EVM chains via RelayUSDC · USDT · ETH
Don’t re-key thirty transfers.
Control one batch.
validate x route x approve x execute x reconcile
Sheaf lets finance teams prepare, approve, coordinate and reconcile many digital-asset payouts from one place. Every recipient is validated, routed, tracked and reconciled on its own. Private externally, transparent internally.

Most payout tools ask you to trust a button. Sheaf asks for a CSV, shows you every row, every route and every fee, waits for a second person to approve the exact set, and then executes one payment at a time with a record of everything.
Upload a CSV
Any row, any size
Drop the contractor CSV. It is parsed in a background thread and every row is checked for a valid checksummed address, an exact amount, duplicates and the right asset. Invalid rows are kept, explained and fixable in place, and the batch only moves on when every row is valid.
TemplateAliases10,000 rows
- Ada Okafor0x1b3f…9f0a1,250.00valid
- Mateo Ruiz0x9f0e…7f8e980.50valid
- K. Watanabe0x7a9b…5f243,200.00dup
- Priya N.0x3c4d…1c2d2,100.00valid
- Elias Berg0x2df0…9a70abcamount
Route and review
Approve the exact set
One route and one fee quote per recipient, labelled as estimates. The review screen lists totals, funding requirement, route readiness and unresolved warnings. An approver who did not edit the rows signs off on a hash of the exact recipient set. Change a row and the approval is void.
Fee estimateFour eyesHash-bound
- Recipients
- 16 valid · 0 invalid
- Total
- 24,396.89 USDC
- Est. fees
- $1.94 (estimate)
- Routes
- 16/16 ready
- Asset · network
- USDC · Base
- Funding req.
- 24,398.83 USDC
approver@northwind.example approved 16 recipients
set hash b2b0fe28…2ac382c · any edit voids this
Execute
One payment at a time
Funding is confirmed, then each payment becomes its own job with an idempotency key. Failures are isolated and classified; retries are explicit and never sent while a previous attempt is pending or unknown. Results land in reconciliation with references, fees and an export.
IdempotentRetriesExport
- Row 1Completed
- Row 2Completed
- Row 3Confirming
- Row 4Retry eligible
- Row 5Scheduled
- Row 6Completed
1 job per payment · idempotency keys · retries explicit
CSVTemplateHeader aliases
Upload one CSV. Not thirty transfers.
name x address x amount x reference
— 01 / 06 —
ValidateFix in place
Every row checked. Nothing dropped.
checksum x exact decimals x duplicates x asset
— 02 / 06 —
RouteFee estimate
One route per recipient. Fees shown.
quote x estimate x readiness
— 03 / 06 —
Four eyesHash-bound
Approval bound to the exact set.
hash of recipients x second person x void on edit
— 04 / 06 —
QueueRetries
Executed one at a time. Tracked one at a time.
idempotency key x bounded retries x no resend through unknown
— 05 / 06 —
ReconcileExportAudit
Reconciled, exported, audited.
references x fees x timestamps x simulated flag
— 06 / 06 —
What’s under the hood
CSV payroll imports
Template download, header aliases, files up to 10,000 rows parsed off the main thread so the page never freezes.
Open appRow-level validation
Checksum-aware address checks, exact decimal amounts, duplicate and asset detection, with a reason on every invalid row.
Open appOne route per payout
Every recipient gets a route, a quote, its attempts and a provider reference you can inspect and copy.
Open appHash-bound approvals
Approvals bind to a hash of the recipient set, record who and when, and are invalidated by any later change.
Open appExecution monitoring
Live progress, per-payment timelines and an activity feed of every state change, retry and failure.
Open appPartial failures
Completed payments stay completed. Failed ones are classified as retryable or final, with the provider's reason.
Open appReconciliation
Search, filter, mark matched or exception, and export a CSV with a simulated flag on every demo row.
Open appAudit trail
Original CSV, approvals, funding, attempts, downloads and exports are recorded with actor and time. Append-only.
Open app
Private externally · transparent internally
Who it’s for: finance teams that pay people.
Our position: honest privacy.
Settling on open rails.
The stack:
[ Relay ]

The routing layer in real mode. Each payout is quoted through Relay's public API and signed by your wallet. Relay sees every route; its request feed is public. That is documented, not hidden.
[ USDC on Base ]

The default asset and network. Same-chain routes are plain transfers with no external privacy benefit, which the review screen tells you before you approve.
[ Your treasury wallet ]

Funds never leave your control before you sign. The server holds no private key; it prepares steps, records hashes and polls status.
Bring your CSV
One header, five columns
Name, wallet address, amount, asset and an optional internal reference. Header aliases such as “wallet” or “amt” are recognised, amounts are parsed as exact decimals, and the template already carries the right columns.
name,address,amount,asset,reference
Public limits
- Rows per CSV10,000
- File size5 MB
- Route quotes50 / min on the public Relay API
- Retriesbounded per organisation, default 3
- Submission spacing0 to 30 minutes, off by default
- Rolesowner · finance · approver · viewer
Everything above is enforced on the server and documented in the docs.
In one line
Validate, route, approve, execute, reconcile. Every payout on its own.
Sign in to the demo workspace with seeded batches at every stage, or create your own organisation. No funds move in demo mode; every record is labelled simulated.








