Orykto
VaultPositions
Whitepaper/Operation11 / 15Download PDF

How it operates

The structure has been set out part by part. This chapter runs it once as a whole (capital entering, deployed, earning, verified, paid, and leaving) and reads, at each junction, the same three things: what could fail there, the property of the structure that contains the failure, and the limit that remains after it is contained.

Entry

Capital enters through the Vault and takes a position in one of two pools, during a published open window. The Vault holds the interface, not discretion. It does not choose names and it does not hold money state. A contributor chooses the position, not the name.

An entry taken after the window has closed, or on terms quietly moved, is refused by the rail's own logic: deposit reverts past the close date with no operator action, and the terms of a position are immutable once set. What remains is a limit, not a promise: the window and the lock term are defined and published by the pool, and withdrawal before the term is not assured.

The position is recorded on the ledger before it is anything else, and proven against the on-chain anchor. The ledger is the source of truth; the chain is the proof.

Placement decides how the position is held. The senior pool holds the whole book to a modeled per-pool baseline, protected first by the book's own diversification and, where realized revenue falls short, by a finite support sequence (the partner's contractual support, then the Reserve as the last tier); the junior pool takes one name directly, with nothing standing ahead of it. Held as a book, each name's downside is isolated beneath the surplus the curve produces, so no single name can break the whole, and each pool is one contract, so one stuck pool never masks the others. The isolation belongs to the senior tier: the junior pool holds one name, principal at risk in full. Isolation bounds how far a single loss can reach; it does not remove the loss inside a pool.

Deployment and production

Once a position enters, the capital is deployed off-chain to fund the production cycle, committed for the term rather than held aside against it. The funded production earns revenue, settled off-chain in fiat over a recurring cycle; the revenue never touches operations, and the return is the realized revenue of the book, net of the cost of operating it.

The revenue is contingent and may fall short of the baseline. The floor does not depend on any single source holding: it is met by a fixed sequence (realized revenue, then the monetization partner's support, then the Reserve), the partner standing ahead of the Reserve, so a partner shortfall advances to the next buffer rather than to capital directly. The baseline is modeled, not assured; if the sequence is exhausted the floor can be missed, and Stable capital then bears the shortfall. Until the Reserve is reached, the senior baseline depends on the partner's contractual standing.

One limit here the structure cannot design away. During operation the principal is off-chain, deployed into production, for the lock term; if it is not re-funded, only what remains in the contract can be distributed. The path is not fully trustless, and is not described as if it were.

Settlement and the ledger

Each cycle, revenue is verified before it is paid. The order is not reversed, and nothing is paid against revenue that has not been verified. What guards the payment is not an oracle reporting a number; the chain cannot perform the verification. Settlement is a real movement of money and then a snapshot of the balance it leaves: the realized revenue must already sit in the account, the call is automated and the funding is not, and the truth is the balance. The limit is exactly that human step: the chain records the result, it does not produce the revenue behind it.

Beneath every step is the ledger, double-entry, append-only, holding every position and movement. Money state lives here, and only here. A fact the books cannot explain refuses to post and alarms. Append-only contains revision: the ledger cannot be rewritten behind a published anchor. What it proves is the internal consistency of the record, not the truth of the world behind it. That is verification's job.

A periodic Merkle root of the ledger is anchored on-chain, and anyone can check that the published state matches the anchored root. The anchor proves consistency, not solvency: it shows the published state is the state that was committed, unaltered behind the root. What the chain cannot prove on its own (the off-chain revenue that backs the state) it hands forward to Proof. The chain is a dependency, not an infallible oracle.

How loss is borne

Distribution follows the order set out in How loss is borne. The two pools do not share a loss line. A junior position meets its name's loss directly, with nothing standing ahead of it. The senior baseline is protected first by the book's own diversification, then by the finite support sequence behind it (realized revenue, then the partner's support, then the Reserve); that support order is fixed, outside governance, which cannot reach it at all.

The Reserve is finite and can be exhausted; once it is, the Stable baseline can be missed and its capital is at risk. A junior position was fully exposed from entry, with nothing ever standing ahead of it. Capital in any tier can be lost in part or in full. The structure isolates risk; it does not remove it.

Exit

A position is redeemed on the terms of its pool at the end of its lock term, settled against the ledger and proven on-chain: it leaves the way it entered, recorded first, proven second. The senior pool is always-open once the term is met; the junior pool is window-bound.

Under stress, redemption may be gated. Gating preserves the order in which the structure pays. It does not move any position ahead of another, and it does not draw a pool's principal to meet a redemption. The limit is the one deployment already named: withdrawal before the term is not assured, and if it is not re-funded, only what remains in the contract can be distributed.

One property

Read one junction at a time, each of these is a separate safeguard: recording before proving at entry, an interface without discretion, actors bounded to their function, a support order no cycle re-orders, verification before payment, an append-only ledger beneath it all. Read across the whole sweep, they are one property under different names: at every junction the failure is bounded by the shape of the structure rather than by trust in the party standing at it, and at every junction the bound is stated together with the limit it does not cross. The structure does not ask any actor to be trustworthy at the moment it matters.

That is the whole of what the structure claims for itself, and the heaviest limit travels with it: during operation the principal is off-chain, deployed into production, for the term. It does not change whether loss can happen; it changes where loss lands. The senior position's return is drawn from holding the whole book across the curve (the surplus the many names carry together), never from any single name; a junior position takes one name for what that name returns.

Returns come from the curve, not the bet.