Roles and permissionsLink to this section
TL;DRLink to this section
- Counting work, authorizing settlement, paying gas, and displaying results are separate permissions.
- An emergency pause stops settlement and new reward funding, not every owner action.
- Upgrade administrators can change the work and reward contracts, so their decisions matter to owners.
- Only the current NFT owner can claim its rewards; approving an NFT operator isn't enough.
What can an owner control?Link to this section
If you own a Miner NFT, you can transfer it and request eligible claims or merges. Ownership doesn't let you change sensor measurements, authorize settlement, or change reward rules. Giving an operator permission to manage an NFT doesn't give that operator permission to claim its SQK rewards.
Other roles handle those parts of the system. The Pi records accepted sensor passages, the Oracle checks signed records, and the Reporter signs permission to settle eligible work. A relayer submits that signed transaction and pays gas; it can't change what was authorized.
Who can stop or change the contracts?Link to this section
The Guardian can pause Core, stopping settlement and new reward funding through checkpoints. Already funded claims can still work because they don't call Core or mint SQK. Transfers, mint registration, and merges aren't blocked by the pause alone, though their other checks still apply.
Upgrade administrators have broader powers: through Timelock governance, they can change Core and Mining code. A malicious Mining upgrade could mint the remaining SQK supply without work or misuse funds held for rewards. The supply cap and governance delay don't prevent those outcomes.
Technical detail: roles and authorityLink to this section
| Actor | Responsibility |
|---|---|
| Pico and Pi | Pass sensor readings to the Pi, which counts and saves accepted work |
| Oracle | Check signed records, approve eligible rounds, and track settlement |
| Reporter | Sign permission to settle an exact batch under Core's rules |
| Relayer | Submit the signed transaction and pay Ethereum gas |
| Guardian | Pause Core and change the Reporter while Core is paused |
Timelock proposer/canceller |
Schedule or cancel governance operations |
Timelock executor |
Execute a ready operation after its delay |
Core and Mining ProxyAdmins |
Apply authorized contract-code upgrades |
| NFT owner | Transfer NFTs and request eligible claims or merges |
| Indexer, API, and browser | Display public data |
PermissionsLink to this section
| Authority | Can do | Cannot do |
|---|---|---|
| Oracle | Accept, reject, quarantine, and audit telemetry; approve counter epochs through a recorded action | Invent passages or settle work |
| Reporter | Authorize an exact batch that advances settlement | Change difficulty or bypass limits, nonce, deadline, or implementation checks |
| Relayer | Submit a valid signed batch | Change signed fields or authorize work |
| Guardian | Pause/unpause Core; change the Reporter while paused |
Set difficulty, mint SQK, or directly upgrade contracts through this role |
Timelock governance |
Authorize upgrades through the relevant ProxyAdmin |
Skip its delay through normal scheduling and execution |
Mining |
Check work, request SQK, record NFT rewards, pay funded claims, and burn merge donors | Exceed Token's lifetime cap |
| NFT owner | Claim for 1–32 sorted, unique, live owned NFT IDs; merge eligible same-Level owned NFTs | Claim using operator approval alone or skip activation and cooldown checks |
| Public observer | Read APIs, events, and contracts | Change measurements or authorize settlement |
Anyone can submit a valid Core signature. That does not give them permission to authorize work.
GuaranteesLink to this section
Core administrative changes invalidate pending settlement signatures, and Core rejects previously used Reporter addresses. A settlement signature applies only to its exact batch, chain, proxy, and implementation.
Only Mining can call Token to mint SQK, and minted SQK goes only to Mining. Token has no owner, administrator roles, transfer pause, or upgrade mechanism.
AssumptionsLink to this section
Core and Mining upgrade administrators remain trusted despite the Timelock delay. A malicious Mining upgrade could mint the remaining SQK supply without work or misuse funds held for rewards; Token cannot enforce Mining's reward rules.
Measurement-host and hosted-service administrators remain trusted within their roles. Their credentials and recovery procedures are not public developer features.
Failure behaviorLink to this section
- Paused
Corerejects settlement, andMiningcheckpointrevertsCorePaused. Corepause alone does not stop claims, NFT transfers, mint registration, or merges.- Claims do not read
Coreor mint SQK, but still require NFT ownership and workingTokenpayments. - Minting and merging check
Corewithout processing rewards. If a required dependency fails, the transaction fails. - Unauthorized calls and invalid signatures fail without granting any permissions.