> For the complete documentation index, see [llms.txt](https://qiro.gitbook.io/qiro-vaults/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://qiro.gitbook.io/qiro-vaults/technical-overview/protocol/protocol-actors.md).

# Protocol Actors

Every role in a Qiro vault, what it can and cannot do, and which powers sit behind a delay.

A Qiro vault separates authority across several roles rather than concentrating it in one administrator. This page lists each role, what it controls, and what it cannot reach.

One distinction runs through the whole table and is worth reading first.

### Instant authority and delayed authority

Every governed contract carries two authorities, not one. The split is by **direction of risk**, not by seniority:

```mermaid
flowchart LR
    OWN["owner<br/>instant"]
    TL["timelock<br/>delayed"]
    DE["De-risking<br/>remove a PM, lower a cap,<br/>pause, rotate a role holder"]
    RI["Risk-increasing<br/>whitelist a PM, raise a cap,<br/>change fee rates"]

    OWN --> DE
    TL --> RI

    classDef instant fill:#6B56F1,stroke:#6B56F1,stroke-width:0px,color:#FFFFFF;
    classDef delayed fill:#3D28B8,stroke:#3D28B8,stroke-width:0px,color:#FFFFFF;
    classDef act fill:#1E1B3A,stroke:#6B56F1,stroke-width:2px,color:#FFFFFF;

    class OWN instant;
    class TL delayed;
    class DE,RI act;
```

Anything that reduces exposure can be done immediately; anything that increases it waits. The timelock is seeded to the owner at construction and handed to an external timelock contract afterwards — see [Smart Contract Architecture](/qiro-vaults/technical-overview/protocol/smart-contract-architecture.md#timelockgovernable) for why that handoff cannot be reversed.

### Roles

| Role                           | Can do                                                                                                                                                                                                      | Cannot do                                                                                                                              | Constraint                                                                                                           |
| ------------------------------ | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------- |
| **Owner**                      | <p>Rotate role holders — fee manager, whitelist manager, pausers, curator<br>Remove a position manager<br>Lower a sanctioned limit<br>Service the redemption queue<br>Cancel a request administratively</p> | <p>Change fee rates<br>Whitelist a position manager<br>Raise a cap<br>Add a subaccount<br>Move investor capital to itself</p>          | <p>Instant.<br>Non-renounceable; transfer is two-step and blocked until the timelock is wired</p>                    |
| **Timelock**                   | <p>Change fee rates and collectors<br>Whitelist a position manager<br>Raise a sanctioned limit<br>Add a subaccount<br>Rotate the timelock itself</p>                                                        | Anything reserved to the owner or the curator                                                                                          | Every call sits behind the external timelock's delay                                                                 |
| **Fee Manager**                | Collect accrued performance and management fees to their configured collectors                                                                                                                              | <p>Set fee rates<br>Set collector addresses<br>Touch investor capital</p>                                                              | Collections must be at least **15 days** apart after the first                                                       |
| **Curator**                    | <p>Deploy capital to a whitelisted subaccount via <code>invest()</code><br>Pull it back via <code>redeem()</code><br>Post the NAV mark via <code>setNAV()</code></p>                                        | <p>Move capital to an address that is not a whitelisted subaccount<br>Add a subaccount<br>Set its own limits<br>Withdraw to itself</p> | <p><code>setNAV()</code> is bounded by a time-weighted deviation guard<br>Fees settle against the old mark first</p> |
| **Investor Whitelist Manager** | Add and remove investor addresses from the whitelist                                                                                                                                                        | Anything else                                                                                                                          | Exists only in permissioned vaults; reverts if the vault is permissionless                                           |
| **Pauser**                     | Pause and unpause the vault                                                                                                                                                                                 | Any configuration or capital movement                                                                                                  | Several pausers may hold the role at once; added by the owner                                                        |
| **Investor**                   | <p>Deposit and mint<br>Request redemption<br>Claim and cancel<br>Delegate to an operator</p>                                                                                                                | Transfer shares to a non-whitelisted address                                                                                           | <p>Must be whitelisted in a permissioned vault<br>Deposits and requests require the vault unpaused</p>               |
| **Operator**                   | Request, claim and cancel on behalf of a controller who approved them                                                                                                                                       | Anything the controller could not do                                                                                                   | Approved per address by the controller via `setOperator`                                                             |

Contracts hold authority over one another too. The Vault accepts capital instructions only from its Vault Strategy Manager, and share movements tied to redemption only from its Redemption Manager; the VSM accepts capital calls only from a position manager it has already whitelisted.

### What the timelock gates

Five calls sit behind the delay. Every one of them either opens a new route for capital or increases what can flow down an existing route.

| Contract                                                                                                       | Call                              | Effect                                      |
| -------------------------------------------------------------------------------------------------------------- | --------------------------------- | ------------------------------------------- |
| `StakedVault`                                                                                                  | `setFeeConfig`                    | Changes fee rates and collector addresses   |
| `VaultStrategyManager`                                                                                         | `setWhitelistStatus(pm, true, …)` | Admits a new position manager               |
| `VaultStrategyManager`                                                                                         | `raiseSanctionedLimit`            | Increases a position manager's cap          |
| `SubaccountPositionManager`                                                                                    | `addSubaccount`                   | Admits a new destination wallet for capital |
| <p><code>StakedVault</code><br><code>VaultStrategyManager</code><br><code>SubaccountPositionManager</code></p> | `setTimelock`                     | Rotates the timelock authority itself       |

Their de-risking counterparts are deliberately **not** delayed: removing a position manager is `setWhitelistStatus(pm, false, …)` and lowering a cap is `lowerSanctionedLimit`, both instant on the owner, so a position manager behaving badly can be dropped without waiting.

Two properties keep the delay from being sidestepped. `setTimelock` is itself timelocked, so the authority can only be rotated through its own delay and the owner can never re-point it. And `raiseSanctionedLimit` rejects a value that is not strictly greater than the current cap, so it cannot be used as a back door to lower one instantly.

***

See [Smart Contract Architecture](/qiro-vaults/technical-overview/protocol/smart-contract-architecture.md) for the contracts these roles act on.
