THEPROTOCOL

CANOPY

#26 of 27Frontier · a future case10/12 primitives live in production
Carbon Removal and Environmental Attestation

Removal paid from escrow on an accredited verifier’s signature, each quarter released once, and every retirement signed where a second claim on the same tonnes is plain to see.

Open the live chamber in the app
The animated flow, the attack replays and the deep architecture run there; this page is the reference text.

Who this serves

The problem

Carbon removal is bought years before it is delivered and verified months after it happens. Between the kiln and the claim, a tonne passes through a sensor network, a verification report, a registry entry, a purchase order and a sustainability report, each kept in a different system, and the joins between them are spreadsheets. The same tonne can be sold twice, a failed batch can be quietly re-run, and a buyer’s claim rests on a reconciliation somebody performs once a year.

The system

CANOPY is a carbon removal network in which each project’s country runs its own registry frame: a cooperative running 38 biochar kilns in the Ember Hollow valley, 164 reforestation plots in the northern uplands and a mineralisation plant on a basalt coast, each checked by independent verifiers and sold to buyers who run frames of their own. At 07:40 on a Tuesday in October, verifier-07 signs Ember Hollow’s third-quarter batch: 1,240 tonnes of removal, drawn from readings that every kiln’s probes signed as they were taken. The buyer’s offtake, 4,800 tonnes for the year at 18 units a tonne, has sat in escrow since January, and the signature releases 22,320 units to the cooperative’s treasury the same morning. Every unit that leaves the escrow arrives in the treasury, and an independent auditor checks continuously that none were created on the way.

A tonne is claimed in the open. When the buyer’s claims desk retires those 1,240 tonnes, it signs the retirement under its own identity, citing verifier-07’s attestation and the carbon registry’s serial numbers, and the entry sits beside the attestation on a ledger that only appends. A second claim on the same batch cites the same attestation, so the buyer, the registry and any auditor see both at once instead of months later in a spreadsheet reconciliation. In July the second quarter’s first attestation failed on a nine-day gap in one kiln’s logs; the failure stayed where it was signed, the corrected batch without that kiln’s tonnes sits beside it, and anyone reading the quarter sees both.

The buyer is a freight line on another continent, on its own frame and in its own currency. Its offtake desk is the treasury’s own sub-agent: it holds no wallet, and every offtake it signs is checked against the mandate Sana Varga, its head of sustainability, signed for twelve months, as that mandate stands at the moment. Its capability token names three projects and a budget of 120,000 units, and a token can only narrow what its issuer holds. The year’s money crossed through an FX pool between sovereign frames and landed once, on the project registry’s frame. When an accreditation body withdraws a verifier, the registry operator suspends its agent: its identity dies in under 500ms, and nothing it signs after that reaches a release.

The cast and their ceilings

AgentRoleCeiling
kiln-probesMeasure each kiln, sign every readingSign their own readings under certificates that live hours, not years. Hold no budget and cannot attest a batch.
verifier-07Checks the readings, signs each batchAttests batches on the offtakes that name it, one attestation per batch. Its signature releases a tranche to the payee the contract names, and to no one else.
offtake-deskFunds the buyer’s offtakesThe treasury’s sub-agent, with no wallet: every offtake is checked against Sana Varga’s mandate. Its token names three projects and 120,000 units; a fourth project is refused before a unit moves.
claims-deskRetires tonnes against the buyer’s claimSigns retirements for the buyer, each citing its attestation and the registry’s serials. Moves no money.
coop-deskClaims each quarter, holds the co-op treasuryThe members vote distributions. Cannot attest its own batches, release escrow or remove an entry.

The flow, step by step

  1. In January the buyer’s offtake desk funds the year from its own frame: 4,800 tonnes at 18 units a tonne.
  2. The FX pool carries it across sovereign frames. The escrow lands on the project registry, exactly once.
  3. All quarter, the probes on 38 kilns sign every temperature trace and every weighed load.
  4. At 07:40 on a Tuesday in October, verifier-07 signs batch Q3: 1,240 tonnes, one attestation, one key.
  5. The attestation unlocks the third-quarter tranche and nothing else.
  6. 22,320 units release to the Ember Hollow co-op’s treasury: 1,240 tonnes at 18 units.
  7. The release lands on the ledger beside the attestation that earned it.
  8. The buyer’s claims desk signs the retirement of the 1,240 tonnes, citing the attestation. A second claim is plain to see.

Each need, mapped to a live primitive

The needThe protocol primitiveStatus
Every probe and every signer an identitySPIFFE identity per probe gateway and agent, short-lived certificatesLIVE
Readings, batches and retirements, signedSigned attestations from identified parties, append-onlyLIVE
Offtake money held before the first tonneContract spine: escrow at award, quarterly milestones in strict orderLIVE
A named person behind the offtakeCockpit Card mandate, scope-clamped, re-derived per requestLIVE (gated)
Three projects and a budget, as boundsIRONKEY L4 capability caveats: counterparty allowlist, atomic budget debitLIVE
Each quarter paid once, whatever the retriesIdempotency keys, two-layer dedup (cache + ledger unique index)LIVE
Buyers on other frames, in other currenciesCross-registry transfer, exactly-once; FX pools across sovereign framesLIVE
The co-op’s own treasuryOrganizations: shared treasuries, member votes, dividendsLIVE
A withdrawn verifier signs nothing moreCoordinated suspension: mTLS identity revoked in under 500ms, account suspendedLIVE
A register anyone can replayImmutable event ledger; conservation independently auditedLIVE
Each registry’s declared limitsJurisdiction profile signed into the registry cardSHADOW
A sensor threshold proven, the series withheldZK attestation over a new circuit, not yet writtenDESIGNED

The attack this chamber refuses: The withdrawn verifier

The attack. In November the accreditation body withdraws verifier-07 over a conflict of interest, and the registry operator suspends its agent. The co-op’s desk asks the old verifier to sign batch Q4 anyway, for the same buyer.

Why it fails. The suspension is one coordinated action: the agent’s identity is revoked over the event stream in under 500ms and its account is suspended. A suspended agent is refused at authentication, so it cannot submit an attestation or approve a milestone, and the fourth-quarter tranche releases only on an accepted verifier’s signature.

Rail S08 · Coordinated suspension. One action revokes mTLS, suspends the account, and blocklists cross-frame receipt.

What actually happens. The Q4 tranche stays in escrow until an accredited verifier signs. Every batch verifier-07 signed before its withdrawal stays on the ledger, and so does its revocation.

The attack this chamber refuses: The quiet deletion

The attack. Before resubmitting, the co-op’s desk asks for the failed second-quarter attestation to be deleted, so the corrected batch reads as a first pass.

Why it fails. The ledger is append-only and no operation removes an entry, for the project, the verifier or the registry operator. A correction is a new signed entry beside the old one, so the corrected batch is verified on its own evidence and the failure stays readable next to it.

Rail S14 · Immutable ledger. Append-only, replayable, forensically searchable. History cannot be edited.

What actually happens. The corrected batch still settles on its own attestation. A reviewer replaying the quarter sees the failure, the gap that caused it and the correction, in order.

Deep architecture

CANOPY deployed: the project registry’s frame holds the offtake contract, its escrow and the tonne ledger; the buyer acts from its own frame and currency, and the verifier signs from its own; the kilns, the sensors and the MRV platform stay where they are, signed at the edges. The trace replays one quarter at Ember Hollow, from the buyer’s mandate to the retired tonne.

The deployment, traced

  1. Sana Varga underwrites the buyer’s treasury for twelve months. Its offtake desk carries a token: three projects, 120,000 units.
  2. In January the desk funds the year from the buyer’s frame: 4,800 tonnes at 18 units a tonne.
  3. The FX pool carries it across frames. The escrow lands on the project registry, exactly once.
  4. All quarter the probe gateways sign every reading, under certificates that live hours, not years.
  5. In October the co-op desk claims the third quarter: 1,240 tonnes.
  6. The verifier works the batch on its own bench, over the signed readings.
  7. At 07:40 verifier-07 signs batch Q3: one attestation, under its own identity.
  8. The signature crosses the fabric; the relaying peer is a courier, never the principal.
  9. The offtake contract releases the third-quarter tranche, and only that one.
  10. 22,320 units land in the co-op treasury, where the members vote what happens next.
  11. The buyer’s claims desk retires the 1,240 tonnes, couriered home the same way.
  12. The retirement lands beside the attestation it cites. A second claim on the same batch is plain to see.

Adoption, phase by phase

Discover: One past year, re-read as signed entries.

Pilot: One project, one quarter, a small offtake.

Production: The registry runs its own frame.

Federation: Buyers and registries bring their own frames.

Sizing

LevelWhatContainers
L1Projects, verifiers and buyers join with accounts and agents only0 of theirs
L2A project runs its probe gateways and desks against a hosted seatagents only
L3A national registry’s own frame, and each buyer’s, federateda full frame each

One batch, signature to retirement

sequenceDiagram
  participant Buy as buyer desks (their frame)
  participant Ver as verifier-07 (its frame)
  participant Off as offtake contract
  participant TEG as offtake escrow
  participant Co as co-op treasury
  participant ES as tonne ledger
  Buy->>TEG: the year funded via the FX pool, 4,800 t at 18
  Ver->>Off: batch Q3 attested, 1,240 t, signed
  Off->>TEG: release the Q3 milestone
  TEG-->>Co: 22,320 units, exactly once
  TEG-->>ES: the release, beside the attestation
  Buy->>Off: retirement of 1,240 t, signed, citing the attestation
  Off-->>ES: the retirement, append-only
  Note over Off: the Q3 milestone releases once#59; a retry moves nothing
  Note over ES: a failed batch stays#59; its correction sits beside it

Topology, as declared

flowchart LR
  P["kiln-probes<br/>signed readings"] -->|"readings"| V["verifier-07<br/>one attestation per batch"]
  V -->|"batch Q3, signed"| G{"release gate"}
  B["offtake-desk<br/>buyer frame"] -->|"via the FX pool"| E["offtake escrow<br/>project registry"]
  E -->|"Q3 tranche"| G
  G -->|"22,320 units"| C["co-op treasury"]
  E --> L[("tonne ledger<br/>append-only")]
  D["claims-desk"] -->|"retire 1,240 t"| L

Standing it up

Runs beside what you already have

A full sovereign frame is nine containers and boots in about two minutes, on anything from a Raspberry Pi to a rack. That is cheap enough to run the whole system in parallel with the legacy stack: the old system keeps running, real work mirrors onto the rails, and you compare ledgers until the evidence settles the argument. Nothing is ripped out.

Planned: a public proxy library. Free, ready-made connectors for the systems above and whatever else a merge needs, so the bridge is an import, not an integration project.

What this does not claim