# Two challenges with the current timelock-based operation

**URL:** <https://forum.openzeppelin.com/t/two-challenges-with-the-current-timelock-based-operation/34042>\
**Category:** Defender\
**Created:** [December 31, 2022, 12:15pm UTC](https://forum.openzeppelin.com/t/two-challenges-with-the-current-timelock-based-operation/34042 "2022-12-31T12:15:41Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![ZaK3939](https://sea2.discourse-cdn.com/flex022/user_avatar/forum.openzeppelin.com/zak3939/32/17313_2.png) [@ZaK3939](https://forum.openzeppelin.com/u/ZaK3939)\
**Post date:** [December 31, 2022, 12:15pm UTC](https://forum.openzeppelin.com/t/two-challenges-with-the-current-timelock-based-operation/34042/1 "2022-12-31T12:15:42Z")

</div>

Thank you for offering the wonderful service of Defender. I particularly think it is great that non-engineers can perform the timelock operation.

However, I think there are two challenges with the current timelock-based operation.

1. One is that if the timelock has the sole authority to upgrade the contract (in the case of multisig=\>timelock=\>target contract), it is not possible to upgrade the contract as described in the following tutorial without temporarily transferring authority to the multisig.

Ref.

> **[Upgrading a contract via a multisig - OpenZeppelin Docs](https://docs.openzeppelin.com/defender/guide-upgrades#upgrade-the-contract)**

1. The second challenge is that the SDK does not support the pattern of using a timelock as an intermediary in the "create proposal" function (only supports multisig =\> target contract). If this is not supported, it is very painful to create a timelock-mediated proposal because manual work is required.

Ref

> **[defender-admin-client](https://www.npmjs.com/package/defender-admin-client)**
>
> Defender Admin acts as an interface to manage your smart contract project through one or more secure multi-signature contracts. Defender Admin holds no control at all over your system, which is fully controlled by the keys of the signers.. Latest...

Please let me know if my understanding is incorrect.

---

<div class="post-metadata">

**Author:** ![ZaK3939](https://sea2.discourse-cdn.com/flex022/user_avatar/forum.openzeppelin.com/zak3939/32/17313_2.png) [@ZaK3939](https://forum.openzeppelin.com/u/ZaK3939)\
**Post date:** [December 31, 2022, 12:16pm UTC](https://forum.openzeppelin.com/t/two-challenges-with-the-current-timelock-based-operation/34042/2 "2022-12-31T12:16:14Z")

</div>

I also read these material  
([https://docs.openzeppelin.com/defender/admin#creating\_timelocked\_proposals](https://docs.openzeppelin.com/defender/admin#creating_timelocked_proposals))  
([https://github.com/OpenZeppelin/defender-client/blob/master/packages/admin/src/models/proposal.ts#L19](https://github.com/OpenZeppelin/defender-client/blob/master/packages/admin/src/models/proposal.ts#L19))
