Skip to content

Who decides, and who checks

A money system is only as trustworthy as the people allowed near the controls. This chapter is about who those are, how slowly those controls turn, and what you can do if you disagree.


Three locks on the rules

The bank handles day-to-day management itself. But the rules themselves, like the height of the tax or the size of the Basic Pulse, are not something anyone can just turn. Every change has to pass three locks in a row.

Lock I: no rule may touch the backing. No change to a rate, a threshold or the size of the floor may push the backing below one kilowatt-hour per coin. This is about the rules, not about issuance; printing more in an emergency is arranged separately, further down. Anyone who wants to issue unbacked has to take that route and show it to everyone, not through some small rate that happens to have the same effect. And for the Basic Pulse a ratchet applies: it can only go up, and only when new renewable generation stands behind it. Turning it down to absorb a shortfall is not possible. A floor that gives way is not a floor.

Lock II: it goes straight into the ledger. Every change is published, with the signatures of whoever put it through underneath it. Adjustments without that publication are simply refused by the network. There is no quiet version.

Lock III: it takes long and it expires by itself. At least 30 days sit between announcement and implementation, so there is time to protest. And every change has a shelf life: after a year it lapses, unless someone openly extends it. So anyone who wants to slip something through has to slip it through again every year.

Why that one knob weighs so heavily. The Basic Pulse is paid from the purchase margin on new storage (see how money appears). The height of that rate therefore decides how much of the yield from all new electricity goes to everyone instead of to whoever generated it. That is not a rate in the margins but the distribution key of the whole system. The ratchet in Lock I is thus anything but decorative: without the requirement that structural income carries it, raising the floor would force the bank to mint unbacked, and that is the one act forbidden here.

And if you do not trust the bank, you walk away. Three locks are a brake, not a guarantee. The real counterweight is that nobody is stuck: a neighbourhood can disconnect, convert its claims into electricity that physically exists, and reconnect later to a restored bank or to a new one the people found themselves (see architecture). Whoever sits at the knob knows there is a door. That corrects more firmly than any voting procedure.

THE GUARANTEE behind the vault door LOCK I backing & ratchet ↑ LOCK II everything public LOCK III slow & temporary three locks, nothing more: backed · public · slow

Who looks over the shoulder

First the distinction, because this one matters. The rule set CBER-1 knows only three checking roles: an independent auditor, at least three external witnesses who co-sign every interval, and a verifier under confidentiality. Those three are in the grammar and are enforceable. The elected gatekeeper below is not in it: that is a governance proposal laid on top, not a rule that binds the instance. Anyone testing this design has to test the first block; the second is the shape we propose for it.

The gatekeeper is elected, for three years at most, and stands apart from the bank's board. A misjudgement does not cost him his term: if you could send a gatekeeper away over an error of judgement, then "error" becomes the little lever with which an irritated bank pushes aside every awkward auditor. Mistakes are judged by the voter at the end of the ride. Lying, meter fraud and bribery are judged by the court, and the court can step in right away.

And he is not paid by the bank. Everyone pays their own people: the bank pays its meters, the government pays its gatekeeper, justice pays its judges. The salary is fixed for the length of the term and dismissal takes a heavy procedure, just as with a judge. An auditor on the payroll of the party he audits is not an auditor.

The bank's own costs are in the ledger too. What the bank spends is just as visible as what it measures. Anyone can follow the sensor data from the storage stations live.

There is nothing to earn here. No shareholders, no profit payouts. The costs come out of fixed margins written into the open protocol. A bank with no profit motive has no reason to tinker with the meter.


The Gatekeeper elected by you · externally anchored Open ledger everyone watches Auditors co-sign every interval THE BANK measures & publishes zero secrets Government & Justice mandate & sanctions the bank never checks itself; appointing and punishing happens outside the bank

When something goes wrong

In a storm, a blackout or an act of sabotage, a waiting period of 30 days helps nobody. So there is an emergency button, with firm limits around it.

In a declared state of emergency the waiting period lapses, so the bank can correct course at once.

But the floor stays put. Even in an emergency the Basic Pulse may not go down to spare industry. Anyone who cuts the poorest first in a crisis has not understood the design.

After 72 hours the emergency measure expires by itself, unless the bank accounts for it and the gatekeeper extends it. A state of emergency that renews itself is no longer an emergency but a regime.

Abuse costs the board their jobs, and goes to the court.

Printing more in an emergency

Sometimes it has to happen. After a disaster more may be needed than sits in the batteries, and then printing more is the least bad option. It is allowed, and it is not a breach in the design but exactly the spot where the design proves itself.

The difference with an ordinary central bank is not whether more gets printed, but whether anyone can see it. If the backing drops to 84%, every coin still yields 0.84 kWh and from that moment on the coin publicly carries the status under-backed (colloquially: fiat). Nobody is deceived; it stands on the front page to two decimal places.

The floor notices nothing. The Basic Pulse is a right to electricity and not to a number of coins, so your heat and light simply carry on. The dilution falls entirely on the Luxury balances.

And a way back belongs to it. Without that way back, every emergency grab is a permanent devaluation with a nice story attached. The rule that keeps it honest: a fixed share of the purchase margin burns coins until the backing is restored. So borrowing from the future is fine, but the repayment must not be booked in advance. "This will pay for itself" is a forecast, and forecasting is allowed nowhere here, not even when it suits you.

That gives the backing ratio a second meaning: it shows how deep you went and how far you have climbed back.


Across the border

Countries running the same model can tie their reserves together. Exchange rate risk then disappears from the trade between them, because a kilowatt-hour is a kilowatt-hour on both sides. The condition is that both stick to the same requirements.

You let each other check the sums, not the people. The gatekeepers of both countries verify each other's signed totals, fingerprints and attestations, plus a sample by an auditor bound to professional secrecy. Data at the level of a connection, account or person never crosses a border, in any form. No mutual check, no link.

And you unlink when the other one slips. If a partner country lets its backing slide structurally below the norm, the link comes off, so the problem does not blow over. Trade can simply carry on, only at a rate that reflects that country's actual backing.


Walking away, and coming back

The word "federating" appears often in this manual; here is what it means technically, without poetry.

Federating is what e-mail does. You are with provider A, your colleague with provider B, and yet you can mail each other, because all providers speak the same protocol. The modern example is Mastodon (the ActivityPub protocol): thousands of separate servers, each with its own rules, but one language between them. CBER applies that pattern to money: an instance is a bank or cooperative running the open CBER protocol, the protocol handles the traffic (payments, netting, meter readings, audits), and the grammar is the admission requirement: honest meter, audit rights, redemption at the meter rate, basic floor, signed code. The house rules (tax, tariffs, floor height) remain free per instance.

THE CENTRAL SYSTEM instances with a centre · sells certainty the centre this is where the guarantees live THE FREE SWARM instances without a centre · sells freedom nobody can pull the plug one grammar migrate · trade · link back, always at the meter rate mirror-image weaknesses: if the centre falls, the swarm catches; if the swarm fragments, the centre anchors

What does seceding mean physically? Nobody cuts cables. The secession is an administrative boundary in the software; surplus power keeps flowing physically to neighbouring districts, but is settled differently. It resembles a hard fork in open source software: a group copies the rules and continues on its own track. Or more tangibly: a citizen taking their gold bars out of the national vault to guard them at home. The total amount of gold does not change; only the custody moves.

Why the national backing does not break on secession: whoever leaves takes, at the meter rate, both their claims and the matching share of the reserve. Both sides of the balance sheet shrink by exactly the same amount, so the backing ratio of the remaining system does not change: 1:1 stays 1:1, before and after the split. No hole appears and nothing is diluted; reality simply splits in two, each with its own meter that adds up.

Practical vignette: the bicycle in Amersfoort

A district in Utrecht secedes as a free federation. A resident travels to Amersfoort (central system) and buys a bicycle there. As long as both instances speak the grammar, the payment simply settles at the meter rate: 1 backed kWh claim is 1 backed kWh claim, whatever flag flies over the instance. No chaotic exchange rate, because both coins are backed in the same thing. Only when an instance abandons the grammar (no honest meter, no audit rights) does that equivalence lapse, and you trade with it as with any foreign money: at a rate.


Power that piles up, under the lamp

Large battery owners are simply a pyramid again, and that is correct: a biggest bird always emerges. CBER does not promise the pyramid disappears; it promises that it stands under the lamp, sits behind locks, wears out, and has a door next to it.

the lamp: public meter power = kWh of storage wears: battery upkeep or decay the door: exit at the meter rate the locks: ceiling · premium · threshold lit · wearing · leavable: that is domestication

Power has a unit of measurement here: kWh of storage. And once power is a physical thing, its nature changes: it wears out (batteries degrade, so power has maintenance costs), it does work (a battery doing nothing earns nothing and wears anyway), it has an address (it cannot be carried to a tax haven), it can be bought at the hardware store with ordinary work, and it sits on a public meter. The current system has concentration as the default outcome of sitting still (money attracts interest); CBER flips the default: large balances bleed the leakage, luxury trade and large holdings pay the levy, and the basic floor cannot be bought. A winner is inescapable and that is fine: the top may keep the top, as long as it earns it anew every month by serving. The system removes only two things: winning in your sleep and hostage power.

Four rules apply to the top of the pyramid:

  • The dependency ceiling: the bank spreads its purchasing the way a supermarket does not buy all its bread from one baker: never does more than a fixed percentage of the guaranteed floor lean on one counterparty. No ownership ban (a ban chases power into strawmen and the dark), and above the ceiling capital is not dead: the luxury market, industry and other federations do buy it. The only thing a giant cannot buy is the position to hold everyone's warmth hostage.
  • The diversification premium: the reverse auction slightly prefers a thousand small suppliers over one giant, so concentration becomes unprofitable before it becomes dangerous.
  • Power loses privacy as it grows: small owners are citizens with privacy. Above a threshold that is both relative and absolute (so nobody is named merely because the instance is small) the position becomes visible: legal persons by name, natural persons as an anonymised share that can only be looked up on a demonstrated legitimate interest, with the lookup logged and the holder notified. Privacy is for people, transparency is for power.
  • The concentration meter: next to the backing ratio, the ledger shows live the share of the largest suppliers, and a quarterly aggregated outflow risk shows whether a giant is on its way, without pointing at any one person with a date.

Today's pyramid is dark, interest-bearing and inescapable. This one is lit, wearing and leavable. That is not utopia; that is domestication.


Privacy: what is visible, and to whom

The system leans on openness, and that rubs against the wallet. One rule resolves it: privacy is for people, transparency is for power.

What is public, and what is not

The ledger publishes levels, not lives. Public: system levels. The total reserve, the backing ratio, the flows per storage station (aggregated over several stations only), the concentration meter as anonymised shares, and every payment by the bank itself. Never public, in any form and not even pseudonymously: individual balances, transactions, calls, queue positions and delivery records. Of your own entries you receive a private proof that they were counted correctly in the sum. A wallet is pseudonymous towards the ledger: unlike a bank account, which carries your name, and emphatically unlike a blockchain, where every payment stands publicly visible forever. Your own instance does know you (see below). Transparency rises with power: a citizen below the threshold is pseudonymous (detail data encrypted to the person themselves), a large holder above the threshold can be looked up by anyone demonstrating a legitimate interest, with every lookup logged and the holder notified; legal persons are named outright (see the pyramid under the lamp), and the bank itself is fully glass: its only forbidden sin is silence.

Verification is public

CBER needs no mining or block confirmations. The instance (the bank or cooperative) is the referee per transaction: it checks the balance, signs the payment cryptographically, and prevents double-spending because the ledger is kept centrally. Every payment gets a signed proof in an append-only log with a hash chain. The ledger publishes, per interval, only the fingerprints (Merkle roots) and the totals, so anyone can verify that nothing was altered or deleted afterwards, without being able to read a single individual payment. The backing ratio stays publicly visible and never carries a blur; so does the reserve, but rounded downward to a grain published in advance, between half of its own measurement uncertainty and that uncertainty itself. No rule whatever computes on that displayed number: internally the booked value stays exact. Who can recompute them has changed: the auditor, the co-signing witnesses and an independent verifier under confidentiality. An ordinary member cannot do it at this scale, because the series that would be needed point at exactly the people they are meant to protect. And whether a published series is still personal data in law is assessed per series and in writing; it is never a blanket claim made in advance.

And the number of coins in circulation no longer appears per interval, for a reason that sounds counterintuitive at first. Backing ratio, reserve, coins and queue hang together in one formula: publish three of them and the fourth is fixed exactly, however coarsely you round. The queue consists of individual claims by people, and in a village that is often one person. So one of the four had to go, and it became the money supply: that is the one you need least. What you actually want to know is not how many coins exist, but whether coins are quietly being added. That stays visible: every issuance is published per period as a percentage of the total, with the auditor's statement that the caps were held. But call it a shift, and not the same thing as before. Those percentages are percentages of a number you no longer see, and the closing control (that the backing ratio was computed on the book values and not on the display values) has moved from the reader to the auditor. The level returns once holdings are spread widely enough: only when the largest anonymous holding stays below a fixed threshold for twelve months running, at most a fifth of the same margin the label runs on. That test deliberately runs over holdings and not over redemptions, because a threshold on redemptions is something the bank can steer itself through the timing of settlement and delivery, and that steering works out precisely at the expense of the largest holder. What becomes public is only the outcome, pass or fail, never the share the test ran on.

What is no longer publicly recomputable is the composition of those sums. Every series built from person-bound measurements falls under thresholds, and in a community of two hundred households those thresholds are often not met; the series is then suppressed, and the suppression itself is announced. That no coin appears from nowhere is demonstrated in that phase by an independent auditor and by co-signing witnesses, not by you being able to recompute it yourself. That is a real retreat and it stands here because it is true: full public recomputability returns only once holdings are spread widely enough, and not at some number of participants. The claim that system verification requires no insight into persons at all is one we will make only once the mathematics that enforces it actually runs; until then it would be a nicer sentence than the system deserves.

Tracing is layered

  • Yourself: complete. Your own payment history is yours, encrypted to your key.
  • The bank: minimal, but honestly not blind. In phase 0 the instance is a closed cooperative with a membership register: it knows its members by name and sees the transactions it settles. Pseudonymity holds towards the ledger and towards other instances, not towards your own bank. What it may do with that is bounded: no profiling on consumption patterns, retention periods per category, and every lookup of a member record is logged.
  • Unmasking: there is nothing to unmask that the bank does not already know. In phase 0 your cooperative simply knows you, and that is exactly why there is no separate linking facility: a threshold system that lays out keys in advance to link pseudonyms to names must not exist while the membership register already is that link. That saves precisely one back door. Once you federate and an instance does not know its members, the threshold procedure returns: several independent trustees, only after a lawful order from a competent authority (in the Netherlands including a public prosecutor's demand), and only within the EU.
  • The looking is watched, but without putting you in the stocks. Public are the counts: how many demands arrived, from what kind of authority, on what legal basis, on a fixed cadence and also when the number is zero. Who was opened is not in there: you hear that privately, and if an investigation orders that notice deferred, it arrives automatically once the deferral lapses.
  • Whoever looks in your file is known. Every consultation of a member record traces to a named person, is logged, and you are notified. Anyone sharing your household, address or first-degree family cannot reach it at all.

What we deliberately do not offer

Full anonymity. Anonymous money rules out the levy and fraud detection; that is an honest choice, not an omission. The promise is pseudonymity with legal locks, not invisibility.

Walking away works for your money, and only half for your data. The exit is real: your claims and your share of the reserve travel with you at the meter rate, and nobody can stop you. Your traces do not all travel back. What is settled is settled, and aggregates already published stay published; the ledger is append-only and that is exactly what makes it checkable. What is enforceable: your person-bound records are destroyed within the fixed retention periods, your status history does not travel to another instance, and on dissolution or bankruptcy member data never belongs to the estate. That is the honest position: money is portable, history only partly.

Division along the grammar. That the bank publishes system levels and never account levels, that individual access requires a lawful order and itself leaves a public trace, that retention and data minimisation carry fixed maxima, and that the code is open: grammar. Threshold heights and dashboard design: house rules.


One person, one floor

The Basic Pulse is per person, so the system must guarantee that one person cannot draw a hundred floors (a Sybil attack), including across federated instances. The trap is the obvious solution: a central database linking names to wallets. That database is exactly the honeypot the privacy rules forbids. The Anchor protocol solves it without that database.

1 · EUDI wallet zk proof, seed from wallet pseudonym 2 · Blind mill threshold OPRF, nobody sees anything 3 · Nullifier same person = same stamp 4 · Shared set second attempt bounces: refused the village attests: alive, lives here no attestations: floor lapses after grace the wallet proves you are unique, the village proves you are alive, the mill keeps both blind, the set keeps the sum
  • The seed cannot be forgotten, but it may not exist yet. The secret seed must come from an identity attribute meeting strict conditions: issued by the state, the same for a person every time, one value per person across the whole federation, and with enough randomness in it. Deliberately not a personal number. Honestly stated: it is not certain that the European identity wallet supplies such an attribute, because a wallet that invents a fresh pseudonym per service does not qualify. Until a country demonstrably offers one, enrolment on this anchor cannot start and only the social route remains.
  • The blind mill. The nullifier (the stamp) is computed as a threshold OPRF: the key is split across several parties, the input is blinded, and nobody (including any single instance) can compute or look up anyone's stamp. The stamp is scoped per instance and not federation-wide, precisely to avoid creating a lifelong number that follows you everywhere.
  • The set is not public. Earlier versions published the stamp list. That is gone: a published list of stable tokens is a re-identification surface, and publication was never necessary for the purpose. Public are only a signed fingerprint of the list, the distribution of assurance levels, and aggregates. Uniqueness is enforced with a proof that you are not yet in it. Legally the stamps remain personal data, so every instance runs a mandatory DPIA.
  • The wallet proves uniqueness, an attestation proves life. An identity document does not know whether you are still alive or where you live. So small periodic attestations arrive. They may come from your own community, but a single attestation from an institution bound by professional secrecy (GP, shelter, neighbourhood team, housing association) replaces the entire neighbourhood round: anyone who does not want to be seen need ask their neighbours nothing. Who attested stays hidden from the instance. And this is the crucial correction: an absence of attestations never extinguishes your floor by itself. A human decides first, from outside the community and outside operations, with prior notice, suspensive effect and ninety days of grace.
  • Whoever has no papers still takes part, and so does whoever declines. Web-of-trust enrolment is possible at a lower, honestly declared assurance level. And there is a manual route: a human establishes that you are one person, with no token and no neighbourhood attestations, with the risk resting on the instance. Saying no to the identity layer must not cost you your subsistence floor. Paying, posting a deposit or doing computational work as an entry gate remains forbidden: the floor is unconditional, so the gate must never cost money.
  • If you are in danger. Anyone who declares that visibility puts them at risk can move their payout immediately: no announcement, no waiting period, no objection right for whoever held the old binding, no fresh neighbourhood attestations. Outward, the old picture keeps standing, and every attempt to open your status is recorded and disclosed to you. See the privacy statement.
  • And the familiar muscle for the edge cases: a corrupt document issuer (duplicate personal numbers) gets a lower assurance level in the coupling contracts and is suspended from the shared floor context: the same decoupling logic as for a fallen backing ratio, now applied to identity.

In one sentence: the wallet proves you are unique, an attestation proves you are alive, the mill keeps both blind, and the list stays in. That a shared nullifier set exists is grammar; which anchor (EUDI wallet, another eID, web-of-trust) an instance accepts is a house rule, and the door, as always, stays open.

The bank governs the human, and the human governs the bank.