Permissions
Looking for a practical guide to run nodes? Follow the Curated Module v2 guide or the CSM guide.
These modules combine caller-specific permissions for Node Operator management, committee-operated flows, Easy Track actions, and role-based controls for protocol administration.
Role assignments can be changed by governance, so the deployed contracts and their on-chain role membership are the source of truth. See the deployed addresses for CMv2 and CSM.
Node Operator permissions
Each Node Operator acts through two addresses set at creation, a manager address and a reward address. These actions are available in all of these modules:
- Add validator keys up to the configured
keysLimitand remove keys that have not been deposited. - Top up their bond independently of adding validator keys, and claim published rewards or available excess bond.
- Manage their manager and reward addresses and configure reward splits.
- Exit validators through a standard voluntary exit or request an EIP-7002 exit through
Ejector. After a withdrawal is reported, any bond that is no longer required can be claimed. - Compensate an active general delayed penalty from available excess bond.
Where they differ:
| CMv2 | CSM | |
|---|---|---|
| Joining | Through the CuratedGate for the operator type, with a valid Merkle proof. Each eligible address can use a given gate only once | Permissionlessly through PermissionlessGate, or through VettedGate for the ICS and IDVTC profiles |
| Key removal | No charge for key removal | A configurable keyRemovalCharge applies to each removed key |
| Manager permissions | Always enabled, so the manager is the Node Operator owner | Depend on whether extended manager permissions were enabled at creation |
| Name and description | Stored in MetaRegistry and updatable, unless metadata edits have been restricted | Not stored by the module |
In CMv2, creating a Node Operator does not make it eligible for deposits. The Curated Module Committee must add it to an operator group through Easy Track before it receives a stake allocation weight.
For the detailed manager and reward address permissions, see Roles for CMv2 and Operator Roles for CSM.
None of these permissions reach the validator private keys, which are created and held by the Node Operator alone. The modules store validator public keys and deposit signatures only.
Committee permissions
Each module has a committee with narrowly scoped operational permissions. These are the Curated Module Committee (CMC) and the Community Staking Module Committee.
Both committees can:
- Report and cancel general delayed penalties for protocol rule violations, and manage the associated additional fines.
- Initiate approved Easy Track flows, which are used to settle general delayed penalties, report slashed withdrawals, and update gate Merkle trees.
- Trigger emergency pauses for designated module contracts through CircuitBreaker.
In addition:
- The CMC can update Node Operator names and descriptions and restrict further metadata edits by the Node Operator owner, create or update operator groups and allocation shares, and pause an individual Curated Gate to stop new Node Operator creation for that type.
- The CSM Committee can assign or reset an existing bond curve for a Node Operator, and manage the default and per-curve key-removal charges.
Neither committee can upgrade contracts, grant itself additional roles, or resume paused contracts through these operational roles. The CMC additionally cannot change an existing Node Operator's bond curve or reset its manager or reward address.
Lido DAO governance permissions
Lido DAO governance acts through the Aragon Agent, which holds DEFAULT_ADMIN_ROLE on the main module contracts and is the proxy admin for upgradeable components. Through governance, it can:
- Upgrade proxy-based contracts or change their proxy administration.
- Pause and resume module contracts, effectively stopping or resuming the creation of new Node Operators, validator key uploads, and claims of rewards and excess bond.
- Grant and revoke contract roles, including operational roles that are unassigned by default.
- Use the emergency
OPERATOR_ADDRESSES_ADMIN_ROLEto forcibly reset a Node Operator's manager and reward addresses. - Create and modify bond curves, change the curve assigned to an existing Node Operator, and configure Node Operator type parameters. In CMv2 this also covers allocation weights.
- Change the module's stake-share limit and other configuration in the Staking Router.
- Manage Performance Oracle committee membership and quorum.
- Change administrative settings such as the bond-lock period, charge recipient, reward-rebate recipient, and the
Ejectorused byValidatorStrikes.
Holding DEFAULT_ADMIN_ROLE does not automatically grant each operational role. In the configured deployments, routine reporting, settlement, group management, oracle, and emergency actions are delegated to specialized actors.