Developers
Custody internals
Withdraw

Withdraw

The two paths

SafeVault
Mechanismthe owner acts directly on the SafeERC-4626 redeem
Heron's involvementnone requirednone required
Timelock.applies to cap increases, not to exits

The design goal is that a withdrawal never depends on Heron being reachable. A user with the owner key can exit through the underlying protocols using the published ABI and a public RPC endpoint.

What is built, and what is not

⚠️ The unwind leg exists; the trigger does not. The internal flow document records this as an open gap rather than a completed path, and it is repeated here so the site does not read as more finished than the system is.

The lockout that is disclosed rather than argued away

⛔ A container with a single owner means an outage at the key provider is a lockout, not an inconvenience. This does not hold for an owner who never acts unless a condition-gated exit is live.

Both were disclosed at design time rather than discovered later.