Skip to content

Roles and permissionsLink to this section

TL;DRLink to this section

  • Counting work, authorizing settlement, paying gas, and displaying results are separate permissions.
  • An emergency pause stops settlement and new reward funding, not every owner action.
  • Upgrade administrators can change the work and reward contracts, so their decisions matter to owners.
  • Only the current NFT owner can claim its rewards; approving an NFT operator isn't enough.

What can an owner control?Link to this section

If you own a Miner NFT, you can transfer it and request eligible claims or merges. Ownership doesn't let you change sensor measurements, authorize settlement, or change reward rules. Giving an operator permission to manage an NFT doesn't give that operator permission to claim its SQK rewards.

Other roles handle those parts of the system. The Pi records accepted sensor passages, the Oracle checks signed records, and the Reporter signs permission to settle eligible work. A relayer submits that signed transaction and pays gas; it can't change what was authorized.

Who can stop or change the contracts?Link to this section

The Guardian can pause Core, stopping settlement and new reward funding through checkpoints. Already funded claims can still work because they don't call Core or mint SQK. Transfers, mint registration, and merges aren't blocked by the pause alone, though their other checks still apply.

Upgrade administrators have broader powers: through Timelock governance, they can change Core and Mining code. A malicious Mining upgrade could mint the remaining SQK supply without work or misuse funds held for rewards. The supply cap and governance delay don't prevent those outcomes.

Technical detail: roles and authorityLink to this section

Actor Responsibility
Pico and Pi Pass sensor readings to the Pi, which counts and saves accepted work
Oracle Check signed records, approve eligible rounds, and track settlement
Reporter Sign permission to settle an exact batch under Core's rules
Relayer Submit the signed transaction and pay Ethereum gas
Guardian Pause Core and change the Reporter while Core is paused
Timelock proposer/canceller Schedule or cancel governance operations
Timelock executor Execute a ready operation after its delay
Core and Mining ProxyAdmins Apply authorized contract-code upgrades
NFT owner Transfer NFTs and request eligible claims or merges
Indexer, API, and browser Display public data

PermissionsLink to this section

Authority Can do Cannot do
Oracle Accept, reject, quarantine, and audit telemetry; approve counter epochs through a recorded action Invent passages or settle work
Reporter Authorize an exact batch that advances settlement Change difficulty or bypass limits, nonce, deadline, or implementation checks
Relayer Submit a valid signed batch Change signed fields or authorize work
Guardian Pause/unpause Core; change the Reporter while paused Set difficulty, mint SQK, or directly upgrade contracts through this role
Timelock governance Authorize upgrades through the relevant ProxyAdmin Skip its delay through normal scheduling and execution
Mining Check work, request SQK, record NFT rewards, pay funded claims, and burn merge donors Exceed Token's lifetime cap
NFT owner Claim for 1–32 sorted, unique, live owned NFT IDs; merge eligible same-Level owned NFTs Claim using operator approval alone or skip activation and cooldown checks
Public observer Read APIs, events, and contracts Change measurements or authorize settlement

Anyone can submit a valid Core signature. That does not give them permission to authorize work.

GuaranteesLink to this section

Core administrative changes invalidate pending settlement signatures, and Core rejects previously used Reporter addresses. A settlement signature applies only to its exact batch, chain, proxy, and implementation.

Only Mining can call Token to mint SQK, and minted SQK goes only to Mining. Token has no owner, administrator roles, transfer pause, or upgrade mechanism.

AssumptionsLink to this section

Core and Mining upgrade administrators remain trusted despite the Timelock delay. A malicious Mining upgrade could mint the remaining SQK supply without work or misuse funds held for rewards; Token cannot enforce Mining's reward rules.

Measurement-host and hosted-service administrators remain trusted within their roles. Their credentials and recovery procedures are not public developer features.

Failure behaviorLink to this section

  • Paused Core rejects settlement, and Mining checkpoint reverts CorePaused.
  • Core pause alone does not stop claims, NFT transfers, mint registration, or merges.
  • Claims do not read Core or mint SQK, but still require NFT ownership and working Token payments.
  • Minting and merging check Core without processing rewards. If a required dependency fails, the transaction fails.
  • Unauthorized calls and invalid signatures fail without granting any permissions.