Skip to main content

Decision

OpenZeppelin Governor whose voting weight is an operator’s delivered bytes over a trailing window — not TOKEN balance — with a 4% quorum and a 2-day timelock. All governable parameters have hardcoded safety bounds that governance cannot override. A 3-of-5 emergency multisig can pause contracts, add emergency blacklist entries, decide slash appeals, and suspend a compromised regional governance body. Its sunset is split by capability: the protocol-wide pause() brake has a 12-month sunset enforced via an immutable constructor deadline — governance cannot extend it; prolonging pause() past the deadline requires deploying a new contract version and migrating through the standard upgrade path. The narrow unlawful-content-removal power — emergency blacklisting — is permanent, discharging an ongoing legal-compliance duty the ~10-day governance cycle cannot meet.

Voting weight

Voting weight is each operator’s served bytes over a trailing window (default ~1 quarter, governable), scaled by a tenure ramp and capped per operator (default 5% of the window’s bytes). Bytes are counted a week at a time, and each week’s count is additionally capped at what the capacity the operator declared that week could physically have delivered.
  • Passive TOKEN holders have no vote. Governance power tracks real delivery, not holdings — you must operate a node and serve bytes to vote.
  • Fresh operators ramp in. A new operator that serves heavily on day one still votes at a fraction of its byte share until the tenure ramp completes over several months.
  • Declared capacity caps weight; it never grants it. Bytes above what an operator’s declared tier could deliver in a week earn no weight, and an operator that declared zero capacity contributes zero for that week however many bytes it served. This is what stops a lightly-bonded operator inflating its weight by serving traffic to accounts it controls.
  • Slashing zeroes out the vote. A slashed operator’s weight drops to zero for the rest of the window, then recovers as the window slides past the slash.
Bytes are read from the on-chain FeeRouter settlement counter, so weight is auditable and cannot be claimed without paid delivery. Voting power is delegable by signed message; the bond itself is not.

Launch phase

Served-bytes DAO voting only activates once the operator set is large enough to make it safe. Until then — the first 6–12 months post-launch — a 5-of-9 bootstrap multisig (distinct from the emergency multisig) operates the protocol within the same safety bounds. The multisig never holds governance authority directly: the timelock holds it from deployment onward, so the 2-day delay applies to every parameter change regardless of who requested it. What the bootstrap phase confines is the right to schedule. The phase ends when the multisig judges the operator set broad and diverse enough — a manual decision, not a threshold that trips on its own. It schedules a single timelock batch granting the Governor the right to propose and cancel, then revoking its own. Executing that batch strips the multisig’s ability to schedule anything, including a proposal restoring itself, so the transition is irreversible: only the inheriting DAO could hand the role back, by its own vote.

Hardcoded safety bounds

Even governance cannot set parameters outside these bounds: The three FeeRouter shares must sum to exactly 100% on every update. The burn share is the one that also accepts zero, so the buyback sink can be switched off entirely; what it cannot be is nominally on at a negligible share — either off, or at 5% or more. Bounds are enforced in require() checks in the setter functions. A malicious governance proposal that attempts to push the operator revenue share below its floor simply reverts. (The 5% / 15% / 50% slash ladder is a fixed constant in the bond contract, not a governable parameter — see slashing.)

Emergency multisig

3-of-5 signers. Limited to:
  • Pause any contract (Pausable)
  • Add emergency blacklist entries (with 14-day auto-expiry or 90-day for CSAM/terrorist categories — see takedown)
  • Decide slash appeals — fast-track or reject an open appeal; the escrow movement itself is performed deterministically by the bond contract
  • Suspend a regional governance body — governance must ratify or reverse within 14 days, and silence lapses the suspension rather than sustaining it
Can not:
  • Move funds
  • Change parameters
  • Grant roles
The sunset is split by capability, and the split is structural rather than a shared clock. The 12-month deadline attaches to pause() alone: every pausable contract fixes it as an immutable at its own construction, after which pause() reverts for every caller — governance included. The pause is the protocol-wide brake and the most centralization-sensitive power the multisig holds, so it is the one that expires. The other three capabilities carry no deadline. Emergency blacklisting (emergencyAdd, emergencyAddOrigin) and the regional-body suspension backing it live on the non-pausable blacklist contract, discharging a permanent, time-critical legal duty — CSAM, court-ordered and sanctions removal — that the ~10-day governance cycle cannot meet, and touching no economic, treasury or governance lever. Deciding slash appeals likewise never expires; it moves only already-escrowed funds along deterministic grant/uphold paths. Governance cannot modify the pause() deadline; retaining pause() past the sunset requires deploying a new contract version with a new deadline and migrating to it via the standard upgrade path (timelock + governance vote). This guarantees the sunset cannot be silently extended.

Proposal flow

  1. Proposer’s served-bytes weight ≥ the proposal threshold.
  2. propose() with target, calldata, description.
  3. Voting period (default 7 days, after a 1-day voting delay).
  4. Quorum check — 4% of total delivered bytes in the trailing window.
  5. Queue in timelock (2 days).
  6. Execute.
The combined ~10-day minimum delay (voting delay + 7-day period + 48-hour timelock) is deliberately longer than the OpenZeppelin Governor defaults, reflecting operator-class participation cadence.

Why 4% quorum

Low enough that realistic participation can reach it — voting weight tracks active service delivery rather than circulating supply, so a bar calibrated against holdings would quickly exceed engaged voting power. Quorum is not the concentration defense and is not sized as one: the per-operator cap is what bounds any single operator. The hardcoded safety bounds do the rest — even a captured vote can only move parameters within the safe range.

Regional governance bodies

Content takedown introduces regional governance bodies with region-scoped blacklist authority. This is the only role that’s partitioned by jurisdiction; all other roles are single-tier global governance.