βœ… Master DAO Permission Systems

Understand role hierarchies, assignment, and security patterns

Design access control for DAO operations

βœ“ Key Takeaways

🎯 Core Concepts

  • πŸ”
    RBAC = Security Architecture: Role-based access control isn't just permission managementβ€”it's the foundation of DAO security. Roles limit blast radius of compromised wallets. Admin with treasury access gets hacked? If they also have contract upgrade powers, attacker can do more damage. Separate roles = defense in depth.
  • πŸ“Š
    Permission Hierarchies Match Risk: Critical operations (treasury transfers, contract upgrades) require multi-sig + time-locks + governance votes. High-risk (role changes, emergency pause) needs admin + oversight. Medium (moderation) uses dedicated role. Low (voting) is permissionless. More risk = more layers.
  • πŸ‘€
    Role Assignment is Governance: Unlike Web2 (HR clicks button), DAO role changes go through on-chain processes: proposal β†’ discussion β†’ vote β†’ execution β†’ on-chain record. High-privilege roles require community approval. Immutable by defaultβ€”can't quietly revoke access like database edit.
  • πŸ›‘οΈ
    Security Models Evolve: Start simple (single admin for speed), add layers as value grows (3/5 multi-sig at $100K+, 5/9 + time-locks at $1M+, governance + guardian at $10M+). Match security overhead to treasury size and operational tempo. Progressive decentralization is the norm.
  • πŸ”„
    Hybrid Systems are Pragmatic: Pure models rarely work in production. Real DAOs combine: multi-sig for routine ops (fast), time-locked governance for upgrades (transparent), guardian for emergencies (reactive), and on-chain votes for major decisions (democratic). Layer mechanisms, don't choose one.
  • πŸ’‘
    Least Privilege Principle: Grant minimum necessary permissions. New contributors start as Member, not Admin. Prove competence before elevation. If compromised, damage is limited. Can always upgrade permissions laterβ€”revoking is harder (requires governance vote).

πŸ›οΈ Real-World Examples

MakerDAO Multi-Sig

6/10 multi-sig for treasury (3 core, 3 community, 3 investors, 1 backup). Requires majority approval, survives loss of 4 keys. Time-locked upgrades with 48h community review. Layered security for $7B+ protocol.

Aave Guardian

Elected guardian can pause lending markets during exploits. Stopped March 2023 CRV price manipulation ($100M+ at risk). Governance can revoke guardian power via vote. Fast response + democratic oversight.

Uniswap Governance

All protocol changes require UNI holder vote (40M token quorum, 7-day period). Transparent on Tally.xyz. Time-lock delays execution by 2 days post-vote. Community can detect malicious proposals and organize counter-votes.

ENS Stewards

Working group stewards elected for 1-year terms. Must re-apply with accomplishments report. Time-limited roles prevent entrenched power. Ensures active contributors and fresh perspectives in governance.

πŸŽ“ Test Your Knowledge

Take a 5-question quiz to verify your understanding of DAO permissions, role hierarchies, security models, and governance best practices.