# Navigation tour

The left sidebar groups the app into three sections. The items you see depend on your deployment features and permissions.

## KEYS

| Item | What it does |
|---|---|
| **Vaults** | Create and manage on-chain vaults, wallets, wallet security groups, and each vault's Signing Policy |
| **Offchain Keys** | Import, generate, version, rotate, freeze, and delete exchange or API keys; manage off-chain key security groups |
| **Signing Policies** | Open the Offchain policy or a vault's on-chain policy and manage its ordered signing rules |

Select **Vaults** to open the on-chain workspace. Select a vault to move between its **Wallets**, **Security Groups**, and **Signing Policy** tabs.

## ORGANIZATION

| Item | What it does |
|---|---|
| **Admin Policy** | Controls who can perform each administrative action and which vaults a rule covers |
| **Users & Groups** | Creates and manages groups, human users, and Machine Users & Agents |

## SYSTEM

| Item | What it does |
|---|---|
| **System Settings** | Enables or disables testnets and price-based Signing Policies across the deployment |
| **Venues** | Configures the signing scheme and encoding used for exchanges |
| **Audit Logs** | Filters and reviews administrative and signing events, including vault and wallet activity, and exports them to CSV |
| **Backup** | Opens the recovery-kit export dialog |

## How permissions affect the app

The app hides or disables actions that the current user cannot perform. For example:

* **Create New Vault** requires **Create Vaults**.
* Wallet management follows **Create & Manage Wallets/Keys** and can be limited to selected vaults.
* Signing Policy and security group management follows **Manage Signing Policies & Security Groups** and can be limited to selected vaults.
* **Edit settings** requires **Modify System Settings**.
* Audit viewing and export require **View & Export Audit Log**.

If an expected control is missing or disabled, ask an administrator to review your group assignments and the vault scope of the relevant Administrative Policy rule.

## Freeze controls

Emergency controls exist at several levels:

* Use **Freeze All Vaults** on the Vaults page to halt all on-chain wallet signing.
* Freeze selected vaults from the Vaults table.
* Freeze a vault or selected wallets from the vault detail page.
* Use **Freeze All Keys** on the Offchain Keys page to halt off-chain key signing.

Freeze and unfreeze are separate Administrative Policy capabilities. Each confirmation dialog shows the phrase you must type before the action runs.

## Account menu and passkeys

Your profile appears at the bottom of the sidebar. Use the account menu to open passkey management, add a passkey, or remove an existing one. See [Passkeys and account security](/guide/users-groups/passkeys-account-security).
