Governance as a rating modifier
Reviews the structures and controls governing protocol upgrades, token issuance, and parameter changes. The assessment is decomposed into four dimensions covering who can change the protocol, who can issue tokens, how privileged roles are composed and disclosed, and how much time elapses between approval and execution of critical actions.
Contract upgradability permissions
Who holds authority to change deployed contract code, and how concentration and transparency of that authority affect the rating.
Mint authority permissions
Who can issue new tokens and under what constraints, including how many independent parties must authorize issuance.
Signer composition and role verifiability
Whether privileged roles are independently composed and externally verifiable. A signing threshold means little without signer independence.
Timelock duration on critical actions
The delay between approval and execution of upgrades and mints, and whether it is monitored. The timelock is the user's exit window.