Three planes — compliance, physical, economic
Earlier articles kept deferring one question, because it deserved its own: the record's state and the world's state are not the same thing. Who says the metal is really in the vault? What happens when the signature is stale — or wrong? This article is the deferred answer: the three planes of state in full, and the design's deepest move — attestation as a state that decays, signed by accountable parties, wired directly to the asset's ability to trade.
A record can enforce its rules perfectly and still be wrong about the world. The bridge between record and world is attestation — and the design's core move is to stop treating it as a certificate issued once and start treating it as a state that decays. Accountable parties sign it, on a clock. Fresh signature: the asset trades. Stale signature: the asset stops. Wrong signature: one named party is on the hook for it. That is the core of the security model, and it fits in three sentences because it was designed to.
- State is split across three planes on purpose: compliance (what may the asset do?), physical/custody (does the underlying exist, where, in what condition?), and economic/valuation (what is it worth, what does it owe or earn?). Different questions, different writers, different clocks — separating them is what keeps each one honest.
- Planes 2 and 3 never move the asset themselves. They fire the triggers the compliance machine responds to. A moisture reading is not a suspension; it is a fact that fires one.
- An attestation is not a document. It is a signed, scoped, expiring claim by a licensed party about an observable property — and the roles are separated by design: the attester is never the custodian and never the issuer.
- Two different decays do the work and must not be confused: attestation freshness decays on a schedule (miss the window → automatically restricted), and value decays with the asset's condition (a published curve converts physical state into a priceable haircut).
- Stale and wrong are different failures with different answers. Stale is handled by the machine — automatically, before harm. Wrong is handled by accountability — a named signer, bounded liability, insurance, and a supervised correction path on the record.
Why three planes, and not one
It is tempting to design a tokenized asset as one big bundle of fields: owner, grade, value, restrictions, all in a row. Every failure this series has catalogued argues against that. The three questions the planes answer are owned by different people, verified by different methods, and true on different clocks. What an asset may do is a matter of rules and authority — it changes when a regulator or an issuer acts. What an asset is is a matter of observation — it changes when the world does, and someone must be paid, licensed and liable to go and look. What an asset is worth is a matter of markets and models — it changes continuously and belongs to no single authority at all. Fold those into one field-set with one writer and you have rebuilt the warehouse receipt: a single document, signed once, asserting rules, condition and value all at the same time, drifting from all three at once.
So the machine keeps them apart, and connects them in exactly one direction. Planes 2 and 3 observe; Plane 1 acts. A condition breach or a lapsed attestation fires the transition to S3 Restricted; a maturity fires S7; a missed premium fires S3 and then, uncured, S4. The observers never touch the asset directly — they produce facts, and the compliance machine, with its named authorities and typed transitions, is the only thing that ever moves it. One-way wiring is what makes the whole system auditable: every state change traces back to either an authority's signed decision or a trigger's signed fact.
Plane 1, briefly — the part already built in public
The compliance plane was the subject of Article 6 and needs only its summary repeated: every asset is in exactly one named state, S0 Pre-Issuance through S7 Settlement/Wind-down (plus the S2a observation state), each state carries a named authority, every transition is explicit and typed, freeze is regulator-only with no issuer bypass, and rules change means state change — never re-issuance. What this article adds is the observation that Plane 1 is deliberately boring. It contains no judgment about the world, no opinions about value — only rules and authority. All of the world's messiness is pushed out into the two planes built to carry it, which is precisely why the compliance machine can be small enough to verify and stable enough to trust.
Plane 2 — what an attestation actually is
Strip the word to its working parts. An attestation in this design is a signed, scoped, expiring claim by a licensed party about an observable property of the underlying. Each word carries load. Signed: the claim is cryptographically attributable to one named attester, forever — there is no anonymous "the warehouse says." Scoped: an assayer attests grade and moisture, not ownership; a vault auditor attests bar count and lineage, not value; nobody signs beyond their license, and the record is built to reject out-of-scope claims. Expiring: every attestation carries a freshness window set by the class profile — hours for a monitored sensor feed, days for a grain inspection, a quarter for a vault audit — after which it is stale by definition, without anyone needing to discover the fact. Licensed: attesters join the network the way participants have always joined depositories — by signed agreement, with financial liability and insurance behind their signatures. And observable: attestations are claims about things a competent party can verify — weight, grade, presence, condition — not opinions about worth. Worth belongs to Plane 3.
Role separation is the other half of the definition. The attester is never the custodian and never the issuer — the three functions that, fused in one party, produced the great warehouse frauds, where the entity storing the goods also graded them and also issued paper against them. Separated, each party's signature checks the others: the custodian holds, the attester observes, the issuer issues, and a lie now requires coordinated dishonesty across independently licensed, independently liable firms rather than one convenient desk.
The full physical lifecycle then reads naturally: deposited (custody established) → assayed/graded (genesis attestation — the first and most consequential signature) → in storage, monitored (scheduled re-attestation, sensor feeds) → re-graded (condition changed, curve updates) → partially withdrawn (fractions burned against release) → released (custody ends, plane goes quiet). None of these events moves the asset's compliance state by itself. Each is a signed fact — and the wiring decides what fires.
Think of a jurisdiction's periodic vehicle inspection. The certificate does not make the car roadworthy — it attests roadworthiness, it expires on a date printed on its face, and an expired certificate means the car may not be driven, whether or not anything is actually wrong with it. Nobody considers this strange; it is how societies handle machines too numerous to inspect continuously. The asset-state design applies the same logic to collateral: the expiry is the enforcement. What is strange is the current system, which issues the certificate once, never expires it, and lets the vehicle drive forever on the day it was inspected.
The two decays — and why they must not be confused
Two different things decay in this design, and much confusion in the industry comes from collapsing them into one.
The first is attestation freshness, and it lives on Plane 2. It decays on a schedule, not with the asset: the moment the freshness window passes without a new signature, the attestation is stale — a binary fact, requiring no judgment. The wiring is the series' sharpest single idea, stated in Article 6 and tested in Article 7: stale attestation fires auto-S3, and unattested stock goes illiquid instead of fraudulently liquid. Re-attestation is the cure that restores S2; an uncured lapse falls to S4. The fraud economics invert precisely here. The classic warehouse frauds run on a common engine — a record that stays tradable after it has parted from reality — and this wiring attacks its largest branch, the passive one: drift alone no longer produces a tradable lie, because the stale record is the trading halt, automatically, before the loss compounds. Staying fraudulent now requires fresh, attributable acts — re-signed lies, not quiet neglect.
The second is value decay, and it lives on Plane 3. It is continuous, not binary: grain at 14% moisture is worth more than grain at 18%; a policy three months into lapse-risk is worth less as collateral than one auto-debited for a decade. The instrument here is the published decay curve — a valuation-adjustment function, referenced in the class profile but authored by independent, licensed valuation publishers, a role separated from the issuer exactly as the assayer is separated from the warehouse — that maps attested physical state to a stated haircut. Moisture rises, grade falls, collateral value falls by a stated percentage; the vault audit is clean, gold's curve is flat, and the profile simply says so. The word doing the work is published. A published curve can be disputed, back-tested, priced and insured — it is a market object, not a proprietary opinion. Lenders do not need certainty; they need a number they can haircut against, and the difference between "custody risk, unquantified" and "custody risk, priced by a stated function of attested state" is the difference between collateral a bank discounts toward zero and collateral it lends against.
Decay is only half of Plane 3's question — "what does it owe or earn?" is the other half, and it is live state too. A coupon accruing, a premium due, rent flowing to fraction-holders, surrender value building inside a policy: today each of these is computed separately by every institution that cares, reconciled quarterly, and discovered to disagree. As entitlement state on the record, they are computed once by the entitlement engine, read by everyone, and paid as state changes — which is why Article 4 could describe a coupon as an entitlement event rather than a reconciliation project. The same engine generalises across classes the way the state machine does: coupon, premium, rent and claim are one mechanism with different profiles, and the decay adjustment is simply one more entry in it.
Keep the two decays straight and the planes' division of labour becomes obvious: freshness decay is Plane 2's clock firing Plane 1's triggers — it changes what the asset may do. Value decay is Plane 3's curve reading Plane 2's facts — it changes what the asset is worth. A design that muddles them either halts assets for losing a little value, or keeps mispriced assets trading — the two failure modes the current system alternates between.
The decay curve quietly redistributes who bears uncertainty. Today the lender bears it, blind, and prices it as a crushing discount on every honest borrower — the market Article 2 showed through Kwame, whose clean cargo paid the fraud premium of every duplicated receipt before his. With a published curve, uncertainty is carried where it can be managed: the attester carries observation risk (and insures it), the curve-publisher carries model risk (and defends it publicly), and the lender carries only priced, stated residual risk. Unpriced risk doesn't disappear from a market — it becomes a tax on the honest. Pricing it is how the tax gets repealed.
When the signature is wrong — the accountability perimeter
Stale is the easy failure: the machine handles it without anyone's judgment. Wrong is the hard one, and honesty about it is what separates a security model from a slogan. A false genesis assay creates a well-formed lie that then travels with all the fluency of the truth — Article 4 called this the garbage-in problem, and no cryptography fixes it, because the record faithfully enforces whatever it was told.
What the design does instead is concentrate the problem where it can be governed. In the old world, verification is diffuse: every counterparty re-checks everything, badly, at its own expense, and when fraud surfaces the liability dissolves into a fog of disclaimers — everyone checked, so no one is responsible. Here the structure is inverted. Verification happens once, at the record, by a party who is named, licensed, insured and liable — and because every attestation is signed and scoped, every attestation has exactly one signer. The security perimeter of the entire system is the attester's accountability, and the design spends its effort making that perimeter strong: role separation so a lie needs conspirators; financial liability and mandatory insurance so a lie has a price; licensing so a lie can end a business; and scheduled re-attestation so a lie must be re-signed, again and again, by a party aware that each signature compounds the exposure. A fraud that once required indifference now requires nerve.
And when a wrong or disputed attestation does surface, the response is a supervised path on the record, not an off-ledger scramble: the affected asset moves to S2a observation — placed there by the regulator, the one authority with that power — or to S3 restriction, because a raised dispute is itself a trigger the profile wires in. Either way trade is restricted or supervised without the holding being destroyed. The correcting attestation is a new signed fact appended to the same history; nothing is erased, so the record of being wrong — who signed what, when, and who caught it — is permanent, and feeds directly into the attester's standing. Contrast this with the paper world, where a false certificate is discovered in a lawsuit years later and the intervening chain of transactions has to be unwound by litigation. Here the blast radius is one asset, restricted within its cure window, with a named signer already on the hook.
What the planes cannot do
Limits, plainly. Attestation narrows the gap between record and world; it cannot close it. Sensors can be spoofed, assayers can be corrupted, and role separation raises the price of collusion without abolishing it — the claim is that fraud becomes expensive, attributable and self-limiting, not impossible. The freshness window is a dial, not an oracle: set it too long and drift returns; too short and attestation costs strangle thin-margin classes — tuning it per class is real operational judgment that no architecture removes. Decay curves are models, and models are wrong at the tails; a published wrong model is better than a private one only because it can be challenged before it is trusted. And the deepest limit was named in Article 4 and stands: the record is only as true as its first entry, and the genesis attestation — one signature, before any history exists to check it against — remains the single most consequential act in the life of the asset. The design surrounds that moment with licensing, liability and separation. It cannot make it infallible.
What remains, after the limits, is still the reversal that matters: every failure mode above has a named owner, a price, and a supervised correction path — where today's system offers diffuse checking, dissolved liability, and discovery by lawsuit. The planes do not promise a true record. They promise an accountable one, and accountable records are what financial systems are actually built on.
Plane 1 makes the asset governable. Plane 2 makes it real. Plane 3 makes it priceable. Remove any one and you rebuild a familiar failure: rules without truth, truth without value, or value without enforcement.
One piece of the design now remains. States, planes, attesters and curves describe what should be true and who says so — but something must make the asset physically incapable of disobeying its own state. That is the token layer: the standards that turn "restricted" from a flag someone should check into a transfer that cannot execute. The final article opens that box: the shapes of holding, the enforcement surface, and the stack that binds state to asset — making state enforceable.
- How real-world assets move today — the ecosystem problem
- Five people, five assets, one broken system — the problem made real
- Imagine the other world — financial Legos and the positions nobody can take today
- Nine problems, nine answers — what tokenization actually fixes
- Rules change. Should the asset? — the new problem tokenization creates
- The Universal Asset State Machine — Decibel Labs' answer
- One machine, five assets — the state machine tested against real asset classes
- Three planes — compliance, physical, economic (you are here)
- The Universal Asset Token stack — making state enforceable