Governance
The controls intended to govern privileged actions across the platform, the treasury and the asset registry.
Separation of duties
Operational, compliance, finance, treasury, content and audit responsibilities are separated by role. The platform is built so that no single account can both initiate and approve a sensitive action.
Maker-checker approval
Sensitive actions — publication of asset claims, changes to token configuration, compliance decisions and treasury operations — are designed to require a second, independent approval before taking effect.
Multi-signature control
Privileged smart-contract roles are intended to be held by a multi-signature arrangement rather than an individual key. The signer set and threshold have not been established.
Audit trail
Administrative actions are recorded in an append-only, tamper-evident audit log capturing the actor, time, action, record, previous and new values, and the reason. The log cannot be edited or deleted through the interface.
Current status
These controls are implemented in the platform. The people, entities and signer arrangements that would operate them are not yet appointed.