Keys, thresholds and blast radius.
Every control in chapter 01 is exercised by a signing key. Bantu supports native account-level multisignature governance — co-signers, weighted signing, and separate thresholds for low-, medium- and high-risk operations — without relying on a smart contract to implement any of it.
Institutional N-of-M, natively.#
An institution can add co-signers, assign signing weights and set thresholds for operations of differing risk. Dual control, four-eyes approval, segregation of duties, treasury approval hierarchies, HSM or MPC signing workflows, board-level approval for high-risk actions, independent compliance approval for freeze or clawback, and disaster-recovery key structures are all expressible as account configuration.
- Customer trustline approvalCompliance key with low threshold1
- Routine treasury transferOperations plus treasury approval2
- Asset issuanceMulti-party high threshold3
- Freeze or clawbackCompliance, risk, legal and treasury approval4
- Change issuer policiesSenior governance or board-controlled threshold5
- Emergency recoveryPre-defined disaster-recovery multisig arrangement5
Separate what creates value from what moves it.#
A secure Bantu deployment separates the account that creates the asset from the accounts that distribute, control and trade it. The primary issuance authority can remain offline and inaccessible to routine business operations, which limits operational exposure to the accounts that are necessarily online.
Creates the regulated asset. Offline or highly restricted; kept out of routine business operations.
Customer issuance, redemption, liquidity, treasury distribution and settlement.
Trustline authorization, freezes and customer access controls.
Controlled by institutional multisignature policy.
Market making, FX routing and settlement operations.
It completes in full, or it fails in full.#
A Bantu transaction can contain multiple operations — payments, asset exchanges, trustline changes, signer changes and order-book operations. The transaction either completes entirely or fails entirely. There is no partially applied state to detect, reverse or reconcile.
- Delivery-versus-payment
- Payment-versus-payment
- FX settlement
- Simultaneous debit, conversion and credit
- Redemption and asset burn
- Conditional treasury releases
- Controlled disbursement workflows
Claimable balances.#
An asset can be held on ledger for defined claimants under specified conditions, with claimant conditions enforced by the protocol rather than by an intermediary. Creation and claiming are native operations.
- Escrow
- Conditional merchant settlement
- Payroll disbursement
- Grant or aid distribution
- Refund workflows
- Supplier-payment release
- Time-bound claims
- Inheritance or recovery procedures
- Settlement pending compliance approval
Sponsored reserves.#
One account can sponsor another account's ledger reserve requirements — including accounts, trustlines, signers, offers, data entries and claimable balances. A bank, PSP, government or wallet provider can therefore pay the network-reserve cost on behalf of end users.
Pays the ledger reserve for accounts, trustlines and claimable balances it creates on behalf of users.
Holds a zero balance of the network asset and still transacts normally in the regulated asset.
Removes the requirement for a retail customer to source a network token before receiving money.
Who watches the ledger.
Custody structure determines who can act. Chapter 03 documents who can see — the AML operating model, the audit trail exposed through the Expansion API, and what a supervisor can monitor without privileged access to any institution's systems.