# Privy server wallets

> Privy's policies stay inside Privy and its transaction webhooks fire after broadcast, so the agent asks Immiscible before it sends.

Source: https://immiscible.fly.dev/docs/guides/privy

[Privy policies](https://docs.privy.io/controls/policies/overview) allow or deny wallet requests by method and condition. [Authorization keys and key quorums](https://docs.privy.io/controls/authorization-keys/keys/overview) decide who may make a request. [Transaction webhooks](https://docs.privy.io/wallets/gas-and-asset-management/assets/transaction-event-webhooks) report a transaction once it is broadcast, confirmed or failed.

**There is no outside approval call** before signing. A key quorum could include a key held by another service, but that service would then hold a key, which Immiscible does not.

## How to use them together

- The agent asks Immiscible first, through the SDK's `decideThenSign` or `decide_then_sign`, and sends only after an allow whose receipt covers the exact transfer. See [Crypto payments](https://immiscible.fly.dev/docs/guides/crypto-payments.md).
- As a backstop, a Privy policy can hold the same recipient addresses as the agent's crypto rule.
