Tutoring incoming students, the hardest part is always keeping two related ideas from blurring into one in someone's head. Reading through Dusk's privacy stack this week gave me the same problem.

Citadel and Dusk's confidential transaction layer solve different questions that sound like the same question. Citadel is about proving who you are: age, residency, accreditation, issued and verified through a self-sovereign identity toolkit, so you can prove you qualify for something without handing over your full ID. The transaction layer, through Moonlight and Phoenix, is about proving what you did was compliant: ownership limits, transfer eligibility, verified without exposing the raw transaction data to the public.

Put together, that's the actual claim behind "programmable privacy": one proof for identity, a separate proof for behavior, neither one requiring the other to go fully public to satisfy a regulator who's actually authorized to check.

What I keep turning over: identity requirements aren't the same across jurisdictions, what counts as sufficient proof of residency or accreditation in one regulatory regime isn't automatically what another one asks for. I haven't seen how flexible Citadel's license issuance actually is when the attribute a regulator wants isn't one of the ones already defined. That's less a privacy question and more a "how many regulators can this actually serve at once" question.

#dusk $DUSK @Dusk