Follow a unit of public money from issuance to attested reconciliation. Every stage below is common to a central bank digital currency and a reserve-backed stablecoin, with one exception: what actually backs the holder's claim. This deck is illustration-first – each panel's picture carries the idea, and the animation shows value moving, never decoration.
Before any of the stages below run, the arrangement declares which kind of settlement asset it is moving. That declaration decides whether stage 1 checks anything at all.
| Model | Whose liability | What backs the claim | Backing invariant |
|---|---|---|---|
| Direct / one-tier CBDC | Central bank | Nothing – it is the money | Vacuous, no set to check |
| Two-tier / intermediated CBDC | Central bank | Still the central bank | Vacuous; the real controls are distribution and wallet tiering |
| Synthetic / pooled-account | The operator | Central bank money in an omnibus account, 1:1 | Real, a single reconcilable number |
| Fiat-reserve-backed stablecoin | The issuer | A reserve portfolio (cash, short government paper) | Real, but not one number – maturity, credit and custody all bear on it |
| Tokenized deposit | A commercial bank | The bank’s balance sheet | Not a segregated pool – the question is capital adequacy |
The two models look the same from outside – both move a fungible unit of value between wallets. Only one of them has a portfolio behind it that can gain, lose, or be mispriced.
Where a backing set exists, the arrangement holds it across some number of buffers – a reserve account, a partner rail, a treasury sleeve. That number is a property of the arrangement, not a fixed count of three: the invariant only holds across all of them added together.
A movement can leave the buffer set’s grand total unchanged while its composition breaks – that is exactly the failure a per-account check cannot see and an aggregate check can.
art-521 · backing invariant, N buffersA buffer set is a cost as long as it sits idle, and a stall risk the moment it runs short. The computed floor is the line between the two – above it, capital is parked and earning nothing; below it, an incoming payment has nowhere to settle.
Neither zone is a recommendation. The panel states an invariant and a computed number; nothing here schedules a sweep or a top-up.
Payers reach the operator over whatever rails an arrangement actually has – a real-time rail, a batch file, an offline tap. Each leg settles exactly once; the settle-once verdict is what the receipt records, not which rail carried it.
Where a netting period exists, the many small flows collected in stage 4 are netted over that period first, and only the residual crosses a rail boundary. Where no netting period exists – some arrangements settle each payment individually by design – this stage is skipped, not forced.
art-259 · art-368 · net the period, cross the residualSalaries, pensions, social transfers and vendor payments go out as one bulk run. The run is internally consistent, and its total matches what was authorised, item by item and in aggregate.
A tiered-wallet arrangement adds a failure mode this stage must recognise: a payment can be authorised, funded, and still unable to land because the receiving wallet is capped.
art-518 · bulk disbursement integrityThe stated population is compared against what actually happened, over a stated window. Exceptions are named, not hidden inside a passing total, and the run itself – that it happened, over which population, with which exceptions – is attested.
art-516 · daily reconciliation attestationThe last stage evidences the controls around every stage above: a log covering transactions and administrator activity that has no gap, and a check that duties which must stay separate actually are – the person who can post a disbursement is not the same identity who can approve it.
art-517 · audit-trail completeness · art-459-sod-matrix-check · segregation of dutiesAll eight stages above are wired as a single composed OpenChainGraph chain, government-payment-lifecycle: art-521 (backing, with art-06/art-512/art-280 supplying reserve facts only where the settlement asset is issuer-reserve-backed) → art-513 (collect) → art-259/art-368 (net then cross) → art-518 (disburse) → art-516 (reconcile) → art-517 + art-459-sod-matrix-check (controls). The settlement asset is a declared parameter on the same chain, not a second chain – the same wiring runs a centrally-issued asset and a reserve-backed one, and only the backing branch differs.
Naming a real scheme here is illustration of how a model actually works, not a claim about any procurement, bidder, or issuer. Every fact below is dated; check the source before relying on it, since limits, tiers and reserve rules change.
As of 2026-08-02, per the Central Bank of The Bahamas and sanddollar.bs.
As of 2026-08-02, per circle.com/transparency.
Set side by side, the pair shows the whole span the taxonomy covers: one model where the backing invariant does not exist because the instrument is already central bank money, and one where it is a live, portfolio-level question that changes with market conditions.
Every stage above computes over inputs the caller declares. The receipt chain evidences that the computation ran correctly over those declared inputs – it says nothing about whether the declarations were true. The backing panel is the sharpest case: it evidences that a declared set of balances satisfies a declared invariant, not that the money is actually sitting in the accounts named.
All content on this page is static and processed locally in your browser. No data is transmitted. Do not enter real personal data into any OpenChainGraph tool. Use synthetic or anonymised inputs only.