A wallet holding 1,000 vault shares does not necessarily hold 1,000 units of the underlying asset. A share balance is one quantity; the amount of assets it represents is another. For an institution, ERC-4626 integration should preserve that distinction through transaction booking, valuation and withdrawal planning.
The standard makes the interface easier to integrate. It does not remove the need to inspect the deployed vault, its strategy or the meaning of the quantities it returns. An administrator should be able to explain where every number in the position report came from and what question that number answers.
Keep the share and the asset as separate records
ERC-4626 defines vault shares using ERC-20 and a single underlying ERC-20 asset. Shares represent a fraction of the vault's underlying holdings. The position record should therefore identify both contracts and their units rather than use one symbol and balance for the entire relationship.
A hypothetical vault share might represent 1.2 underlying tokens at an observation point. An investor holding 1,000 whole shares would then have an indicative exposure to 1,200 underlying tokens under that simplified relationship. The example assumes the stated conversion and does not determine the investor's actual executable withdrawal or financial-statement treatment.
Record the network, vault address, underlying asset address, raw share balance and metadata for each quantity. OpenZeppelin's ERC20 reference includes the vault implementation alongside other token contracts. Its presence in a shared library should not cause an integration to treat vault shares as ordinary underlying-token balances.
Shares and assets can use different scales. A reconciliation should compare raw share movements with raw asset movements, then convert each using its own approved metadata. A display that puts both under the heading units can conceal a scale error even when the arithmetic appears reasonable.
Conversion, preview and maximum answer different questions
The standard separates convertToAssets and convertToShares from operation-specific preview functions and maximum functions. Conversion functions describe an idealised relationship and exclude operation-specific fees; previews account for the specified operation's fees but do not enforce its limits. Maximum functions address how much the relevant operation permits. These distinctions are set out in the ERC-4626 specification.
The reporting model should not substitute one category for another. A conversion estimate can inform an exposure calculation. A withdrawal plan also needs the relevant limit and a check of the actual proposed operation. A positive preview alone does not establish that the position can be withdrawn in that quantity.
For a particular holder, record the share balance, conversion result, applicable maximum and operation preview at an identified state. Label them clearly. A dashboard number called redeemable assets should not be calculated from an ideal conversion alone if the intended meaning is what the holder can actually withdraw at that moment.
Refresh the state for an execution decision. A figure used at the previous reporting close may be appropriate historical evidence while being inappropriate for today's withdrawal. The distinction should remain visible in the user interface and in the supporting export.
Reconcile the transaction that actually occurred
A deposit instruction specifies assets and results in shares; a mint instruction specifies shares and requires assets. Withdraw and redeem reverse the relationship with different specified quantities. Book the actual executed quantities rather than copying an estimate from the request into the completed transaction record.
The transaction file should retain the intended operation, expected range, actual asset movement, actual share movement and any fees that the integration can substantiate. Where the result differs from the request preview, investigate the relevant state, fee and rounding assumptions. Do not assume every difference is earned yield.
The existing explanation of DeFi lending and vault yield addresses the economic sources of return. Share accounting is the operating layer beneath that analysis: it establishes what was deposited, which claim was received and what changed in the claim's asset representation.
Use both wallet movements and vault transaction evidence to avoid double counting. Depositing an underlying asset and receiving shares can replace one representation of a position with another. A consolidated exposure report should not report the transferred underlying asset as still independently held by the investor simply because it remains in the vault.
Review the vault's calculation, not just its interface
OpenZeppelin's ERC-4626 guide discusses rounding and inflation attacks involving changes in the asset-to-share relationship, including donations to a vault. The institutional lesson is to investigate a surprising conversion change rather than automatically classifying it as strategy performance.
Ask what totalAssets includes in this deployment and how the vault accounts for managed positions, fees and direct transfers. The institution needs the implementation and strategy evidence to interpret the result. A generic interface description cannot establish whether the observed value is a reliable basis for the intended reporting purpose.
If the conversion ratio jumps while shares remain unchanged, distinguish possible sources through evidence: a strategy result, fee adjustment, donation, accounting change or data error. These are investigative categories, not a claim that every vault behaves the same way. The report should state which explanation was supported.
Monitoring should include relevant implementation and configuration changes. A consistent share balance does not mean the calculation behind its asset representation has stayed constant. Tie the valuation adapter to the approved deployed implementation and review changes that affect the meaning of the returned values.
Carry liquidity separately from indicative value
A report can show an indicative asset equivalent and an available withdrawal quantity at the same time. A limit on withdrawal does not necessarily change the share quantity, but it matters to liquidity planning. The portfolio owner should receive both values with the observation time and any unresolved constraints.
For an exit instruction, consider the actual holder, spender authority, transaction route and required quantity. A withdrawal performed by another approved account may involve permissions that do not apply to a direct holder call. The execution plan should follow the deployment's supported path rather than infer it from a preview returned to another caller.
Do not equate the underlying token with cash in the institution's bank account. Even after a successful withdrawal, another conversion or redemption may be needed. A liquidity report should distinguish vault exit, possession of the underlying asset and availability of the ultimate settlement asset.
This distinction belongs beside digital asset fund administration and NAV. The chain supplies quantities and observations. The administrator must apply an approved valuation method and reporting policy, including treatment of restrictions and uncertainty.
Use consistent state for the close
Pin share balances, asset metadata and selected conversion reads to the reporting state where the provider supports it. Retain the block reference and raw results. Calling latest repeatedly can mix observations made before and after a deposit, fee update or other activity.
Reconcile opening shares, deposits or mints, transfers, withdrawals or redemptions and closing shares. Separately explain changes in the asset equivalent. A ratio increase can change the latter without changing the former. Combining both in one net movement column makes the source of the change difficult to inspect.
If the vault adapter cannot reproduce a historical conversion, record that limitation. It should not fill the gap with today's conversion and label the result historical. A reporting close needs evidence tied to the period being measured, with any estimation method and review clearly stated.
Third-party statements should disclose whether they report share quantity, asset equivalent or a reporting-currency value. Obtain the conversion basis and observation time when reconciling them with internal books. Matching a number without matching its definition can produce apparent agreement between records that measure different positions.
Give unresolved conversion differences a case owner rather than a generic tolerance.
Test a complete lifecycle before relying on the report
An integration test should run a deposit, transfer of shares where permitted, partial exit and final reconciliation. Include fee-bearing operations, quantities near a rounding boundary and a limit that prevents the requested withdrawal. The model should show why the preview, permitted amount and actual result differ.
Also test an increase in managed assets with no new shares, and an unexplained ratio change. The first should not be booked as a new deposit by the holder. The second should enter the exception process until the team establishes its cause. These tests examine whether the report understands the position rather than merely displaying contract outputs.
The close should leave a reviewer with four distinct answers: how many shares the institution holds, which asset they reference, what conversion evidence supports the report and what the holder can withdraw under the relevant conditions. The ERC-4626 interface supplies useful tools. Accurate institutional accounting depends on using each for its stated purpose.