{"templateId":"markdown","versions":[{"version":"v1.39","label":"v1.39 STS","link":"/products/custody/governance/genesis/plan-your-first-users","default":true,"active":true,"folderId":"c15a2701"},{"version":"v1.38","label":"v1.38 STS","link":"/products/custody/v1.38/governance/genesis/plan-your-first-users","default":false,"active":false,"folderId":"c15a2701"},{"version":"v1.34","label":"v1.34 LTS","link":"/products/custody/v1.34/governance/genesis/plan-your-first-users","default":false,"active":false,"folderId":"c15a2701"},{"version":"v1.26","label":"v1.26 LTS","link":"/products/custody/v1.26/governance/genesis/plan-your-first-users","default":false,"active":false,"folderId":"c15a2701"},{"version":"v1.19","label":"v1.19 LTS","link":"/products/custody/v1.19/governance/genesis/plan-your-first-users","default":false,"active":false,"folderId":"c15a2701"},{"version":"v1.15","label":"v1.15 LTS","link":"/products/custody/v1.15/governance/genesis/plan-your-first-users","default":false,"active":false,"folderId":"c15a2701"}],"sharedDataIds":{"sidebar":"sidebar-products/custody/@v1.15/sidebars.yaml"},"props":{"metadata":{"markdoc":{"tagList":[]},"type":"markdown"},"seo":{"title":"Plan your first users","description":"User guides, API reference, and support resources.","siteUrl":"https://docs.ripple.com","lang":"en-US","llmstxt":{"hide":false,"sections":[{"title":"Table of contents","includeFiles":["**/*"],"excludeFiles":[]}],"excludeFiles":[]}},"dynamicMarkdocComponents":[],"compilationErrors":[],"ast":{"$$mdtype":"Tag","name":"article","attributes":{},"children":[{"$$mdtype":"Tag","name":"Heading","attributes":{"level":1,"id":"plan-your-first-users","__idx":0},"children":["Plan your first users"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Plan the users and role assignments that must exist before the environment starts. These users must be able to satisfy every policy workflow that is required at launch."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"inputs","__idx":1},"children":["Inputs"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Use the domain model from ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/products/custody/governance/genesis/design-your-domains"},"children":["Design your domains"]}," and list:"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Roles that create launch-critical intents."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Roles that approve launch-critical intents."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Roles that need read access."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Bot users required for automated workflows."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Emergency or recovery users."]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"role-model","__idx":2},"children":["Role model"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Start with role responsibilities, not names."]},{"$$mdtype":"Tag","name":"div","attributes":{"className":"md-table-wrapper"},"children":[{"$$mdtype":"Tag","name":"table","attributes":{"className":"md"},"children":[{"$$mdtype":"Tag","name":"thead","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Responsibility"},"children":["Responsibility"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Example role"},"children":["Example role"]}]}]},{"$$mdtype":"Tag","name":"tbody","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Root administration"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["platform-admin"]}]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Policy changes"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["policy-operator"]}]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Transaction operations"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["transaction-operator"]}]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Compliance review"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["compliance"]}]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Emergency recovery"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["emergency-operator"]}]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Read-only audit"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["auditor"]}]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Automation"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["transaction-operator-bot"]}]}]}]}]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Choose names that operators will understand. Role names are strings that you can define whenever you need them, but users receive those roles only through genesis or a governed user intent after launch. Use the same role names in users, policies, and domain read access."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"quorum-coverage","__idx":3},"children":["Quorum coverage"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["For each policy workflow, confirm that the launch users can satisfy quorum."]},{"$$mdtype":"Tag","name":"div","attributes":{"className":"md-table-wrapper"},"children":[{"$$mdtype":"Tag","name":"table","attributes":{"className":"md"},"children":[{"$$mdtype":"Tag","name":"thead","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Workflow"},"children":["Workflow"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Check"},"children":["Check"]}]}]},{"$$mdtype":"Tag","name":"tbody","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Maker step"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["At least one launch user has the role that creates the intent."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Checker step"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Enough independent users have the checker role."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Multi-role approval"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Each required role has enough users."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Emergency approval"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Emergency roles exist and credentials are controlled."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Bot workflow"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Bot users exist only where automation is intentional."]}]}]}]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Do not rely on users that can only be created after launch to satisfy policies that must work at launch."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"genesis-user-guidance","__idx":4},"children":["Genesis user guidance"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Genesis users are the initial root of trust. They cannot be deleted, so choose them carefully. They can be locked later, but the launch model should not depend on a single person or a single credential."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Recommended checks:"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["At least two human users for critical human roles."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["No single user can complete a high-risk workflow alone."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Bot users are limited to the workflows they need."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Emergency users are independent from routine operators where possible."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Role names match the policy workflows exactly."]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"genesis-user-examples","__idx":5},"children":["Genesis user examples"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["The following example shows users as they appear inside a genesis domain's ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["users"]}," array. Genesis users do not include a ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["type"]}," field because they are embedded in the genesis domain setup, not submitted as ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["v0_CreateUser"]}," intents. For post-genesis user creation, see ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/products/custody/governance/users/manage-users-and-roles#create-a-user-with-the-api"},"children":["Manage users and roles"]},"."]},{"$$mdtype":"Tag","name":"CodeBlock","attributes":{"data-language":"json","header":{"controls":{"copy":{}}},"source":"[\n  {\n    \"id\": \"e1fe3431-f899-427b-9e67-a75fb9fe5e57\",\n    \"alias\": \"platform-admin-1@example.com\",\n    \"publicKey\": \"MFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAEe32vCCfM0LXmT6VuZo4AykiZ8YfBMB92nKNX8K+PRhN7/qPhILzGlOv/7kDyefTxHSrytXG28OB0cPwErlHgyQ==\",\n    \"roles\": [\"platform-admin\", \"policy-operator\"],\n    \"loginIds\": [\n      {\n        \"id\": \"platform-admin-1@example.com\",\n        \"providerId\": \"harmonize\"\n      }\n    ],\n    \"lock\": \"Unlocked\",\n    \"description\": \"Genesis platform administrator\",\n    \"customProperties\": {\n      \"userType\": \"human\"\n    }\n  },\n  {\n    \"id\": \"7bf37a53-51a5-48da-b7d1-c2fa05bd3f14\",\n    \"alias\": \"compliance-1@example.com\",\n    \"publicKey\": \"MFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAET1BnSIvToEO6r5BMmaG+O3GL0/A7JilzCdmJ3trIWIsXDuv8jAcGizraMouqWIHTx2hi3rxoH7eABURbfSSryw==\",\n    \"roles\": [\"compliance\"],\n    \"loginIds\": [\n      {\n        \"id\": \"compliance-1@example.com\",\n        \"providerId\": \"harmonize\"\n      }\n    ],\n    \"lock\": \"Unlocked\",\n    \"description\": \"Genesis compliance approver\",\n    \"customProperties\": {\n      \"userType\": \"human\"\n    }\n  }\n]\n","lang":"json"},"children":[]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Use the same role strings in:"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["The ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["roles"]}," array for each user."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Domain read access permissions."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Policy workflow steps."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Policy conditions that check author or target roles."]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"output","__idx":6},"children":["Output"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["By the end of this step, you should have:"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["First-user list."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Role assignments by domain."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Quorum coverage table."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Bot user list."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Emergency user list."]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Use the output as input for ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/products/custody/governance/genesis/design-your-policies"},"children":["Design your policies"]},"."]}]},"headings":[{"value":"Plan your first users","id":"plan-your-first-users","depth":1},{"value":"Inputs","id":"inputs","depth":2},{"value":"Role model","id":"role-model","depth":2},{"value":"Quorum coverage","id":"quorum-coverage","depth":2},{"value":"Genesis user guidance","id":"genesis-user-guidance","depth":2},{"value":"Genesis user examples","id":"genesis-user-examples","depth":2},{"value":"Output","id":"output","depth":2}],"frontmatter":{"seo":{"title":"Plan your first users"}},"lastModified":"2026-08-04T20:25:11.000Z","pagePropGetterError":{"message":"","name":""}},"slug":"/products/custody/governance/genesis/plan-your-first-users","userData":{"isAuthenticated":false,"teams":["anonymous"]},"isPublic":true}