Numis TrustNumis Trust Docs

Clients & Users

Understanding your organization setup and user access in Numis Trust

Clients & Users

Your organization is set up as a Client in Numis Trust. This gives you a completely isolated and secure environment for managing your digital assets.

Your Organization as a Client

As a client, your organization has:

  • Complete privacy - Your data and assets are completely separate from other clients
  • Full control - Manage your own users, accounts, and security settings
  • Dedicated support - Direct access to our institutional support team
  • Custom configuration - Settings tailored to your specific compliance and operational needs

How Client Records Connect

A client is the top-level record for your organization. Accounts, addresses, and transfer destinations all belong to a client so that assets, approvals, and audit history stay separated from every other organization on the platform.

Accounts

An account is a digital asset account owned by your organization. Accounts hold one asset type in one workspace, have their own deposit address, and use quorum settings to control who can move assets out.

Clients can have many accounts because teams often separate assets by purpose, asset type, or operating model. For example, one account might hold long-term BTC, while another supports more frequent ETH activity.

External Addresses

An external address is a blockchain address outside your organization that has been submitted for review. It might belong to an exchange, a counterparty, or another provider where your organization controls an account.

External addresses exist before they are usable for withdrawals. They capture the address, asset, ownership context, and business purpose so your team can review the destination before any assets move.

External Destinations

An external destination is an approved external address that is available in the withdrawal flow. This extra distinction keeps the send experience focused on destinations that have already cleared the required checks for the asset and account type being used.

Internal Destinations

An internal destination is another account owned by the same client. Internal destinations make it possible to move assets between your own accounts while keeping the transfer inside your organization's controlled environment.

User Types in Your Organization

Client Administrator

The most senior person in your organization with complete access to:

  • Add, remove, and manage all users
  • Access all accounts and view all transactions
  • Modify organizational settings and security policies
  • Generate reports and manage compliance requirements

Regular Users

Your day-to-day operational team members. Each user can have one or more of these roles:

Initiator

  • Starts transactions and account creation requests
  • Cannot complete actions alone - always requires approval from another person
  • Typically your traders, portfolio managers, or operations team

Approver

  • Reviews and approves requests made by Initiators
  • Provides the critical second set of eyes on all actions
  • Usually senior traders, compliance officers, or fund managers

How This Protects Your Assets

Two-Person Rule

  • No single person can move your assets alone
  • Every transaction requires at least two people to review and approve
  • Complete audit trail of who did what and when

Flexible Security Levels

  • High security: Initiator → Approver 1 → Approver 2 (three people)
  • Standard security: Initiator → Approver (two people)
  • Operational: Single person (only for small amounts)

Real-World Example

  1. Your trader wants to move $500,000 in Bitcoin to a counterparty
  2. Trader initiates the transaction with all details
  3. Your compliance officer approves after reviewing
  4. Your fund manager signs to complete the transfer
  5. Transaction executes and all three people receive confirmation

Best Practices

User Management

  • Assign roles based on job responsibilities and seniority
  • Remove access immediately when employees leave
  • Regular reviews of who has access to what
  • Clear escalation procedures for urgent transactions

Security Policies

  • Never share login credentials between users
  • Use strong passwords and enable two-factor authentication
  • Separate duties - avoid having one person in multiple critical roles for the same transaction
  • Document procedures for your team to follow

On this page