Operations for web3 and crypto companies
Web3 companies are usually excellent at the part that is on chain and improvising everything else. The gap between the two is what fails diligence, and it is ordinary operations work to close.
In short
Web3 companies are usually excellent at the part that is on chain and improvising everything else. The entity structure has drifted from what the filings say, treasury is reconciled by one person from memory, contributors are onboarded in a Discord thread, and none of it survives contact with a serious counterparty. The fix is ordinary operations work, applied to a company that skipped it.
What we take on
Entity and good standing
Most of these companies run two or three entities across jurisdictions and can no longer say which one holds what. Registered agent, annual filings, foreign qualification and the calendar that keeps them current, owned by somebody rather than noticed when a letter arrives.
Treasury that reconciles
Fiat in one system, tokens in another, and a spreadsheet holding them together in one person head. One record, a reconciliation that runs on a rhythm, and every difference explained rather than defended.
Contributor operations
Contractors across eight time zones with no HR function behind them. Onboarding, access, offboarding and the paperwork that makes each of those defensible, written down once so it does not depend on whoever is awake.
Support and community
Discord is a support desk whether or not anybody decided that. Volume, routing, response times and what escalates, with the same discipline any other support function gets.
Diligence readiness
Exchanges, investors, banking partners and auditors all ask the same questions, and the answers live in six places. Getting them into one, before somebody asks, is worth more than any deck.
Process that survives a rule change
The regulatory answer moves. A process built around today one is a rebuild waiting to happen. Separating what the rule requires from how you satisfy it means only the second part changes.
Sophisticated on chain, a group chat everywhere else
There is a pattern in web3 companies that almost never appears elsewhere. The technical work is genuinely sophisticated, audited, versioned, tested against adversaries. The company running it is held together by a group chat and one person who remembers everything.
That gap is invisible while things are going well, because the people involved are capable and they absorb it personally. It becomes visible the moment a counterparty asks a normal question. Which entity signed this. Who approved that payment. Where is the record of the contractor agreement. What is your process when a wallet key holder leaves.
Filings are where it usually surfaces first. A company can be excellent at everything it considers its actual work and still fall out of good standing because nobody owned the calendar, and the state does not accept that as a reason. The remedy is unglamorous and it takes days, not months.
Treasury is the second. Holding both fiat and tokens means two systems that will never agree by themselves, and reconciliation is treated as a periodic emergency rather than a weekly habit. The businesses that get audited comfortably are the ones that made it boring.
Contributor operations is the third and the most personal. Paying people across borders, granting and removing access, and being able to show later that all of it was done properly. Access in particular tends to be granted generously and removed never, and that is a finding waiting to happen.
None of this is web3 expertise. It is ordinary operations work applied to a kind of company that skipped the part where somebody sets it up, usually because the first two years were spent shipping and the shipping mattered more. It is also fast to fix, because there is rarely legacy process in the way, only an absence of it.
Questions we get
Do you understand this space or is this generic operations advice?
I cofounded a Web3 platform, structured it as a Delaware public benefit corporation, and ran its entity, IRS and platform work end to end. So the answer is the specific one: I have filed the things, held the calendar and had the awkward conversation with a bank.
What that does not make me is a protocol engineer or a token lawyer, and the page is honest about where those lines sit.
Do you audit smart contracts?
No, and you should be wary of anyone who offers it alongside operations work. Contract auditing is a specialist security discipline with its own firms and its own track records.
What happens here is the operational layer around it: who can deploy, what the review step is before a deployment, how key holders are added and removed, and what the record shows afterwards.
Can you advise on token compliance or securities questions?
No. That is counsel, and it needs to be counsel who does this specific thing in your jurisdiction.
What is useful is the layer underneath: separating what the rule actually requires from how your company satisfies it, so that when the answer moves, and it will, only the second part gets rebuilt. Working alongside your counsel rather than instead of them is the whole point.
Our contributors are all contractors in different countries. Is that a problem?
It is normal and it is manageable, and it is usually the least documented part of the business.
The work is a written onboarding and offboarding path, an access list that is actually accurate, agreements that exist and are signed, and a payment process that does not depend on one person being online. None of that changes how you work, it just makes it provable.
We keep failing diligence on the boring questions. What fixes that?
Answering them before they are asked. Almost every counterparty asks the same set: entity chart, filings current, signing authority, payment approvals, contractor agreements, access control, incident history.
Assembling that once, and then keeping it current on a rhythm, converts a recurring scramble into a folder. Companies that do this close faster and negotiate better, because the other side stops discounting for uncertainty.
Do you take payment in crypto?
No. Engagements are invoiced and paid conventionally.
That is a deliberate choice rather than a judgment about your treasury. Introducing a volatile asset into a service relationship adds a variable neither side needs.
Our processes change constantly because the rules do. Is documenting them pointless?
The opposite, though it does change what you document. Writing down a procedure that assumes a specific rule is fragile. Writing down what the rule requires, separately from how you currently satisfy it, is durable.
When the requirement moves you rewrite one layer. Most companies write only the second layer, which is why every change feels like starting over.
We are small and moving fast. Will this slow us down?
It should not, and if it does the scope is wrong. The point is removing the things that stop being possible when one person is asleep, not adding approval to work that never needed it.
The test is whether the team can do more without asking anyone. If the answer after an engagement is no, it failed.
Can you work with a foundation or offshore entity in the structure?
Yes, and it is a common shape. What matters operationally is that the chart is written down, that each entity has a named owner for its obligations, and that intercompany arrangements are documented rather than understood.
Where a jurisdiction needs local counsel or a local agent, that gets brought in for that piece.
What does the first two weeks look like?
Mapping what exists: entities and their status, who holds what access, how money actually moves, and where the records live. Most of that comes from watching rather than from asking.
The output is a picture of the operation as it really runs and a ranked list of what to fix first. It is usually the first time anyone has seen the whole thing on one page.
More in the guides and every answer in one place.
Shaheer Shaikh, operations lead at LARVOL, a San Francisco AI company working with global pharma on clinical trial data and model benchmarking. Six Sigma on the process side, Anthropic certified on the Model Context Protocol, ten years across eight industries. More about the firm
Read next
The pieces this usually breaks into, and where each one is covered.