A multisig doesn't know what the vote decided.
Running capital as a group means wiring together systems that were never built to know about each other. The funds sit in one place, the decisions in another, the record in a spreadsheet, and the strategy in somebody's personal account. Every join between them is a person who promised to go and do the thing. A vault is one object: a contract holding the money, and one record for everything that decides what happens to it.
One object, not five integrations.
A vault holds the treasury, the decisions, the membership, the work and the record as one thing. That is the whole design. Not because a group needs fewer tabs open, but because a decision that cannot reach the money is advice, and a role that cannot stop an action is a description of who ought to be trusted.
The money itself sits in a smart contract. That is the part nobody in the group can argue with: it holds the funds, it releases them on its own terms, and each member signs their own deposit from their own wallet — Fexr never holds the key. What a vault adds is everything a contract has no way of knowing: who is in the group, what they decided, who confirmed the work, and what the group has to show for it afterwards.
It is deliberately not one product. A vault is declared with a type, and the type decides which parts of the machinery you actually use. Most vaults use two or three.
A second choice decides what the money does while it sits there: a plain shared pool, a savings pool with reward tiers, or a position in an established protocol — Aave, Lido, Spark, Compound. Ten strategies, set when the vault is created.
Five capabilities, and the joins between them.
A treasury that knows why the money moved.
A multisig is a good custodian and a poor bookkeeper. It records that three of five signed and a transfer went out. It cannot tell you which proposal that was, whether the proposal passed, or what the payment was for, because it has no idea those things exist.
A vault's treasury is a contract position, not a balance in somebody's database. Money arrives because members signed deposits and because the vault earned it, and it leaves on the contract's terms through payouts and payments for work. What the vault adds is the half a contract cannot supply: each movement carries what caused it, because the proposal, the payout request and the work that earned it are records in the same system — and the balances themselves are read back from the contract's own events rather than typed in.
An outcome that can actually do something.
This is the join that is missing everywhere else. A vote held on one system and funds held on another means the result is advisory — somebody still has to go and execute it, and until they do, the decision and the balance disagree.
Proposals and polls belong to the vault that holds the treasury, so an outcome is a state the vault is in rather than a screenshot of a tally.
Vaults carry a verification threshold — how much agreement a thing needs before it counts. It is set per vault, between one and ten, because a four-person savings group and a protocol treasury should not need the same number.
A vault can hire, and a vault can get paid.
Agents are brought into a vault and paid by it for research, monitoring and signal generation. A group affords work that no single member would buy on their own — that is most of the reason to be a group.
Money moves the other way too. When a vault's signals and insights are queried, the payments land in the vault's treasury, not in the account of whoever created it. The vault is the earning entity.
Reputation the vault owns, not its founder.
A vault accumulates a signal win rate and a count of what it has tracked, and epochs give it a clock — activity is measured in periods with leaderboards rather than as one undated blur. Every treasury movement sits in the vault's transaction history.
Because the record belongs to the vault, it survives the departure of any individual member. A history assembled from someone's exports is only as durable as their continued involvement.
Getting in is a decision. So is what you can do once you're there.
Joining runs through a request that somebody approves, or an invitation with a code. Inside, authority is roles rather than goodwill — assigned, revocable, and enforced at the point of action rather than written down as a convention.
Where a vault runs staking, the pools carry slashing conditions: the terms under which a stake is lost, written down before anyone stakes rather than argued afterwards. Members also carry sybil-resistance scoring, so one person with twelve accounts is a solvable problem instead of a governance disaster.
Pooled vaults solved the money. They left the rest.
The vault pattern in DeFi is a good one and it earned its place. Hyperliquid's version is among the sharpest: the leader has to hold a share of the vault and cannot pull it while depositors are in, performance is public, and the fee only pays on profit. Those are real answers to why a stranger should be trusted with a strategy.
What that design deliberately does not cover is everything around the capital. There is a leader and there are depositors, and no answer to who else decides, who joins, who does the work, who gets paid for it, or what the group still owns when the leader walks away. A vault is that second half, wrapped around a contract that answers the first.
- The operator is in it themselves, with a floor they cannot withdraw below
- Performance is public and continuous, not a quarterly letter
- The fee only pays when there are gains to pay it from
- Anybody can start one — no mandate, no minimum institution
- A treasury that belongs to the group rather than to a strategy
- Decisions with a threshold, a tally and a record
- The ability to hire work and to be paid for output
- Membership, roles and a reputation that outlives any one person
What a vault does not do for you.
Structure removes some problems and leaves others exactly where they were.
- Governance only works if people vote. A threshold that never gets met is a decision that never gets made. Small vaults should set a small threshold and raise it as they grow, rather than the reverse.
- A vault earning is not the same as members earning. Signal revenue and fees accrue to the treasury. What the group does with the treasury is a governance question, and an unanswered one until somebody proposes it.
- The record is descriptive, not predictive. Win rates and epoch standings are computed from what a vault actually did. Where a vault publishes a strategy, its verification is re-evaluated on a schedule and removed when the vault stops meeting the bar. Past performance still tells you nothing about the next trade.
- A contract can lose money, and nobody here can overrule it. Where a vault's strategy is a real position in a real protocol, it carries that protocol's risk and the market's. The same thing that stops Fexr moving your stake against you stops us moving it for you — if the terms lock funds, the terms are the answer.
- Most of the machinery will not apply to you. Eight types exist because a research panel and a savings group want almost nothing in common. Expect to use a fraction of it.
Most of this already exists. None of it is connected.
Every capability described here can be assembled from separate tools today, and plenty of groups have done exactly that. What cannot be assembled is the part where the pieces agree with each other — where a passed proposal moves funds without anyone being asked to go and do it, where a role stops an action instead of describing who should be trusted with it, and where the record is a consequence of what happened rather than a summary written afterwards.
That is the only thing a vault is for.
- Vault Safety — the check on every claim, event and payment
- Agents — the work a vault can hire
- Market Signals — what a vault's output can be worth
- Copy Strategies — following a vault that publishes one
- Enterprise — vaults run at institutional size
