What the keys can do
Every power, in one table.
Most products of this kind describe their trust model in a paragraph you have to parse. This is the matrix: every party that holds a key, against every thing that could go wrong. A yes is a power. A no is a contract reverting.
| Can they… | The launcher | OWED attester key | OWED registry owner | pons | The builder |
|---|---|---|---|---|---|
| Move money out of a box | no | no | no | no | yesonly the bound wallet, only what is owed |
| Take back what is owed | nothere is no recovery window, at launch or ever | no | no | no | no |
| Redirect the fee route away from the vault | nothe factory is the deployer of record | no | no | read the fine printpons's locker owner controls who may trigger collection, never where it goes; a future pons upgrade is pons's, not ours | no |
| Change the builder's share | no | no | no | no | no |
| Say which wallet a GitHub login is | no | propose onlyone signature, 48 hours in public, then anyone finalises | nocannot propose, cannot bind | no | chooses the walletthe builder picks the address and posts it themselves |
| Cancel a pending binding | no | yesduring the 48 hours | yesduring the 48 hours; the only emergency brake | no | no |
| Change a binding once it is final | no | no | no | no | no |
| Rotate the attester key | no | no | yesafter a 48 hour public notice | no | no |
| Decide when fees become collectable | no | no | no | yespons sweeps LP positions on its own cadence; claimable lags earned | no |
| Harvest fees into a box | anyone | anyone | anyone | anyone | anyone |
Where a GitHub box is weaker than a wallet box, in plain words
Wallet box
- Owed to one address, fixed at launch.
- Reads no registry, trusts no key of ours.
- If the builder loses that wallet, the box waits forever. That is the trade.
GitHub box
- Owed to a login. The builder chooses the wallet later, once.
- Depends on our attester saying the login is that wallet. That is the one trusted thing here, and it is bounded: propose only, 48 hours in public, permanent after.
- If the builder's GitHub account is taken over inside those 48 hours, the registry owner can cancel the post. That is what the brake is for, and it is all the brake can do.