[DRAFT] Endowment permissions to KPK Update #10

Abstract

This proposal is a routine update to the Endowment Manager permissions. It expands the Endowment’s access to real-world-asset (RWA) and fixed-income positions, adds a set of curated Morpho yield vaults and the Aave v3 Horizon market, enables Maple (Syrup) swap routing, and introduces a dedicated reward-claim role. No permissions are removed.

Motivation

The update continues the diversification of the Endowment’s stable and ETH allocations into vetted yield and fixed-income venues while keeping all activity within the Investment Policy Statement (IPS). New access covers fixed-yield principal tokens via Pendle, curated lending and yield vaults on Morpho (kpk, Steakhouse, Smokehouse, and Sentora), and the RLUSD market on Aave v3 Horizon. A separate Harvest role is introduced so that protocol reward claims can be executed with payouts forced to the Endowment safe, without granting broader permissions.

Specification

Additions

1. Token Approvals

Token Functions Allowed Mainnet Address
sUSDS approve 0xa3931d71877C0E7a3148CB7Eb4463524FEc27fbD
PT-sUSDS-26NOV2026 approve 0xdc169abe56461a2e0c034da431ac2a3ebf596094
PayPal USD (PYUSD) approve 0x6c3ea9036406852006290770BEdFcAbA0e23A0e8
Ripple USD (RLUSD) approve 0x8292Bb45bf1Ee4d140127049757C2E0fF06317eD

2. RWA and Fixed-Income Positions

Contract Functions Allowed Contract Address
Pendle Router V4 swapExactTokenForPt swapExactPtForToken redeemPyToToken 0x888888888889758F76e7103c6CbF23ABbF58F946
kpk Euler RWA Vault deposit withdraw redeem 0x2B47c128b35DDDcB66Ce2FA5B33c95314a7de245

3. Morpho Yield Vaults

Vault Functions Allowed Contract Address
kpk USDC Yield (Vault V2) deposit withdraw redeem 0xD5cCe260E7a755DDf0Fb9cdF06443d593AaeaA13
kpk ETH Yield (Vault V2) deposit withdraw redeem 0x5dbf760b4fd0cDdDe0366b33aEb338b2A6d77725
Steakhouse High Yield USDC deposit withdraw redeem 0xbeeff7aE5E00Aae3Db302e4B0d8C883810a58100
Smokehouse USDC deposit withdraw redeem 0xBEeFFF209270748ddd194831b3fa287a5386f5bC
Sentora PYUSD Main deposit withdraw redeem 0xb576765fB15505433aF24FEe2c0325895C559FB2
Sentora RLUSD Main deposit withdraw redeem 0x6dC58a0FdfC8D694e571DC59B9A52EEEa780E6bf

4. Aave v3 Horizon Market

Contract Functions Allowed Contract Address
Aave v3 Horizon Pool (RLUSD) supply withdraw 0xAe05Cd22df81871bc7cC2a04BeCfb516bFe332C8

5. Swaps (CoW Protocol token lists)

Token Change Mainnet Address
syrupUSDC Add to sell and buy lists 0x80ac24aA929eaF5013f6436cdA2a7ba190f5Cc0b
syrupUSDT Add to sell and buy lists 0x356B8d89c1e1239Cbbb9dE4815c39A1474d5BA7D

6. Reward Claims (new Harvest role)

Distributor Functions Allowed Contract Address
Fluid Distributor claim 0x7060FE0Dd3E31be01EFAc6B28C8D38018fD163B0
Fluid GHO Distributor claim 0xF398E66B1273a34558AeBbEC550DccaF4AcC7714
Merkl Distributor claim 0x3Ef3D8bA38EBe18DB133cEc108f4D14CE00Dd9Ae

All token approvals are spender-pinned to the specific protocol contract they enable. A new Harvest role is created to isolate reward-claim permissions, with all claim payouts forced to the Endowment safe.

Removals

None in this update.

Reviewing the Permissions Policy

To review, the following resources are provided:

Considerations

All positions conform to the Endowment’s risk tolerance under the Investment Policy Statement (IPS). All venues in this update are permissionless; the Aave v3 Horizon RLUSD position is on the stablecoin supply side, which requires no onboarding or whitelisting, and no other position in this update carries an onboarding precondition.

Next Steps

The proposal will be introduced in the next meta-governance call. Pending review from Blockful and no revisions following discussion during the meta-governance call, this proposal will progress to an on-chain executable vote.