Owner • Timelock • Keys
Security
The owner is a 48 hour timelock
Need's admin actions go through a 48 hour timelock built into the program. Every parameter, the attester set, the reserve, the guardian and the proposer change only through it: a proposal is an account anyone can read, and anyone executes it once 48 hours have passed, and the queue is read live on the protocol page. Every parameter is bounded in code, so even a queued change cannot set a fee above 3% or an award window above an hour.
One action outside the timelock
Binding the $NEED token is a single instruction, bind_token, allowed once and only while no token is bound. It sets the first slash and the ceiling every later slash must respect. The token is bound on the day it exists, so this call does not wait 48 hours; after it, the bond token can never change.
The guardian pauses entries, never exits
The guardian key can stop new intents and new awards (paused: no). Release, expire, lapse, claim, unbond and pool claims keep working while paused, so every escrow keeps its permissionless exit.
The keys and what each one does
| Part | Does | Bounded by |
|---|---|---|
| Offer relay | Streams signed offers, applies the soft close, commits the book's root with the award. | Offers are signed by sellers; the committed root lets anyone check what was on the table. |
| Delivery attester | Checks a delivery's hash, format and size and sends release_attested with its key. | It can only release an order to the seller that won it, at the signed price. |
| Epoch publisher | Posts the day's pool root with its inputs as JSON. | The inputs are public and the root can be recomputed by anyone. |
| Fee relay | Pays the network fee for buyer-signed posts, awards and receipts, and the rent of an intent until it closes. | It holds no buyer funds; it co-signs only Need's own post, award and receipt instructions, each carrying the buyer's signature, and they are simulated first. |
| Hook router | Runs inside every transfer of fill dollars: award, bond, epoch, fee split, the market's hook. | Holds the USDC behind fill dollars; it pays out only fee shares inside a fill and redemptions to holders. A market's hook can refuse a fill, never move it. |
| Pool owner | Owns the clean-fill pool inside Need, the machine wallet. | Standard distributor guarantees: withdrawals are visible and credits become a recorded shortfall. |
Tests before every deploy
The programs' own binaries run on a local Solana runtime with a clock the tests move: the book's whole lifecycle (refused paths included) and fills through Token-2022 with both reference hooks. The protocol page lists what each test covers.
Report a problem
Write to the account on X linked in the footer. A report that shows a way to move escrow outside the rules on the protocol page is answered first.
