NoxSafe

NoxSafe

Confidential payroll rails for Safe{Wallet} · iExec Nox · ERC-7984

Auditor portal

A read-all VIEWER, granted by one multisig tx (grantAuditor → addViewer on every line). Full visibility, zero on-chain leak.
Read-only storyboard of the auditor’s read-all view — already proven on Sepolia (the grantAuditor tx is linked in /verify). Toggling here simulates the granted/revoked states; it does not perform an on-chain grant.
Auditor access granted by multisig

Roster #1 — all lines

Meridian Collective · every amount decrypts for the auditor; each row’s ACL is provable on-chain.
#NameRecipientAmountAccess control
0Ada0x4cd3…46FF12,000.000000 cUSDrail · recipient · auditor
1Mira0x2641…Ea7A4,200.000000 cUSDrail · recipient · auditor
2Wren0xd37D…611E1,800.000000 cUSDrail · recipient · auditor
3Oona0x1c13…4a683,500.000000 cUSDrail · recipient · auditor
4Ivo0xB1fC…a0d92,500.000000 cUSDrail · recipient · auditor
5Probe0xaeF5…980f2,000.000000 cUSDrail · recipient · auditor
Roster total (auditor-only): 26,000.000000 cUSDEtherscan shows none of this

Compliance officer (ADMIN)

A distinct role: grantOfficer → allow gives admin — decrypt AND extend viewers without a new multisig round-trip.
Admin grants are irrevocable by design — which is exactly why the officer role is a deliberate multisig decision.