privacy · proofs · compute
v3.2 · checksummed

§6. The Triad and the Monetary Candidate

v3.1
Cite this section

Copy/paste (plain text):

Jason St George. "§6. The Triad and the Monetary Candidate" in Next Generation Stores of Value: Privacy, Proofs, Compute. Version v3.1. /v/3.1/read/part-ii/6-triad-as-monetary-base/

The Triad and the Monetary Candidate

Traditional monetary regimes pick a base reality and build promises on top of it:

  • Gold: geology + metallurgy.

  • Fiat: law, taxation, and war.

  • Bitcoin: thermodynamics and code.

Each regime implicitly answers two questions:

  1. What counts as real work?

  2. What object or capacity will we treat as the canonical memory of that work?

In a civilization where intelligence is largely machine-executed and verification can be cheap and public, the answer shifts: work is what machines can do and humans can verify cheaply, and the “object” that records that work no longer has to be a metal or a pure ledger entry. It can be a capacity.

This thesis treats three capacities as monetary primitives:

  • Privacy: censorship-resistant settlement that preserves agency.

  • Proofs: portable attestations of computation and provenance.

  • Compute: useful work wrapped in succinct guarantees.

Each is:

  • Indispensable in a dense digital economy (no safe commerce without privacy; no safe coordination without proofs; no AI without compute).

  • Verifiably scarce at any point in time (bandwidth, cycles, proof capacity are bounded by physics and capital).

  • Cheap to verify (you can check whether you have privacy, a valid proof, or a verified FLOP without trusting a platform).

The physical and service base in this frame is the networked capacity to deliver Privacy, Proofs, and Compute under adversarial conditions. It is not itself money. Those services may support an associated bearer base asset as a conditional monetary candidate only if all nine links pass; Work Credits remain typed claims on service or capacity.

A few distinctions help:

Services vs. instruments:
DVC measures how much verifiable Privacy/Proofs/Compute per unit time the stack can deliver at target SLOs. Work Credits slice specified service capacity into transferable claims; staking and LP positions are derivatives or operating claims; the separate base asset is the only monetary candidate.

Nominal vs. real:
Nominal pricing of the triad will oscillate in terms of fiat and BTC. Real value is “does this capacity still buy me censorship-resistant settlement, proofs, and verified FLOPs when repression and AI get worse?”

Symbol vs. utility:
Gold and BTC partly trade as symbols. The triad trades as plumbing: “can I still pay people, prove things, and run intelligence without asking permission?”

For the associated base asset, recurring service demand is necessary but insufficient:

  • Treasuries and individuals purchase private settlement to escape surveillance and yield-curve control.

  • Platforms, enterprises, and states purchase proofs to secure provenance, compliance, and audit trails in an AI-polluted information environment.

  • AI labs, agents, and applications purchase verified compute to sell trustworthy services.

The claim is not that the triad services behave like a reserve asset. “Private Money” and “AI Money” are analytical lenses on settlement and compute demand. Monetary premium, if any, belongs to the associated base asset after deliverability, non-bypassability, holder quality, and the remaining chain conditions pass.

The Conditional Chain, End to End

§0: Introduction promised that the thesis would establish its claim through a conditional chain rather than an assertion. That chain is defended link by link across six Parts, which makes it easy to lose. This section walks it once, in one place, and says where each link is argued and what would sever it.

Utility demand \rightarrow standardized work \rightarrow receipts \rightarrow stress-deliverable service \rightarrow markets \rightarrow fee flows \rightarrow a scarce asset (only under non-bypassable accrual) \rightarrow a persistent, self-custodied, loss-bearing, regime-responsive holder constituency \rightarrow a possible store-of-value premium.

Every arrow is a conditional. None is asserted as inevitable, and the chain is only as strong as its weakest link—which is why we name the weak ones explicitly at the end rather than leaving the reader to find them.

  1. Utility demand exists and persists. A dense, synthetic-media, AI-mediated economy must keep buying private settlement, portable attestations, and verified compute through every cycle—including, and especially, under financial repression (§2: The World Forces New Monetary Primitives, §7: Privacy as Private Money, §8: Proofs as Attestation Money, §9: Compute Through the “AI Money” Lens).

    Severed if: the demand turns out to be cyclical discretionary spend rather than structural necessity.

  2. Demand standardizes into canonical work. Diffuse demand becomes an economic unit only when workloads are specified precisely enough that two providers are selling the same thing—canonical workload registries, hardware profiles, and SLA tiers (§19: Layer 4: Truth & Work).

    Severed if: workloads stay bespoke, so no fungible unit forms and there is nothing to price.

  3. Work produces cheap-to-check receipts. Standardized work emits portable artifacts—PIDL receipts binding claim, proof, workload ID, tier, and timestamps—and verification stays far cheaper than production, r(W)=v(W)/p(W)1r(W) = v(W)/p(W) \ll 1 (§19: Layer 4: Truth & Work, Appendix A: Formal Model of Verification Asymmetry & VerifyPrice).

    Severed if: verification cost creeps toward production cost, at which point “anyone can verify” collapses into “trust the prover.” This is Red Line 1, the hinge (§27: Risk Analysis & Failure Modes).

  4. Receipts represent stress-deliverable service. A receipt is evidence, not capacity. For each disruption scenario, Delivered Verified Capacity traces the full path from energy and fuel through firm power, switchgear, cooling, hardware, network, workload, proof, verification, settlement, and usable service; issuance is bounded by the surviving max flow and active minimum cut (§14: Layer 0: Verifiable Machines & Energy).

    Severed if: gross installed capacity or benign-state output materially exceeds the service that survives substitution latency and common-cause failure.

  5. Receipts enable markets. Cheaply checkable receipts over deliverable service let strangers transact without trusting each other: proof factories, neutral routers, SLA escrow and slashing, and procurement of proofs and verified FLOPs as spot or forward capacity (§19: Layer 4: Truth & Work, §21: The Modular Stack).

    Severed if: routers, provers, or matching engines capture the market and rent replaces work—Red Line 3 territory.

  6. Markets produce fee flows. Working markets generate recurring, measurable revenue rather than one-off grants or subsidies, visible as fee-coverage ratios against the security budget (§19: Layer 4: Truth & Work, §23: Extended Telemetry).

    Severed if: fee coverage collapses and workload demand proves to be speculative rather than budgeted.

  7. Fee flows accrue to a scarce asset—only under non-bypassable rules. This is the load-bearing link and the one most theses skip. Utility does not become money by being useful. The §10: Work Credits: Energy-Anchored Claims states the five conditions: required fee medium, meaningful burn or retirement, staked collateral, disciplined issuance, and no bypass channel delivering equivalent service without touching the asset (§10: Work Credits: Energy-Anchored Claims, §10: Work Credits: Energy-Anchored Claims).

    Severed if: users obtain equivalent triad capacity through hyperscalers, stablecoins, or custodial APIs without the asset—Red Line 6 (§27: Risk Analysis & Failure Modes, §25: Operator & Investor Checklist).

  8. A monetary-risk warehouse forms. Gross native demand is not an anchor. A persistent, self-custodied, loss-bearing, regime-responsive constituency must retain balances, lengthen holding periods, and accumulate countercyclically rather than merely acquire fees just in time, recycle operator inventory, satisfy collateral rules, or hold wrappers (§23: Extended Telemetry).

    Severed if: native demand disappears into immediate sell-through, leverage, wrappers, or forced deleveraging during the very stress in which the asset is meant to preserve agency.

  9. A scarce, captured, anchored asset may earn a store-of-value premium. If the asset also remains liquid, neutral, verifiable, legally holdable, and agency-preserving, it can plausibly earn monetary premium (§31: Why a Base Asset Behind These Could Become Money, §13: SoV Evaluation Framework, §3: First Principles: What a SoV Must Survive). This final link, not fee accrual or gross demand, is where the premium is argued to live (§10: Work Credits: Energy-Anchored Claims).

    Severed if: any of the nine store-of-value requirements fails, or telemetry showing them is captured (Red Line 4).

The Chain Says Nothing About Price

Completing all nine links would establish only that the base asset is a defensible monetary candidate. It would not establish when, or with what volatility, price reflects that. Wrappers, leverage, dealer hedging, and allocation mandates can move price with no protocol use at all, in either direction (§10: Work Credits: Energy-Anchored Claims). The chain is measured on the protocol, capacity, and native-buyer boards; price is interpreted separately through VerifyFlow (§23: Extended Telemetry) and never cited as evidence for the chain.

The chain rests on something beneath it.

Links 2 through 6 consume bulk power, and link 3—the verification hinge—is denominated in real resources on reference hardware. That makes the chain dependent on conditions that states partly set: energy availability and pricing, the obtainability of unprivileged reference hardware, and the continuity of every conversion edge through usable service (§4: Threat Model, §14: Layer 0: Verifiable Machines & Energy). Sovereign Optionality measures pathway diversity; Delivered Verified Capacity measures surviving flow. The chain is not suspended in mathematics; it is bolted to a grid and held on balance sheets.

Where the chain is weakest.

Honest accounting rather than uniform confidence:

LinkStrengthWhy
Utility demandStrongStructural drivers are already observable
Standardized workMediumPoUW constructions are a research direction, not a shipping monetary base
ReceiptsStrongStructurally well specified; VerifyPrice makes it measurable
Stress-deliverable serviceMediumScenario max-flow/min-cut and common-cause data are specified but not yet demonstrated at scale
MarketsMediumMarket microstructure for proof and compute capacity is the least developed part of the design
Fee flows to assetStrongFormalized as a lemma with public boards—but establishes cash-flow accrual, not monetary premium (§10: Work Credits: Energy-Anchored Claims)
Non-bypassabilityMediumWritten as a binary; the economics requires a magnitude (Δ\Delta) that is nowhere estimated (§10: Work Credits: Energy-Anchored Claims)
Native holder anchorMediumTransactional, collateral, and wrapper demand do not establish countercyclical loss-bearing capacity
SoV premiumMedium (conditional)Nine requirements, eighteen red lines; premium derives from link 9 plus state-contingency, not from fee accrual (§10: Work Credits: Energy-Anchored Claims)

Link-by-link strength of the conditional chain. Six links remain Medium or Medium (conditional): standardized work and market formation are engineering-maturity risks; stress-deliverable service is a physical-topology and common-cause risk; non-bypassability is an unmeasured magnitude; the native holder anchor is an unproven risk warehouse; and monetary premium remains conditional on the entire chain.

The medium ratings are the point.

Non-bypassability is a magnitude: bypass is never impossible, only priced, and the marginal buyer’s willingness to pay for the protocol’s differential properties has not been estimated. Delivered service is not nameplate capacity: substitution latency and common-cause cuts can erase apparently diverse supply. Holder demand is not risk absorption: fee purchases, burns, collateral, and wrappers can coexist with no constituency willing to own the asset through a drawdown. The premium, if it exists, comes from link 9 together with the state-contingency of differential value (§10: Work Credits: Energy-Anchored Claims). Ratings that go up are self-congratulation; ratings that identify the unmeasured bridges carry information.

The rest of this Part defends links 7 through 9, where the monetary argument actually lives. Parts III and IV defend links 2 through 6 by building and measuring the stack that supplies them. Parts V and VI make every link falsifiable.

Topological Scarcity and the Pressure–Capacity Corridor

Topological Scarcity Lemma

A nominal stock of resources, capital, or capacity does not secure a monetary service. The relevant quantity is the stress-deliverable flow through the narrowest non-substitutable edge connecting input to holder utility.

Aggregate abundance and local scarcity can therefore coexist without contradiction. Crude is not diesel when refining is the minimum cut; savings are not duration absorption when no balance sheet can hold DV01; installed accelerators are not verified service when power, cooling, firmware, connectivity, verification, or settlement fails. The topology—the transformation path, location, actor, and horizon—determines the service.

The physical-conversion example is adapted selectively from Doomberg’s Endangered Specious [Doomberg 2026b]; the duration-absorption example from Michael Green’s Anchors Aweigh, My Boys [Green 2026b]. Both are analyst commentary used for mechanism rather than quantities. The lemma and its application to verified service are ours.

Let RR denote regime pressure, Δ(R)\Delta(R) the holder’s differential value over the best institutional substitute, Afull\mboxstack(R)A_{\mathrm{full\mbox{-}stack}}(R) the availability of the complete service path under that pressure, and H(R)H(R) the holder’s practical ability to self-custody, transact, prove, and exit. The monetary service scales with the product of the three, on the product-form premise

Πmonetary(R)    Δ(R)×Afull\mboxstack(R)×H(R).\Pi_{\mathrm{monetary}}(R) \;\propto\; \Delta(R)\times A_{\mathrm{full\mbox{-}stack}}(R)\times H(R).

This is the Pressure–Capacity Corridor. Its likely shape is an inverted U, not a crisis escalator. At low pressure, courts, custodians, and indemnitors work, so Δ\Delta is thin. At moderate pressure, substitutes weaken while the open stack and holder remain operational, so differential value can rise. At extreme physical or political pressure, power, networks, hardware, liquidity, custody, or exit may fail and the service falls with them. More crisis does not imply more premium.

The Triad Coherence Test

Privacy settlement, portable proof, and verified compute are different goods with different users, bottlenecks, collateral needs, political risks, and duration warehouses. A common asset is justified only if shared security, settlement, liquidity, and transaction-cost benefits exceed cross-subsidy, governance, and wrong-way-risk costs.

ArchitectureStrengthBurden of proof
A: One native monetary assetStrongest direct value capture and shared liquidityGreatest reflexivity, governance scope, and cross-domain collateral risk
B: Neutral reserve plus service-specific creditsClean separation between reserve money and typed service claimsWeaker new-token capture; requires interoperable settlement and independent credit markets
C: Shared settlement plus modular domain collateralCommon payment rail with service-specific risk containmentMore operational complexity; collateral fragmentation and bridge governance must remain legible

Triad architectures under test; none is pre-selected.

For each architecture ask: Do the services share a security budget and users? Does demand for one improve the economics of the others? Are bottlenecks complementary or correlated? Does common settlement reduce transaction costs more than it creates cross-subsidy? Can one constitution credibly govern all three? Does one service dominate issuance, fees, or political risk? Architecture A is a candidate, not the thesis.

Monetary Objects and Value Capture

The thesis claims that triad capacity can earn a “durable store-of-value premium.” For that claim to be testable, we must answer four questions without poetry:

  1. What exactly is the asset?

  2. What do users pay in?

  3. How does holding capture value?

  4. Why doesn’t value leak entirely to operators?

Question 1: What is the asset?

The triad stack can issue several kinds of holdable instruments:

InstrumentWhat It RepresentsScarce?Transfer?SoV?
Base AssetConditional bearer monetary candidate; fee and settlement unitYesYesCandidate only
Work CreditsTyped capacity or service claims, bounded by deliverable outputYesYesNot presumed
FCR/FER/PIDL artifactsEvidence of physical conditions or completed workNoYesNo
Project NotesExplicit duration-bearing infrastructure creditYesYesNo
LP/StakingRights to fee share from corridors, pools, validatorsYesSometimesDerivative
Capacity VouchersPrepaid access at fixed ratesNoYesNo

Instrument hierarchy. Utility, evidence, credit, derivatives, and the conditional monetary candidate remain distinct.

The base asset is only a conditional monetary candidate: the unit in which fees may be paid, burns may occur, and collateral may be posted. Work Credits can be valuable, transferable, workload-specific, location-specific, SLA-specific, and temporally perishable without becoming savings instruments. FCRs, FERs, and PIDL receipts are evidence; project notes warehouse duration and bear default risk; LP and staking positions are derivatives or operating claims.

A terminology contract.

This thesis uses two distinct words that are easily confused, and the distinction carries real analytical weight:

  • Native instruments are protocol-internal claims: the base asset, typed Work Credits, staking and LP positions, corridor claims, capacity vouchers, and evidence artifacts. They touch the protocol, but only the base asset is evaluated as a monetary candidate.

  • External financial wrappers are conventional market products written on the asset: spot ETFs, exchange-traded products, treasury companies, custodial balances, futures, options, swaps, and leveraged or inverse ETPs. They do not touch the protocol. Holding them exercises nothing.

Both are sometimes called “wrappers” in casual usage. From here forward, “wrapper” without qualification means an external financial wrapper. The full object hierarchy runs from physical capacity out to recursive financial claims, and monetary treatment differs sharply along it.

Object layerExampleTouches protocol?Path dependenceMonetary treatment
Service capacityPrivacy, proof, compute throughputYesNoNon-monetary input measured by DVC
Typed service claimWork Credit / capacity voucherYesMediumNot presumed money or SoV
Native monetary objectBase assetYesLowConditional SoV candidate
Native derivativeStaking or LP sharesYesMediumSecondary claim
Custodial claimExchange balance, spot ETF shareIndirectlyLow–mediumPrice exposure, not full monetary function
Synthetic wrapperFutures, swaps, optionsNoMedium–highFinancial exposure only
Daily-reset leveraged wrapper2×2\times / 3×3\times ETPNoExtremeTrading product; explicitly not SoV
Recursive wrapperLeveraged product on another wrapperNoExtreme, nonlinearSystemic-risk instrument

Object hierarchy from base capacity to recursive financial claims. Monetary properties do not survive the descent: a daily-reset leveraged wrapper cannot inherit the underlying asset’s store-of-value status, because its return depends on the path, not merely the endpoint (Appendix H: Formal Model of Market Realization, Wrapper Flows, and Price Capture).

How to read Questions 2–4.

The answers below are stated in the reference-design register: they specify routing rules — where fees go, what must be locked, what may not be inflated away. They are design commitments, not findings, and two things they deliberately do not do. They do not establish that the routed fee is large: that is the level question, taken up in §10: Work Credits: Energy-Anchored Claims, where the sustainable fee is bounded by differential value Δ\Delta rather than by anything in this section. And they do not establish that any of this is monetary premium rather than a cash-flow claim: §10: Work Credits: Energy-Anchored Claims withdraws exactly that reading, and §10: Work Credits: Energy-Anchored Claims relocates the monetary claim to a holder-side service flow. The percentages below are illustrative of a design space, not measurements of a market.

Question 2: What do users pay in?

In the reference design, all triad services are quoted and settled in the base asset:

  • Proofs: paid to provers in the base asset; a published share retired.

  • Privacy settlement: corridor fees paid in the base asset; a published share retired.

  • Verified compute: inference and MatMul paid in the base asset; a published share retired.

  • Staking/collateral: provers, routers, and LPs lock the base asset to participate.

This is a routing rule, not a demand theorem. It creates transactional demand only to the extent that users cannot route around it (Value-Capture Condition 1; Red Line 6), and even where they cannot, the demand it creates is for a medium of settlement held for seconds, not for a store of value held through a cycle. §10: Work Credits: Energy-Anchored Claims bounds what that toll can be, and §10: Work Credits: Energy-Anchored Claims names the incumbent that already routes around it. Nothing in this list is evidence of moneyness.

Question 3: How does holding capture value?

Fee value reaches holders through four routing channels. Each is a cash-flow or lockup mechanism; none is monetary premium, and the thesis says so at §10: Work Credits: Energy-Anchored Claims:

  1. Fee retirement (burn) (30–50% of fees): a pro-rata buyback. It reduces net issuance only when retired fees exceed scheduled issuance, which at early-phase fee coverage they will not; it is published as its own series and read as such.

  2. Staker yield (20–40% of fees): income for holders who stake — a dividend on a productive claim.

  3. Operator share (20–40% of fees): incentive for provers, routers, and LPs.

  4. Collateral requirements (10–20% of capacity value): immobilizes float and sets a valuation floor; §10: Work Credits: Energy-Anchored Claims shows why it is a floor and a slope effect rather than proportional accrual, and bounds the fixed dollar quantity it can lock.

The first three channels are a partition of one fee pool, not three independent receipts: burn share, staker yield, and operator share must sum to 100% of every fee collected. The bands above are alternative interior choices within that partition, not independent ranges, and any point allocation — such as Design A’s 40/30/30 split (§6: The Triad and the Monetary Candidate) — must close the identity. Reading the bands as additive would sum the maxima to 130% of the pool, which is not an allocation the design can make.

Question 4: Why doesn’t value leak entirely to operators?

The “utility token trap” occurs when operators capture all economic value while token holders merely provide exit liquidity. The routing rules are designed so that a positive fee, if one exists, does not leak entirely to operators:

  • Fee retirement: 30–50% of fees are retired pro rata to all holders — a buyback, with the accrual (not moneyness) reading §10: Work Credits: Energy-Anchored Claims gives it.

  • Staking yields: Passive holders can stake to earn fee share without operating infrastructure.

  • Collateral requirements: Operators must hold significant base-asset collateral, aligning their interests with holders.

  • Governance rights: Holders vote on fee splits, issuance changes, and protocol upgrades, within the constitutional constraints of §22: Layer 6: Governance & Telemetry.

  • Issuance constraints: Base-asset issuance follows the constitutional schedule and is independent of Work Credit dynamics; it is Work Credits that are minted only against verified capacity growth, with minting beyond real capacity triggering SLO breaches visible in dashboards.

Net effect, routing only: these rules route a fee of size fQf \cdot Q to retirement, staking, and operator share. Whether ff can be positive at all is a function of differential value Δ\Delta, not of routing; whether the routed revenue constitutes monetary premium is a separate question this Part takes up in §10: Work Credits: Energy-Anchored Claims and answers in the negative at §10: Work Credits: Energy-Anchored Claims.

Three Reference Designs

To make the thesis testable, we commit to three concrete designs. Implementations may vary, but at least one must be viable for the SoV claim to hold.

Design A: Base Token as SoV (Primary)
  • Issuance: Fixed schedule with halvings (like BTC) or capacity-linked ceiling.

  • Fee medium: All triad services priced in base token.

  • Burns: 40% of fees permanently destroyed (a point choice inside the 30–50% reference band).

  • Staking: 30% of fees to stakers; 10–15% collateral requirement.

  • Operators: 30% of fees to provers/routers/LPs.

  • Governance: Token-weighted voting on parameters.

SoV properties: Credible scarcity (capped + burns), native demand (fees), duration-neutral (no coupons), cheap verification (VerifyPrice dashboards).

Risk: If demand stalls, burns decline and scarcity weakens.

Design B: Work Credits as Capacity Vouchers (Hedge Instrument)
  • Issuance: Minted against verified work (FERs + proofs); no fixed cap.

  • Redemption: Burnable for priority access to proofs/compute/settlement at SLA-guaranteed rates.

  • Expiry: Credits decay or expire after NN years to prevent hoarding and bank-run dynamics.

  • Transferable: Yes, but primarily used for cost hedging, not long-term savings.

Use case: Enterprises hedge against compute cost spikes; treasuries lock in future settlement capacity.

Not a SoV: Supply expands with capacity; expiry prevents indefinite accumulation. This is infrastructure hedging, not a store of value.

Design C: Triad Index Token (SoV Candidate)
  • Backing: Diversified revenue streams across privacy corridors, proof pools, and compute markets.

  • Value capture: Protocol revenue used for periodic buyback-and-burn or dividend distribution.

  • Issuance: Fixed supply; no new minting after genesis.

  • Governance: Index holders vote on revenue allocation and rebalancing.

SoV properties: Diversified exposure to triad demand; fixed supply; yield via buybacks or dividends.

Risk: Concentration in specific corridors or proof markets; governance capture.

Which design does the thesis endorse?

None by default. These instrument designs sit inside the broader architecture comparison of §6: The Triad and the Monetary Candidate. A fixed-supply base token may be tested as the monetary candidate; capacity vouchers remain service hedges; an index token is a revenue-bearing security whose buybacks or dividends do not establish moneyness. The text uses “base asset” for the monetary candidate and “Work Credit” only for a typed capacity or service claim.

What actually differs, and who loses.

The three designs are not three shades of the same bet; each one moves the risk onto a different balance sheet. Design A concentrates it in the base asset: if demand stalls, burns decline, and the scarcity story thins with it — the holder discovers that a burn schedule is a claim on volume, not a property of the token. Design B pushes the risk onto the service buyer: capacity vouchers hedge compute cost beautifully until capacity is scarce in exactly the state the buyer hedged for, at which point delivery terms rather than price are the binding constraint, and the hedge is only as good as the stressed path behind it. Design C hands the risk to governance and to the revenue mix: an index token is a claim on whatever the protocol happens to earn, so concentration in particular corridors or proof markets is not a footnote to the thesis but the thesis, and buybacks do not convert a revenue stream into money (§10: Work Credits: Energy-Anchored Claims). Watch the same three numbers in all three cases — fee share actually paid in the native asset, net supply after burns, and the share of exposure sitting in wrappers (§10: Work Credits: Energy-Anchored Claims) — because §10: Work Credits: Energy-Anchored Claims takes up the question these boxes deliberately do not answer: not where the fee is routed, but whether there is a fee to route.

Tip: hover a heading to reveal its permalink symbol for copying.