Reference
Security and dev log
Who can do what with the contracts, and what each role is bound by in code.
| Role | Can | Bound by |
|---|---|---|
| Timelock (owner) | parameters, probers, publisher, guardian, reserve | 48 h delay, bounds in code, never capital |
| Prober | post measurements | deadline, outage rule, public records, majority of probers |
| Publisher | post customer roots | slash ceiling, 3x per customer, public logs |
| Guardian | pause new issues and backing | exits, settlement and claims never pause |
| Binder | bind the $PBI address | once, irreversibly |
The owner
A TimelockController with a 48-hour minimum delay owns BondBook, ProbeLog and Compensation. Its proposer and executor is the machine wallet. Every change is queued in public and shown on the protocol page before it can run. No owner function reaches bond capital, premium balances, earned premium or compensation (invariant I7).
Roles
The prober decides what was measured. The outage rule, the published raw records with their proof of time, and later a majority of probers bound it. The compensation publisher posts the customer list, recomputable from public USDG Transfer logs. The registrar names operators after checking a signed bond.json. The relayer pays gas for passkey accounts and settles x402 payments, and cannot sign for anyone.
Pause
The guardian can stop new issues and new backing. Exits, settlement, compensation claims and premium claims never pause. Experimental contracts, unaudited: read them before you trust them. The full role list is on the security page.
Dev log
The dev log ties each entry to a public record: a transaction, a verified contract, the SDK's hash, a queued parameter, a service added to the watch, a settlement and the compensation it paid.