Recovery questions

Common questions about terminal owner recovery and what it can and cannot do.

Does recovery need anyone besides the owner?

No. Recovery requires only the vault owner's own wallet signature — not an agent, not an approver, not a governance ceremony, and not the hosted platform being available. This is a deliberate design choice; see Owner recovery for why.

Can an agent or approver block or delay recovery?

No. Recovery is a break-glass operation specifically designed so that no other party's cooperation or absence affects it. An agent's or approver's key has no role in the recovery operation at all.

What happens to agents and approvers after recovery?

Recovery is terminal for the vault: once performed, the vault has no further live covenant state, so any previously configured agent or approver keys have nothing left to act on for that vault. This happens automatically as a consequence of the vault's lifecycle ending — there is no separate step to "remove" them afterward.

Is recovery reversible?

No. Recovery is terminal for that specific vault. If you only need a temporary stop, use pause instead, which is fully reversible.

What if I've lost the owner key?

There is no PolicyVault-side recovery mechanism for a lost owner key — nobody operating PolicyVault, hosted or self-hosted, can recover it for you. This mirrors ordinary Kaspa wallet custody exactly: protect the owner's seed phrase the way you would protect any wallet holding real funds. See Owner.

Can I recover only part of a vault's balance?

Recovery's exact mechanics (whether a partial withdrawal is possible versus a full terminal withdrawal) depend on the specific covenant version a vault runs — check Covenant enforcement and the vault's presented options in the dashboard rather than assuming; this documentation intentionally does not guess at behavior that varies by version.

Does recovery require the hosted server to be honest or even online?

No. Because recovery needs only the owner's signature verified directly by Kaspa consensus, it works even if the hosted PolicyVault server is down, degraded, or fully compromised — see If the hosted server is compromised.

See also: Owner recovery, Recover a vault.