The flow
Who signs what
Before Tx 1, the venue registers the investor’s party (hosted on its custodian’s node) under a holder id, and records its attributes: an operator makes the record, an approver under another sign-in checks it.
Under the register keeper’s admission consent
For an asset whose configuration requires the register keeper’s credential, the admission is one transaction under the register keeper’s standing admission consent (Set up an asset, Tx 5 and Tx 6). The register keeper signs nothing per admission, and the investor and its custodian sign and accept nothing.
No attributes are recorded: the KYC provider issues the investor its credential, and the venue presents it with the admission. The register keeper’s credential names the investor as the subject of its claims and is held by the register keeper, as the DA Registry’s allowlist does; the registry counts it for the investor, and the venue serves it in the registry’s contexts for the investor’s wallet. An investor admitted on the venue’s credential before the asset moved to the register keeper’s is re-issued the same way: the transaction revokes the venue’s credential and creates the register keeper’s.
Worked example
From the demo (chapter 2):Controls
- The ledger carries the claims as codes (a country code, an investor type, an expiry) and no personal data; the evidence’s hash and reference stay in the venue’s records.
- Recording or changing an investor’s attributes takes four eyes: an operator and an approver.
- A missing or unverified claim, a deny list, or a full fund (its holder cap) stops the offer before it reaches the ledger, and the refusal names the rule.
- Under the register keeper’s admission consent, the ledger itself refuses an admission whose KYC credentials are not from a trusted provider, have lapsed or disagree, or whose residency or investor type the consent’s terms do not admit. The venue cannot create the register keeper’s credential outside those terms, set its end, or revoke it; the register keeper revokes it.
- The registry enforces the credential: every mint, transfer and burn checks it, and an investor whose credential lapsed can neither receive, send nor redeem until it renews.
- When an admitted investor’s attributes change, the next offer replaces its credential in one step, so the investor is never left with none, or with two.
- The issuer and DA’s registry operator see the credential’s claims; nobody but the investor sees the venue’s offer. The register keeper’s credential the venue sees too, which observes it to serve it.
Do it
POST /v1/holders:onboard registers, binds the provider’s case and records the attributes in one call. See Onboard investors.
Related: Set up an asset · Subscriptions · Holds, freezes and issuer powers
