Legal structure and operating risk
Which layer has an addressee and which does not — and why a 3-of-5 multisig says nothing yet about key management.
This lesson has had no expert review. It was written for this platform and against the evidence it cites; nobody has gone through it independently.
Learning objectives
- You can separate the three layers of an institutional on-chain position and assign each its addressee.
- You can name what a multisig threshold leaves unstated.
- You can separate technology risk from market risk even when both materialize on the same day.
Check your prior knowledge
Answer these for yourself before reading on. Wherever you hesitate is where this lesson pays off.
- Which legal person in your organization would hold the position?
- Which service providers sit between your order and its execution today?
- Who may revoke an authorization in your organization, and how fast?
Core concept
Three layers, two addressees
An institutional on-chain position has three layers: the vehicle holding it (a legal person with articles, governing bodies and supervision), the service providers in between (custodian, signing hardware, RPC and indexing providers — each under contract), and the protocol itself. The first two layers have addressees: someone carries an obligation. The third usually has none. Conflating the layers means looking for contractual duties where there is no contracting party.
A threshold is not yet key management
“3-of-5” describes a condition in the contract, nothing more. What stays open: where do the five keys physically sit? Do they all come from one hardware vendor? Are two holders in the same room? How is a key revoked when a holder leaves the organization, and how long does that take? Those questions decide whether the threshold holds when it matters — the contract answers none of them.
Outsourced means relocated, not removed
Between the decision and the chain sit providers that rarely appear in the risk register: the RPC endpoint used for reads and sends, the indexer the reporting is built on, the signing hardware. A service contract typically governs availability, not correctness: an endpoint serving stale data is available. Whether that case is covered has to be checked in the contract — it cannot be assumed.
Two causes, one day
When a position loses money on a day the indexer was also down, two causes are in play and they belong apart: the market loss would have happened regardless; the outage cost the ability to see it in time. Only separating them leads to a usable action — one calls for a different position size, the other for a second data path.
Definitions
- Vehicle
- The legal person that holds a position and to which the supervisory obligations attach.
- Threshold signature in the glossary
- A rule under which a transaction becomes valid only with a minimum number of signatures.
- RPC endpoint in the glossary
- The interface through which an application reads a chain and sends transactions to it.
Model
Vehicle — legal person, governing bodies, supervision: addressee present
Service providers — custody, signing, data: addressee by contract
Protocol — mechanism plus governance: usually no addressee
Consequence: claims stop at the second layer
Formulas
What an m-of-n threshold states
able_to_act if reachable_keys >= m ; externally_controlled if controlled_keys >= m- m
- Number of signatures the contract requires
- n
- Total number of keys issued
- reachable_keys
- Keys whose holders can actually sign in time
- controlled_keys
- Keys that could be controlled by the same party
Limit: The formula counts keys, not their independence. If all n keys come from one vendor, sit in one building or rest with one provider, the effective number of independent holders can be far below n — while the threshold stays formally unchanged.
Worked example
A threshold that carries less than it appears to
- Threshold
- 3 of 5
- Hardware
- all five devices from one vendor, same firmware version
- Locations
- three holders at the same site
- Revocation process
- documented, last rehearsed 14 months ago
Formally m = 3, n = 5. Measured against independent failure sources: one firmware defect touches all five devices at once, one site outage touches three holders at once — exactly the threshold.
The threshold is effective against a single dishonest holder and ineffective against a common vendor defect.
Reading: The number “3 of 5” is correct and still misleading as long as the independence of the five is not documented alongside it. The action follows directly: a second vendor, a second site, a rehearsed revocation — not a higher threshold.
Retrieval
Exercise on real data
Read the guiding questions and mark which of them a service contract can answer and which only the protocol itself can.
Dimension 3: technology →Application
Write the custody-control line for an operations manual so an auditor can follow it without a follow-up question.
Related case studies
Institutional reading
- Bank
- In which risk register does an RPC provider outage sit today?
- Insurance
- Would a key loss caused by a vendor defect be a covered event or an excluded one?
- Advisory
- Which of these items would you commit to a client in writing?
Key takeaways
- The vehicle and the service providers have addressees; the protocol usually does not.
- An m-of-n threshold counts keys, not their independence.
- Availability commitments do not cover correctness — that is in the contract or nowhere.