PROTOLEDGER MONEY STANDARD
A Two-Layer Standard for Evaluating Money and the Systems That Issue It
Fitness for purpose, at a stated readiness · Outcome-scored · Evidence-graded · Tail-aware · Value-disclosed · Falsifiable
Specification v4.0 · June 2026 · Open for Community Review
Authored by Oleh Bezuhlyi · CryptoBeholder.com
Released under Apache 2.0 — fork it, challenge it, improve it.
What this version is
v4.0 closes the four structural gaps that separated v3.0 from a working measurement instrument:
- An evidence protocol. Every property now names its admissible evidence types, evidence tiers, and time windows, so two independent assessors converge instead of defending divergent intuitions.
- An instance rule. The object being scored is no longer ambiguous. "Bitcoin" held as a native UTXO, as a Lightning balance, as a wrapped token, and as an exchange IOU are four different holdings with four different profiles. Every assessment names the holding form.
- Use-based scope. A subject is scored on the layers it actually serves in practice, not the layers its issuer chooses to claim. Scope can no longer be gamed by under-claiming.
- Tail-aware scoring. Properties whose headline claim is reliability or stability are scored on their failure distribution, not their average day. A stablecoin that is perfect every day until the day it is zero is not a 9.
It also: assigns a gate set to every archetype (not just one); splits each property's score into a Today score and a Ceiling score, replacing the single readiness flag; adds B10 — Claim Enforceability for all IOU-shaped money; sharpens the B3/B4 boundary to eliminate double-counting of decentralisation; adds assessor conflict-of-interest disclosure; and gives every published assessment a validity period and event-triggered re-score rule.
What it preserves from v3.0, unchanged in spirit: two objects, two scales, never summed; outcome over mechanism; contested values disclosed, never scored; fitness for a named purpose; and the standard's own falsifiability.
On the word "standard"
This document aims to be complete in its axis set and procedure — every property of money and of monetary systems that can be scored objectively is scored here, and everything genuinely contested is disclosed here. It does not and cannot claim completeness by decree. Its claim to completeness is operational: Section XII defines the process by which any omission can be demonstrated and incorporated. A standard is complete the way a scientific theory is complete — until a counterexample survives challenge. That is the only kind of "complete" worth having.
Design commitments
- Two objects, two scales, never summed. A perfect system can be poor money, and excellent money can run on an unsound system. Collapsing them into one number hides the exact thing this standard exists to expose.
- Outcome, not mechanism. A property is satisfied by its result. No design is rewarded for resembling a preferred architecture, and none is penalised for reaching the outcome a different way.
- Evidence, not assertion. Every score cites evidence of a named tier. Issuer claims are the lowest tier of evidence, not a substitute for it.
- The tail, not the average day. Where the claim is stability or assurance, the score reflects the failure distribution: probability × severity × recoverability of the bad day.
- Today and Ceiling are different numbers. Each property carries both. A ceiling may never pose as a working system.
- Contested values are disclosed, not scored. Privacy posture, personhood, issuance ethic, and autonomy are positions on an axis — because reasonable experts disagree on which pole is correct.
- Fitness for a named purpose. Money does conflicting jobs for conflicting masters. The standard reports a profile for a declared use-case, not one context-free rank.
- Scope follows use, not claims. If a thing functions as money at scale, it is scored as money, whatever its disclaimer page says.
- Falsifiable and un-owned. Defaults are published so they can be rejected. The contribution is the honest axis set and procedure, not the verdict; the weights belong to whoever is reading.
I. The Object: Subject, Instance, and Scope
I.1 Subject and Instance
An assessment names not just a subject ("Bitcoin", "USDC", "the US dollar") but an instance — the concrete form in which a holder actually holds and transfers it. Instances of the same subject can differ radically on usability, settlement assurance, and control, and a score that does not name its instance is ambiguous in a way an adversary can exploit.
| Field | Meaning | Examples |
|---|---|---|
| Subject | The monetary asset as commonly named. | Bitcoin, USDC, USD, Monero |
| Instance | The holding form and venue being scored. | Native L1 self-custody · L2 channel/rollup balance · Wrapped/bridged representation on a named chain · Custodial IOU at a named class of institution · Physical bearer form |
| Profile family | A subject's set of instance profiles. | "Bitcoin" = {L1 self-custody, Lightning, wBTC-on-Ethereum, exchange IOU, ETF share} |
Rules.
- Every published assessment names exactly one instance. Comparisons across subjects must compare like instances or disclose the mismatch.
- A bridged or wrapped instance inherits the minimum of its own soundness and the soundness of every bridge, custodian, and contract in its dependency path. Dependency paths are listed in the assessment.
- Where one instance dominates real-world holding (e.g., custodial IOUs for most retail crypto holders), an assessment of the self-custody instance must say so, so that the published profile is not silently mistaken for the typical user's experience.
I.2 Scope rule — use-based, not claim-based
A subject-instance is scored on:
- Layer A if it is used as money — held, priced in, or transferred as value — at non-trivial scale, regardless of how the issuer describes it.
- Layer B if it is, or depends on, a system that issues, settles, or custodies that money. A bearer instrument with no system dependency scores Layer A only; everything else has a Layer B surface somewhere in its dependency path, and that surface is what gets scored.
N/A-by-design remains available — a central-bank currency is not penalised on decentralisation-flavoured items — but it now requires a positive argument logged in the assessment, stating why the property's outcome is structurally inapplicable rather than merely unachieved. Absence of a marketing claim is not an argument. A property that does not apply is not a failure; a property dodged is.
II. Archetypes and Their Gates
Every assessment names a use-case archetype. The same subject-instance scores differently across archetypes; that divergence is information, not noise.
| Archetype | Evaluated for | Gates (verdict capped unless all hold) |
|---|---|---|
| A — Daily Medium of Exchange | Retail payments and remittances: low friction, stable enough to price a coffee, safe for non-experts. | A1 ≥ 7 and A3 ≥ 7 |
| B — Long-Horizon Store of Value | Savings and reserve: supply integrity, resilience, durability across years. | A1 ≥ 7 and B1 ≥ 7 |
| C — Censorship-Resistant Settlement | Value movement no authority can stop. | A1 ≥ 7 and B3 ≥ 7 and B4 ≥ 7 |
| D — Programmable Collateral / Base Layer | Foundation for contracts and settlement: assurance, programmability, freedom from invisible rent. | B2 ≥ 7 and B5 ≥ 7 |
| E — Unit of Account | Denomination and pricing: stability of the measuring-stick over the short horizon. | A2 (short-horizon) ≥ 7 |
Universal gates, all archetypes:
- Any "money in use" / "ready today" verdict requires A1 ≥ 7 on the Today score. A thing nobody takes is a collectible, not a currency, however elegant the rest of its profile.
- Any "sound system" verdict requires B1 ≥ 7 and B2 ≥ 7 on the Today score.
- Ceiling scores never satisfy a gate for a "ready today" verdict — only for a verdict explicitly labelled ceiling.
Gates are conjunctive by design: these properties are necessary together, not substitutable. A gate failure caps the verdict and must be stated, not footnoted.
III. Layer A — Monetary Fitness
Does it work as money for its users? Scored on the result, never the mechanism. Each property lists its admissible evidence; see Section VI for evidence tiers.
| # | Property | Outcome required | Primary evidence (Today score) |
|---|---|---|---|
| A1 | Acceptability & Liquidity | Counterparties will take it, and it can be entered or exited at scale without large loss. The master property. | Bid-ask spread and order-book depth at defined trade sizes on top venues; realised slippage; count and breadth of acceptance points (merchants, counterparties, jurisdictions); volume that is not wash-traded (exclude venues failing volume-integrity checks). |
| A2 | Value Stability | Predictable purchasing power over the relevant horizon. Short-horizon (unit-of-account) and long-horizon (store-of-value) figures reported separately. Tail-scored: see VI.3. | Realised volatility at 30d/1y/5y windows; maximum drawdown; for pegged assets, peg deviation history including worst deviation, duration, and recovery; depeg/redemption-suspension event count and severity. |
| A3 | Usability & Safety | A non-expert can hold and transfer it without specialised skill, and survive error, loss, theft, and fraud without catastrophe. | Documented loss rates from error/theft/fraud for the instance class; recoverability of mistaken transfers; key/credential-loss outcomes; attack surface a non-expert actually faces (phishing, seed loss, address poisoning); independent usability studies where they exist. |
| A4 | Portability & Divisibility | Moves and splits cleanly at the scale and speed of real transactions, including across borders. | Settlement time at p50 and p95; minimum and maximum practical transfer sizes; cross-border availability; smallest spendable unit vs typical price points. |
| A5 | Fungibility | Units are interchangeable in practice; no unit carries history that degrades its acceptance. (Depends on, but is distinct from, the privacy posture disclosed in Layer C: A5 scores the observed outcome — do tainted-unit discounts, blacklists, or selective refusal exist — not the privacy design.) | Documented blacklisting/freezing of specific units; exchange or merchant discrimination by unit history; market price differentials between "clean" and "tainted" units. |
| A6 | Recognizability | Easy for an ordinary holder to authenticate; hard to counterfeit. For digital instances this means: hard to spoof — fake tokens, ticker confusion, look-alike contracts, address poisoning, and phishing rank here, not physical counterfeits. | Prevalence and success rate of spoofing/impersonation attacks against the instance; availability of authoritative verification a non-expert can actually perform; for physical instances, counterfeit rates. |
| A7 | Cost Efficiency & Capacity | Low cost to transact and to hold at the declared archetype's scale — not merely at today's load. Cost at current load is not capacity at target load. | Median and p95 fee/spread per transaction at current load; fee behaviour under historical peak load; demonstrated or measured throughput headroom against the archetype's plausible user base; holding costs (custody, account, inactivity). |
IV. Layer B — System Soundness
Is the system behind the money sound? Reframed from mechanism to outcome, and held separate from the definition of money itself.
| # | Property | Outcome required | Primary evidence (Today score) |
|---|---|---|---|
| B1 | Supply Integrity | No privileged party can quietly dilute holders; the issuance rule is known and hard to change. A fixed cap is not required — a rule-bound elastic supply qualifies. | Verifiable supply audit (on-chain supply proof, or attested reserve/issuance reporting); history of unscheduled issuance events; difficulty class of changing the issuance rule (who, how, observed precedent). |
| B2 | Settlement Assurance | Confirmed transactions stay confirmed and behave as promised; no silent reversal, no double-spend. Tail-scored. | Reorg/reversal history with depth and value at risk; finality type (probabilistic/economic/legal) and observed worst case; double-spend incidents; for institutional rails, observed reversal and clawback practice. |
| B3 | Resilience, Liveness & Capacity | Keeps settling — at usable capacity — through attack, outage, partition, and the failure or coercion of any single operator. (Liveness outcome: "does it keep running?") | Uptime history including worst outage; behaviour under documented attacks and partitions; operator-failure drills or natural experiments; degradation profile under peak load. |
| B4 | No Single Point of Control | No one party can unilaterally rewrite state, censor transactions, seize funds, or gate participation arbitrarily. Includes resistance to cheaply manufactured consensus identities. (Integrity/censorship outcome: "can anyone bend it?" — score evidence here only if it concerns control over state or inclusion; pure availability evidence belongs in B3. The same fact must not be scored twice.) | Measured concentration of block production / validation / issuance authority; documented censorship or seizure events and whether they required coalition or a single actor; cost of acquiring unilateral control; gate-keeping of participation. |
| B5 | Rule Auditability | Anyone can independently verify the rules and the current state. | Open, buildable implementation; reproducible state from genesis or audited snapshots; formal verification counts as evidence; for institutional systems, the strength and independence of the audit regime. |
| B6 | Forward Security Margin | Cryptographic and economic assumptions have headroom against foreseeable threats. Post-quantum readiness is one case, not the whole line. | Inventory of cryptographic assumptions and their current margin; published migration paths and their state; economic-security budget vs value secured, with trend. |
| B7 | No Invisible Rent | Operators cannot skim value from transaction ordering, position, or privileged information. The outcome that MEV-resistance targets. | Measured extraction (sandwiching, ordering rents, internalisation) as a share of transferred value; existence and observed effectiveness of mitigations; for institutional rails, disclosed and undisclosed float/spread capture. |
| B8 | Capture-Resistant Rule-Change | The rules for changing the rules are explicit and resist takeover by any single faction. | Documented rule-change history: who proposed, who could veto, what happened to contested changes; concentration of effective change authority; precedent of forced or stealth changes. |
| B9 | Resource Proportionality | Running cost is proportional to the value secured; no waste for its own sake. Mechanism-agnostic. | Total operating resource cost vs value secured and transferred, compared against peer systems serving similar assurance levels. |
| B10 | Claim Enforceability | Where the money is a claim on an issuer or custodian (stablecoins, deposits, IOU instances of any asset): the claim is legally enforceable, the backing is bankruptcy-remote, and redemption works in practice — including on a bad day. Tail-scored. Bearer instances with no claim structure: N/A by design, with the argument logged. | Legal opinion or statute establishing the claim's seniority and enforceability; reserve attestations vs full audits (different tiers); segregation/bankruptcy-remoteness of backing; observed redemption performance under stress; freeze/suspension authority and its use history. |
V. Layer C — Disclosed, Not Scored
These are genuinely contested. The standard records a subject-instance's position on each axis and discloses it; it never marks a position "wrong" or awards points for it. Assessors then check alignment against a values-vector they choose and state. Treating any of these as an objective measurement is precisely how a standard launders ideology through a number.
Layer C also carries mechanism facts — descriptive, not contested, but disclosed rather than scored because the standard scores outcomes only.
| Axis | Type | Disclosed as |
|---|---|---|
| Privacy posture | Contested value | From fully transparent, through fungibility-grade privacy, to total untraceability. (The outcome side of privacy — whether units are in fact discriminated — is scored in A5.) |
| Identity / personhood model | Contested value | Anonymous → pseudonymous → verified unique human. Flagged dual-use: a personhood proof is at once a freedom tool and a powerful instrument of control. |
| Issuance ethic | Contested value | Fixed cap, rule-bound elastic, work-based, egalitarian mint, or pre-allocated. |
| Autonomy ⇄ Accountability | Contested value | Independence from issuer or state versus recourse, consumer protection, and legal acceptability. |
| Consensus / cost mechanism | Mechanism fact | Proof-of-Work, Proof-of-Stake, BFT, institutional, or none. |
| Governance model | Mechanism fact | Ossified, on-chain vote, or institutional — with its characteristic capture surface named: sclerosis, plutocracy, or opacity. |
| Jurisdictional posture | Mechanism fact | Issuer/operator jurisdictions, applicable regimes, and known legal constraints on holders by region. (Whether a redemption claim is enforceable is scored in B10; where and under what law it lives is disclosed here.) |
| Catastrophic failure modes | Mechanism fact | The named worst cases for this instance — depeg, bridge failure, custodian insolvency, 51% capture, protocol bug class — with the tail-scored properties they feed (A2, B2, B10). |
VI. The Scoring Model
VI.1 Two scores per property: Today and Ceiling
Each Layer A and Layer B property receives two integers, 0–10, against the outcome rubric:
- Today — supported only by Achieved-tier evidence: real systems demonstrating the outcome now, for this instance. This is the score that feeds gates and "ready today" verdicts.
- Ceiling — what the property could reach with known, specified work. Each Ceiling score carries an evidence class: Buildable (the parts exist and are specified) or Speculative (unproven, or no known implementation). Speculative ceilings are reported but can never anchor a comparative claim against another subject's Today score.
This replaces the v3.0 single readiness flag, which forced a partially-achieved property with a known ceiling into one bucket. The verdict's readiness mix is computed as: share of properties where Ceiling − Today ≤ 1 (mature), where the gap is Buildable, and where the gap is Speculative — by property count, equal weight, stated as three percentages.
VI.2 Outcome bands
| Points | Level | Definition |
|---|---|---|
| 7–10 | Strong | Outcome substantially achieved; minor gaps or caveats. |
| 4–6 | Partial | Outcome partially achieved; significant gaps that affect real users. |
| 0–3 | Weak / Absent | Outcome nominally addressed but materially missing, or not addressed at all. |
VI.3 Tail rule
Properties marked tail-scored (A2, B2, B10) are scored on the failure distribution, not the typical day:
Tail-scored property score = the typical-day band, capped by the bad-day record. A property cannot score above 6 if a failure of material severity has occurred within the assessment window without full recovery and a demonstrated structural fix; cannot score above 8 if the worst credible failure mode is uninsured, unrecoverable, and borne entirely by the holder. Probability, severity, and recoverability of the named catastrophic failure modes (Layer C disclosure) are cited as evidence.
This rule exists because mean-behaviour scoring actively misleads for exactly the asset class where stability is the headline claim.
VI.4 Evidence tiers
Every score cites evidence. Tiers, from strongest to weakest:
- T1 — Independently verifiable data: on-chain measurements, reproducible market data, published incident records.
- T2 — Independent third-party: full audits, peer-reviewed studies, regulator findings, formal verification.
- T3 — Attested: attestations, agreed-upon-procedures reports, signed legal opinions.
- T4 — Issuer claims: documentation, marketing, whitepapers.
A Today score above 6 requires at least one T1 or T2 citation. T4 evidence alone supports a score of at most 3. Conflicting evidence is resolved upward in tier, not in favour of the subject.
VI.5 Time windows
Unless a property states otherwise: market and incident evidence covers a 3-year window (or full life, if shorter, disclosed); stability is additionally reported at 30d / 1y / 5y horizons; "current" structural facts (concentration, authority, reserves) are measured within 90 days of publication.
VI.6 Aggregation and weights
- The headline pair is the unweighted mean of Layer A Today scores (M) and Layer B Today scores (S), each on 0–10, N/A-by-design items excluded from the denominator. The two means are presented as a pair — never added, never multiplied, never blended.
- Archetype-weighted views are permitted and useful, but every weighted figure must publish its full weight vector beside it, and the unweighted pair must appear with it. Weights are values; the standard's defaults (published per archetype in the companion calibration file) exist to be rejected.
- A leaderboard, if published at all, must be per-archetype, per-instance-class, and must show its weights.
VI.7 Verdict format
M ·.· / 10 · S ·.· / 10 — for subject (instance), archetype X, readiness target (today / ceiling) · readiness mix __% / __% / __% · gate check: pass / capped (reason) · Layer C disclosures attached · assessed date, valid until date.
Profile glyph. For legibility without scalar collapse, the pair may be rendered as a position on a fixed 10×10 M×S grid (M horizontal, S vertical). A grid position is shareable like a grade but cannot be mistaken for one. Any glyph must carry the archetype and instance labels.
VII. Assessment Lifecycle
- Validity. A published assessment is valid for 12 months from its assessment date, after which it must be re-affirmed or it is marked stale and removed from any leaderboard.
- Event triggers. A re-score of affected properties is mandatory within 30 days of: a depeg or redemption suspension; a chain reorg or settlement failure of material depth; a successful attack or exploit on the instance's dependency path; a sanction, seizure, or freeze event; a contentious fork or forced rule change; an issuer insolvency event anywhere in the dependency path. The triggering event and the score delta are published together.
- Versioning. Assessments are versioned and archived. A score is always read as (subject, instance, archetype, standard version, assessment version, date). Historic scores are never silently edited.
VIII. Assessor Disclosure
A standard that claims neutrality must make its assessors legible. Every published assessment carries:
- The assessor's identity (or stable pseudonymous identity with track record).
- Holdings disclosure: any position in the subject, its competitors, or instruments correlated with the verdict.
- Funding disclosure: who paid for the assessment, if anyone. Subject-funded assessments are permitted but must be labelled as such on the verdict line itself, not in an appendix.
- Affiliations relevant to Layer C values (an assessor's stated values-vector is itself a disclosure, not a flaw).
An undisclosed conflict, once demonstrated, voids the assessment and is recorded in the challenge log.
IX. How to Use It
- Name the subject, the instance, the archetype, and the readiness target ("ready today" or "ceiling"). State the values-vector you will judge Layer C against. List the instance's dependency path.
- Score Layer A on outcomes: Today and Ceiling per property, citing tiered evidence, applying the tail rule where marked.
- Score Layer B the same way, marking N/A-by-design items with their logged argument rather than zeroing them.
- Apply the gates for the named archetype plus the universal gates. If a gate fails, cap the verdict and say so explicitly.
- Record Layer C positions — contested values, mechanism facts, catastrophic failure modes — and note alignment or misalignment with your stated values-vector.
- Report the pair (M / S), the readiness mix, the disclosures, the assessor disclosure, and the validity date. Never reduce it to one number.
X. Scorecard Template
Subject: ________ Instance: ________ Dependency path: ________ Archetype: ____ Readiness target: ____ Assessor & disclosures: ________ Assessment date: ____ Valid until: ____ Standard version: 4.0
Layer A — Monetary Fitness
| # | Property | Today 0–10 | Ceiling 0–10 (B/S) | Evidence (tier) |
|---|---|---|---|---|
| A1 | Acceptability & Liquidity | |||
| A2 | Value Stability (tail rule) | |||
| A3 | Usability & Safety | |||
| A4 | Portability & Divisibility | |||
| A5 | Fungibility | |||
| A6 | Recognizability | |||
| A7 | Cost Efficiency & Capacity |
Layer B — System Soundness
| # | Property | Today 0–10 | Ceiling 0–10 (B/S) | Evidence (tier) |
|---|---|---|---|---|
| B1 | Supply Integrity | |||
| B2 | Settlement Assurance (tail rule) | |||
| B3 | Resilience, Liveness & Capacity | |||
| B4 | No Single Point of Control | |||
| B5 | Rule Auditability | |||
| B6 | Forward Security Margin | |||
| B7 | No Invisible Rent | |||
| B8 | Capture-Resistant Rule-Change | |||
| B9 | Resource Proportionality | |||
| B10 | Claim Enforceability (tail rule; N/A for pure bearer instances, argument logged) |
Layer C — Disclosures
| Axis | Position | Note |
|---|---|---|
| Privacy posture | ||
| Identity / personhood | ||
| Issuance ethic | ||
| Autonomy ⇄ Accountability | ||
| Consensus / cost mechanism | ||
| Governance model | ||
| Jurisdictional posture | ||
| Catastrophic failure modes |
Verdict: M ___ / 10 · S ___ / 10 Readiness mix: __% mature / __% Buildable gap / __% Speculative gap Gate check: pass / capped (reason: ____) Grid position: (M, S)
XI. Worked Reads (Illustrative)
Judgement-based illustrations of how the instrument reads under v4.0 rules — not figures derived from the full evidence rubrics. Note how the instance rule changes the picture relative to v3.0.
| Subject (instance, archetype) | Illustrative pair | What the v4.0 rules reveal |
|---|---|---|
| Fiat USD (insured bank deposit, A) | M high · S mixed | Strong acceptability, stability, usability. B10 strong (deposit insurance, legal claim); B1 moderate (discretionary issuance); B4 low and not N/A — the deposit instance has a clear single point of control, disclosed and scored, unlike physical cash where several B items are N/A by design. The instance rule splits "the dollar" into materially different profiles. |
| Bitcoin (native L1 self-custody, B) | M mixed · S strong | Tail rule leaves B2 strong (no material settlement failure in window) but probabilistic finality is named in disclosures. A3 is the binding weakness for non-experts (irrecoverable error/loss). Ceiling > Today on B6 (PQ migration: Buildable, unexecuted). The dominant real holding instance — exchange IOU — would score as a different profile with B10 and B4 in play. |
| Fiat-backed stablecoin (issuer-direct, A) | M strong · S guarded | The tail rule and B10 do the work v3.0 left to a footnote: peg history caps A2; redemption-under-stress, reserve audit tier, freeze authority, and bankruptcy-remoteness now produce a scored B10 figure instead of a disclosure-only caveat. Single-issuer control reads on B4. |
XII. Reflexivity and Challenge Process
This document encodes choices, and it says so. Its defaults — gates, tail rule thresholds, evidence tiers, time windows, archetype weights — are published so they can be rejected. Its claim to being a complete standard is procedural, not declarative: completeness means every demonstrated omission has a path into the standard, and every score has a path to correction.
The challenge process runs at three levels:
- Leaf challenge — disputes a score for a specific subject-instance, with evidence. Resolved against the evidence tiers; higher tier wins.
- Constitutional challenge — proposes adding or removing a property, changing a gate, the tail rule, the evidence tiers, or default weights, with argument.
- Completeness challenge — demonstrates a monetary property or system property that is objectively scorable yet absent, or a contested value treated as scorable. A sustained completeness challenge produces a new property or axis in the next version, with the challenger credited.
All challenges are versioned and public, so the framework itself stays falsifiable — not only the arithmetic inside it. Accepted challenges produce a published correction; the challenger is credited by name.
XIII. Open Problems
Carried honestly, as before:
- Calibration data. The evidence rubrics now name what to measure; the companion calibration file must fix the numeric thresholds per band (e.g., what spread/depth earns A1 = 7 at each archetype). Those thresholds will be contested, and should be.
- Tail estimation. The tail rule caps on observed failures; estimating the probability of unobserved failure modes (a never-yet-depegged stablecoin, a never-yet-reorged chain) remains judgement wearing a number. The rule bounds the damage; it does not eliminate it.
- The stability tension. A2 is something the egalitarian "one share per human" monetary tradition explicitly trades away. The conflict between a fair supply and a stable one is real and unresolved; the standard exposes it rather than picking a side by omission.
- Profile legibility. The M×S grid glyph mitigates but does not solve the shareability gap against a single dishonest number.
- Assessor incentives. Disclosure makes conflicts visible; it does not fund independent assessment. Who pays for honest measurement at scale is an economic problem this document can name but not solve.
A standard's job is the honest axis set and the honest procedure, not the verdict. The weights belong to whoever is reading.
ProtoLedger Money Standard v4.0 · Apache 2.0 · cryptobeholder.com