Product · trust & control
Who did what, and who is allowed to.
Orla cannot move your money on its own. Everything below is how that holds up: the permissions, the second signature, the log that keeps the old value next to the new one.
Getting in
Password, Google, passkeys, Sign-In with Ethereum, and TOTP two-factor with ten single use recovery codes. Your last remaining sign-in method cannot be removed, so no setting can lock you out.
Devices, and a log of your own
Every signed-in device with its browser, OS, IP and last active time, revocable one by one. Under it, a security log of sign-ins, failed attempts and changes to your password, 2FA and passkeys. Orla emails you about all of them.
Roles that mean something
Owner, admin, member, viewer. Team pages and payment approvals show up in family and business spaces, inheritance only in family ones. In a personal space those pages say why they are empty. On Pro and Scale an owner can also tune twelve permissions per member on top of their role.
A seat for the bookkeeper
The accountant role reads the whole picture and keeps the paperwork: invoices, pay links, contacts, documents, and recording money that came in. It cannot post a transaction, propose or approve a payment, pay a bill, or touch accounts, team or settings. Everything it does lands in the log.
Accounts that are not everyone's business
Restrict an account and it disappears for everyone except the people you name, along with its balance and its operations. Their reports, net worth, goals, calendar and exports quietly cover only what they can see, and say so rather than pretending the number is complete.
A second signature, by rule
The owner sets an amount above which a payment needs co-signers, and can demand approval for any destination that is not in the address book. The proposer never counts toward their own quorum. Payments waiting on a signature sit on one page until someone signs or rejects them.
An activity log with the diff
Every action, with the old and new value on each edit. Bulk operations and syncs collapse into one row with a count, and anything the system did is labelled as such. Filter by area and date.
A document vault
Folders, versions, search, and sharing by member or by member only link. Receipts attach straight from a transaction, so the paperwork sits next to the money.
Inheritance, for when you are not there
In a family space the owner can set up inheritance: a regular check-in, and if the check-ins stop past the grace period, the listed heirs inherit access by their shares. It is slow on purpose. An inheritance that fires quickly is a lockout waiting to happen.
- Sign-in
- Password (12+) · Google · passkey · Ethereum wallet · TOTP
- Recovery codes
- 10, single-use, shown once, regenerable
- Roles
- Owner · admin · member · viewer · accountant
- Per-member permissions
- Twelve toggles on top of the role (Pro and Scale)
- Restricted accounts
- Hidden from everyone but the members you name
- Approvals
- N co-signers above an owner-set USD threshold
- Address-book mode
- Forces approval for destinations that are not saved contacts
- Activity log
- Field-level diffs, system rows labelled, filterable
- Documents
- Vault with folders, versions, search, member-link sharing
- Inheritance
- Family spaces: life-beat check-in, heirs by share
- Analytics
- One opt-out switch; never amounts, balances or contacts
Can Orla sign a transaction for me?
No. Wallet keys are encrypted in your browser and every send is signed there. Exchange connections are read-only. What Orla can do is refuse to broadcast something that failed your own approval rule.
What exactly does usage analytics record?
Which sections and features you use. It stays on Orla's servers, is never sold, and never includes amounts, balances or contacts. One switch in Settings turns it off.
What if I stop checking in and inheritance triggers by mistake?
There is a grace period after a missed check-in, and the owner sets it. It is slow on purpose, because an inheritance that fires quickly is a lockout waiting to happen.
What if I lose my two-factor device?
Sign in with one of the ten recovery codes you were shown when you turned 2FA on, then generate a fresh batch. Your last sign-in method cannot be removed, so nothing locks you out.
Who can read the activity log?
Owners and admins, in shared spaces. It keeps the old value beside the new one, and labels anything the system did rather than a person.
Set the threshold once.
Then let the rule argue instead of you.