ProtoLedger Money Standard
A Two-Layer Standard for Evaluating Money and the Systems That Issue It
Fitness for purpose, at a stated readiness · Outcome-scored · Evidence-graded · Tail-aware · Value-disclosed · Falsifiable.
The M×S grid glyph (§VI.7): two scales, never summed.
What this is
A two-layer instrument for evaluating money and the systems that issue it. Layer A — Monetary Fitness asks whether a thing works as money for its users. Layer B — System Soundness asks whether the system behind it is sound. The two are scored on their own 0–10 scales and reported as a pair — never added, never blended.
Every property is scored on its outcome, not its mechanism; every score cites evidence of a named tier; reliability claims are scored on the tail, not the average day. Genuinely contested choices — privacy, personhood, issuance ethic, autonomy — are disclosed, never scored. And the Standard is falsifiable: §XII defines how any omission can be demonstrated and incorporated.
7 Layer A properties · 10 Layer B properties · 8 Layer C disclosure axes · 5 use-case archetypes.
Layer A — Monetary Fitness
Does it work as money?Acceptability & Liquidity
Counterparties will take it, and it can be entered or exited at scale without large loss. The master property.
Evidence & detail →Value Stability
Predictable purchasing power over the relevant horizon. Short-horizon (unit-of-account) and long-horizon (store-of-value) figures reported separately. Tail-scored.
Evidence & detail →Usability & Safety
A non-expert can hold and transfer it without specialised skill, and survive error, loss, theft, and fraud without catastrophe.
Evidence & detail →Portability & Divisibility
Moves and splits cleanly at the scale and speed of real transactions, including across borders.
Evidence & detail →Fungibility
Units are interchangeable in practice; no unit carries history that degrades its acceptance. Scores the observed outcome, not the privacy design (see Layer C).
Evidence & detail →Recognizability
Easy for an ordinary holder to authenticate; hard to counterfeit. For digital instances: hard to spoof — fake tokens, ticker confusion, look-alike contracts, address poisoning, and phishing rank here.
Evidence & detail →Cost Efficiency & Capacity
Low cost to transact and to hold at the declared archetype's scale — not merely at today's load. Cost at current load is not capacity at target load.
Evidence & detail →Layer B — System Soundness
Is the system behind it sound?Supply Integrity
No privileged party can quietly dilute holders; the issuance rule is known and hard to change. A fixed cap is not required — a rule-bound elastic supply qualifies.
Evidence & detail →Settlement Assurance
Confirmed transactions stay confirmed and behave as promised; no silent reversal, no double-spend. Tail-scored.
Evidence & detail →Resilience, Liveness & Capacity
Keeps settling — at usable capacity — through attack, outage, partition, and the failure or coercion of any single operator. (Liveness outcome: "does it keep running?")
Evidence & detail →No Single Point of Control
No one party can unilaterally rewrite state, censor transactions, seize funds, or gate participation arbitrarily. Includes resistance to cheaply manufactured consensus identities. (Integrity/censorship outcome.)
Evidence & detail →Rule Auditability
Anyone can independently verify the rules and the current state.
Evidence & detail →Forward Security Margin
Cryptographic and economic assumptions have headroom against foreseeable threats. Post-quantum readiness is one case, not the whole line.
Evidence & detail →No Invisible Rent
Operators cannot skim value from transaction ordering, position, or privileged information. The outcome that MEV-resistance targets.
Evidence & detail →Capture-Resistant Rule-Change
The rules for changing the rules are explicit and resist takeover by any single faction.
Evidence & detail →Resource Proportionality
Running cost is proportional to the value secured; no waste for its own sake. Mechanism-agnostic.
Evidence & detail →Claim Enforceability
Where the money is a claim on an issuer or custodian: the claim is legally enforceable, the backing is bankruptcy-remote, and redemption works in practice — including on a bad day. Tail-scored. Bearer instances with no claim structure: N/A by design, with the argument logged.
Evidence & detail →Layer C — Disclosed, not scored
Contested values & mechanism factsThese are genuinely contested or purely descriptive. The Standard records a position and discloses it; it never marks a position "wrong" or awards points for it.
Privacy posture
contested valueFrom fully transparent, through fungibility-grade privacy, to total untraceability. (The outcome side — whether units are in fact discriminated — is scored in A5.)
Identity / personhood model
contested valueAnonymous → pseudonymous → verified unique human. Flagged dual-use: a personhood proof is at once a freedom tool and a powerful instrument of control.
Issuance ethic
contested valueFixed cap, rule-bound elastic, work-based, egalitarian mint, or pre-allocated.
Autonomy ⇄ Accountability
contested valueIndependence from issuer or state versus recourse, consumer protection, and legal acceptability.
Consensus / cost mechanism
mechanism factProof-of-Work, Proof-of-Stake, BFT, institutional, or none.
Governance model
mechanism factOssified, on-chain vote, or institutional — with its characteristic capture surface named: sclerosis, plutocracy, or opacity.
Jurisdictional posture
mechanism factIssuer/operator jurisdictions, applicable regimes, and known legal constraints on holders by region. (Whether a redemption claim is enforceable is scored in B10.)
Catastrophic failure modes
mechanism factThe named worst cases for this instance — depeg, bridge failure, custodian insolvency, 51% capture, protocol bug class — with the tail-scored properties they feed (A2, B2, B10).
Archetypes & gates
The same subject scores differently across use-cases; that divergence is information, not noise. Each archetype names conjunctive gates that cap the verdict unless all hold.
| # | Archetype | Evaluated for | Gates (verdict capped unless all hold) |
|---|---|---|---|
| A | Daily Medium of Exchange | Retail payments and remittances: low friction, stable enough to price a coffee, safe for non-experts. | A1 ≥ 7 and A3 ≥ 7 |
| B | Long-Horizon Store of Value | Savings and reserve: supply integrity, resilience, durability across years. | A1 ≥ 7 and B1 ≥ 7 |
| C | Censorship-Resistant Settlement | Value movement no authority can stop. | A1 ≥ 7 and B3 ≥ 7 and B4 ≥ 7 |
| D | Programmable Collateral / Base Layer | Foundation for contracts and settlement: assurance, programmability, freedom from invisible rent. | B2 ≥ 7 and B5 ≥ 7 |
| E | Unit of Account | Denomination and pricing: stability of the measuring-stick over the short horizon. | A2 (short-horizon) ≥ 7 |
Universal gates (all archetypes)
- Any "money in use" / "ready today" verdict requires A1 ≥ 7 on the Today score.
- Any "sound system" verdict requires B1 ≥ 7 and B2 ≥ 7 on the Today score.
- Ceiling scores never satisfy a gate for a "ready today" verdict — only for a verdict explicitly labelled ceiling.
A speculative protocol assessed against the Standard — a labelled ceiling verdict, never "ready today."
Three levels: leaf, constitutional, completeness. The framework stays falsifiable.
CryptoBeholder hosts assessments and tools built on the Standard.