privacy · proofs · compute
v2.0 · checksummed

§22. Layer 6: Governance & Telemetry

v1.9
Cite this section

Copy/paste (plain text):

Jason St George. "§22. Layer 6: Governance & Telemetry" in Next Generation Stores of Value: Privacy, Proofs, Compute. Version v1.9. /v/1.9/read/part-v/22-layer-6/

Layer 6: Governance & Telemetry

Layer 6 is the control plane and the nervous system of the stack.

Everything below it—hardware, comms, distribution, identity, proofs, settlement—can drift, centralize, or quietly break without anyone noticing until it’s too late. Layer 6 refuses to let that drift remain invisible. It insists that:

  • Neutrality (no favored flows, no hidden house edge),

  • Repression-resilience (still works under capital controls and censorship), and

  • Verification economics (VerifyPrice, VerifyReach, VerifySettle)

are service-level objectives (SLOs), not marketing copy.

“No Dashboards, No Trust”: Public SLOs as Constitution

Most protocols ship documents called “constitutions.” In practice, the real constitution is whatever you cannot silently violate without getting caught.

For this stack, the constitution is:

  • a set of SLOs on triad capacity and neutrality, plus

  • a set of dashboards and receipts that make violations obvious.

Examples:

  • “p95 VerifyPrice for canonical workloads stays below TT seconds on commodity hardware.”

  • “Top-N prover/LP/router share remains below X%X\% by hashpower/FLOPs/liquidity.”

  • “BTC\leftrightarrowZEC/XMR corridors achieve 95%\geq 95\% success with 100% refund safety.”

  • “At least KK distinct jurisdictions and hardware profiles are actively verifying.”

These are not just operational goals; they are the monetary invariants. Layer 6’s first job is to publish and maintain these SLOs as public contracts.

Control Surfaces: Parameters, Upgrades, Emergency Powers

The second job of Layer 6 is to define the control surfaces: the knobs that can be turned, by whom, and with what receipts.

Economic Parameters:
  • Block reward curves and Work Credit issuance schedules.

  • Fee policies (floor, burn, split between security and dividends).

  • PoUW weighting across workloads.

Technical Parameters:
  • Circuit versions and proof-system parameters.

  • Accepted hardware profiles (additions, deprecations).

  • Corridor policies (timelocks, refund windows, anonymity thresholds).

Operational Parameters:
  • Telemetry granularity and reporting requirements.

  • Incident severity levels and response playbooks.

  • Key ceremonies and quorum sizes.

For each surface, Layer 6 specifies: (1) who can propose a change, (2) who can ratify it, (3) what data must be presented, (4) what delays and rollback mechanisms exist, and (5) which changes are “emergency powers.”

Bell-Labs-Style R&D vs. On-Chain Governance vs. Off-Chain Norms

There are three governance “forces” that need to be reconciled:

  1. Bell-Labs-style R&D. A research org with autonomy to explore new circuits, proof systems, hardware profiles, and corridor designs.

  2. On-chain governance. Token- or Work-Credit-weighted voting, parameter changes baked into protocol logic.

  3. Off-chain norms and institutions. Foundations, labs, dev collectives, and community norms.

Layer 6’s thesis is not “pick one.” It is:

Use Bell-Labs-style R&D to discover, on-chain governance to ratify and constrain, and off-chain norms to fill the gaps—but keep all three under telemetry.

Concretely:

The R&D lab:
  • Maintains public roadmaps and risk registers.

  • Publishes upgrade proposals with quantified impacts on VerifyPrice, VerifyReach, VerifySettle, decentralization, and hardware profiles.

  • Runs testnets and shadow deployments.

On-chain governance:
  • Controls scarce resources: issuance, reward splits, canonical workloads, acceptance/deprecation of proof systems and hardware profiles.

  • Is bounded by constitutional SLOs: certain changes are simply not allowed if they push metrics beyond thresholds unless higher-order safety processes trigger.

Off-chain institutions:
  • Operate under public charters that explicitly state their mandate and constraints.

  • Are expected to publish minutes, risk assessments, and incident reports.

This three-body system is inherently unstable; Layer 6 keeps it from drifting into pure plutocracy or pure priesthood by insisting that all three bodies are visible in telemetry:

  • Changes in code and parameters appear on-chain.

  • Lab work appears in open repos and benchmarks.

  • Institutional decisions appear in charters, public calls, and reports.

No dark corners; no “just trust us, we’re the stewards.”

Governance Capture Risk

Token-weighted governance creates capture risk: large holders can centralize control over issuance, fee routing, and telemetry rules. The stack mitigates this through hard constitutional constraints that governance cannot override (see §22: Layer 6: Governance & Telemetry), timelocks on parameter changes, independent measurement infrastructure, and non-governable red lines (§27: Risk Analysis & Failure Modes). If governance can alter issuance, fee routing, or telemetry rules without hard constraints, this is itself a red line.

Governance as SLOs: The Five Invariants

Governance and operations exist to keep one invariant true under stress:

Pay the machine only for work anyone can verify cheaply—and give humans lawful privacy by default.

Everything below—roles, metrics, runbooks, and legal posture—turns that sentence into procedures, with receipts. Where policy pressure rises, we default to measurement and non-custodial design rather than new gatekeepers. “No dashboards, no trust” is not a slogan; it is the rule for deciding when the system is still safe to treat as money.

Governance and operations are about what happens when the world pushes back. They are the difference between a beautiful mechanism that works in a friendly lab and an actual monetary substrate that survives YCC (yield-curve control), capital controls, app-store bans, and “secure enclave” mandates.

We can summarize the protocol’s “constitution” as five invariants:

  1. Verification asymmetry. For each canonical workload WW, verification stays much cheaper than production. Formally, the verification overhead r(W)=v(W)/p(W)r(W) = v(W)/p(W) remains at or below a published bound (e.g., 0.3, with a stretch goal of 0.1), and this is reported via VerifyPrice(W)(W) on the Proof & Compute Board. If r(W)r(W) drifts up or p95 verify times blow past targets, the economic hinge of the triad fails; this is a Sev-1 condition.

  2. Open admission. Anyone who brings correct work clears. Admission is not gated by identity, licensing, or proprietary hardware. Routers are neutral and open-source; house share and time-to-first-fill for new provers/LPs are visible on the Neutrality & Admission Board. If honest new entrants cannot join and get paid within a bounded window, decentralization is already drifting.

  3. Useful-work security budget. Block rewards and fees underwrite useful work—MatMul-PoUW, verified inference, provenance and settlement proofs—under explicit SLAs. The security budget is tied to canonical workloads with published VerifyPrice rather than to a puzzle with no external buyer. That is a deliberate trade and not a free improvement: a work function with a buyer has a demand curve somebody can move, which is the objectivity a buyerless hash puzzle gets for nothing (§30: Objections & Responses).

    Inference Verification Tiers and WC Eligibility: Under the “AI Money” analytical lens, inference Work Credits remain service claims. To prevent weak spot checks from being marketed as high-assurance verification, workloads are tiered by verification strength:

    TierVerification TypeWC Eligibility
    Tier ACryptographic (full ZK)Full eligibility (1.0×\times)
    Tier BProbabilistic (bounded error, audited)Discounted (0.6×\times)
    Tier CAttestation-only (TEE + sampling)Service market only; no WC issuance

    Inference verification tiers and WC eligibility.

    Rule: Only Tier A and Tier B verified inference is eligible for Work Credit issuance. Tier B issuance is discounted by a published “soundness haircut” reflecting error bounds and audit rate. Tier C can exist as a service market but is not collateral-grade—it represents trust in TEE vendors, which is exactly what the thesis aims to minimize.

  4. Lawful privacy by design. Settlement is neutral and non-custodial by default—adaptor-sig atomic swaps, shielded pools, privacy rails—but comes with viewing keys and auditable PIDL receipts so law-abiding users can evidence obligations without re-introducing chokepoints. The Settlement & Privacy Board reports swap success, refund safety, and anonymity-set health; flows that never touch custodians should still leave enough receipts that auditors can do their jobs.

  5. Verifiable machines at Layer 0. Canonical proving and attestation paths run on open designs with sampled supply chains; hardware attestation becomes one input to proofs, not a vendor priesthood. Hardware profiles, lot-sampling coverage, and profile incidents show up on the Hardware/Layer-0 panes of the boards.

These invariants are hard to change and easy to measure. Everything else—fee curves, circuit versions, work-function parameters, corridor lists—is configuration.

To keep configuration from degenerating into a governance circus, we tie changes to observable triggers instead of vibes:

  • If VerifyPrice p95 for a workload WW drifts above its target band for a sustained window, that workload’s circuit and parameters are queued for revision. Blocking the change requires an explicit override that cites alternative SLOs and appears in the governance log.

  • If entry latency for new provers/miners/LPs rises beyond a threshold, or the top-N share and house share breach caps, neutral routers automatically ratchet down house share and prioritize small bidders until the metric recovers.

  • If a swap corridor’s refund-safety ever falls below 100% in VerifySettle, that corridor is removed from admissible routes by default. Re-listing requires a synthetic regression suite to pass (including stress tests) plus a public post-mortem.

In this frame, “governance” does not micromanage every adjustment; it writes the SLOs and the triggers. Operations enforces them and publishes the receipts. Most changes are data-driven roll-forward: parameters evolve in response to Verify* drift, with clear before/after numbers.

To keep rule-making separate from rent-collection, we distinguish two broad roles:

  • A spec & telemetry steward that publishes ABIs, PIDL schemas, canonical workloads, hardware profiles, and the VerifyPrice/Reach/Settle dashboards. It does not run routers or take custody. Its mandate is to keep the bill of materials and metrics honest and up to date.

  • Market participants—miners, provers, routers, corridor LPs—who compete on price and reliability under those public SLOs, with SLA escrow and slashing keyed to PIDL receipts. Their incentives are economic; their constraints are the invariants and metrics.

This “two-chamber” structure keeps the job of defining rules and SLOs distinct from the job of selling capacity under those rules. It avoids the familiar pattern in which the entity that can edit parameters also happens to own the biggest fleet of nodes.

Governance as SLOs, not personality, is what lets the system answer policy pressure with dashboards and runbooks instead of press releases. When asked “how do you survive X?”, the right answer is not “trust the foundation,” but “look at this board, this trigger, and this incident playbook.”

Constitutional Enforcement

“SLO-bounded governance” is only credible if the enforcement mechanism is specified.

Machine-Enforced Constraints (Hard)

Certain invariants are enforced on-chain or in protocol code:

ConstraintEnforcement
Issuance cap per epochSmart contract rejects minting transactions exceeding cap
Corridor refund timeoutAtomic swap contracts enforce timeout
House-share capNeutral router contracts reject bids exceeding share
VerifyPrice bound violationWorkload suspended from WC eligibility

Machine-enforced constitutional constraints.

Override Path (Slow, Expensive)

Some constraints need flexibility. The override path is deliberately expensive:

  • Supermajority: 67%\geq 67\% of governance weight.

  • Long timelock: 30\geq 30 days (90 days for issuance-related).

  • Risk memo: Mandatory written analysis, hash anchored on-chain.

  • Sunset clause: Override auto-expires after 12 months.

Emergency Path (Narrow)

True emergencies (proof system break, active exploit) require faster action. The emergency path is narrow and auditable:

AllowedNot Allowed
Deprecate proof systemIncrease issuance
Delist corridorConfiscate user funds
Quarantine hardware profileBypass refund safety
Freeze workload classMint unbacked credits

Emergency path scope limitations.

Requirements: 3\geq 3 of 5 security signers; auto-expire in 7 days; postmortem within 14 days.

Reconciling the emergency path with Red Line 8.

§27: Risk Analysis & Failure Modes retires the thesis if governance can alter issuance, fee routing, or telemetry rules without hard constraints. Read carelessly, this path appears to grant exactly that: five signers on a seven-day fuse. The reconciliation is structural and worth stating as a constitutional rule rather than leaving to inference:

  • Emergency powers are subtractive only. Every allowed action removes or restricts a protocol claim (deprecate, delist, quarantine, freeze). No allowed action redirects value: no fee re-routing, no issuance change, no collateral-rule change, no telemetry amendment. A body that can only shrink the protocol cannot steal from it; the worst case is a smaller protocol, which is a survivable failure and the correct bias for a seven-day fuse.

  • Subtractive is not free. Quarantining a hardware profile concentrates verification (Red Line 3’s condition); freezing a workload class cuts its fee flows. Emergency use therefore carries its own falsification weight: emergency actions must be logged against the red-line conditions they aggravate, and repeated or routine use of subtractive powers — the “emergency governance becoming routine” failure named under Red Line 12 — trips Red Line 8’s spirit even though each individual action was constitutional. The test is not whether any single action was permitted but whether the emergency path has become a de facto governance channel.

  • Signers are named, accountable, and rotating. The five seats are filled by published charter, occupied by independent security researchers and operators (not the foundation, not the largest holders), subject to rotation, and removable by the standard override path. Anonymity of the signer set is itself a Red Line 4 telemetry failure.

Monetary Constitution

Issuance Envelope

Work Credit issuance is governed by:

  • Base schedule: Halving every NN blocks (e.g., 4-year halvings).

  • Capacity modulator: ±10%\pm 10\% based on verified capacity growth.

Capacity modulator formula:

Issuanceepoch=BaseScheduleepoch×(1+0.1×tanh(CapacityGrowthRateTargetGrowthRate))\text{Issuance}_{\text{epoch}} = \text{BaseSchedule}_{\text{epoch}} \times \left(1 + 0.1 \times \tanh(\text{CapacityGrowthRate} - \text{TargetGrowthRate})\right)
Fee Routing
DestinationShareMechanism
Capacity providers70%Paid via SLA escrow
Protocol burn20%Permanently removed
Assurance budget10%Funds sampling, audits, security

Fee routing split.

Why burn? Burn creates deflationary pressure tied to usage. High demand \to high fees \to high burn \to supply reduction \to value appreciation. This closes the loop between utility and asset value.

Cross-reference: This fee routing supports the §10: Work Credits: Energy-Anchored Claims from §6: The Triad and the Monetary Candidate. Its 20% burn is the same conservative variant used in the Layer 4 worked example (§19: Layer 4: Truth & Work) rather than the 30–50% reference band of §6: The Triad and the Monetary Candidate, because here the remaining 10% funds assurance. The burn component is what converts usage into scarcity; the assurance budget funds the Layer 0 sampling that keeps hardware claims credible. Changes to the fee split are governance parameters, but reducing the burn below 10% or eliminating it entirely would undermine the value-capture loop and should be treated as a constitutional constraint.

Retirement Rule

In addition to fee burn, base-asset units are retired in specific circumstances:

TriggerRetirement
Work Credit redemptionAny base-asset fee paid to fulfill the capacity claim is retired under the fee rule; the Work Credit itself is retired as a fulfilled service claim
Slashing100% of slashed collateral is burned (not redistributed)
Failed workloadsFees for failed proofs (prover fault) are burned, not paid

Base-asset and service-claim retirement triggers.

Risk Haircuts

Work Credits minted under weaker assurance levels receive discounted issuance:

FactorHaircutExample
Hardware profile (L0 grade)L0-A: 0.9×\times; L0-B: 1.0×\times; L0-C: 1.1×\times; L0-D: 1.2×\timesLower-assurance hardware earns fewer credits
Verification tierTier A: 1.0×\times; Tier B: 0.6×\times; Tier C: 0.3×\timesProbabilistic verification earns less than cryptographic
Prover concentration>>20% share: 0.9×\times; >>30%: 0.8×\timesConcentrated provers earn progressively less
FCR confidence gradeMissing/unverifiable FCR: issuance cap; low-confidence FCR: 0.85×\timesFacilities that cannot substantiate physical capacity claims earn fewer, capped credits
Sovereign optionality (Os\mathcal{O}_s)High band: 1.0×\times; moderate: 0.9×\times; low: 0.75×\times and issuance capFacilities whose physical capacity is fully substantiated but structurally fragile earn fewer credits

Risk haircuts for Work Credit issuance.

These haircuts are protocol parameters (not discretionary); they appear in dashboards and apply automatically.

Two distinct physical factors.

The last two rows look similar and do different work. The distinction matters enough to state explicitly, because collapsing them leaves a gap that a well-run fragile operator can walk through.

  • FCR confidence grade is epistemic. It asks whether we can see the physical substrate at all. It penalizes opacity.

  • Sovereign optionality is strategic. It asks whether what we can see is survivable. It penalizes fragility (§14: Layer 0: Verifiable Machines & Energy).

Without the second row, a facility that reports complete, signed, independently verified FCR data documenting a single interconnect, one fuel source, no backup duration, and a jurisdiction with an active rationing regime would receive no haircut whatsoever. It would in fact score well, because its disclosures are impeccable. Transparency about fragility is not the same as resilience, and an issuance schedule that rewards only the former is measuring candour rather than durability.

This is the operational form of the distinction drawn in §14: Layer 0: Verifiable Machines & Energy: verifiability and availability are separate properties, and Work Credit issuance should price both.

Interaction with the affordability hinge.

These haircuts must not become a back door for degrading verification cost. Per §14: Layer 0: Verifiable Machines & Energy, a resilience premium is acceptable only while benign-state Physical VerifyPrice stays inside its constitutional SLO band. If pursuing a higher Os\mathcal{O}_s band pushes a network’s verification cost outside that band, the SLO wins and the optionality target is deferred. Haircuts adjust issuance; they do not license breaching a constitutional target.

Coverage Target

The fee-coverage ratio measures what share of the security budget comes from fees vs. issuance:

FeeCoverage=FeeRevenue+BurnTotalSecurityBudget\text{FeeCoverage} = \frac{\text{FeeRevenue} + \text{Burn}}{\text{TotalSecurityBudget}}
TargetTimeline
FeeCoverage 30%\geq 30\%Year 1
FeeCoverage 50%\geq 50\%Year 3
FeeCoverage 80%\geq 80\%Year 5+

Fee coverage trajectory.

Why this matters: A system that relies entirely on issuance is inflating its way to security. A system where fees cover the budget has structural demand. The trajectory from issuance-funded to fee-funded is the path from “speculative token” to “productive asset.”

Value Capture Loop
+---------------------------------------------------------------+
|                    VALUE CAPTURE LOOP                         |
+---------------------------------------------------------------+
|  DEMAND (users need Privacy, Proofs, Compute)                 |
|    |                                                          |
|    v                                                          |
|  Users pay fees in the base asset for triad services         |
|    |                                                          |
|    +-- 70% -> Capacity providers (stakers hold base asset)    |
|    +-- 20% -> Burned (supply reduction)                       |
|    +-- 10% -> Assurance budget (sampling, audits)             |
|    |                                                          |
|    v                                                          |
|  Provers/routers must stake base asset as collateral          |
|    |                                                          |
|    v                                                          |
|  Issuance capped by schedule + capacity modulator             |
|    |                                                          |
|    v                                                          |
|  NET EFFECT: Demand -> Fees -> Burns + Staking -> Accrual     |
|  Monetary premium still requires holder and agency conditions |
+---------------------------------------------------------------+

Why demand doesn’t simply expand supply proportionally:

  1. Issuance cap is hard: Protocol enforces epoch-level cap regardless of demand.

  2. Burn is automatic: Higher demand \to higher fees \to higher burn \to lower net supply.

  3. Staking locks supply: More provers/routers \to more collateral locked \to less circulating supply.

  4. Haircuts constrain issuance: Weak verification or concentrated provers earn less, limiting supply growth.

This is the “bond indenture” that makes the SoV claim auditable, not asserted.

Tip: hover a heading to reveal its permalink symbol for copying.