Risks addressed
- An ineligible investor acquires units.
- Eligibility rests on unverified KYC.
- An investor keeps acting after its eligibility lapses.
- A sanctioned investor transacts.
Controls
- The DA Registry checks the holder’s credential on every mint, burn and transfer, wherever the transfer starts, so an investor without one gets no units.
- Where the asset requires its register keeper’s credential, the ledger creates it only under the register keeper’s standing admission consent: the claims are read off live credentials from the KYC providers the register keeper trusts, and the residency and investor type must be ones its terms admit. The credential is the register keeper’s own, which it holds, naming the investor; the investor and its custodian accept nothing. The register keeper signs the consent once and does nothing per admission.
- Where the asset requires the venue’s credential, each claim, such as residency or investor type, is recorded in the venue’s records under four eyes, against the hash of the KYC evidence, and does not count until it is verified.
- Each claim carries the end of its evidence, and the venue reads the claims afresh at each of its acts, so a claim past its end no longer counts there. The venue’s credential lapses at the end it names; the register keeper’s names none, and the register keeper ends it by revoking it. An investor with no live credential stops receiving, sending and redeeming until it is admitted again.
- A sanctions screening hit freezes the investor at the venue at once, and the register keeper blocks its party on the registry. The register keeper’s terms can deny a residency outright, and it can revoke its own credential.
- The ledger carries claim codes and their expiry, and no personal data; the KYC evidence stays with whoever ran the KYC.
Evidence
- Admissions and credentials, with their issuer, issue, re-issue and revocation.
- The register keeper’s admission consent: its terms, each change of them and when it took effect.
- The KYC credentials each admission under the consent read its claims from.
- Claim records, each with its maker, approver and evidence hash.
- Refusals, each with the rule that refused.
- Restrictions, and the register keeper’s block-list changes.
How it works: the credential
How it works: the credential
- Each asset names whose credential its registry requires: its register keeper’s, issued under the register keeper’s standing admission consent, or the venue’s. The register keeper chooses which, in the asset’s configuration on its registry, and whoever issues that credential decides who may hold the asset.
- Under the consent the venue asks for the admission and presents the investor’s KYC credentials; the ledger reads the claims, checks them against the register keeper’s terms, and creates the register keeper’s own credential in the same transaction. The register keeper holds it, and its claims name the investor, as the DA Registry’s allowlist does: the investor signs nothing, and its custodian vets nothing of the venue’s. The venue cannot create that credential outside the terms, set when it ends, or revoke it: withdrawing an admission cancels the venue’s offers and revokes only a credential the venue issued.
- The venue’s own credential is offered to the investor on admission, and created when the investor’s custodian accepts it from its own wallet.
- The terms are the asset’s policy, kept on the ledger: the KYC providers the register keeper trusts, the claims an admission needs, the residencies admitted and denied, and the investor types admitted. The venue proposes a change and the register keeper accepts it on the ledger; a tightening takes effect on the acceptance, and a loosening only after the consent’s delay.
- A re-issue revokes the old credential and creates its successor in the same transaction, so an investor never holds two, or none. An offer whose claims no longer hold is withdrawn first. An asset that moves to the register keeper’s credential re-issues each holder’s this way, with nothing for the holder to do: the venue’s credential is revoked, and the register keeper’s created.
- An admission that falls short is refused before the ledger, naming the rule:
eligibility:residency,eligibility:investor-type,eligibility:accreditation,eligibility:trusted-credentialoreligibility:claims-conflict; and under the consent,policy:countryandpolicy:investor-typefor a residency or an investor type its terms do not admit, with the gateadmission-consent.
How it works: claims
How it works: claims
- For the venue’s credential, claims are recorded under four eyes, either directly or in one call that binds an outside KYC provider’s case to the holder.
- For the register keeper’s credential, the claims are the trusted KYC providers’ own, on their credentials to the investor. Where two providers give a claim differently, the admission is refused, and each claim carries the earliest end of the credentials it was read from.
- An asset can trust credentials that named KYC providers issue. Their claims are read at the moment of each act, so a withdrawn claim counts at once.
- Your provider’s verification webhook issues a claim or expires it. See KYC and screening.
- The asset’s policy can use the claims to allow or deny countries and require investor types, checked at admission, subscription and on receiving a transfer. A denied country also stops redemptions and distributions.
How it works: screening
How it works: screening
A screening system that finds a hit freezes the investor at the venue with the reason
sanctions, and the venue refuses every act of the investor from then on. The block on the registry is the register keeper’s act. Its own systems read the venue’s freezes on every asset (GET /v1/block-list, under the registrar role), and it lists each frozen investor’s party on the registry’s block list, so the registry refuses its transfers wherever they start. It takes the party off once the venue lifts the freeze. Two approvers at the venue lift a freeze. See Interventions.
