Protocol
Permissions and trust
Who can do what. The admin can approve bidders and register sessions; no one can move your TSLAx or set a price.
| Role | Can | Cannot |
|---|---|---|
| Vault admin | Register sessions. Approve and revoke bidders. Set the bidder stake for new stakes. Hand the role to an account that accepts it. | Move or withdraw funds or stakes, set prices, change the vault’s parameters |
| Program upgrade authority | Create the vault once. Deploy new program code until the authority is renounced. | Change anything under the current code |
| Keeper, or anyone | Send the permissionless steps | Choose the close mark, use a session the admin didn’t register, or choose who gets paid |
| Depositors | Deposit, withdraw, collect premium, move shares | Touch another position |
| Approved or staked bidders | Bid once per round, claim calls and refunds | Change or cancel a bid |
| TSLAx issuer | Freeze, pause, move tokens with its permanent delegate, change the multiplier | Nothing in Shear stops these |
Fixed at creation#
The strike rule (5% above), the oracle confidence limit (1%), the auction length (five minutes) and the reserve price are set when the vault is created and can’t be changed. The TSLAx mint, the USDC mint, the Pyth feed and receiver, and the token programs are written into the program.
Who becomes admin#
Only the program’s upgrade authority can create the vault, and it becomes the vault admin. That stops anyone else from claiming the calendar and bidder roles first. The admin can then hand the role on with set_admin; it moves only when the named account signs accept_admin. SHEAR governance holds it that way; see Governance.
What you are trusting#
- The calendar. The program checks each session’s hours; which dates trade comes from the calendar the admin registers.
- The bidder list. The admin decides who can bid by approval, which affects how competitive the auction is. A wallet that stakes needs no approval.
- Program upgrades. Until the upgrade authority is renounced, new code can be deployed.
- Pyth. The close is Pyth’s price; a wrong or missing price leads to a dispute or the fallback.
- The issuer. TSLAx is the issuer’s token, with the powers above.