Governance
Reviews the structures and controls governing protocol upgrades, token issuance, and parameter changes. The assessment is decomposed into four dimensions covering who can change the protocol, who can issue tokens, how privileged roles are composed and disclosed, and how much time elapses between approval and execution of critical actions.
Contract Upgradability Permissions
Evaluates who holds the authority to change deployed contract code. Upgrade authority is the protocol's root authority, so the concentration and transparency of upgrade rights is the primary input.
Mint Authority Permissions
Evaluates who can issue new tokens and under what constraints. The number of independent parties required to authorize issuance, and whether issuance is constrained at the contract level, are the primary inputs.
Signer Composition, Role Documentation, and On-Chain Verifiability
Evaluates whether privileged roles are independently composed and externally verifiable. A nominal threshold carries information only if signer independence and role assignment can be confirmed by an outside observer.
Timelock Duration on Critical Actions
Evaluates the delay between approval and execution of upgrades and mint actions, and whether that delay is actively monitored. The timelock is the user's exit window before contested actions occur.