The engine and its API run at the venue and act only as the venue’s party. Register keepers, price sources and investors act on their own systems; see Who runs what.
The parts
NodeAsset is the engine and its API. It ships no screens: the venue builds its own on the API, or has its systems integrator build them, and the demo shows a screen for each role.
The ledger is the source of truth. Every holding, reserve, subscription, credential and price is a contract on the parties’ Canton nodes, and the engine reads them back through PQS. Its own database holds only what it decided: the requests it took, who approved them, what it stopped, and what reconciliation found.
Every asset runs on the same Daml packages. Adding an asset records its configuration, under four eyes, and deploys no contract.

