts unless a condition-gated exit is live.
Both were disclosed at design time rather than discovered later.