{"templateId":"markdown","versions":[{"version":"v1.40","label":"v1.40 STS","link":"/products/custody/v1.40/get-started/design/policies/breakglass","default":true,"active":false,"folderId":"c15a2701"},{"version":"v1.39","label":"v1.39 STS","link":"/products/custody/v1.39/get-started/design/policies/breakglass","default":false,"active":false,"folderId":"c15a2701"},{"version":"v1.38","label":"v1.38 STS","link":"/products/custody/v1.38/get-started/design/policies/breakglass","default":false,"active":false,"folderId":"c15a2701"},{"version":"v1.34","label":"v1.34 LTS","link":"/products/custody/v1.34/get-started/design/policies/breakglass","default":false,"active":false,"folderId":"c15a2701"},{"version":"v1.26","label":"v1.26 LTS","link":"/products/custody/v1.26/get-started/design/policies/breakglass","default":false,"active":false,"folderId":"c15a2701"},{"version":"v1.19","label":"v1.19 LTS","link":"/products/custody/v1.19/get-started/design/policies/breakglass","default":false,"active":false,"folderId":"c15a2701"},{"version":"v1.15","label":"v1.15 LTS","link":"/products/custody/v1.15/get-started/design/policies/breakglass","default":false,"active":true,"folderId":"c15a2701"}],"sharedDataIds":{"sidebar":"sidebar-products/custody/@v1.15/sidebars.yaml"},"props":{"metadata":{"markdoc":{"tagList":["admonition"]},"type":"markdown"},"seo":{"title":"Breakglass policy","description":"User guides, API reference, and support resources.","siteUrl":"https://docs.ripple.com","lang":"en-US","llmstxt":{"hide":false,"sections":[{"title":"Table of contents","includeFiles":["**/*"],"excludeFiles":[]}],"excludeFiles":[]}},"dynamicMarkdocComponents":[],"compilationErrors":[],"ast":{"$$mdtype":"Tag","name":"article","attributes":{},"children":[{"$$mdtype":"Tag","name":"Heading","attributes":{"level":1,"id":"breakglass-policy","__idx":0},"children":["Breakglass policy"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["The policy engine is designed to enforce governance strictly, with no super-admin user capable of single-handedly reconfiguring the system."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["A breakglass policy provides an override mechanism that fully complies with the ","Ripple Custody"," governance framework, for scenarios where you need to bypass policies, for example:"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["A court order requiring the custodian to freeze an account against the will of the client's policies."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["An improper policy deployment locking down the access to certain features of the system with no recourse."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["The loss of some user keys required to complete an approval workflow."]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["The main objective of a breakglass policy is to force a subdomain to execute an intent, even if doing so bypasses the subdomain's own policies. In scenarios such as those outlined above, a root domain armed with a proper breakglass policy can:"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Force a subdomain to freeze an account."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Unlock a subdomain that was locked due to an improper policy setup."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Force the creation of new users or a policy update in a subdomain locked because of lost user keys."]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"characteristics-of-a-breakglass-policy","__idx":1},"children":["Characteristics of a breakglass policy"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["A breakglass policy has the following characteristics:"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Applies to intents submitted in a parent domain with one of its subdomains as the target domain."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["The parent domain has a governing strategy of ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["CoerceDescendants"]},". For more information, see ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/products/custody/v1.15/get-started/deployment/system-setup/setup#governing-strategy"},"children":["Governing strategy"]},"."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["The parent domain has a policy with scope ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["Descendants"]}," or ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["SelfAndDescendants"]}," that matches the intent."]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["For more information and an example, see ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/products/custody/v1.15/get-started/design/policies/overview#scope-of-a-policy"},"children":["Scope of a policy"]},"."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"recommended-setup","__idx":2},"children":["Recommended setup"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["The recommended setup for a breakglass policy is as follows:"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["The breakglass policy is created in the root domain."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["The root domain can trigger any intent within its subdomains, subject to a strict approval workflow requiring multiple approvals from senior members of the custodian management team."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["The size of the quorum should not be so small that the breakglass policy becomes a concentrated point of compromise, but it should equally be large enough to ensure that the loss of breakglass user keys does not affect the ability to execute an operation."]}]},{"$$mdtype":"Tag","name":"Admonition","attributes":{"type":"warning"},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Given the criticality of a proper breakglass setup, we recommend that you contact Ripple for guidance if you are not sure how to define the proper governance and exception clauses."]}]}]},"headings":[{"value":"Breakglass policy","id":"breakglass-policy","depth":1},{"value":"Characteristics of a breakglass policy","id":"characteristics-of-a-breakglass-policy","depth":2},{"value":"Recommended setup","id":"recommended-setup","depth":2}],"frontmatter":{"seo":{"title":"Breakglass policy"}},"lastModified":"2025-10-28T02:35:57.000Z","pagePropGetterError":{"message":"","name":""}},"slug":"/products/custody/v1.15/get-started/design/policies/breakglass","userData":{"isAuthenticated":false,"teams":["anonymous"]},"isPublic":true}