Sign in

Reference

Security and dev log

Who can do what with the contracts, and what each role is bound by in code.

RoleCanBound by
Timelock (owner)parameters, probers, publisher, guardian, reserve48 h delay, bounds in code, never capital
Proberpost measurementsdeadline, outage rule, public records, majority of probers
Publisherpost customer rootsslash ceiling, 3x per customer, public logs
Guardianpause new issues and backingexits, settlement and claims never pause
Binderbind the $PBI addressonce, irreversibly

The owner

A TimelockController with a 48-hour minimum delay owns BondBook, ProbeLog and Compensation. Its proposer and executor is the machine wallet. Every change is queued in public and shown on the protocol page before it can run. No owner function reaches bond capital, premium balances, earned premium or compensation (invariant I7).

Roles

The prober decides what was measured. The outage rule, the published raw records with their proof of time, and later a majority of probers bound it. The compensation publisher posts the customer list, recomputable from public USDG Transfer logs. The registrar names operators after checking a signed bond.json. The relayer pays gas for passkey accounts and settles x402 payments, and cannot sign for anyone.

Pause

The guardian can stop new issues and new backing. Exits, settlement, compensation claims and premium claims never pause. Experimental contracts, unaudited: read them before you trust them. The full role list is on the security page.

Dev log

The dev log ties each entry to a public record: a transaction, a verified contract, the SDK's hash, a queued parameter, a service added to the watch, a settlement and the compensation it paid.