Configure Vault V2 Roles
This tutorial guides you through setting up and managing roles for a Morpho Vault V2. A clear understanding and proper assignment of roles are critical for the vault's security, governance, and operational success.
The Role Setup Workflow
Setting up roles for a new Vault V2 follows a specific sequence. The Owner first assigns the Curator and Sentinels (actions which are immediate). Then, the Curator proposes strategic changes, such as appointing an Allocator.
Crucially, most of the Curator's actions are timelocked. The process for these actions depends on whether a timelock duration is set.
Managing Roles via the Curator App
The Curator app exposes a UI for Vault V2 role setup and role management. Use it when you prefer a guided flow; the Etherscan flow below remains useful for low-level verification.
- Open the app and select your vault.
- Connect the wallet that controls the required role:
Ownerfor appointing theCuratoror adding and removingSentinels.Curatorfor submitting timelocked role changes such as adding or removingAllocators.Sentinelfor revoking pending actions from the Sentinel tab.- Any address for executing an already-submitted action after its timelock expires.
- Open the Roles tab and review the current
Owner,Curator,Allocators, andSentinels. - For immediate
Owneractions, fill the new address, verify it carefully, and sign the transaction. - For timelocked
Curatoractions, submit the proposal, wait until it becomes executable, then return to execute it. A Curator or Sentinel can revoke the pending proposal before execution.
Managing Roles via Etherscan
For manual role management, interact with the vault through Etherscan.
Owner Actions (Immediate)
As the Owner, connect your wallet to the Vault V2 contract on Etherscan and use the Write Contract tab to:
- Execute
setCurator(address newCurator)to appoint the Curator. - Execute
setIsSentinel(address account, bool newIsSentinel)to add or remove Sentinels. - Execute
setOwner(address newOwner)to transfer ownership.
Curator Actions (Timelocked)
As the Curator, connect your wallet to:
- Submit the Proposal:
- Use a tool like Foundry's
cast calldatato ABI-encode your intended function call (e.g.,setIsAllocator(0x..., true)). - Call the
submit(bytes)function with the encoded data.
- Use a tool like Foundry's
- Wait for the Timelock: Check
executableAt(bytes data)to see when execution is allowed. - Execute the Proposal: After the timelock, anyone can call the original function to finalize the change.
Checking Role Status
Use the Read Contract tab to verify current roles:
owner(): Returns the current ownercurator(): Returns the current curatorisAllocator(address): Check if an address is an allocatorisSentinel(address): Check if an address is a sentinel