Policy Engine Development for Transaction Management

We design and develop full-cycle blockchain solutions: from smart contract architecture to launching DeFi protocols, NFT marketplaces and crypto exchanges. Security audits, tokenomics, integration with existing infrastructure.
Showing 1 of 1All 1305 services
Policy Engine Development for Transaction Management
Complex
~1-2 weeks
Frequently Asked Questions

Blockchain Development Services

Blockchain Development Stages

Latest works

  • image_website-b2b-advance_0.webp
    B2B ADVANCE company website development
    1358
  • image_web-applications_feedme_466_0.webp
    Development of a web application for FEEDME
    1250
  • image_websites_belfingroup_462_0.webp
    Website development for BELFINGROUP
    956
  • image_ecommerce_furnoro_435_0.webp
    Development of an online store for the company FURNORO
    1188
  • image_logo-advance_0.webp
    B2B Advance company logo design
    646
  • image_crm_enviok_479_0.webp
    Development of a web application for Enviok
    929

Imagine: a multi-sig wallet with 5 signers, daily limit $2M. An employee initiates a withdrawal of $1.8M to an address that was added to the OFAC sanctions list an hour ago. Signatures are collected, but the policy engine at the pre-check stage calls Chainalysis KYT, gets a risk score of 85—the transaction is blocked. Without such an engine, the funds would be frozen for weeks, and the company could face a fine of up to $500,000. We design and implement a rule system for custodial wallets and corporate multisigs. The engine applies a set of rules before signing—this is a key difference from post-processing. Our team has 8 years of experience in blockchain development and over 40 implementations for major custodial solutions.

How does the transaction management system work?

Policy engine—a layer between the initiator and execution. It evaluates rules before the transaction goes to signature and into the mempool. Rules check parameters, context (sender role, time), external data (compliance API), and on-chain state. Result: allow, deny, request additional signatures, or delay.

According to the Safe{Core} Protocol specification, Hooks' preCheck is called before transaction execution.

Architecture of the rule system

Levels of policy application — policy system design

The policy engine can exist on several levels—they are often mixed, causing problems:

  • Off-chain pre-execution — the most common. Rules are checked in the service before signing. Flexible, cheap, supports any logic. Drawback: requires trust in this service.
  • On-chain enforcement — a smart contract, the entry point for all transactions. Safe{Core} Protocol Hooks is an example. Stronger guarantees, but logic is limited on-chain: no access to external data without oracles, each check costs gas.
  • Hybrid — policies are verified off-chain, the contract accepts a proof (commitment scheme or trusted signer attestation).

Why combine off-chain and on-chain?

Off-chain evaluation is 10 times faster and does not consume gas, but on-chain provides immutable guarantees. The optimal solution is a hybrid architecture: fast off-chain rules as the first filter, critical policies (protocol limits) in smart contracts. In one project, we process 500+ rules with latency under 5 ms, saving up to 70% time on manual moderation. Development cost is estimated individually but pays off through reduced compliance incidents. One unblocked transaction can save over $1 million, and annual savings can reach $5 million.

Rule model

A rule consists of a condition and an action. Conditions can be:

  • Parametric: amount > threshold, recipient in whitelist, token == USDC
  • Contextual: sender.role == OPERATOR, time_of_day in 09:00-18:00, daily_volume + amount <= limit
  • External: chainalysis_risk_score(recipient) < 70, ofac_check(recipient) == CLEAR
  • On-chain: recipient.is_contract == false, token.paused == false

Actions: ALLOW, DENY, REQUIRE_APPROVAL(n_signers), DELAY(duration), NOTIFY(channels).

Rules have priorities, conflicts are possible. Need clear semantics: first-match, all-must-pass, whitelist-overrides-blacklist. This is a design decision.

Example rule interface
interface PolicyRule {
  id: string;
  priority: number;
  conditions: Condition[];
  conditionLogic: 'AND' | 'OR';
  action: PolicyAction;
  metadata: { name: string; owner: string; updatedAt: number };
}

interface PolicyAction {
  type: 'ALLOW' | 'DENY' | 'REQUIRE_APPROVAL' | 'DELAY';
  params?: {
    requiredApprovers?: string[];
    minApprovals?: number;
    delaySeconds?: number;
    notifyChannels?: string[];
  };
}

Evaluator: evaluation order

The engine must process rules efficiently—especially when there are hundreds of rules and some require external calls (compliance provider API).

The optimal strategy: short-circuit evaluation with caching. First, cheap local conditions (transaction parameters, roles) are checked, then cached external data, and finally fresh API calls with timeout.

class PolicyEvaluator:
    def evaluate(self, tx: Transaction, context: EvalContext) -> PolicyDecision:
        sorted_rules = sorted(self.rules, key=lambda r: r.priority, reverse=True)
        
        for rule in sorted_rules:
            cheap_conditions = [c for c in rule.conditions if c.type == 'PARAMETRIC']
            if not self._eval_conditions(cheap_conditions, tx, context):
                continue
            
            expensive_conditions = [c for c in rule.conditions if c.type == 'EXTERNAL']
            cache_key = self._cache_key(expensive_conditions, tx)
            cached = self.cache.get(cache_key)
            
            results = cached if cached else self._eval_external(expensive_conditions, tx)
            self.cache.set(cache_key, results, ttl=300)
            
            if self._eval_conditions_with_results(rule.conditions, results, rule.conditionLogic):
                return PolicyDecision(action=rule.action, rule_id=rule.id)
        
        return PolicyDecision(action=DEFAULT_ACTION)

On-chain implementation: Safe Hooks

The Safe{Core} Protocol (EIP-7579 compatible) provides a hook mechanism:

interface ISafeProtocolHooks {
    function preCheck(
        Safe safe,
        SafeTransaction calldata tx,
        uint256 executionType,
        bytes calldata executionMeta
    ) external returns (bytes memory preCheckData);
    
    function postCheck(
        Safe safe,
        bool success,
        bytes calldata preCheckData
    ) external;
}

preCheck is called before execution. If it reverts—the transaction fails. Here you can: check whitelist/blacklist (stored in hook storage), check limits (via accumulators by addresses/tokens), require additional approval via timelock.

Example limit hook:

contract DailyLimitHook is ISafeProtocolHooks {
    mapping(address => mapping(address => uint256)) public dailyVolume;
    mapping(address => mapping(address => uint256)) public lastResetDay;
    mapping(address => mapping(address => uint256)) public dailyLimit;

    function preCheck(Safe safe, SafeTransaction calldata tx, uint256, bytes calldata)
        external returns (bytes memory)
    {
        address token = _extractToken(tx.data);
        uint256 amount = _extractAmount(tx.data);
        
        uint256 today = block.timestamp / 1 days;
        address safeAddr = address(safe);
        
        if (lastResetDay[safeAddr][token] < today) {
            dailyVolume[safeAddr][token] = 0;
            lastResetDay[safeAddr][token] = today;
        }
        
        require(
            dailyVolume[safeAddr][token] + amount <= dailyLimit[safeAddr][token],
            "DailyLimitExceeded"
        );
        
        return abi.encode(token, amount);
    }

    function postCheck(Safe safe, bool success, bytes calldata preCheckData) external {
        if (success) {
            (address token, uint256 amount) = abi.decode(preCheckData, (address, uint256));
            dailyVolume[address(safe)][token] += amount;
        }
    }
}

How to integrate compliance API?

For financial products, the policy engine inevitably includes integration with compliance providers. Key ones:

  • Chainalysis — KYT API checks addresses (risk score) and transactions (exposure to known clusters). Latency: 200–800ms, need cache and graceful degradation.
  • Elliptic — similar functionality, different risk assessment model. Used in Fireblocks.
  • TRM Labs — specializes in cross-chain analysis, good coverage of Solana and Tron.
  • OFAC screening — can be done through the same providers or via a self-maintained snapshot of the SDN list (updated infrequently, can be stored locally and updated via webhook).

Important: compliance APIs have SLAs and may be unavailable. The policy engine must have a clear policy for the EXTERNAL_CHECK_TIMEOUT case: fail-open (allow with log) vs. fail-closed (block). This is a business decision, but it must be documented.

Provider Features Latency Network Coverage
Chainalysis KYT, risk scores 200-800ms Ethereum, Bitcoin, 10+ networks
Elliptic Focus on sanctions 300-600ms Major L1s
TRM Labs Cross-chain, Solana 150-500ms 30+ networks

How we implement the policy engine?

  1. Requirements analysis — determine business rules, compliance obligations, technical constraints (latency, throughput).
  2. Rule model design — design rule hierarchy, conditions, actions, conflict resolution policies.
  3. Evaluator development — write the engine core with short-circuit evaluation, caching, and external API integration.
  4. Integration and testing — connect the engine to the wallet or multisig, perform load and regression testing.

Order policy engine development to protect your assets.

Monitoring and audit

A rule system without a full audit log is useless for compliance. Each decision must contain:

  • Transaction hash or pre-tx ID
  • List of applied rules and their results
  • Values of all conditions at the time of evaluation
  • Final decision and executor
  • Timestamp with millisecond accuracy

This is an immutable log. Storage: PostgreSQL with an append-only table + replication to S3/Arweave for long-term retention. For regulatory requirements — minimum 5 years.

Component Technology
Rule storage PostgreSQL + Redis cache
Evaluator Go / Python service
On-chain hooks Solidity (Safe Protocol)
Compliance API Chainalysis / Elliptic / TRM
Audit log PostgreSQL → S3
Admin UI React + role-based access

What's included in development

  • Project documentation (architecture, rule model)
  • Source code of the engine (off-chain evaluator and on-chain hooks)
  • Integration with compliance providers (Chainalysis, Elliptic, etc.)
  • Caching and graceful degradation setup
  • Audit log deployment and configuration
  • Team training and administrator documentation
  • 3 months post-release support

Get a consultation on policy engine implementation—we'll help design and deploy a turnkey solution.

Blockchain Infrastructure Deployment: Nodes, RPC, Indexing

Subgraph fell at 3:47 AM. By morning users saw outdated balances, transactions "hung" in the UI, support received 47 tickets in an hour. Cause: the handler in the subgraph failed on a transaction with a non-standard event log — and the entire index stopped. We have encountered such situations dozens of times. Our experience shows: blockchain infrastructure does not forgive gaps in observability. Guaranteeing uptime without multi-layered monitoring and fault-tolerant architecture is impossible. Over 8 years working with Ethereum, Polygon, and Solana, we have developed an approach that allows predictable deployment of infrastructure of any scale — from a single node to a multichain grid with dozens of subgraphs.

RPC Layer Architecture

Every dApp interaction with the blockchain goes through RPC — the JSON-RPC API provided by a node. Three options:

Managed providers — Alchemy, QuickNode, Infura, Ankr. Minimal operational costs, SLA, built-in monitoring. Limits: rate limits (Alchemy Free: 300 RU/sec), vendor lock, potential downtime during provider incidents. For most projects — the right choice at the start.

Self-owned nodes — full control, no rate limits, no third-party dependence. Cost: archive Ethereum node requires 2.5–3TB SSD, a strong server, and DevOps support. Sync from scratch on Ethereum via Geth/Nethermind — 3–7 days. Justified under high load or latency requirements.

Hybrid — self-owned node as primary, managed provider as fallback. Standard for protocols with high TVL. Proper load balancing can reduce costs by 20–30% compared to pure managed setup. Under high monthly request volume, hybrid saves significantly.

Provider Strength Limitation
Alchemy Supernode, Enhanced APIs, webhooks Expensive on high-volume
QuickNode Low latency, multi-chain More expensive than Alchemy on basic plan
Infura Historical reliability Rate limits on free, one major incident halted half of DeFi
Ankr Cheap, 40+ chains Less stable

How to Set Up an RPC Layer Without a Single Point of Failure?

At least two providers, DNS round-robin with health check every 5 seconds, automatic fallback when latency >500 ms. In practice, this gives 99.99% availability during any provider failure. For protocols with high TVL, we recommend a custom HA-proxy (nginx or Envoy) in front of two managed providers.

Why Is a Hybrid RPC Scheme More Cost-Effective Than Pure Managed?

At high request volumes, managed providers can be very expensive; a hybrid using a self-owned node as primary and a managed fallback cuts costs significantly without losing SLA.

Ethereum Node Clients

Execution clients: Geth (most used), Nethermind (C#, fast sync), Besu (Java, enterprise), Erigon (fastest sync, efficient archive mode ~2TB instead of 3TB).

Consensus clients (post-Merge): Lighthouse (Rust), Prysm (Go), Teku (Java), Nimbus (Nim). Each node after The Merge requires a pair of execution + consensus clients.

For DevOps: eth-docker — Docker Compose configurations for all client combinations. Setting up monitoring via Grafana + Prometheus is mandatory; a standard dashboard is available in each client's repository.

The Graph: Event Indexing

The Graph Protocol — decentralized indexing. A subgraph describes which events from which contracts to index and how to transform them into a GraphQL schema.

Subgraph structure:

  • subgraph.yaml — manifest: contract addresses, startBlock, events to handle
  • schema.graphql — GraphQL schema of entities
  • src/mapping.ts — AssemblyScript event handlers
dataSources:
  - kind: ethereum
    name: UniswapV3Pool
    network: mainnet
    source:
      address: "0x88e6A0c2dDD26FEEb64F039a2c41296FcB3f5640"
      abi: UniswapV3Pool
      startBlock: 12370624
    mapping:
      eventHandlers:
        - event: Swap(indexed address,indexed address,int256,int256,uint160,uint128,int24)
          handler: handleSwap

AssemblyScript handlers — not TypeScript. No nullable types, no closures, no many standard APIs. An error in the handler stops the subgraph indexing on that transaction. Important: add try-catch for operations that can fail (e.g., store.get() for an entity that may not exist).

How to Avoid Subgraph Indexing Stops?

Graph Node logs are monitored in real-time; on hasIndexingErrors = true an alert fires and an automatic node restart (via systemd or Kubernetes). Typical downtime on error — 150–300 seconds to recover. Additionally, for production we set up a watchdog that restarts Graph Node if subgraph lag exceeds 50 blocks.

Choosing Between Hosted Service and Decentralized Network

Graph Hosted Service (free, centralized) is deprecated in favor of Subgraph Studio + Graph Network. For production: deploy on Graph Network with GRT curation signal — the subgraph gets indexers proportional to curation.

Alternatives to The Graph: Ponder (TypeScript, self-hosted, easier to debug), Envio (ultra-fast indexer, supports EVM + non-EVM), Subsquid (TypeScript, own network), Moralis Streams (managed, webhook-based). Our experience shows: for high-load projects with unique logic, Ponder or Envio are more effective — they give full control over the process and do not require GRT tokenomics.

Webhooks and Real-Time Notifications

Alchemy Webhooks and QuickNode Streams allow receiving events in real-time via HTTP webhook or WebSocket. For monitoring addresses, new transactions, mints — this is faster than polling RPC.

Tenderly — platform for monitoring and alerts. You can set up an alert for a specific contract event, balance change, function call with certain parameters. Transaction simulation via Tenderly API is invaluable for debugging.

Monitoring and Observability

Minimum monitoring stack for a protocol:

On-chain: OpenZeppelin Defender Sentinel — watches contract events, triggers webhook or Autotask when conditions are met. Forta Network — community-maintained bots detect anomalies (large withdrawals, flash loans, governance attacks).

Infrastructure: Grafana + Prometheus for nodes, Datadog or Grafana Cloud for managed metrics. Alerts on: node is 10+ blocks behind, RPC latency >500ms, subgraph lag >100 blocks.

Uptime: Better Uptime or PagerDuty on RPC endpoint and subgraph health endpoint (The Graph provides _meta { hasIndexingErrors, block { number } }).

Why Is Monitoring Without Tenderly Insufficient?

Tenderly provides transaction simulation and detailed traces — critical for debugging subgraph and smart contract errors. Forta focuses on network anomalies, not your infrastructure. The combination of Tenderly plus a custom Grafana dashboard covers 90% of incident scenarios.

Multichain Infrastructure

A protocol on 5 chains = 5 separate RPC endpoints, 5 subgraphs, 5 monitoring configs. Manageable but requires deployment automation.

For subgraph multi-network deployment: graph deploy --network mainnet, graph deploy --network arbitrum-one etc. with a unified codebase and network-specific addresses in separate config files.

Chainlink CCIP and LayerZero for cross-chain messaging require monitoring of both chains and transactions on intermediate relayers. A reorg on the source chain after a confirmed mint on the target chain is a classic bridge problem. Solution: wait for finality (on Ethereum ~15 minutes after Merge for economic finality) before confirming on the target chain.

Infrastructure Setup Process

  1. Audit current stack — determine chains, request volume, latency and availability requirements.
  2. Architecture design — select providers, load balancing, redundancy.
  3. Subgraph development — manifest → schema → handlers → testing on local Graph Node → deploy to testnet → mainnet.
  4. Monitoring configuration — Tenderly alerts, Grafana dashboard, PagerDuty integration.
  5. Documentation and runbook — what to do when: subgraph falls behind, RPC downtime, node desync.
  6. Handover to operations — team training, access transfer, first month support.

What's Included

  • Deployment of managed or self-hosted Ethereum, Polygon, BNB Chain nodes
  • RPC layer setup with primary/fallback and load balancing
  • Subgraph development and deployment for your protocol
  • Monitoring connection (Tenderly, Grafana, alerts)
  • Runbook and operations documentation
  • Team training (up to 4 hours online)
  • 30-day support after delivery

Timeline

Task Duration
RPC and basic monitoring setup 1–2 weeks
Subgraph for one protocol 2–4 weeks
Self-hosted node with monitoring 2–3 weeks
Full infrastructure (multi-chain, monitoring, runbooks) 6–10 weeks

All projects are managed in a GitHub/GitLab repository with CI/CD; configuration code stays with you. Order infrastructure deployment — we'll show how to cut costs by 20–30% without losing reliability. Get a consultation — we'll demonstrate how we deployed infrastructure for a protocol with large TVL on Ethereum and Arbitrum. Contact us.