🛡 Spending limits and the Proposer role

Last updated: September 28, 2026

Spending limit

Proposer role

What it grants

Permission to move assets up to a cap, without collecting signatures

Permission to create transactions for signers to review

Can move assets alone

Yes, within the limit

No

Enforcement

Onchain, by a contract your Safe Account owns

Off-chain, by Safe{Wallet}

Setup cost

A Safe transaction, signed and executed, gas applies

Instant, no transaction, no gas

Revoke

A Safe transaction

Instant

Record

Onchain, publicly verifiable

In Safe{Wallet} only

Spending limit

A spending limit lets one address (the spender can be anyone, signers or outsiders) send a set amount of one token from your Safe Account, without collecting any signatures.

You choose the spender, the token, the amount, and how often the amount resets. Once the setup transaction executes, that spender transfers directly from the account. Signers are not involved in each transfer.

What it does not do

A spending limit does not restrict where funds go. A spender with a 100 USDC daily limit can send that 100 USDC to any address. The limit is the only control. If you need payments restricted to known recipients, a spending limit will not give you that.

The dollar figure is an estimate, not the rule. When you enter an amount in USD, Safe{Wallet} converts it to a token amount at the time of setup. Enforcement is on the token amount. If the token doubles in price, the limit is worth twice as much and nothing changes onchain. Read the token amount as the real limit.

How it works

  1. Enable the module. The first spending limit on an account enables the Safe Allowance Module. Later limits on the same account skip this step.

  2. Set the allowance. The setup transaction records the spender, the token, the amount, and the reset period.

  3. Sign and execute. Setup follows the normal transaction flow. Your account's signing threshold applies, and gas applies.

  4. The spender transfers. The spender pays gas on their own transfers. Transfers above the remaining amount fail.

Resets

Choose a one-time allowance or a recurring one. A recurring allowance restores to the full amount at the end of each period. Unspent amounts do not roll over.

Managing limits

Spending limits cannot be edited. To change an amount, remove the limit and create it again. Revoke is per token, so removing a USDC limit leaves an ETH limit for the same spender in place. A revoke is a Safe transaction, so it needs signatures and gas, and it takes effect once executed.

Who to give one to

Use spending limits for recurring, bounded, low-value work: paying a contractor, funding a bot, topping up a hot wallet for gas. Match the cap to what the job actually needs, and set a recurring period rather than a large one-time amount.

Proposer role

A Proposer creates transactions in Safe{Wallet} for your signers to review. That is the whole of it. A Proposer cannot sign, cannot execute, and cannot move assets. Every transaction a Proposer creates still needs your account's full signing threshold before anything happens onchain.

Use it for the person who prepares payment batches but should not hold signing authority, for an operations teammate who builds transactions for a signer to check, or for anyone who needs visibility and drafting rights and nothing more.

How it differs from every other policy

The Proposer role is granted off-chain. It is a Safe{Wallet} permission, not a contract your Safe Account owns. It leaves no onchain record and it is not covered by the audits that cover the Allowance Module.

Two things follow. First, it is fast: granting or revoking a Proposer takes effect immediately, with no transaction, no signatures, and no gas. Second, it protects nothing onchain. A Proposer never had the power to move assets, so there is nothing for a contract to restrict. The security of the account rests entirely on its signers and its threshold.

Where a grant applies

A Proposer grant applies to one Safe Account on one network. Granting Proposer rights on Ethereum does not grant them on Base. Add the grant on each network where the person needs it.

Adding and removing a Proposer

Adding requires a signature from one of the account's signers, to prove the grant is authorized. It is a signature, not a transaction, so nothing is submitted onchain and no gas is charged. Removal is immediate.

Review your Proposers when someone changes team. Because the grant has no onchain record and no expiry, nothing will remind you.

Common questions

Does a spending limit change my signing threshold? No. Your threshold is unchanged for every normal transaction. The limit creates a separate path that bypasses it for that spender, that token, and that amount only.

Can a Proposer also be a signer? Yes, but there is no reason to grant it. Signers can already create transactions.

Can I apply one policy to every Safe Account at once? Not yet. Policies are set per account, per network. Bulk apply is planned.

Who pays gas? You pay to set up or remove a spending limit. The spender pays for their own transfers. The Proposer role costs nothing.

Can I see every policy across my Workspace? Yes. The Workspace policies page reads live onchain state across every Safe Account in the Workspace and tells you how many accounts it scanned, so nothing is hidden from the view.

What happens to a spending limit if I change signers? Nothing. The allowance belongs to the account, not to its signers. Review your spending limits whenever signers change.