Confidential payroll rails for Safe{Wallet} · iExec Nox · ERC-7984
Auditor portal
A read-all VIEWER, granted by one multisig tx (grantAuditor → addViewer on every line). Full visibility, zero on-chain leak.
Read-only storyboard of the auditor’s read-all view — already proven on Sepolia (the grantAuditor tx is linked in /verify). Toggling here simulates the granted/revoked states; it does not perform an on-chain grant.
Auditor access granted by multisig
Roster #1 — all lines
Meridian Collective · every amount decrypts for the auditor; each row’s ACL is provable on-chain.
#
Name
Recipient
Amount
Access control
0
Ada
0x4cd3…46FF
12,000.000000 cUSD
rail · recipient · auditor
1
Mira
0x2641…Ea7A
4,200.000000 cUSD
rail · recipient · auditor
2
Wren
0xd37D…611E
1,800.000000 cUSD
rail · recipient · auditor
3
Oona
0x1c13…4a68
3,500.000000 cUSD
rail · recipient · auditor
4
Ivo
0xB1fC…a0d9
2,500.000000 cUSD
rail · recipient · auditor
5
Probe
0xaeF5…980f
2,000.000000 cUSD
rail · recipient · auditor
Roster total (auditor-only): 26,000.000000 cUSDEtherscan shows none of this
Compliance officer (ADMIN)
A distinct role: grantOfficer → allow gives admin — decrypt AND extend viewers without a new multisig round-trip.
Admin grants are irrevocable by design — which is exactly why the officer role is a deliberate multisig decision.