Zusammenfassung
Permissioned ledgers are commonly dismissed as centralised because admission is restricted. Separating permissioning from control distribution makes validator identity externally costly collateral: public legal identity, charter state, liability and audit exposure, with affiliation-aware voting caps and per-member collusion margins.
Introduction
Permissioning and control distribution are different design properties. Permissioning answers who may validate: the admission rule, evidence required for admission, and governance process that maintains the validator set. Control distribution answers how validation power, operational failure domains, governance influence, and collusion feasibility are spread after admission. A ledger operated by named validators can concentrate control in one institution, one jurisdiction, one vendor stack, or one founder group; it can also distribute control across mutually independent operators whose public identity makes misbehaviour attributable. The design question is the distribution of accountable control across admitted validators.
The two-axis design space separates the familiar comparators from the proposed model: openness of admission and distribution of post-admission control vary independently (1). Identity-staked consensus sits in the restricted-admission quadrant, but its decentralisation claim depends on measured control distribution across affiliation classes, attributable validator constellations, and externally realisable loss.
Settlement infrastructure makes that question sharper. Financial-market-infrastructure principles treat legal basis, governance, risk management, operational reliability, participation requirements, finality, and accountability as system properties for infrastructure design.(Committee on Payment and Settlement Systems and Technical Committee of the International Organization of Securities Commissions 2012) A digital settlement ledger that aims to serve accountable markets needs known operators, auditability, recourse, and protocol finality, while preserving resilience against unilateral rewriting and hidden capture. The usual opposition between a public anonymous chain and a private institutional database leaves that design space under-specified.
Existing consensus families supply the comparators. Ethereum’s proof-of-stake design secures validation through endogenous capital posted inside the protocol and made slashable for dishonest behaviour.(Ethereum.org 2026b) Proof-of-authority already stakes something exogenous: authorised signers put identity and reputation behind block production, and Clique maintains the signer set and signer-voting process inside Ethereum-compatible headers.(Ethereum.org 2026a; Szilágyi 2017) The missing structure is the content of that collateral: how much a given signer stands to lose, through which channel the loss is realised, how correlated the signers are across jurisdiction, ownership, and vendor stack, and how likely misconduct is to be detected, attributed, and acted on.
This paper proposes identity-staked consensus: a trust model that makes those collateral questions explicit for settlement infrastructure. The model consumes the actor-assurance ontology of Multi-Jurisdictional Actor Identity Assurance for Capability Gating, including source-graded confirmation and reliance events, capability gates, and jurisdictional anchoring.(Kurz 2026c) It also consumes the root/profile anchor and assurance-at-time layer of Credentials and Triangulated Trust Signals on a Single Accountable Identifier, which gives the ledger an identity object to host or reference while reusing the identity-tier mechanics.(Kurz 2026a) The research question is which conditions allow a permissioned validator set to be decentralised through exogenous identity stake, affiliation-class weighting, observer-supported detectability, and bootstrap governance.
The paper states those conditions as a formal trust model. It defines chartered validators as actor-assured institutions or legal arrangements, separates admission from voting power, models collusion over affiliation-constrained coalitions, and states the loss-realisation channels through which external identity stake can become costly. It then locates the ledger in a base-plus-domain topology: the base layer records stable identity, validator, ordering, protocol-finality, and ledger-evidence-record invariants, while domain-specific compliance and activity rules remain at higher layers. A downstream delegated-authority paper can then use the ledger as a substrate for mandate records and durable model attribution while the consensus layer stays focused on validator evidence, ordering, and replay.(Kurz 2026b)
Contribution
The contribution is a formal trust model for accountable settlement ledgers operated by chartered validators. The model treats a validator as an actor-assured juridical entity, legal arrangement, or public body constituted under public law whose admission evidence is recorded through the actor-assurance event grammar. Validator signing is a constellation: a juridical actor, an accountable natural officeholder or role, and a machine actor that controls the signing node. Validator governance is a constellation. This is the first distinction from proof-of-authority: the model authorises key use by an accountable actor constellation under a governing-law gate, with the authorised signing key as one field in the security object.
The first formal move is to separate validator admission from validation power. Let be the validator set. Each validator has an actor identity , charter state , affiliation vector , voting weight , conditional identity-loss magnitude , protocol penalty exposure , and one or more loss-realisation channels. The affiliation vector records shared-failure classes such as jurisdiction, sector, ownership or control group, public-grant source, critical vendor, governance affiliation, commercial-counterparty concentration, admission cohort, and hosting or network path. Independence is derived by comparing those vectors across validators. Voting weights are capped by institution and by shared-failure class, so another recognised institution adds validation power only when the relevant caps still have room. If a cap binds, the candidate may join as an observer or service provider with zero validation weight until diversity recovers.
The second formal move is to replace raw validator count with threshold-coalition coverage and per-member deterrence. For finality threshold , a coalition is security-relevant when . The paper reports the weakest affiliation diversity available to such coalitions, then asks whether each required coalition member expects misconduct to be unattractive. In compact form, the member condition is , where is the joint probability of detection, attribution, and external realisation, is conditional identity-loss magnitude given realisation, is protocol penalty exposure, and is the member’s expected gain. A phase-indexed admission floor prevents zero-stake institutions from entering as full validators while leaving calibration to implementation.
The third formal move is to specify loss realisation. External identity loss becomes stake only when governance design makes it reachable. The model requires each admitted validator to have at least one contracted or legally reachable realisation channel: consortium expulsion and forfeiture of access or governance rights, contractual liability to relying parties, litigation exposure for attributable misconduct, reputational discipline in the validator’s own market, and, where misconduct falls inside the relevant external body’s authority, loss of a public grant, accreditation, licence, or public-law charter. Contracted consortium consequences are design commitments. Licence, accreditation, public-grant, and public-law consequences remain jurisdiction-specific legal questions. A charter needs a realisable channel to contribute stake; pure reputation contributes softer exposure.
The fourth formal move is operator incentive-compatibility. A validator participates when the expected benefit of node operation exceeds operating cost, compliance cost, residual liability, and the option value of remaining outside the validator set. Benefits may include direct settlement access, governance voice, audit access, cost recovery, reputational positioning, and public-interest or charter-aligned duties. The model ties those benefits to service, evidentiary, and governance roles, while validation power remains capped by institution and shared-failure class.
The fifth formal move is to make detectability endogenous to the design. The probability term depends on attributable signatures, data availability, evidence retention, dispute records, and observer capability. The ledger design can provide read access, audit trails, and escalation interfaces to auditors, public-interest observers, and supervisors whose own authority permits participation. Observer activity follows those actors’ legal or contractual roles; validation remains separate by default. The scope assumption is fixed: the settlement asset is regulated, validators are chartered, validator operation follows consortium governance, and supervisory authority over validation arises only where an applicable legal regime creates it.
The sixth formal move is bootstrap honesty. Early validator cohorts have disclosed concentration risk, so the model introduces a bootstrap state with admission sequencing, founder caps, public audit, class-diversity targets, and sunset rules. Stronger decentralisation claims arise only when the measured affiliation classes and minimum-loss threshold coalition support them. Admission state is a consensus-owned state variable for each validator; admission-rule amendments are versioned governance objects that are anchored to the base layer, become effective only through a defined supermajority and delay, and leave historical validator state replayable under the rule version in force at the relevant time.
The seventh formal move is the consensus/application boundary. Let classify a candidate enforcement rule or record invariant. The base layer owns invariants whose violation would compromise the ledger’s evidentiary substrate: validator admission state, signature validity, ordering, protocol finality, hash integrity, identity-anchor uniqueness, and ledger evidence record integrity. Higher layers own domain rules that change with law, market practice, or supervisory interpretation; they anchor their evidence to the base ledger while preserving their own amendment paths.
Research
Inputs from actor assurance and anchoring
This paper uses the preceding identity papers only at the interface where validator status becomes a consensus-security object. The actor-assurance paper supplies the gate grammar, actor constellations, source-graded confirmation events, reliance events, and jurisdictional anchoring needed to decide whether an institution may enter the validator set.(Kurz 2026c) The trust-anchor paper supplies the root/profile anchor and assurance-at-time layer needed to bind validator evidence to a replayable identity object.(Kurz 2026a) This paper adds the control-distribution and collusion model that belongs to the ledger layer.
The validator gate is stricter than ordinary institutional presentation because validation is an infrastructural act. For validator signing, the admissible constellation is : the juridical institution or public-law entity, an accountable natural officeholder or role, and the machine actor that controls the signing node. For validator governance, the admissible constellation is . The validator gate consumes live status, governing-law evidence, a register or public anchor, authority-bearing roles, charter or purpose evidence, an accountability path, record-retention commitments, at least one realisation channel, and a phase-indexed minimum conditional identity-loss floor. Equation Eq. 1 turns the general capability-gate form into a validator-admission predicate for consensus security.
Validator anchoring also differs from ordinary profile anchoring. The trust-anchor paper keeps ordinary root/profile bindings off-chain to support profile-scoped presentation. Validator admission uses a role-scoped public anchor instead: the validator-specific institutional profile anchor is linked to the root institutional anchor for attribution, replay, and retention. That waiver is narrow. It covers the validator role, the validator set, and the evidence needed to replay admission and signing authority. Validator service also sets a retention obligation for the validator anchor and validator gate during the service period, dispute window, and applicable record-retention window. The ledger stores or anchors the admission result, rule version, evidence pointer, public validator anchor, and retention pointer; the upstream identity papers continue to supply the detailed actor-assurance and profile-binding mechanics.
Validator state and affiliation
At time , the validator set is . Each admitted validator record contains the admission predicate , public validator anchor , actor identity , live charter state , affiliation vector , voting weight , conditional identity-loss magnitude , protocol penalty exposure , and realisation-channel set . The tuple is kept in prose because the later model consumes the fields directly. Admission, voting, and loss are separate objects: admission states who may validate, voting states how much control the admitted validator carries, and loss states what the validator stands to lose if misconduct is detected, attributed, and realised.
The affiliation vector is a validator-level shared-failure object. It is related to the actor-assurance paper’s confirmation-event failure classes, but it works one layer higher: actor assurance discounts correlated evidence, while this paper discounts correlated validators as independent control. The main classes in 1 identify concentration channels that can make several named validators respond as one control bloc.
| Class | Reason for inclusion | Example concentration risk |
|---|---|---|
| Jurisdiction | Public law, courts, sanctions, and emergency powers can affect validators together | Several validators exposed to one national measure |
| Sector | Sectoral incentives and business cycles can align conduct | Banks or insurers facing the same market pressure |
| Ownership or control group | Formal independence can mask common control | Subsidiaries validating as separate institutions |
| Public mandate source | The same grantor or supervisor can shape institutional incentives | Two banks under one supervisor share more than jurisdiction |
| Critical vendor | Shared software, custody, or operational provider creates a technical failure mode | Common validator client or key-management provider |
| Governance affiliation | Common consortium governance can align voting beyond technical validation | Founder bloc retaining amendment control |
| Commercial-counterparty concentration | Shared reliance on a narrow customer or relying-party set creates commercial pressure | Validators dependent on one settlement sponsor |
| Admission or founder cohort | Actors admitted under the same origin conditions may share implicit loyalties | Genesis validators preserving early allocation choices |
| Hosting region or network path | Infrastructure concentration can persist across nominally different vendors | Distinct providers using one availability region or network route |
Voting weight is assigned after admission and then constrained by affiliation class. For each capped class extracted from , Equation Eq. 2 prevents admission growth from becoming silent control concentration.
Coalition coverage and margin
Coalition analysis begins with the threshold that can affect finality, ordering, or rewriting under the selected protocol. Equation Eq. 3 defines the set of coalitions that matter for that threshold by voting weight.
Class caps are governance rails, while coverage is the publishable decentralisation metric. Equation Eq. 4 reports the weakest diversity present in threshold coalitions along each affiliation dimension.
A single headline value can report the weakest class dimension when the governance process needs one public number. Equation Eq. 5 compresses the coverage vector to the lowest threshold diversity across capped classes.
Coverage says whether threshold coalitions are diverse enough to support a decentralisation claim. Margin asks whether each required member expects misconduct to be unattractive. Equation Eq. 6 avoids the average-stake error by evaluating the expected deterrence condition for each member of a candidate coalition.
The model’s system margin is the weakest member in the weakest threshold coalition. Equation Eq. 7 identifies the governance repair target by focusing on the lowest exposed member across threshold coalitions.
Detectability, observers, and participation
The probability term in the member margin is itself a design object. Equation Eq. 8 fixes the convention: is a conditional loss magnitude, and carries the probability that misconduct is detected, attributed, and externally realised.
Observers raise detectability while carrying zero validation weight. Let be the observer set. An observer admitted under gate has attributable identity, audit or reporting rights, and zero voting weight. Observer independence is measured through the same affiliation vector used for validators, because an observer affiliated with the coalition it monitors adds little to detection or attribution. Observer reports are L1-anchored and evidentiary: they create durable evidence and escalation paths while leaving finality unchanged.
External loss realisation remains partly contractual and partly jurisdiction-specific. Consortium expulsion, forfeiture of access or governance rights, and contractual liability are channels that the ledger governance can design directly. Litigation exposure, reputational discipline, and loss of a public grant, accreditation, licence, or public-law charter depend on governing law, institutional form, and the authority of the external body. The paper treats those channels as model requirements and future evidence-template work; governing-law analysis determines whether a given validator faces a specific legal consequence.
The validator also needs an honest reason to participate when voting weight is capped. Equation Eq. 9 states the participation condition as a separate trade-off from collusion deterrence.
Bootstrap claims and enforcement boundary
Bootstrap governance is a phase-indexed claim-control mechanism. The bootstrap state carries the phase, founder caps, class-diversity targets, phase-specific , observer rights, sunset rules, and audit cadence. Early phases can support replayable evidence, attributable validation, and published concentration metrics. Mature decentralisation claims require class caps, threshold coverage, positive coalition-margin review, observer capability, and phase exits governed by published rules. The claim ladder in 2 assigns each phase the claim level supported by its evidence.
| Phase | Supported claim | Required evidence | Claim boundary |
|---|---|---|---|
| Pilot | Replayable records and attributable validation | Named validators, rule versions, signatures, retention, and disclosed concentration | Concentration metrics define the claim ceiling |
| Guarded growth | Measured control distribution under published caps | Affiliation classes, cap compliance, observer access, phase-specific | Independence claims require class evidence |
| Mature operation | Distributed accountable control under current metrics | Threshold coverage, coalition-margin review, observer reports, sunset completion, and public audit cadence | Legal-finality and immunity claims require external proof |
The enforcement boundary classifies candidate rules by replayability and amendment locus. Equation Eq. 10 keeps mutable domain law out of consensus by assigning a rule to the base layer only when breaching it would make prior records unreplayable and when its amendment path belongs to the ledger’s versioned protocol process.
The boundary is easiest to audit by applying both tests to candidate invariants and domain rules. 3 classifies each example by whether a violation breaks replay and where amendment authority sits.
| Invariant or rule | Layer | Replayability test | Amendment locus |
|---|---|---|---|
| Validator admission state | Past signatures require historical admission state | Versioned ledger governance | |
| Signature validity | Invalid signature rules break attribution of prior records | Versioned ledger governance | |
| Ordering and protocol finality | Reordering breaks record sequence and finality replay | Versioned ledger governance | |
| Hash integrity | Payload and predecessor hashes are the replay substrate | Versioned ledger governance | |
| Identity-anchor uniqueness | Duplicate anchors break attribution and state reconstruction | Versioned ledger governance | |
| Evidence-record integrity | Missing evidence pointers break audit and dispute replay | Versioned ledger governance | |
| Product eligibility | Past records remain replayable as records | Domain law, market rule, or supervisor | |
| Reporting format | Payload meaning can be transformed while record order persists | Domain authority or application governance | |
| Market conduct rule | The ledger records the event while rule authority sits elsewhere | Domain law or market governance | |
| Supervisory interpretation | Interpretation changes leave historical ledger facts replayable | External authority |
Ledger evidence record
The base layer stores or anchors the fields needed to replay who acted, under which validator set, under which rule version, and with which evidence pointers. Equation Eq. 11 defines the ledger evidence record as a substrate tuple for domain payloads.
The record is generic enough for settlement events, validator-state transitions, observer reports, reliance records, and later delegated-authority records. The downstream delegated-authority paper can bind mandate and model-attribution semantics to the payload or downstream layer, while this paper supplies only the attributable, ordered, replayable substrate.(Kurz 2026b)
Discussion
The model changes the meaning of decentralisation for settlement infrastructure. In an anonymous token-staked system, the control resource is endogenous stake. In a chartered validator system, the control resource is the combination of voting weight, affiliation class, operational independence, detectability, and conditional external loss. A restricted validator set can be decentralised when threshold coalitions remain diverse across measured classes and when the weakest coalition remains unattractive for each required member. Permissioning is then an admission property; decentralisation is a measured distribution property.
The core distinction from proof-of-authority is the actor constellation. A PoA design can maintain authorised signing keys and signer votes. Identity-staked consensus adds a legal and evidentiary wrapper around key use: the validator signature is attributable to a constellation, governance acts are attributable to , and both are admitted through a gate whose evidence remains replayable. The security claim rests on verifiable actor conditions: public identity, charter state, retention obligation, realisation channel, affiliation class profile, and conditional loss floor.
The series argument is the same independence discipline applied at two layers. The trust-anchor paper discounts correlated evidence when a relying party evaluates assurance-at-time for a gate. This paper discounts correlated validators when a ledger evaluates threshold control. At both layers, repetition from one failure mode has low probative value: several credentials from one failure mode leave the identity presentation weak, and several validators inside one affiliation class leave the decentralisation claim weak.
The hard case is loss realisation. Institutional identity has security value only when misconduct can be detected, attributed, and made costly. Reputation alone is a weak and uneven form of stake. Contractual liability, expulsion, loss of access, litigation exposure, and public-grant consequences create stronger channels, but each channel depends on drafting, governing law, evidence retention, and procedural enforceability. This is why is inside the member margin and why is conditional on realisation. A ledger lacking attributable evidence lowers the expected cost of collusion even when every validator is named.
The observer role is narrower than the technology may suggest. The ledger can expose read access, audit trails, dispute records, and escalation interfaces. Auditors, public-interest observers, and supervisors act through their own legal or contractual authority after admission through . Their reports can strengthen detection and attribution while carrying zero validation weight by default. This keeps the claim hierarchy intact: the settlement asset may sit inside a regulated framework, validators may already be chartered institutions, and validator operation is governed by the consortium and by any legal perimeter that applies to it. Supervisory status remains a separate legal question.
Bootstrap governance is the main adoption risk. Early validator cohorts will be smaller, more correlated, and more dependent on founder choices than a mature validator set. The model handles this by requiring phase-specific claims: a pilot can claim replayable evidence, attributable validation, and published concentration metrics; mature decentralisation claims require affiliation caps, threshold coverage, observer capability, realisation channels, and a positive coalition-margin review. The same logic applies when admitted institutions share a vendor stack, national exposure, ownership group, public-grant source, founder cohort, or hosting region. Each shared-failure class reduces effective independence until caps and governance repair the concentration.
Within the paper series, this paper supplies the record substrate between identity assurance and delegated machine action. The actor-assurance paper supplies evidence for validators and relying parties. The trust-anchor paper supplies the root/profile anchor and assurance-at-time structure. This paper adds the validator trust model, the layer boundary, and the ledger evidence record. The delegated-authority paper can then bind agent activity and durable model attribution to records whose consensus layer already has accountable validators, replayable rule versions, and a defined enforcement boundary.
Conclusion
This paper has defined identity-staked consensus as a trust model for settlement ledgers operated by chartered validators. Its core move is to separate admission from decentralisation: admission determines who may validate, while decentralisation depends on how voting weight, operational dependencies, governance influence, detectability, and externally realisable identity loss are distributed after admission. A named validator set becomes security-relevant only when those post-admission properties can be measured and replayed.
The model makes that claim inspectable. Actor constellations determine which juridical, natural, and machine actors may sign or govern; public validator anchoring binds that role to replayable institutional evidence; affiliation caps and threshold coverage test whether control is distributed across meaningful classes; and the member-margin equations ask whether each required coalition member faces sufficient expected loss. Bootstrap governance then ties public claims to the evidence supported by the current phase, so pilot operation, guarded growth, and mature operation carry different evidentiary burdens.
For the paper series, this paper supplies the ledger substrate between legal identity assurance and delegated machine action. Its evidence record preserves who acted, under which validator set and rule version, with which signatures, evidence pointers, dispute pointers, and observer reports. The delegated-authority paper can bind mandate semantics and durable model attribution to that substrate while leaving consensus focused on accountable validators, ordering, replay, and enforcement boundaries. The result is a consensus account in which institutional exposure becomes a measurable resource for settlement trust.
Limitations and Future Research
The model is conceptual and formal; empirical validator census work remains future work. Future work must test candidate validator populations against the affiliation vector, shared-failure caps, threshold class coverage, and minimum-loss threshold-coalition margin. This includes sectoral, jurisdictional, ownership, commercial-counterparty, founder-cohort, hosting, vendor, and governance correlations.
The minimum conditional identity-loss floor is a calibration problem. This paper places inside validator admission and leaves phase values unset for banks, insurers, universities, public bodies, chambers, standards organisations, and other chartered validators. A high floor strengthens deterrence and may exclude useful institutions whose participation improves diversity, observability, or public legitimacy. A low floor improves inclusion and may weaken the smallest threshold coalition. Implementation must calibrate that trade-off before the ledger claims mature collusion resistance.
The threshold coverage metric depends on governance-quality class definitions. A consortium that defines affiliation classes too coarsely can hide concentration; one that defines them too finely can inflate diversity. Future work must specify class-definition governance, external audit of class assignments, and methods for measuring higher-order correlations across jurisdiction, sector, ownership, public-grant source, vendors, counterparties, founder cohort, and hosting path.
Loss-realisation channels require jurisdiction-specific legal analysis. Consortium expulsion, contractual liability, litigation exposure, reputational discipline, and public-grant consequences differ across banks, insurers, universities, public bodies, chambers, and standards organisations. The paper states the model requirement; future work must map concrete evidence templates, trigger evidence, realising actors, and enforceability rules.
Implementation and proof obligations remain open. A deployed protocol would need precise validator-key governance, evidence-retention rules, observer access control, dispute procedure, amendment mechanics, data-availability guarantees, and a formal security proof under stated network and adversary assumptions. Bootstrap governance also needs live measurement: a ledger should publish the claims supported by its current phase while mature-set claims are reserved for the measured mature state.