Configure Vault V2 Roles

This tutorial guides you through setting up and managing roles for a Morpho Vault V2. A clear understanding and proper assignment of roles are critical for the vault's security, governance, and operational success.

The Role Setup Workflow

Setting up roles for a new Vault V2 follows a specific sequence. The Owner first assigns the Curator and Sentinels (actions which are immediate). Then, the Curator proposes strategic changes, such as appointing an Allocator.

Crucially, most of the Curator's actions are timelocked. The process for these actions depends on whether a timelock duration is set.

Managing Roles via the Curator App

The Curator app exposes a UI for Vault V2 role setup and role management. Use it when you prefer a guided flow; the Etherscan flow below remains useful for low-level verification.

  1. Open the app and select your vault.
  2. Connect the wallet that controls the required role:
    • Owner for appointing the Curator or adding and removing Sentinels.
    • Curator for submitting timelocked role changes such as adding or removing Allocators.
    • Sentinel for revoking pending actions from the Sentinel tab.
    • Any address for executing an already-submitted action after its timelock expires.
  3. Open the Roles tab and review the current Owner, Curator, Allocators, and Sentinels.
  4. For immediate Owner actions, fill the new address, verify it carefully, and sign the transaction.
  5. For timelocked Curator actions, submit the proposal, wait until it becomes executable, then return to execute it. A Curator or Sentinel can revoke the pending proposal before execution.

Managing Roles via Etherscan

For manual role management, interact with the vault through Etherscan.

Owner Actions (Immediate)

As the Owner, connect your wallet to the Vault V2 contract on Etherscan and use the Write Contract tab to:

  • Execute setCurator(address newCurator) to appoint the Curator.
  • Execute setIsSentinel(address account, bool newIsSentinel) to add or remove Sentinels.
  • Execute setOwner(address newOwner) to transfer ownership.

Curator Actions (Timelocked)

As the Curator, connect your wallet to:

  1. Submit the Proposal:
    • Use a tool like Foundry's cast calldata to ABI-encode your intended function call (e.g., setIsAllocator(0x..., true)).
    • Call the submit(bytes) function with the encoded data.
  2. Wait for the Timelock: Check executableAt(bytes data) to see when execution is allowed.
  3. Execute the Proposal: After the timelock, anyone can call the original function to finalize the change.

Checking Role Status

Use the Read Contract tab to verify current roles:

  • owner(): Returns the current owner
  • curator(): Returns the current curator
  • isAllocator(address): Check if an address is an allocator
  • isSentinel(address): Check if an address is a sentinel