Governance: governors, timelocks, Safes
A vault's governor is the address allowed to change it: a wallet, a Safe (multi-signature wallet), or a governor contract that forwards changes by role, usually behind timelocks. The Toolbox reads which one governs each vault and router and adapts the signing step.
Wallet
Sign and send sends directly; the Toolbox waits for the receipt.
Safe
The button reads Send from the Safe. The Toolbox checks the chain, then hands the transaction to the Safe app. Owners sign and execute there. Then Check the effects now finds the executed transaction and reads the market back. Before hand-off, the Toolbox shows the Safe's queue and simulates your transaction after it.
Governor contract and timelock
Governor contracts have several ways in: a role held on the governor itself (a guardian's, for instance), the admin timelock, the wildcard timelock, or a cap risk steward (caps and rate models only). The review shows Send through with every way in to the governor and what your account holds on each. The Toolbox suggests one (or none), and you choose.
Through a timelock, a change takes two transactions: one schedules, one executes after the delay. Nothing changes until the execution. The market's Overview lists what this browser scheduled and says when each operation is ready. It offers Execute on the timelock once an operation is ready (cancelling is offered when you forget a row still on the timelock), and reads the market back afterwards.
Deploy a governor suite
Tools → Governance deploys a governor suite in one transaction through Euler's factory. The suite has a governor contract your vaults and router will name, an admin timelock that alone grants and revokes roles on it, and a wildcard timelock that may change any setting once its delay has passed.
Guardians can act at once in an emergency: lower a borrow LTV, pause a vault, or lower its caps. Undoing any of it waits in the wildcard timelock.
Start from a preset and adjust:
| Preset | Who does what |
|---|---|
| Curator alone | Your Safe proposes, cancels and executes on both timelocks. The guardian can act at once. |
| Curator with a risk partner | The partner proposes routine changes, and anyone may run them once ready. Your Safe can drop them, and alone holds the admin timelock. |
| DAO style | The DAO holds the admin timelock. The curator runs routine changes through the wildcard timelock. |
The delays default to 3 days on the admin timelock and 1 day on the wildcard timelock. Before you sign, a table says in plain words who may do what through the suite and how long each waits.
The deployed suite is listed under Tools → Governance for this browser. A suite deployed elsewhere is added by its governor's address.
Add a risk steward (optional)
A cap risk steward is a fast lane with rails and no delay. Its operators may move a vault's supply and borrow caps by at most 50 % either way, and the allowance recharges over three days after each change. They may swap the interest-rate model only for one from Euler's model factory.
Tools → Governance → Add a risk steward deploys one for a suite. The steward's admin names its operators at once. The suite's admin timelock decides whether the steward may act at all, by granting it its two roles on the governor (Put a steward to work: scheduled, then executed once the delay has passed).
Change who holds which role
Tools → Governance → Change who holds which role lists everyone holding a role on a suite's governor. Add or remove a guardian, revoke an account's or a steward's roles, or grant a role.
Each change is queued on the admin timelock and waits its delay. It then runs from the same page, or is cancelled before it does. The timelocks' own proposers, cancellers and executors are not changed here.
Transfer governance
Configuration → Governor admin → Transfer governance moves every governed vault and the router to a new governor in one transaction, signed by the current governor. Several governors mean several transactions.
Your suites on this network offers the suites this browser knows. Deploy a new suite opens Tools → Governance and comes back to the market with the new governor filled in.
When the new governor is a governor contract, the check shows who can do what once this governor holds the market before anything is prepared. If your account is not among the accounts that can start a change afterwards, or no account the Toolbox can see can queue a role change, it says so and asks you to confirm: I checked who will govern the market after this, and intend it.
Timelocks do not list who holds their roles, so the table shows the accounts this browser knows and yours, each read from the chain.
Each row says whether it moves or why not:
| Row | Result |
|---|---|
| Deprecated by its label | Stays with the current governor |
| No governor | Nothing to move |
| Governor unreadable | Load the market again |
Refused targets:
- The zero address: that renounces governance, irreversibly. Renounce on purpose from a vault's Governor admin or the Router governor section.
- A cap risk steward: it only sets caps and rate models for the governor contract it serves. Transfer to that contract.
Who governs now
Tools → Activity → Who governs these vaults now names each current governor. Beside a governor contract, Show who can do what reads the same table on request.
Read next
- Governance contracts: how the contracts are built and deployed
- Batch Viz: read a Safe or timelock transaction before signing