# Turnkey

> Turnkey's policies and approvals stay inside Turnkey and its webhooks are notifications, so the agent asks Immiscible before it requests a signature.

Source: https://immiscible.fly.dev/docs/guides/turnkey

[Turnkey policies](https://docs.turnkey.com/concepts/policies/overview) allow or deny activities with an `effect`, a `consensus` (which users must approve) and a `condition` (for example on `eth.tx.to` or `eth.tx.value`). Approval comes from Turnkey users or a quorum, inside Turnkey. [Turnkey webhooks](https://docs.turnkey.com/features/webhooks/overview) report activity and balance updates after the fact.

**There is no outside approval call** a service like Immiscible could answer before signing.

## How to use them together

- The agent asks Immiscible first, through the SDK's `decideThenSign` or `decide_then_sign`, and requests the Turnkey signature only after an allow whose receipt covers the exact transfer. See [Crypto payments](https://immiscible.fly.dev/docs/guides/crypto-payments.md).
- As a backstop, write a Turnkey policy whose condition limits `eth.tx.to` to the addresses in the agent's crypto rule.
