Follow a unit of public money from issuance through to attested reconciliation. The operational spine travels well between arrangements: collect, net, disburse, reconcile, evidence the controls. What sits underneath it does not.
Before any of the stages below run, the arrangement declares which kind of settlement asset it is moving. Read the last column: two of these five rows have no backing set for a checker to open. A node built on the assumption that a buffer topology always exists is simply wrong for them, which is why the backing check has to treat an empty set as a conformant answer rather than a shortfall or a bad input.
| Model | Whose liability | What backs the claim | Backing invariant |
|---|---|---|---|
| Direct / one-tier CBDC | Central bank | Nothing – it is the money | Vacuous, no set to check |
| Two-tier / intermediated CBDC | Central bank | Still the central bank | Vacuous; the real controls are distribution and wallet tiering |
| Synthetic / pooled-account | The operator | Central bank money in an omnibus account, 1:1 | Real, a single reconcilable number |
| Fiat-reserve-backed stablecoin | The issuer | A reserve portfolio (cash, short government paper) | Real, but not one number – maturity, credit and custody all bear on it |
| Tokenized deposit | A commercial bank | The bank’s balance sheet | Not a segregated pool – the question is capital adequacy |
From outside, both look identical: a fungible unit moving between wallets. Only one has a portfolio behind it that can gain, lose, or be mispriced.
Where a backing set does exist, the arrangement holds it across some number of buffers: a reserve account, a partner rail, a treasury sleeve. How many is a property of the arrangement, and the invariant only holds across all of them added together.
A movement can leave the grand total untouched while the composition underneath it breaks. Per-account checks pass; the aggregate check is the one that notices.
Idle, a buffer set costs money. Short, it stalls payments. The computed floor is the line between those two, and nothing more.
Neither zone is advice. A number, an invariant, and no instruction to move anything.
Payers reach the operator over whatever rails an arrangement actually has: a real-time rail, a batch file, an offline tap. Each leg settles once, and the receipt records that verdict rather than which rail carried it.
Where a scheme supports offline transfer, value moves while the ledger is not watching. The leg is provisional until it reconciles, and scoring it as final at the moment of the tap would put a settle-once verdict on an event the ledger has not seen yet.
Where a netting period exists, the small flows collected in stage 4 net over that period first, and only the residual crosses a rail boundary. Some arrangements settle each payment individually by design. Those skip this stage rather than being forced through it.
art-259 · art-368 · net the period, cross the residualSalaries, pensions, social transfers and vendor payments go out as one bulk run, and the run has to match its authorisation item by item and in aggregate.
Tiered wallets add a failure the totals cannot show you. A pensioner on a low-KYC wallet is owed a payment that would carry their balance past its cap. The item was authorised. The money was there. It still does not land, and unless this stage recognises a capped wallet as its own outcome, that pensioner reads as paid.
art-518 · bulk disbursement integrityThe stated population is compared against what actually happened, over a stated window. Exceptions get named rather than buried in a passing total, and the run itself is attested: that it happened, over which population, with which exceptions.
art-516 · daily reconciliation attestationThe last stage evidences the controls around every stage above: a log covering transactions and administrator activity that has no gap, and a check that duties which must stay separate actually are – the person who can post a disbursement is not the same identity who can approve it.
art-517 · audit-trail completeness · art-459-sod-matrix-check · segregation of dutiesAll eight stages above are wired as a single composed OpenChainGraph chain, government-payment-lifecycle: art-521 (backing, with art-06/art-512/art-280 supplying reserve facts only where the settlement asset is issuer-reserve-backed) → art-513 (collect) → art-259/art-368 (net then cross) → art-518 (disburse) → art-516 (reconcile) → art-517 + art-459-sod-matrix-check (controls). The settlement asset is a declared parameter on that chain rather than a second chain: the same wiring runs a centrally-issued asset and a reserve-backed one. What changes is the backing branch, plus whatever the model's limits, offline behaviour and redemption path do to the stages downstream of it.
Four live schemes, named to show how the models actually work. This is illustration and nothing else: no endorsement, no involvement, no procurement. Every fact below carries the date it was read, because limits, tiers and reserve rules all move.
Individual tier limits as published on sanddollar.bs/individual, read 2026-08-03; tier structure and offline design per the Central Bank of The Bahamas. Limits and tiers change; check the source.
Per the issuer's published reserve disclosures at circle.com/transparency, read 2026-08-03. Reserve rules and composition change; check the source.
Per Fnality International, fnality.com/payment-systems/british-sterling-payment-system and fnality.com/news (dated 2023-12-14), read 2026-08-03. Fnality does not publish a redemption mechanism or offline capability in this material, so neither is stated here.
Per JPMorgan Chase, jpmorgan.com/kinexys/jpm-coin, read 2026-08-03.
Across the four, the taxonomy's whole span is visible. Sand Dollar has no backing invariant to check, because the instrument already is central bank money. Fnality sits next to it: a private operator's liability, but reconciled against one pooled central-bank account rather than a portfolio. USDC's invariant is a reserve portfolio that moves with market conditions. JPM Coin sits at the other private end: a claim on one bank's own balance sheet, with capital adequacy standing in for a segregated reserve. The four also differ on wallet caps, on whether value can move while the ledger is dark, and on who stands behind a redemption. Calling all four digital money is true and tells you almost nothing.
Every stage above computes over inputs the caller declares. The receipt chain evidences that the computation ran correctly over those declared inputs. It says nothing about whether the declarations were true. Stage 2 is the sharpest case: it evidences that a declared set of balances satisfies a declared invariant. That is not proof of reserves, and nobody should read it as proof that the money is sitting in the accounts named.
All content on this page is static and processed locally in your browser. No data is transmitted. Do not enter real personal data into any OpenChainGraph tool. Use synthetic or anonymised inputs only.