#dusk $DUSK @Dusk

Kept running into the same word across a dozen different Dusk docs without ever actually reading what it DOES.

CITADEL.

Always mentioned in passing, always in a components table, but never explained on its own.
Finally sat down and read the actual identity protocol paper this weekend instead of skimming past it again for other topics in DUSK.

Most compliance checks work the blunt way. Prove you're accredited, hand over your entire financial history.
Prove you're old enough, hand over your full date of birth and government ID.
The system only needed one fact.
It gets your whole file instead.
Citadel is built around a narrower idea:
prove the specific attribute, not the document behind it.
Residency, age bracket, accreditation status, whatever a given workflow actually requires.

The Credential gets issued once, and after that you're proving a fact about yourself without handing over the paperwork that fact came from.
The part that took me longest to actually get: this isn't the same thing as a shielded transaction.

Phoenix hides TRANSACTION details.
Citadel hides IDENTITY details.

But still produces something a license contract can check and accept before letting you do whatever the workflow requires, staking, holding a regulated asset, whatever gate it's sitting behind.

Once I saw that distinction, the earlier posts clicked into place differently.
Selective disclosure for transfers is one problem.
Selective disclosure for the person doing the transfer is a Separate one, Sitting underneath it.

Same underlying design decision, two totally different pieces of a workflow.

But there's still a Question I want to Ask.
Is proving an attribute without the document actually stronger privacy, or does it just move the sensitive part somewhere else, to whoever issued the credential in the first place?