The flow
Who signs what
Between Tx 1 and Tx 2, the venue’s operator records the asset and sets its policy, and an approver under another sign-in checks each. Both are the venue’s records, off the ledger. signs nothing here: the payment asset, such as a tokenized deposit or a stablecoin, is only named in the consent.
Tx 2 to Tx 4 make the fund’s standing consent: a contract that lets the venue mint against an order the price source priced, and pay from the fund’s treasury account, only at that price. Because both the fund’s registrar and its treasury account sign it, the venue can settle each order without either of them signing it. Nothing is deployed for the asset: it is configuration on the package set every party has already approved.
Tx 5 and Tx 6 make the register keeper’s admission consent, for an asset whose configuration requires the register keeper’s credential. The registrar signs it once and does nothing per admission after that: each admission is the venue’s act under the consent, checked on the ledger against its terms, and it creates the register keeper’s own credential about the investor, which the register keeper holds. The investor and its custodian accept nothing. A change of the terms comes with the asset’s policy: the venue proposes it and the registrar accepts it, a tightening taking effect on the acceptance and a loosening after the consent’s delay. An asset that takes the venue’s credential skips Tx 5 and Tx 6.
The register keeper can also move an asset that holders already hold on the venue’s credential to its own: it makes the configuration require its own credential, and the venue re-issues each holder, revoking the venue’s credential and creating the register keeper’s in one transaction. See Onboard investors.
A tokenized deposit or a stablecoin is recorded at par, with a currency and no price source or distributions. A backed instrument is recorded at par or accumulating, then backed by a reserve the issuer and the reserve’s holder accept (Backed issuance). A gold token is recorded with its price provider. See Assets and instruments.
Worked example
The demo’s fund (chapter 1):Controls
- Recording an asset takes four eyes: the operator records it, and an approver under another sign-in checks it before it exists.
- A stricter policy needs one approver and applies at once; a looser one needs two and waits out a day’s notice.
- Once recorded, an asset’s terms change only through its versioned policy; the record itself is never edited.
- The consent binds nobody until both the registrar and the treasury sign, and each reads every term on its own node before signing. The treasury cannot be the registrar, and the price source can be neither the venue nor the fund’s registrar or treasury, so neither side of a sale sets its price. A fund has one live consent per payment asset, so it may take a tokenized deposit and a stablecoin, each under its own consent.
- The admission consent binds the registrar only once it accepts it, reading every term on its own node. Its terms change only by the venue’s proposal and the registrar’s acceptance, and a loosening waits out the consent’s delay. An asset has one live admission consent.

