There’s a particular awkwardness that appears when the same person both prepares the numbers and signs off on them. It runs fine until a small inconsistency shows up, and then the room goes quiet because no one else holds the context to challenge it.

That quiet cost of collapsing two jobs into one feels ordinary. It only becomes noticeable once something actually needs checking.

A financial network runs into a version of the same shape. Nodes agreeing on transaction order is necessary, but it does not answer who is allowed to hold a given asset, or which parties may later see which attributes. Settlement and eligibility are different functions. Treating them as interchangeable leaves a gap that pure consensus does not close.

On Dusk the settlement side is carried by provisioners under Succinct Attestation. One provisioner proposes the block; a separate committee validates; another ratifies. That already splits duties inside consensus. The financial layer needs something further. Citadel brings in License Providers who issue credentials off-chain and register them, and Service Providers who later accept zero-knowledge proofs of those credentials without learning the underlying attributes. The on-chain contract verifies only that a valid, non-revoked license exists and that the proof is correctly formed. It does not decide whether the original License Provider performed its checks correctly.

If that credential layer fails, a transfer that looks perfectly valid to the provisioners can still be blocked at the application level. The network verifies the cryptographic proof. It still has to assume the quality of the off-chain issuance step.

I’m not sure yet how heavy that assumption becomes once real regulated flows start moving through it.

#dusk $DUSK @Dusk $BTC
⛓️ Consensus
Credential issuers
🏦 Service providers
12 heure(s) restante(s)