@Dusk_Foundation

I expected KYC on-chain to work roughly the way it does everywhere else.

Submit your identity once per service, and that service now holds a copy of who you are.

Citadel made me rethink that.

A user gets verified once by a License Provider, which issues a license. From there, a Service Provider can check whether that license is valid without seeing the identity behind it.

I'd been picturing something closer to a password manager. One credential, reused everywhere, still recognizable as belonging to the same person every time someone checks it.

That's not what's happening.

Two different services checking the same person's license can't tell they're looking at the same person. Each verification is unlinkable from the next, even though they're checking the same underlying license.

So the interesting claim isn't simply “your data stays private.”

It's that repeated compliance checks don't have to create a trail connecting those checks together.

That changes the trade-off.

Independent KYC at every service is repetitive and expensive, but each service controls its own verification. Citadel removes that repetition by making the License Provider the party that establishes the original license.

Even recovery follows that architecture: restoring the wallet from its seed phrase is enough to recover the licenses, without requiring the user to maintain a separate license backup.

The downstream experience gets simpler and more private.

But the trust question moves upstream.

What I still don't know is how a License Provider earns that role in the first place, or whether the compliance burden that used to sit with every individual service has really disappeared—or simply moved one layer up.

$DUSK only becomes interesting to me here once I understand who can become a License Provider, and what keeps that role from becoming the new central point of failure.

#dusk