It’s critical to routinely review access control and permission configurations. Permissions accumulate and change over time. New integrations, roles, and dependencies can introduce new vulnerabilities. We published our audit methodology so you can use it as a checklist ↓
3
7
1,722
Supply control Who can change the supply of an asset, and under what conditions? Minting, burning, supply caps, and the permissions that govern them can directly affect dilution, solvency, and the economic security of an asset.

Aug 26, 2026 · 7:29 PM UTC

1
2
137
Governance & protocol control Who can change how the protocol works? Upgrades, parameter changes, privileged roles, timelocks, and emergency powers determine who can alter the system and what safeguards constrain that authority.
1
2
57
Holder controls What authority do privileged actors have over individual holders? Freeze, blocklist, seizure, burn, and pause permissions can determine whether holders retain unrestricted control over their assets and who can intervene.
1
1
25
Price control Who controls the price inputs the protocol relies on? Oracle selection, configuration, fallbacks, and admin permissions can affect liquidations, borrowing, minting, redemptions, and other economically sensitive actions.
1
1
19
Signers Who can exercise privileged permissions in practice? Review signer thresholds, independence, key management, and who can change the signer set. A multisig can still represent a concentrated dependency if control ultimately sits with a small group.
1
1
15
Bridge control What additional control assumptions are introduced when assets move across chains? Bridges can introduce new upgrade, minting, pausing, signer, and validator permissions. Those dependencies become part of the asset’s overall security model.
1
1
19
You can see the methodology applied to weETH and USD3. Each report maps the permissions and dependencies behind the asset, including supply, governance, holder, price, signer, and bridge controls. Explore the reports and the methodology: ac-audit.aragon.org/
1
1
117
If you don’t want to do it yourself, or want an expert set of eyes, we offer Permissions Audits. We map your permission architecture, identify vulnerabilities and critical control paths, and provide recommendations to strengthen your configurations. aragon.org/services/permissi…
1
113
Sort replies: Relevant Recent Liked