TiedTo — Platform Spec v3.1

Two layers: the off-chain app runs business and admin operations; the chain is the source of truth for claims. The server holds no signing keys — every write is a Safe transaction signed by humans.

Platform structure

Off-chain layer

operations

On-chain layer

source of truth
PlanCatalogOwner Safe · timelockedaudience · seatLimit · platformsPerSeat · duration · kind — limits derived, never caller-supplied
RoleCatalogOwner Safe · timelockeduint8 indices, tags immutable — renames map label, records never rewritten
ClientRegistryAdmin Safe onlyregister · subscription · suspend · revoke · setClientAdmin — expiry derived on read
PersonRegistryclient admin SafesaddPerson · addBinding · revoke · releaseSeat — generic lookup per (platform, chatId)
never on-chain: legal names · KYC/KYB documents · emails · usernames · payment details · rep wallet addresses

Trust roles

Admin Safe — operational

2-of-3 TT operators
  • register clients, update subscriptions
  • suspend / revoke clients
  • set client admin wallets

Owner Safe — constitutional

TT owners
  • plan & role catalogs, parameters
  • add/remove Admin Safe signers
⏱ required timelock — public delay (e.g. 48h) so every change can be reviewed

Client admin wallets

per-client, scoped
  • add persons / bindings — own namespace only
  • revoke — fail-closed: turns trust off, never fabricates it
  • custodial plans: isolated per-client Safe, signer set separate from Admin Safe

Three client types, one path

CompanyTeamIndividual
AnchorDomain TXT + KYBDomain TXT, no KYBPublic anchor (token post, snapshotted)
GateKYB off-chainDomain + 2-of-3 review; every member private-KYC'dPublic anchor + private KYC gate (anti-sybil, never displayed)
BillingSeats (persons)No seats — per-member individual plansPer-person plan
TYPE on cardCOMPANYTEAM — never readable as a KYB'd companyINDIVIDUAL
ClaimFull (wallet) / reduced (custodial)Domain-anchored, explicitly no-KYBAnchor-verified, alias-only — the anchor is the claim, KYC is the gate

Seat model — a seat is a person

seatsUsed is increment-only within a term. Revocation never silently frees a seat.

Flows

FLOW A / A2 / A3

Onboarding — one path, one flag

  1. Gate: KYB (company) · domain TXT (team, +2-of-3) · anchor + KYC gate (individual)
  2. Payment verified: tx hash + unique amount
  3. Admin panel builds registerClient — 2-of-3 sign, Admin Safe executes
  4. Real client record for all three types — no null clientId
FLOW C

Add a person

  1. Client admin creates person: name, role from catalog
  2. Per-platform invite links — holder starts each from their own account; stable chatId recorded
  3. One signature activates the whole person — neither admin nor TT alone can produce an active record
FLOW D

Revoke

  1. revokeBinding (left one platform) or revokePerson (left the org)
  2. Seat NOT returned within the term; optional fee-gated releaseSeat
  3. History kept forever — status visible on-chain
FLOW E

Customer check

  1. Forward a message to the official bot — anti-phishing by design, never link-following
  2. Card: TYPE · Namespace · frozen name + live handle (divergence flag) · User ID · Status · explorer link
  3. Unknown account → NOT IN NETWORK — never "scammer"

Security model — what compromise means

CompromiseAttacker gets
Backend serverDoS + wrong cached data — detectable via explorer links. Cannot register, add, or revoke: no TT key exists on the server
One admin signerNothing — Admin Safe needs 2-of-3
Admin Safe (2-of-3)Can onboard fake clients. Cannot fabricate persons for wallet-plan clients; custodial clients isolated behind a separate signer set
Owner SafeFull parameter control — mitigated by timelock
Client admin walletAdds within remaining seats (billing-limited) + revoke. Fail-closed: turns trust off, never fabricates unlimited trust
Team domain DNS / individual anchorPasses TXT / token post for that namespace only — mitigated by similarity screening, cross-reference review, 2-of-3, private KYC

TT never claims a representative is honest. TT proves: this communication account was authorized by this client, and that authorization is currently active.