Profiles
A profile provides the chain and execution address for an executable. ctx.account is the customer-facing execution address, not an internal relayer or executor address. The selected profile determines who can authorize contract calls and who holds the signing authority.
Profile kinds
| Kind | Authority | Gas |
|---|---|---|
Roles (safe_roles) | Customer-owned Safe with an explicit Zodiac Roles target/selector allowlist. | Sponsored through managed Lift. |
Legacy (legacy) | EIP-7702 EOA whose signing key is held by Thyme's remote signer. | Sponsored or wallet-paid. |
Roles profiles are the scoped Safe path. Creation options depend on deployment flags and supported contract stacks; legacy profiles remain a distinct custodial trust model.
Roles authorization
The customer owns the Safe and its Roles module. Thyme controls a separate executor that is a member of one role. That role permits only listed contract addresses and function selectors with zero native value and Call execution. The executor cannot widen the role or administer the customer Safe through that permission.
This release uses target and selector restrictions, without argument-level conditions. Allowing transfer, approve, or transferFrom permits the task to choose recipients and amounts for those calls. Zero native value does not prevent ERC-20 asset movement. Review allowed selectors and give the Safe only the funds and approvals appropriate for the automation.
A permission manifest describes what a release needs. It does not grant authority: the owner must separately approve any required scope extension on-chain.
Bring a Safe or create one
- Bring your own Safe: connect the owner of an eligible deployed Safe 1.4.1 with threshold one. The owner sends the prepared setup transaction and pays its gas.
- Sponsored onboarding: Flow derives or deploys a customer-owned Safe and sponsors the setup. The browser verifies the proposed address and transaction before requesting the owner's signature. Follow the console's deployment and verification steps before funding the account.
Sponsored setup includes an off-chain authorization to relay exactly the signed Safe transaction. Until its nonce is consumed, a broadcast copy of that signature can complete the same setup. Re-preparing a setup cannot erase copies already published to the network.
Use the independent Roles verifier when reviewing the prepared payload and resulting account. On a resumed setup, review the stored allowlist again; the UI distinguishes a policy entered now from one retrieved from the server.
Revocation, changes, and reassignment
Only the Safe owner can authorize a broader Roles scope. Pausing stops Flow automation and sponsorship but is not an on-chain revocation. Remove the role or module through the Safe to revoke on-chain authority; see profile operations.
Executables can move to another active profile in the same project on the same chain, subject to permission checks. In-flight runs finish on their original profile; later invocations use the new profile. Cross-chain moves require a separate executable.
See supported chains, gas, and Flow with Lift.