§22. Layer 6: Governance & Telemetry
Copy/paste (plain text):
Jason St George. "§22. Layer 6: Governance & Telemetry" in Next Generation Stores of Value: Privacy, Proofs, Compute. Version v3.2. /v/3.2/read/part-v/22-layer-6/ Layer 6: Governance & Telemetry
Layer 6 is the control plane and the nervous system of the stack.
Everything below it—hardware, comms, distribution, identity, proofs, settlement—can drift, centralize, or quietly break without anyone noticing until it’s too late. Layer 6 refuses to let that drift remain invisible. It insists that:
-
Neutrality (no favored flows, no hidden house edge),
-
Repression-resilience (still works under capital controls and censorship), and
-
Verification economics (VerifyPrice, VerifyReach, VerifySettle)
are service-level objectives (SLOs), not marketing copy.
“No Dashboards, No Trust”: Public SLOs as Constitution
Most protocols ship documents called “constitutions.” In practice, the real constitution is whatever you cannot silently violate without getting caught.
For this stack, the constitution is:
-
a set of SLOs on triad capacity and neutrality, plus
-
a set of dashboards and receipts that make violations obvious.
Examples:
-
“p95 VerifyPrice for canonical workloads stays below seconds on commodity hardware.”
-
“Top-N prover/LP/router share remains below by hashpower/FLOPs/liquidity.”
-
“BTCXMR corridors achieve success with no protocol-attributable loss.”
-
“At least distinct jurisdictions and hardware profiles are actively verifying.”
These are not just operational goals; they are the monetary invariants. Layer 6’s first job is to publish and maintain these SLOs as public contracts.
Control Surfaces: Parameters, Upgrades, Emergency Powers
Every protocol has knobs. The question that decides whether it is a constitution or a clique is not which knobs exist but who can turn them, with what evidence, and how visible the turning is. The second job of Layer 6 is to inventory the control surfaces — to name the knobs, then bind each one to a proposer, a ratifier, a data requirement, a delay, and a rollback path. A knob that is not on this list is not governed; it is somebody’s private steering wheel.
The knobs come in three families. Economic parameters are the ones that touch money directly: block reward curves and Work Credit issuance schedules, fee policies (floor, burn, and the split between security and dividends), and PoUW weighting across workloads. Technical parameters shape what the network will accept: circuit versions and proof-system parameters, additions and deprecations to the accepted hardware profiles, and corridor policies such as timelocks, refund windows, and anonymity thresholds. Operational parameters govern the watching itself: telemetry granularity and reporting requirements, incident severity levels and response playbooks, and key ceremonies with their quorum sizes. The families differ in blast radius, which is exactly why they are enumerated separately rather than dumped into one list — issuance is not incident management, and pretending they are the same class of decision is how emergency powers leak into monetary policy.
For each surface, Layer 6 specifies: (1) who can propose a change, (2) who can ratify it, (3) what data must be presented, (4) what delays and rollback mechanisms exist, and (5) which changes are “emergency powers.”
Bell-Labs-Style R&D vs. On-Chain Governance vs. Off-Chain Norms
There are three governance “forces” that need to be reconciled:
-
Bell-Labs-style R&D. A research org with autonomy to explore new circuits, proof systems, hardware profiles, and corridor designs.
-
On-chain governance. Voting weighted by governance weight (defined in §22: Layer 6: Governance & Telemetry: time-locked base asset, never Work Credits), with parameter changes baked into protocol logic. Work Credits are excluded from the franchise deliberately: they retire on redemption, so a Work-Credit electorate would be a rolling census of whoever has not yet consumed their service, and a prover could vote with credits it minted against its own work that morning.
-
Off-chain norms and institutions. Foundations, labs, dev collectives, and community norms.
Layer 6’s thesis is not “pick one.” It is:
Use Bell-Labs-style R&D to discover, on-chain governance to ratify and constrain, and off-chain norms to fill the gaps—but keep all three under telemetry.
Concretely:
The R&D lab:
-
Maintains public roadmaps and risk registers.
-
Publishes upgrade proposals with quantified impacts on VerifyPrice, VerifyReach, VerifySettle, decentralization, and hardware profiles.
-
Runs testnets and shadow deployments.
On-chain governance:
-
Controls scarce resources: issuance, reward splits, canonical workloads, acceptance/deprecation of proof systems and hardware profiles.
-
Is bounded by constitutional SLOs: certain changes are simply not allowed if they push metrics beyond thresholds unless higher-order safety processes trigger.
Off-chain institutions:
-
Operate under public charters that explicitly state their mandate and constraints.
-
Are expected to publish minutes, risk assessments, and incident reports.
This three-body system is inherently unstable; Layer 6 keeps it from drifting into pure plutocracy or pure priesthood by insisting that all three bodies are visible in telemetry:
-
Changes in code and parameters appear on-chain.
-
Lab work appears in open repos and benchmarks.
-
Institutional decisions appear in charters, public calls, and reports.
No dark corners; no “just trust us, we’re the stewards.”
Governance Capture Risk
Token-weighted governance creates capture risk: large holders can centralize control over issuance, fee routing, and telemetry rules. The stack mitigates this through hard constitutional constraints that governance cannot override (see §22: Layer 6: Governance & Telemetry), timelocks on parameter changes, independent measurement infrastructure, and non-governable red lines (§27: Risk Analysis & Failure Modes). If governance can alter issuance, fee routing, or telemetry rules without hard constraints, this is itself a red line.
Governance as SLOs: The Five Invariants
Governance and operations exist to keep one invariant true under stress:
Pay the machine only for work anyone can verify cheaply—and give humans lawful privacy by default.
Everything below—roles, metrics, runbooks, and legal posture—turns that sentence into procedures, with receipts. Where policy pressure rises, we default to measurement and non-custodial design rather than new gatekeepers. “No dashboards, no trust” is not a slogan; it is the rule for deciding when the system is still safe to treat as money.
Governance and operations are about what happens when the world pushes back. They are the difference between a beautiful mechanism that works in a friendly lab and an actual monetary substrate that survives YCC (yield-curve control), capital controls, app-store bans, and “secure enclave” mandates.
We can summarize the protocol’s “constitution” as five invariants:
-
Verification asymmetry, by modality. The invariant is stated in the modality terms of §19: Layer 4: Truth & Work, because the aggregate ratio does not protect the property the monetary claim needs. Three clauses. (a) The M1+M2 share of verified units — the fraction of the network’s verified output whose correctness anyone can check cheaply — stays above a published floor, and that share is reported as its own series on the Value Capture Board (§23: Extended Telemetry). (b) Each canonical workload’s stays within its modality band: for M1 SKUs, for M2 SKUs with the soundness parameter published beside the ratio; M3 SKUs carry no target because the ratio is not their operative quantity. (c) The aggregate is retained only as a portfolio-level engineering floor for workloads not yet assigned a band, and no monetary claim reads on it. The Sev-1 condition reads on clauses (a) and (b): the M1+M2 share falls below its floor, or a banded workload’s breaches its constitutional VerifyPrice SLO (§19: Layer 4: Truth & Work) for the published window. A workload drifting above is an engineering incident, not a monetary one; the v3.0 draft called “the economic hinge,” and §19: Layer 4: Truth & Work shows why that was the wrong hinge.
-
Open admission. Anyone who brings correct work clears. Admission is not gated by identity, licensing, or proprietary hardware. Routers are neutral and open-source; house share and time-to-first-fill for new provers/LPs are visible on the Neutrality & Admission Board. If honest new entrants cannot join and get paid within a bounded window, decentralization is already drifting.
-
Useful-work security budget. Block rewards and fees underwrite useful work—MatMul-PoUW, verified inference, provenance and settlement proofs—under explicit SLAs. The security budget is tied to canonical workloads with published VerifyPrice rather than to a puzzle with no external buyer. That is a deliberate trade and not a free improvement: a work function with a buyer has a demand curve somebody can move, which is the objectivity a buyerless hash puzzle gets for nothing (§30: Objections & Responses).
Inference Verification Tiers and WC Eligibility: Under the “AI Money” analytical lens, inference Work Credits remain service claims. To prevent weak spot checks from being marketed as high-assurance verification, workloads are tiered by verification strength:
Tier Verification Type WC Eligibility Tier A Cryptographic (full ZK) Full eligibility (1.0) Tier B Probabilistic (bounded error, audited) Discounted (0.6) Tier C Attestation-only (TEE + sampling) Service-grade only (); collateral-ineligible Inference verification tiers and WC eligibility.
Rule: Tier A and Tier B verified inference are eligible for full and discounted Work Credit issuance respectively; Tier C mints service-grade credits at that are ineligible as collateral (§19: Layer 4: Truth & Work). Tier B issuance is discounted by a published issuance weight (the of the tier table in §19: Layer 4: Truth & Work) reflecting error bounds and audit rate — a weight on what is minted, not a haircut on what is pledged. Tier C can exist as a service market but is not collateral-grade—it represents trust in TEE vendors, which is exactly what the thesis aims to minimize.
-
Lawful privacy by design. Settlement is neutral and non-custodial by default—adaptor-sig atomic swaps, shielded pools, privacy rails—but comes with viewing keys and auditable PIDL receipts so law-abiding users can evidence obligations without re-introducing chokepoints. The Settlement & Privacy Board reports swap success, refund safety, and anonymity-set health; flows that never touch custodians should still leave enough receipts that auditors can do their jobs.
-
Verifiable machines at Layer 0. Canonical proving and attestation paths run on open designs with sampled supply chains; hardware attestation becomes one input to proofs, not a vendor priesthood. Hardware profiles, lot-sampling coverage, and profile incidents show up on the Hardware/Layer-0 panes of the boards.
These invariants are hard to change and easy to measure. Everything else—fee curves, circuit versions, work-function parameters, corridor lists—is configuration.
To keep configuration from degenerating into a governance circus, we tie changes to observable triggers instead of vibes:
-
If VerifyPrice p95 for a workload drifts above its target band for a sustained window, that workload’s circuit and parameters are queued for revision. Blocking the change requires an explicit override that cites alternative SLOs and appears in the governance log.
-
If entry latency for new provers/miners/LPs rises beyond a threshold, or the top-N share and house share breach caps, neutral routers automatically ratchet down house share and prioritize small bidders until the metric recovers.
-
If a swap corridor records a protocol-attributable loss — a party with no no-loss exit within (§20: Layer 5: Value & Settlement) — in VerifySettle, that corridor is marked advisory-delisted in the published route table: default clients stop routing to it, and any client may override the advisory with a visible flag. A hard removal that clients cannot override requires the breach to be reproduced in the public regression suite. Re-listing requires the suite to pass (including stress tests) plus a public post-mortem. User-liveness failures do not trigger this path; they are published under their root-cause class.
In this frame, “governance” does not micromanage every adjustment; it writes the SLOs and the triggers. Operations enforces them and publishes the receipts. Most changes are data-driven roll-forward: parameters evolve in response to Verify* drift, with clear before/after numbers.
To keep rule-making separate from rent-collection, we distinguish two broad roles:
-
A spec & telemetry steward that publishes ABIs, PIDL schemas, canonical workloads, hardware profiles, and the VerifyPrice/Reach/Settle dashboards. It does not run routers or take custody. Its mandate is to keep the bill of materials and metrics honest and up to date.
-
Market participants—miners, provers, routers, corridor LPs—who compete on price and reliability under those public SLOs, with SLA escrow and slashing keyed to PIDL receipts. Their incentives are economic; their constraints are the invariants and metrics.
This “two-chamber” structure keeps the job of defining rules and SLOs distinct from the job of selling capacity under those rules. It avoids the familiar pattern in which the entity that can edit parameters also happens to own the biggest fleet of nodes.
Governance as SLOs, not personality, is what lets the system answer policy pressure with dashboards and runbooks instead of press releases. When asked “how do you survive X?”, the right answer is not “trust the foundation,” but “look at this board, this trigger, and this incident playbook.”
Constitutional Enforcement
“SLO-bounded governance” is only credible if the enforcement mechanism is specified.
Machine-Enforced Constraints (Hard)
Certain invariants are enforced on-chain or in protocol code:
| Constraint | Enforcement |
|---|---|
| Base-asset issuance cap per epoch | Protocol rejects issuance exceeding the envelope of §22: Layer 6: Governance & Telemetry |
| Work Credit minting bound | Protocol rejects a mint whose weighted units exceed delivered, verified work (§22: Layer 6: Governance & Telemetry) |
| Corridor refund timeout | Atomic swap scripts enforce timeout |
| House-share cap | Telemetry and slashing, not a router rejection: see below |
| VerifyPrice bound violation | Workload suspended from WC eligibility |
Machine-enforced constitutional constraints.
The house-share cap is not machine-enforceable without an identity assumption.
The v3.0 table said router contracts “reject bids exceeding share.” A router can only reject a bid it can attribute, and attribution to a house requires knowing which provers are the same party — a Sybil-resistant identity that Layer 3 deliberately does not provide for market participants. Without it, a cap on house share is a cap on the share of any single key, which an operator satisfies by running more keys. The cap is therefore moved from the hard table to telemetry-and-slashing: house share is estimated from receipt correlation (co-location, timing, shared FCR references, shared stake sources), published on the Neutrality & Admission Board with its estimation method, and a router whose estimated house share exceeds the cap is slashed and de-prioritized by the trigger of §22: Layer 6: Governance & Telemetry. If a future Layer-3 design supplies Sybil-resistant operator identity, the cap can return to the hard table with that assumption stated in the row.
Override Path (Slow, Expensive)
Some constraints need flexibility. The override path is deliberately expensive:
-
Supermajority: of governance weight, defined as base-asset units voluntarily time-locked for the vote’s duration plus the override’s timelock, weighted linearly by quantity and capped per address family at the Red Line 8 concentration threshold. Work Credits carry no governance weight (§22: Layer 6: Governance & Telemetry); base asset that is not locked carries none either, so a holder who wants to sell into the decision cannot also make it.
-
Long timelock: days (90 days for issuance-related).
-
Risk memo: Mandatory written analysis, hash anchored on-chain.
-
Sunset clause: Override auto-expires after 12 months.
Emergency Path (Narrow)
True emergencies (proof system break, active exploit) require faster action. The emergency path is narrow and auditable:
| Allowed | Not Allowed |
|---|---|
| Deprecate proof system (hard) | Increase issuance |
| Delist corridor (advisory by default; hard only on a reproduced refund-safety breach) | Confiscate user funds |
| Quarantine hardware profile (hard) | Bypass refund safety |
| Freeze workload class (advisory by default; hard only on a reproduced acceptance-bound break) | Mint unbacked credits |
Emergency path scope limitations. “Advisory” means the action changes the published default route or workload table and every client may override it with a visible flag; “hard” means protocol code refuses the object.
Requirements: of 5 security signers; auto-expire in 7 days; postmortem within 14 days.
Subtractive is not harmless: the compelled-signer problem.
The v3.0 draft treated every subtractive power as safe because it cannot redirect value. That is true of theft and false of censorship. A body that can delist a corridor or freeze a workload class on three signatures is, to a state that can compel three signers, a kill switch for exactly the routes the stack exists to keep open — and Invariant 2 (open admission) and the “no kill switch for any single jurisdiction” commitment of §24: Legal, Policy, and Jurisdictional Posture are both violated the first time it is used that way, with every individual action constitutional. Two of the four powers are therefore advisory by default: an emergency delisting or freeze changes the default table that clients ship with, is logged with its evidence, and can be overridden by any client operator who is prepared to carry the flag. The hard form — protocol code refusing the corridor or workload — is available only when the triggering breach has been reproduced in the public regression suite (a refund-safety loss on the corridor; an acceptance-bound break for the workload class), so that the thing being removed is demonstrably broken rather than merely disfavoured. Proof-system deprecation and hardware-profile quarantine remain hard, because their triggers (a cryptographic break, a compromised attestation root) are themselves publicly verifiable artifacts and there is no honest client that wants to keep verifying against a broken proof system.
Reconciling the emergency path with Red Line 8.
§27: Risk Analysis & Failure Modes retires the thesis if governance can alter issuance, fee routing, or telemetry rules without hard constraints. Read carelessly, this path appears to grant exactly that: five signers on a seven-day fuse. The reconciliation is structural and worth stating as a constitutional rule rather than leaving to inference:
-
Emergency powers are subtractive only, and the censoring subset is advisory. Every allowed action removes or restricts a protocol claim (deprecate, delist, quarantine, freeze). No allowed action redirects value: no fee re-routing, no issuance change, no collateral-rule change, no telemetry amendment. A body that can only shrink the protocol cannot steal from it; the worst case is a smaller protocol, which is a survivable failure and the correct bias for a seven-day fuse — provided that the two powers which shrink the protocol selectively (delist, freeze) cannot be made to bind on clients that disagree, which is what the advisory default secures.
-
Subtractive is not free. Quarantining a hardware profile concentrates verification (Red Line 3’s condition); freezing a workload class cuts its fee flows. Emergency use therefore carries its own falsification weight: emergency actions must be logged against the red-line conditions they aggravate, and repeated or routine use of subtractive powers — the “emergency governance becoming routine” failure named under Red Line 12 — trips Red Line 8’s spirit even though each individual action was constitutional. The test is not whether any single action was permitted but whether the emergency path has become a de facto governance channel.
-
Signers are named, accountable, and rotating. The five seats are filled by published charter, occupied by independent security researchers and operators (not the foundation, not the largest holders), subject to rotation, and removable by the standard override path. Anonymity of the signer set is itself a Red Line 4 telemetry failure.
Monetary Constitution
The v3.0 draft opened this section with “Work Credit issuance is governed by a halving schedule.” That sentence conflated the two instruments the whole document works to keep apart. A halving schedule is a property of a base asset: a fixed, front-loaded supply path that no demand can move. A Work Credit is a per-unit typed claim on a standardized unit of delivered work; it is minted when the work is delivered and retired when the claim is redeemed, and there is no sense in which the number of such claims can “halve” on a calendar without either refusing to mint against delivered work or minting claims against work nobody delivered. The two are now separate subsections with separate rules.
Base-Asset Issuance Envelope
Base-asset issuance is governed by:
-
Base schedule: Halving every blocks (e.g., 4-year halvings). This is the supply path of the monetary candidate and nothing else.
-
Capacity modulator: about the schedule, driven by the growth of audited Delivered Verified Capacity.
Capacity modulator formula:
Here is the per-epoch growth rate of audited DVC (§14: Layer 0: Verifiable Machines & Energy), its published target, and the published scale. The scale is not decoration. The v3.0 formula wrote with a rate: for a two-percentage-point gap, , so the modulator moved issuance by while the prose promised . With the same two-point gap gives , a adjustment, and the envelope is approached only when capacity growth misses target by three or more scale units in an epoch. The modulator is annualized for publication ( for epochs per year) but computed per epoch, so the two readings cannot be swapped to flatter the series.
The growth rate is audited DVC, not prover-reported capacity.
is computed from Delivered Verified Capacity as the boards publish it: verified units delivered, netted of the concentration penalties of §22: Layer 6: Governance & Telemetry, measured by the sampled-attestation regime of Layer 0 and never by a prover’s own declaration. A modulator driven by self-reported capacity is an invitation to report capacity, and a modulator driven by gross rather than concentration-netted capacity rewards the network for growing in one place.
Work Credit Minting Rules
Work Credits have no schedule. They are minted under three rules and no others:
-
One claim per standardized unit of delivered work. A Work Credit is minted only against a registry SKU (§19: Layer 4: Truth & Work) whose acceptance criterion the delivered unit has passed, and it is retired on redemption. There is no issuance “to” anyone; there is only minting against receipts.
-
Weights are at most one. The issuance weights of §22: Layer 6: Governance & Telemetry (verification tier, hardware grade, concentration, FCR confidence, sovereign optionality) multiply the minted quantity and are all . No grade, tier, or bonus mints more credit than work delivered; premia for open hardware or high assurance are paid through collateral grade and routing priority, never through issuance above delivered work.
-
DVC-bounded. The weighted Work Credits minted in an epoch cannot exceed the epoch’s audited Delivered Verified Capacity for the SKU class; a mint that would breach the bound is rejected by protocol code (§22: Layer 6: Governance & Telemetry).
Nothing in these rules references the base asset’s schedule, and nothing in the base asset’s envelope references Work Credit volume, except through the modulator’s dependence on audited DVC — which is a dependence on work delivered, not on credits outstanding.
Fee Routing
| Destination | Share | Mechanism |
|---|---|---|
| Capacity providers and their delegating stakers | 70% | Paid via SLA escrow; delegation terms published |
| Protocol burn | 20% | Permanently removed |
| Assurance budget | 10% | Funds Layer 0 sampling (the Assurance Fund of §14: Layer 0: Verifiable Machines & Energy), audits, security review |
Fee routing split — the reference-design partition. Every worked example in Parts II–V uses this point; the 30–50% burn band of §6: The Triad and the Monetary Candidate is the design space it was chosen from, and Design A’s 40/30/30 is an alternative inside it, not a second reference.
Why burn, and what a burn is. A burn returns fee value to holders pro rata: it is a buyback, and §10: Work Credits: Energy-Anchored Claims and §24: Legal, Policy, and Jurisdictional Posture both say so. The v3.0 draft wrote here “high demand high fees high burn supply reduction value appreciation; this closes the loop,” which is the inference §10: Work Credits: Energy-Anchored Claims withdraws, and it is withdrawn here too. What a burn does, exactly: it reduces net issuance — and reduces supply outright only in an epoch where burned units exceed issued units, which at the Year-1 fee-coverage target of §22: Layer 6: Governance & Telemetry they will not (if retained fees cover 30% of the security budget, gross fees are 37.5% of it and the 20% burn share is 7.5% of the budget, against issuance funding the other 70%). It is published as its own series — gross burns, gross issuance, net issuance — on the Native Monetary Buyer Map, and it is read as supply arithmetic, not as buyer evidence (Appendix H: Formal Model of Market Realization, Wrapper Flows, and Price Capture). It does not by itself create monetary premium: a buyback accrues value to a claim, and accrual is the cash-flow leg of §6: The Triad and the Monetary Candidate, not the moneyness leg.
This routing is what makes the §10: Work Credits: Energy-Anchored Claims from §6: The Triad and the Monetary Candidate more than a slogan: it is the fee plumbing that delivers the lemma’s cash-flow claim, and only that claim. Its 20% burn is the same conservative variant used in the Layer 4 worked example (§19: Layer 4: Truth & Work) rather than the 30–50% reference band of §6: The Triad and the Monetary Candidate, because here the remaining 10% funds assurance. The assurance budget funds the Layer 0 sampling that keeps hardware claims credible. Changes to the fee split are governance parameters — and every such parameter is Howey exposure (§24: Legal, Policy, and Jurisdictional Posture); the constitutional version of this design fixes the split ex ante and removes the knob rather than defending a floor for it.
Retirement Rule
In addition to fee burn, base-asset units are retired in specific circumstances:
| Trigger | Retirement |
|---|---|
| Work Credit redemption | Any base-asset fee paid to fulfill the capacity claim is retired under the fee rule; the Work Credit itself is retired as a fulfilled service claim |
| Slashing | 100% of slashed collateral is burned (not redistributed) |
| Failed workloads | Fees for failed proofs (prover fault) are burned, not paid |
Base-asset and service-claim retirement triggers.
Issuance Weights
Work Credits minted under weaker assurance levels receive discounted issuance. The multipliers below are issuance weights — factors on what is minted — and are named as such; the word haircut is reserved in this document for discounts on what is pledged (collateral grade, bridge class), which are a different instrument applied at a different moment. The v3.0 draft titled this table “Risk Haircuts” and the confusion was not cosmetic: a haircut leaves the claim whole and discounts its pledge value, while a weight mints fewer claims.
| Factor | Issuance weight | Example |
|---|---|---|
| Hardware profile (L0 grade) | L0-A: 0.9; L0-B/C/D: 1.0 | Lower-assurance hardware earns fewer credits; no grade earns more than one credit per unit delivered (§14: Layer 0: Verifiable Machines & Energy) |
| Verification tier | Tier A: 1.0; Tier B: 0.6; Tier C: 0.3 | Probabilistic verification earns less than cryptographic |
| Prover concentration | 20% share: 0.9; 30%: 0.8 | Concentrated provers earn progressively less |
| FCR confidence grade | Missing/unverifiable FCR: issuance cap; low-confidence FCR: 0.85 | Facilities that cannot substantiate physical capacity claims earn fewer, capped credits |
| Sovereign optionality () | High band: 1.0; moderate: 0.9; low: 0.75 and issuance cap | Facilities whose physical capacity is fully substantiated but structurally fragile earn fewer credits |
Issuance weights for Work Credit minting. Every weight is (§22: Layer 6: Governance & Telemetry).
These weights are protocol parameters (not discretionary); they appear in dashboards and apply automatically.
Two distinct physical factors.
The last two rows look similar and do different work. The distinction matters enough to state explicitly, because collapsing them leaves a gap that a well-run fragile operator can walk through.
-
FCR confidence grade is epistemic. It asks whether we can see the physical substrate at all. It penalizes opacity.
-
Sovereign optionality is strategic. It asks whether what we can see is survivable. It penalizes fragility (§14: Layer 0: Verifiable Machines & Energy).
Without the second row, a facility that reports complete, signed, independently verified FCR data documenting a single interconnect, one fuel source, no backup duration, and a jurisdiction with an active rationing regime would receive no issuance discount whatsoever. It would in fact score well, because its disclosures are impeccable. Transparency about fragility is not the same as resilience, and an issuance schedule that rewards only the former is measuring candour rather than durability.
This is the operational form of the distinction drawn in §14: Layer 0: Verifiable Machines & Energy: verifiability and availability are separate properties, and Work Credit issuance should price both.
Interaction with the affordability hinge.
These weights must not become a back door for degrading verification cost. Per §14: Layer 0: Verifiable Machines & Energy, a resilience premium is acceptable only while benign-state Real-Resource VerifyPrice stays inside its constitutional SLO band. If pursuing a higher band pushes a network’s verification cost outside that band, the SLO wins and the optionality target is deferred. Weights adjust issuance; they do not license breaching a constitutional target.
Coverage Target
The fee-coverage ratio measures what share of the security budget comes from fees vs. issuance:
where is fee revenue net of the burned share — the portion that actually funds validators, provers, and operations. Burns do not fund security: a burn is supply arithmetic, not security revenue (Appendix H: Formal Model of Market Realization, Wrapper Flows, and Price Capture), so adding it to the numerator would double-count the burned slice of fees (it is already inside gross fee revenue) or, if read as destruction of issuance, would count destruction as funding. The burned quantity is published as its own series and read as reduced net issuance. Gross fee revenue is likewise published, so the burn share is visible; the convention is pinned here and applies wherever a fee-plus-burn quantity appears (the take-rate of §27: Risk Analysis & Failure Modes uses gross fees, because it measures what buyers pay, not what the budget retains).
| Target | Timeline |
|---|---|
| FeeCoverage | Year 1 |
| FeeCoverage | Year 3 |
| FeeCoverage | Year 5+ |
Fee coverage trajectory. The staged targets apply conditional on scale: they bind from the first quarter in which native-loop volume exceeds the published minimum — 1,000 daily active settlement identities and USD 5M quarterly native-settlement volume, the same viability gate the boards use — so the Year-1 row means “within four quarters of viability,” not “four quarters from genesis,” when bootstrapping runs longer. If the gate has not been met, FeeCoverage is published with the staging flag “pre-viability” and no target is credited or missed.
Why this matters: A system funded entirely by issuance is inflating its way to security — the warehouse paying guards in shares printed that morning (§27: Risk Analysis & Failure Modes gives the analogy its full form). A system where fees cover the budget has structural demand: someone is paying for the service, not merely holding the token. The trajectory from issuance-funded to fee-funded is the path from “speculative token” to “productive asset,” and it is a trajectory, not a switch, precisely because trust in the funding model has to be earned quarter by quarter.
The targets are a hypothesis, and the comparators say an aggressive one.
No precedent supports 30% in year one. Bitcoin, after seventeen years, funds its security budget from fees in the low single digits per cent in a typical epoch, with brief spikes into double digits during fee events. The utility-token cohort the thesis engages in §30: Objections & Responses — Filecoin, Render, Akash [Messari 2024–26] [Token Terminal 2024–26] — reached low-single-digit fee coverage against issuance at maturity, not 30%, and none has approached 50%. The staged table is therefore labelled for what it is: a falsifiable hypothesis that a work function with a buyer can reach fee coverage an order of magnitude above every buyerless and every utility-token precedent, within four quarters of viability. If the Year-1 row is missed, the miss is published against those comparators and the phase does not advance; the table is not revised downward to meet the data.
Value Capture Loop
+---------------------------------------------------------------+
| VALUE CAPTURE LOOP |
+---------------------------------------------------------------+
| DEMAND (users need Privacy, Proofs, Compute) |
| | |
| v |
| Users pay fees in the base asset for triad services |
| | |
| +-- 70% -> Capacity providers (stakers hold base asset) |
| +-- 20% -> Burned (supply reduction) |
| +-- 10% -> Assurance budget (sampling, audits) |
| | |
| v |
| Provers/routers must stake base asset as collateral |
| | |
| v |
| Base-asset issuance capped by schedule + capacity modulator |
| (Work Credits minted separately, one per delivered unit) |
| | |
| v |
| NET EFFECT: Demand -> Fees -> Burns + Staking -> Accrual |
| Monetary premium still requires holder and agency conditions |
+---------------------------------------------------------------+
Why demand doesn’t simply expand base-asset supply proportionally:
-
Issuance cap is hard: Protocol enforces the epoch-level envelope of §22: Layer 6: Governance & Telemetry regardless of demand; Work Credit volume does expand with demand, by design, and is the other instrument.
-
Burn is automatic: Higher demand higher fees higher burn lower net issuance. Not lower supply until burn exceeds issuance, which the coverage trajectory does not reach before Year 5 at the earliest; and a buyback, not a moneyness mechanism.
-
Staking locks supply: More provers/routers more collateral locked less circulating supply.
-
Issuance weights constrain minting: Weak verification or concentrated provers mint fewer Work Credits per unit delivered, so service-claim volume grows more slowly than raw capacity; this constrains the claim instrument, not the base asset.
This is the “bond indenture” that makes the accrual claim auditable, not asserted. It is not, by itself, the SoV claim; that requires the holder-side and agency conditions the diagram’s last line names.
New here? Start with the one-minute version.
Tip: hover a heading to reveal its permalink symbol for copying.