English
English
Appearance
English
English
Appearance
A money system is only as trustworthy as the people allowed near the controls. This chapter is about who those are, how slowly those controls turn, and what you can do if you disagree.
The bank handles day-to-day management itself. But the rules themselves, like the height of the tax or the size of the Basic Pulse, are not something anyone can just turn. Every change has to pass three locks in a row.
Lock I: no rule may touch the backing. No change to a rate, a threshold or the size of the floor may push the backing below one kilowatt-hour per coin. This is about the rules, not about issuance; printing more in an emergency is arranged separately, further down. Anyone who wants to issue unbacked has to take that route and show it to everyone, not through some small rate that happens to have the same effect. And for the Basic Pulse a ratchet applies: it can only go up, and only when new renewable generation stands behind it. Turning it down to absorb a shortfall is not possible. A floor that gives way is not a floor.
Lock II: it goes straight into the ledger. Every change is published, with the signatures of whoever put it through underneath it. Adjustments without that publication are simply refused by the network. There is no quiet version.
Lock III: it takes long and it expires by itself. At least 30 days sit between announcement and implementation, so there is time to protest. And every change has a shelf life: after a year it lapses, unless someone openly extends it. So anyone who wants to slip something through has to slip it through again every year.
Why that one knob weighs so heavily. The Basic Pulse is paid from the purchase margin on new storage (see how money appears). The height of that rate therefore decides how much of the yield from all new electricity goes to everyone instead of to whoever generated it. That is not a rate in the margins but the distribution key of the whole system. The ratchet in Lock I is thus anything but decorative: without the requirement that structural income carries it, raising the floor would force the bank to mint unbacked, and that is the one act forbidden here.
And if you do not trust the bank, you walk away. Three locks are a brake, not a guarantee. The real counterweight is that nobody is stuck: a neighbourhood can disconnect, convert its claims into electricity that physically exists, and reconnect later to a restored bank or to a new one the people found themselves (see architecture). Whoever sits at the knob knows there is a door. That corrects more firmly than any voting procedure.
First the distinction, because this one matters. The rule set CBER-1 knows only three checking roles: an independent auditor, at least three external witnesses who co-sign every interval, and a verifier under confidentiality. Those three are in the grammar and are enforceable. The elected gatekeeper below is not in it: that is a governance proposal laid on top, not a rule that binds the instance. Anyone testing this design has to test the first block; the second is the shape we propose for it.
The gatekeeper is elected, for three years at most, and stands apart from the bank's board. A misjudgement does not cost him his term: if you could send a gatekeeper away over an error of judgement, then "error" becomes the little lever with which an irritated bank pushes aside every awkward auditor. Mistakes are judged by the voter at the end of the ride. Lying, meter fraud and bribery are judged by the court, and the court can step in right away.
And he is not paid by the bank. Everyone pays their own people: the bank pays its meters, the government pays its gatekeeper, justice pays its judges. The salary is fixed for the length of the term and dismissal takes a heavy procedure, just as with a judge. An auditor on the payroll of the party he audits is not an auditor.
The bank's own costs are in the ledger too. What the bank spends is just as visible as what it measures. Anyone can follow the sensor data from the storage stations live.
There is nothing to earn here. No shareholders, no profit payouts. The costs come out of fixed margins written into the open protocol. A bank with no profit motive has no reason to tinker with the meter.
In a storm, a blackout or an act of sabotage, a waiting period of 30 days helps nobody. So there is an emergency button, with firm limits around it.
In a declared state of emergency the waiting period lapses, so the bank can correct course at once.
But the floor stays put. Even in an emergency the Basic Pulse may not go down to spare industry. Anyone who cuts the poorest first in a crisis has not understood the design.
After 72 hours the emergency measure expires by itself, unless the bank accounts for it and the gatekeeper extends it. A state of emergency that renews itself is no longer an emergency but a regime.
Abuse costs the board their jobs, and goes to the court.
Sometimes it has to happen. After a disaster more may be needed than sits in the batteries, and then printing more is the least bad option. It is allowed, and it is not a breach in the design but exactly the spot where the design proves itself.
The difference with an ordinary central bank is not whether more gets printed, but whether anyone can see it. If the backing drops to 84%, every coin still yields 0.84 kWh and from that moment on the coin publicly carries the status under-backed (colloquially: fiat). Nobody is deceived; it stands on the front page to two decimal places.
The floor notices nothing. The Basic Pulse is a right to electricity and not to a number of coins, so your heat and light simply carry on. The dilution falls entirely on the Luxury balances.
And a way back belongs to it. Without that way back, every emergency grab is a permanent devaluation with a nice story attached. The rule that keeps it honest: a fixed share of the purchase margin burns coins until the backing is restored. So borrowing from the future is fine, but the repayment must not be booked in advance. "This will pay for itself" is a forecast, and forecasting is allowed nowhere here, not even when it suits you.
That gives the backing ratio a second meaning: it shows how deep you went and how far you have climbed back.
Countries running the same model can tie their reserves together. Exchange rate risk then disappears from the trade between them, because a kilowatt-hour is a kilowatt-hour on both sides. The condition is that both stick to the same requirements.
You let each other check the sums, not the people. The gatekeepers of both countries verify each other's signed totals, fingerprints and attestations, plus a sample by an auditor bound to professional secrecy. Data at the level of a connection, account or person never crosses a border, in any form. No mutual check, no link.
And you unlink when the other one slips. If a partner country lets its backing slide structurally below the norm, the link comes off, so the problem does not blow over. Trade can simply carry on, only at a rate that reflects that country's actual backing.
The word "federating" appears often in this manual; here is what it means technically, without poetry.
Federating is what e-mail does. You are with provider A, your colleague with provider B, and yet you can mail each other, because all providers speak the same protocol. The modern example is Mastodon (the ActivityPub protocol): thousands of separate servers, each with its own rules, but one language between them. CBER applies that pattern to money: an instance is a bank or cooperative running the open CBER protocol, the protocol handles the traffic (payments, netting, meter readings, audits), and the grammar is the admission requirement: honest meter, audit rights, redemption at the meter rate, basic floor, signed code. The house rules (tax, tariffs, floor height) remain free per instance.
What does seceding mean physically? Nobody cuts cables. The secession is an administrative boundary in the software; surplus power keeps flowing physically to neighbouring districts, but is settled differently. It resembles a hard fork in open source software: a group copies the rules and continues on its own track. Or more tangibly: a citizen taking their gold bars out of the national vault to guard them at home. The total amount of gold does not change; only the custody moves.
Why the national backing does not break on secession: whoever leaves takes, at the meter rate, both their claims and the matching share of the reserve. Both sides of the balance sheet shrink by exactly the same amount, so the backing ratio of the remaining system does not change: 1:1 stays 1:1, before and after the split. No hole appears and nothing is diluted; reality simply splits in two, each with its own meter that adds up.
Practical vignette: the bicycle in Amersfoort
A district in Utrecht secedes as a free federation. A resident travels to Amersfoort (central system) and buys a bicycle there. As long as both instances speak the grammar, the payment simply settles at the meter rate: 1 backed kWh claim is 1 backed kWh claim, whatever flag flies over the instance. No chaotic exchange rate, because both coins are backed in the same thing. Only when an instance abandons the grammar (no honest meter, no audit rights) does that equivalence lapse, and you trade with it as with any foreign money: at a rate.
Large battery owners are simply a pyramid again, and that is correct: a biggest bird always emerges. CBER does not promise the pyramid disappears; it promises that it stands under the lamp, sits behind locks, wears out, and has a door next to it.
Power has a unit of measurement here: kWh of storage. And once power is a physical thing, its nature changes: it wears out (batteries degrade, so power has maintenance costs), it does work (a battery doing nothing earns nothing and wears anyway), it has an address (it cannot be carried to a tax haven), it can be bought at the hardware store with ordinary work, and it sits on a public meter. The current system has concentration as the default outcome of sitting still (money attracts interest); CBER flips the default: large balances bleed the leakage, luxury trade and large holdings pay the levy, and the basic floor cannot be bought. A winner is inescapable and that is fine: the top may keep the top, as long as it earns it anew every month by serving. The system removes only two things: winning in your sleep and hostage power.
Four rules apply to the top of the pyramid:
Today's pyramid is dark, interest-bearing and inescapable. This one is lit, wearing and leavable. That is not utopia; that is domestication.
The system leans on openness, and that rubs against the wallet. One rule resolves it: privacy is for people, transparency is for power.
The ledger publishes levels, not lives. Public: system levels. The total reserve, the backing ratio, the flows per storage station (aggregated over several stations only), the concentration meter as anonymised shares, and every payment by the bank itself. Never public, in any form and not even pseudonymously: individual balances, transactions, calls, queue positions and delivery records. Of your own entries you receive a private proof that they were counted correctly in the sum. A wallet is pseudonymous towards the ledger: unlike a bank account, which carries your name, and emphatically unlike a blockchain, where every payment stands publicly visible forever. Your own instance does know you (see below). Transparency rises with power: a citizen below the threshold is pseudonymous (detail data encrypted to the person themselves), a large holder above the threshold can be looked up by anyone demonstrating a legitimate interest, with every lookup logged and the holder notified; legal persons are named outright (see the pyramid under the lamp), and the bank itself is fully glass: its only forbidden sin is silence.
CBER needs no mining or block confirmations. The instance (the bank or cooperative) is the referee per transaction: it checks the balance, signs the payment cryptographically, and prevents double-spending because the ledger is kept centrally. Every payment gets a signed proof in an append-only log with a hash chain. The ledger publishes, per interval, only the fingerprints (Merkle roots) and the totals, so anyone can verify that nothing was altered or deleted afterwards, without being able to read a single individual payment. The backing ratio stays publicly visible and never carries a blur; so does the reserve, but rounded downward to a grain published in advance, between half of its own measurement uncertainty and that uncertainty itself. No rule whatever computes on that displayed number: internally the booked value stays exact. Who can recompute them has changed: the auditor, the co-signing witnesses and an independent verifier under confidentiality. An ordinary member cannot do it at this scale, because the series that would be needed point at exactly the people they are meant to protect. And whether a published series is still personal data in law is assessed per series and in writing; it is never a blanket claim made in advance.
And the number of coins in circulation no longer appears per interval, for a reason that sounds counterintuitive at first. Backing ratio, reserve, coins and queue hang together in one formula: publish three of them and the fourth is fixed exactly, however coarsely you round. The queue consists of individual claims by people, and in a village that is often one person. So one of the four had to go, and it became the money supply: that is the one you need least. What you actually want to know is not how many coins exist, but whether coins are quietly being added. That stays visible: every issuance is published per period as a percentage of the total, with the auditor's statement that the caps were held. But call it a shift, and not the same thing as before. Those percentages are percentages of a number you no longer see, and the closing control (that the backing ratio was computed on the book values and not on the display values) has moved from the reader to the auditor. The level returns once holdings are spread widely enough: only when the largest anonymous holding stays below a fixed threshold for twelve months running, at most a fifth of the same margin the label runs on. That test deliberately runs over holdings and not over redemptions, because a threshold on redemptions is something the bank can steer itself through the timing of settlement and delivery, and that steering works out precisely at the expense of the largest holder. What becomes public is only the outcome, pass or fail, never the share the test ran on.
What is no longer publicly recomputable is the composition of those sums. Every series built from person-bound measurements falls under thresholds, and in a community of two hundred households those thresholds are often not met; the series is then suppressed, and the suppression itself is announced. That no coin appears from nowhere is demonstrated in that phase by an independent auditor and by co-signing witnesses, not by you being able to recompute it yourself. That is a real retreat and it stands here because it is true: full public recomputability returns only once holdings are spread widely enough, and not at some number of participants. The claim that system verification requires no insight into persons at all is one we will make only once the mathematics that enforces it actually runs; until then it would be a nicer sentence than the system deserves.
Full anonymity. Anonymous money rules out the levy and fraud detection; that is an honest choice, not an omission. The promise is pseudonymity with legal locks, not invisibility.
Walking away works for your money, and only half for your data. The exit is real: your claims and your share of the reserve travel with you at the meter rate, and nobody can stop you. Your traces do not all travel back. What is settled is settled, and aggregates already published stay published; the ledger is append-only and that is exactly what makes it checkable. What is enforceable: your person-bound records are destroyed within the fixed retention periods, your status history does not travel to another instance, and on dissolution or bankruptcy member data never belongs to the estate. That is the honest position: money is portable, history only partly.
Division along the grammar. That the bank publishes system levels and never account levels, that individual access requires a lawful order and itself leaves a public trace, that retention and data minimisation carry fixed maxima, and that the code is open: grammar. Threshold heights and dashboard design: house rules.
The Basic Pulse is per person, so the system must guarantee that one person cannot draw a hundred floors (a Sybil attack), including across federated instances. The trap is the obvious solution: a central database linking names to wallets. That database is exactly the honeypot the privacy rules forbids. The Anchor protocol solves it without that database.
In one sentence: the wallet proves you are unique, an attestation proves you are alive, the mill keeps both blind, and the list stays in. That a shared nullifier set exists is grammar; which anchor (EUDI wallet, another eID, web-of-trust) an instance accepts is a house rule, and the door, as always, stays open.