The parties

A fund’s treasury, the account its payments land in, is a party of its own that signs the fund’s standing consent beside the registrar.

Who signs what

  • The engine acts as the venue’s party alone and holds no other party’s key, so every command it submits is that party’s.
  • Only the registrar creates units: the venue’s party can propose an issue but cannot mint one.
  • Where an asset requires the registrar’s credential, the venue’s party asks for each admission but cannot issue the credential. The ledger creates it under the registrar’s admission consent, which the registrar signs once, and only for a holder whose KYC credentials from the providers the registrar trusts meet the consent’s terms. The credential is the registrar’s own: issued and held by the registrar, naming the holder, so the holder and its custodian accept nothing. The venue cannot set when it ends or revoke it; the registrar can.
  • The issuer’s and the holder’s signatures on a reserve are their standing consent, which covers each mint and redemption at the amounts the investor allocated, never at an amount named later.
  • A reserve’s holdings are its holder’s own, locked to the venue, the issuer and the holder together: none of them can release one alone, and only the reserve can.
  • Every price that moves value is signed by the price source on its own node. The venue reads prices and cannot set one.
  • An investor’s units move with its consent, through its custodian’s allocation. For an investor that consented in advance, the venue’s party can also move them alone, in a forced transfer or a recovery, under the registrar’s standing agreement; the registrar ends that agreement in one act.
  • A role lets a person or a system ask the engine for an act. The ledger decides whether it happens, because each party authorizes its own part on its own node.
Whoever takes over the engine can propose acts but cannot create a unit, set a price, or admit a holder to an asset that requires the registrar’s credential outside the registrar’s terms. The engine’s one direct power over holdings, moving a consenting investor’s units, lasts only while the registrar’s agreement stands, and reconciliation matches every move to the operation that approved it. Each workflow page shows these signatures transaction by transaction; see Actors and roles and, for who decides each kind of change, Duties and governance.

The DA Registry and NodeAsset

The Registry knows units: who holds how many, and whether a party may hold them. NodeAsset knows what the units mean: which order a mint was for, what backs a product, whom income is owed to, and whether a mint should have happened at all. The Registry checks each act as it happens: does the acting party hold the credentials the asset requires, is it blocked, are its holdings locked. NodeAsset checks the acts themselves: was the mint planned, is the product still covered, is the investor within the asset’s policy, do the outside records agree. Reconciliation runs these checks on a schedule and on demand, and a blocking finding stops the book until people release it.

What each party runs

Every other party acts as its own party, on its own node, through its own wallet, registry tools or NAV system. NodeAsset never acts for another party: the engine holds the venue’s party alone, and the venue never holds a register keeper’s, a treasury’s or a price source’s key. What each party runs, signs and vets is on its own page: Register keeper · Price source · Bank and payment registry · Custodians and investors. Deployment patterns gives the rules that make any combination of parties valid. Related: Architecture · Who sees what · Duties and governance