Who can be internal or external
Each role’s page says what that party runs, signs and approves, in both cases: Register keeper · Price source · Bank and payment registry · Custodians and investors.
The rules every combination keeps
- The engine signs only as the venue. It holds the venue’s party alone, and never signs for another party. Where the venue also holds its customers’ accounts, its custody signs for them, apart from the engine.
- The venue never holds a register keeper’s, a treasury’s or a price source’s key. Such a party is never a local party on the venue’s Canton node. Where the venue’s node hosts one, it is an external party that signs with its own key, and the venue’s node only confirms. In production, host it on a second Canton node the venue does not run as well, with a confirmation threshold the venue’s node cannot meet alone.
- An internal register keeper keeps its own key and staff. Its issuance desk and the venue desk are different people, with different roles and keys, even in one organization.
- The price source is a party of its own. NodeAsset refuses the venue’s party as a fund’s price source. Keep it apart from the register keeper’s and the treasury’s parties too.
- The register keeper authorizes every order. For a fund paid on the ledger, it signs the fund’s standing consent once, with the treasury, and each order then settles within the consent’s terms, checked on the ledger in the same transaction. For an order paid off the ledger, it mints the units itself once its bank confirms the cash, and burns a redemption’s units on the investor’s request; the fund then pays the proceeds by bank transfer.
Named patterns
A distributor with an outside issuer and transfer agent
A bank issuing its own products, its own deposit token included
An asset manager selling its own fund
A bank distributing third-party funds against its own deposit token
Backed issuance
See Backed issuance.
Related: Architecture · Parties and the DA Registry · Control matrix

