Manage Profiles
Open Console → Profiles in the project containing your executable. Available creation paths depend on deployment flags and chain support. See profile trust models before selecting one.
Create a Roles profile
- Connect the wallet that will own, or already owns, the customer Safe.
- Choose the available chain and enter a recognizable alias.
- Choose sponsored Safe creation when offered, or supply an eligible deployed Safe 1.4.1 with threshold one.
- Enter the contract targets and function selectors the automation needs.
- Review the derived addresses and decoded setup before authorizing it.
- Complete submission and on-chain verification until the profile is active.
For sponsored creation, the console may deploy the bare Safe first, then request a signature at its live nonce. For a supplied Safe, the owner's wallet sends the setup transaction. These are different gas and signing flows; follow the steps shown for the selected path.
Do not fund an unverified sponsored account solely because a deterministic address is displayed. Review its setup proof and complete the account checks first.
Choose creation payment
When creating a new Roles Safe, choose Sponsored by Thyme or Pay from wallet. Thyme covers one mainnet profile creation per workspace across all projects and supported networks. Later creations are paid by the connected owner wallet. Choosing wallet payment for the first creation saves the unused allowance. Testnet sponsorship is separate.
For wallet payment, review and sign the setup, check the network-fee estimate, then select Pay and create profile. Your wallet pays in the network's native token. The new Safe does not need a gas deposit. If your wallet requires the Safe to exist before signing, Use deploy-first splits this into two paid transactions, with each fee shown before approval. Reverted transactions can still cost gas.
You can resume an unfinished creation from the profile menu. A sponsored creation already in flight keeps its allowance until resolved; deleting or archiving a completed profile does not restore it. Mainnet choices appear only when enabled for your deployment. Creation payment does not change the gas policy for subsequent automation runs.
Verify independently
The console recomputes the sponsored Safe address and expected setup from the owner, profile, and scope before requesting a signature. It also checks the resulting on-chain account and module configuration.
The public CLI includes Roles verification commands for inspecting preparation data and verifying a profile using your own RPC endpoint. Verification describes the account at the time checked; owner-authorized changes can legitimately alter it later.
When resuming setup, read the allowlist again. The console identifies whether it is comparing against values entered in the current session or a policy retrieved from the server.
Change scope
Edit the profile's contract/selector rules and review the resulting permission diff. A scope extension requires the Safe owner's authorization; a release manifest alone cannot grant it. Flow blocks conflicting work while a scope update is in progress and verifies the on-chain outcome before committing the new state.
Selectors are not amount or recipient limits. Allowing a token transfer or approval grants the corresponding calldata choices to the task. Narrow the allowed contracts and selectors to the work you intend.
Pause or revoke
Pause stops Flow's automation and associated sponsorship. On-chain revocation removes the executor's role authority. Complete the revocation flow or revoke from the Safe directly when that authority must end; pausing a UI resource alone is not the same action.
If a setup or scope transaction has a recorded hash but an unknown outcome, reconcile it before signing another conflicting transaction. A timed-out browser request does not prove that the transaction failed.
Existing legacy profiles
Legacy profiles use a remote-signer key and remain a separate custodial model. Deployment controls can disable new creation while preserving existing profiles for operation or migration.
Where offered, legacy migration moves executables to an active Roles profile on the same chain, waits for in-flight work, and sweeps balances. Supply the complete ERC-20 contract inventory: Flow cannot discover every token holding. Inspect unresolved submission hashes and the verified remainder report before retiring the old account.
Archive and sharing
Archiving is blocked while the profile has non-deleted executables; migration guards can add further conditions. Archive is a resource-lifecycle operation, not key destruction or on-chain revocation. Profile sharing/copy options, when offered, do not create a new independent on-chain identity; review their account relationship before use.