Choose one job
For example, a capped payment to a policy-defined recipient.
Put a sensitive function behind a Gatekeeper-only entrypoint or small adapter. Fix the target, recipient, asset, and limits wherever possible.
Keep each wallet confirmation understandable. Public setup and private delivery are separate stages.
For example, a capped payment to a policy-defined recipient.
Store target, selector, cap, expiry, and reuse mode in the public policy.
Approve only the required pass amount, pool fee, and fixed treasury budget.
The wallet deposits publicly, then privately delivers the one-unit note.
The issuer page shows the policy-defined recipient, fixed 0.01 STRK action, expiry, and both wallet confirmation stages.
Do not call the shielding or deposit step private: its address, token, and amount are public. The note transfer and ownership are the private portion handled by the compatible wallet.