English
Ripe Ecosystem
Contents

Whitepaper · a design overview

Brim

A floor that never dilutes. A yield that overflows.

The premium funds the yield.
The reserve funds the floor.
Nothing mints unpaid.
(3,3) with a redeem button.

This page is the full description of Brim's design, checked against the contracts, and the current statement of its launch settings. The yellow paper is the compact formal version, also in Chinese, Korean, and Japanese. The contracts are the final word on any mechanism; this page is not a yield card. The protocol is Brim and its token is BRIM. The only genuine BRIM is the token at the contract address published by @Brim_HQ. Nothing trading under these names before genesis is this protocol.

Numbers on this page are the launch configuration, dated September 2026. Section 18 lists every one with its bound and who enforces it; section 20 says who may change it, and on what delay.

2%redemption fee, kept by the holders who stay
5.00× → 1.10×every offering, a Dutch descent on book value
90%of every ordinary surplus goes to stakers
hourlyreward ticks, cranked by anyone
200%the Well's target, a nominal annual rate it aims at
1%of stake per tick, the most any tick can pay in
5% / 3%tolls to sell and to buy, paid in NVDA, the pool's quote asset
50%rage-quit fee, half burned, half to the patient
7 daysto leave stake for free

The launch in nine numbers. Each is a dial with a bound; none is a promise.

Part I

The idea

What is this?

01What Brim is

A reserve. A reason to stay. A way to leave.

Why this exists

Tokenized stocks trade on Robinhood Chain now. Between trades, most of them do nothing. Nobody has put three things in one token: a basket of those assets that pays a yield, a yield paid only from money that has already arrived, and the basket itself handed back to anyone who asks.

The designs that came close took one of two shortcuts. Some paid a yield by printing it, and the token was worth a little less every time it was paid. Some promised a floor and kept it on a dashboard, so the day the premium died, the only exit was the market. We could not find a design that did all three, so we built one that refuses both shortcuts and lets anyone check the refusal in the mint itself.

The one-paragraph version

Brim is a protocol on Robinhood Chain that turns a basket of tokenized stocks into a yield-bearing token, BRIM. The basket is the reserve. The yield is what the protocol makes from it. The reserve fills to a line the protocol calls the brim: book value per token, what one BRIM's slice of the reserve is worth at accepted prices. New BRIM is only ever sold above that line, and whatever a buyer pays above it is surplus. A split the protocol calls the Waterfall divides the surplus among stronger backing, operating capital, overflow for stakers, and a small developer share. Stakers watch their balance grow in the token itself. New reward tokens are minted into the staked pool, and only against revenue that has already arrived: offering premiums, trading tolls, and profit the operating desk returns. A finite allocation set aside at genesis tops rewards up when those fall short of a target. Any holder can hand BRIM back to the protocol and take their pro-rata slice of the reserve, in kind, while the Tap is open. That is the redeem button.

The vessel the brim book value per token the floor, 0.98× the brim the reserve a basket of tokenized stocks (tokenized Nvidia at launch) the Pour offerings sell new BRIM above the brim, 5.00× down to 1.10× the Spillway overflow becomes new BRIM the Basin the staked pool rewards land here the Well genesis BRIM finite existing BRIM, the gap only the Tap hand BRIM back, take your slice of the basket less the 2% fee the desk and vesting are off this drawing; the map in 03 has every part
F1.1. The vessel. The reserve fills to the brim; the Pour sells new BRIM only above it; the Spillway carries overflow into the Basin as rewards, minted only against revenue that has arrived; the Well tops the Basin up when overflow falls short; the Tap at the bottom pays any holder their slice of the basket. The desk and vesting are off this drawing; the map in 03 has every part.

The genesis plan backs the initial supply with tokenized Nvidia, the first asset in the reserve. After genesis, every registered mint path passes a backing check in the transaction that performs it: no sale, no reward, and no payout to anyone mints a token that was not paid for at the brim or above. Which contracts may mint is a governed list (15). There are no VCs, no insiders, and no pre-sale. The launch is open to anyone who wants to play. Top Juicers will be first in line.

The reserve is meant to be a basket of tokenized stocks. It opens with one, tokenized Nvidia, for two practical reasons: the genesis event takes in one asset, and the token's pool has to be quoted in one. After genesis the Policy Board admits more stocks behind its timelock, each with a live price (15), and every redemption pays a slice of whatever the reserve holds at the time. The sections below say "the reserve" for the whole basket.

Why it has not been built before

The parts are old. Olympus showed that a token sold above its backing can fund a staking flywheel, then minted its rewards on a schedule until the flywheel ran the other way. Terra showed that a backstop which pays is worth having, then made the backstop mint more of the thing that was falling. Reserve-style baskets showed honest onchain redemption, then let two-way minting and redemption pull the price to basket value, so a premium never lasts. Each kept a good idea and gave something up for it. Brim keeps the three good ideas and takes none of the shortcuts. The premium-issuance flywheel stays, with rewards minted only against revenue that has landed. The floor is a function anyone can call, with no mint on the way out. The basket can be taken in kind, with no pin holding the token to it. One inequality does the work, and the contract that mints checks it on every mint. The long form, with Ampleforth and NET beside them, is 16.

Why hold BRIM

Why hold BRIM rather than the basket itself? Any holder can hand BRIM back and take their slice of the reserve at the floor, 0.98× book value, and the market may price it above that. A holder who stakes also takes part in what later activity pays. Every later sale above book value, every trade in the token's own pool, and every profit the desk sweeps back sends most of its surplus to the staked pool as new tokens, backed before they are minted. That participation comes with the token however it was bought, and tokens from an offering can join the pool as they are released, from the cliff on.

An offering sells a stated allocation on a stated price path; the market sells whatever depth it has at the price it quotes. Which price is better on a given day is the buyer's call. Neither route buys extra backing, and nothing protects a premium: the market can take it away while book value stands still (02).

Buyers pay the surplus, traders pay the tolls, and leavers pay the fees that stay for those who remain. The Well, a fixed allocation set aside at genesis, is handed out over time rather than earned. The desk's profits come from investing outside those flows. At launch the staked pool's new tokens depend on offerings filling and on trading; the floor depends on no one buying anything. What remains when activity slows is walked through on the running example's own numbers in 14.

Four claims, four proofs

The four lines on the cover are the whole argument. The rest of this page proves them, one section at a time.

Start here if you are…

ReaderPath
Curious, and want the shape of it01, 02, 06, 19
A buyer or a staker01, 02, 04, 06, 07, then 08 and 10 for the yield and the end of the running example; 05 and 11 if you want the market and the Well; 19 before you decide.
A trader02, 05, 06, 19
A Ripe juicer01, 13, 17, 19
A researcher02, 09, 10, 16, 14, 19
An auditor02, 03, 06, 09, 10, 15, 20, then the yellow paper and the contracts

Yellow paper: abstract.

02Two numbers

Book value is the brim. The floor is the brim less the fee. No protocol action can lower the brim; markets can.

Book value, the brim

The protocol is organized around two quantities anyone can compute from chain state. The first is book value: the reserve's net asset value (NAV) at accepted prices, the prices the protocol's feeds currently accept, divided by the total supply of BRIM. That number is the brim: the fill line, what one BRIM is backed by. Every invariant in the protocol is checked against it.

book value  =  reserve NAV / total supply              (2.1)  the brim

The floor

The second is the floor: what the Tap pays, in reserve assets, to anyone who redeems while the Tap is open. It is book value less the redemption fee, 2% at launch. The fee stays in the reserve; it is what the holders who stay keep.

floor       =  book value × (1 − redemption fee)     (2.2)  fee = 2%

The law

At accepted prices, no protocol action can lower the brim. After genesis, every mint is checked against that rule in the transaction that performs it, by the contract that moves the money. This page calls that contract the door. The offering is one door and the reward engine is the other, and each refuses a mint that fails the check.

The reserve is tokenized stocks; their market prices move, and book value in dollar terms moves with them. What cannot happen, through any registered mint path, is dilution: no sale, no reward, and no payout to anyone mints a token that was not fully paid for. Markets may lower book value; protocol actions, at accepted prices, never will. The doors that exist today enforce the rule; governance can replace them, or change which contracts may mint, through the registry's timelock (15).

The price ladder open market trades here offerings mint here: 5.00× down to 1.10× 5.00× offerings open here 1.10× the offering's minimum: nothing mints below it 1.00× the brim · book value = reserve NAV / supply 0.98× the floor what the Tap pays: book value × (1 − 2% fee) the Tap: redeem for the basket, in kind market (illustrative)
F2.1. The price ladder. The Tap buys at the floor; the offering sells no lower than 1.10× book value; the market price moves on its own; the drawing puts it between the two. The brim is the one line no protocol action can lower. Change the values to move the brim and the floor together; the market marker is free.

Protecting backing per token does not protect the premium someone pays for it. The market can take a premium away while the brim stands still; the brim is the part the protocol controls.

What moves the brim

The fastest way to learn the law is to list every action and ask what it does to the brim.

ActionEffect on the brimWhy
An offering saleUpThe buyer pays above the brim; the reserve keeps at least the backing for the tokens minted, and the reserve's share of the surplus lifts everyone.
A redemptionUpAll the BRIM handed in burns; the payout is computed on that amount less the fee, so the fee's share of the reserve stays behind. The fee is never zero (06).
A reward mintUnchangedRewards are minted only against overflow moved into the reserve in the same transaction, at the brim, checked once when the overflow enters the reserve and again when the new tokens are minted, so a stale price cannot slip through.
A Well drawUnchangedPre-minted supply moves from the Well into the staked pool. Neither supply nor reserves change.
A tollUpThe reserve's share of the toll is banked; the rest becomes overflow, desk capital, and the developer share.
A desk sweepUpThe reserve's share of a named sweep is banked. The desk never touches the reserve otherwise.
A rage quitUpHalf the fee burns; the other half stays in the pool.
A reserve-asset price moveEither wayThe dollar value of the reserve moves with its assets. This is the one row the protocol does not control.

T2.1. What moves the brim. Every protocol action is up or unchanged; only the assets' own prices go both ways.

A mint that passes, a mint that fails

The law is one inequality, and the door runs it on every mint: the value paid, times the supply before the mint, must be at least the tokens minted, times the reserve's value before the mint. A sale above the brim passes. A mint below it is refused in the same transaction, whoever proposed it.

A mint that passes, a mint that fails a sale the door accepts reserve 100 · supply 100 brim 1.000 sale at 2.0× the brim: buyer pays 10, receives 5 BRIM reserve 110 · supply 105 brim 1.048 ↑ 10 × 100 ≥ 5 × 100 ✓ (payment × supply ≥ minted × NAV) a mint the door refuses reserve 100 · supply 100 brim 1.000 mint 10 BRIM for a payment of 5 reserve 105 · supply 110 brim 0.955 ↓ 5 × 100 ≥ 10 × 100 ✗ refused in the transaction illustrative units · the backing check alone; a real sale also runs the Waterfall (04)
F2.2. A mint that passes, a mint that fails. The same check, run on two proposals. The first raises the brim and goes through; the second would lower it and is refused at the door.

Every BRIM that exists was paid for.

Six words

The page uses six economic terms that are easy to run together. They are defined here and mean the same thing everywhere else.

WordMeaning
book valuereserve NAV divided by total supply, the formal quantity every invariant is checked against.
the brimthe same number, as the fill line: what one BRIM is backed by.
floorwhat the Tap pays: book value less the redemption fee.
surplusvalue that arrives above the brim, from a sale, a toll, or the desk.
Waterfallthe governance-set split of that surplus: overflow for stakers, capital for the desk, backing for the reserve, and a developer share.
overflowthe stakers' leg of the Waterfall, waiting for the Spillway's tick.

T2.2. Six words.

the running example

One balance sheet is carried through this paper. A reserve worth $10,000 backs 10,000 BRIM, so the brim is $1.00 and the floor is $0.98. 5,000 BRIM are staked, 2,000 sit in the Well, and the developers' payee is set, so the split pays all four legs. Prices hold still and transfers are exact, so every number that follows is the protocol's own arithmetic. It continues in 04 (a purchase), 09 (the split), and 10 (the tick, then a redemption, and the four-state table).

Yellow paper: § 1.

03The parts, and how value moves

Small single-purpose contracts, two doors out, one lock, and receipts instead of promises.

The map

The protocol is a set of small, single-purpose contracts. Each has one job. Value moves through them in a fixed order, and the map follows it. The map shows every part as a box and every flow as an arrow. Two doors are marked: the only way backing leaves, and the only way overflow becomes rewards. Backing leaves the reserve only through the Tap, and overflow becomes staker rewards only through the Spillway. The desk sits beside the reserve, never inside it, behind a wall it does not cross.

The system map holder buyer the offering (Pour) the Decanter vesting · claims the pool (Tollbooth) the Waterfall the split governance sets every dial the reserve (Reservoir) backing the Tap redemption the desk (Mill) separate sleeve the Spillway overflow waits here the tick mints → the Basin staked pool the Well genesis BRIM the wall mints stakes → · ← exits (withdraw, redeem, rage quit) ↓ burns BRIM draws:a transfer pays backing kept≥ M × book value ↑ the basket, in kind only door out moves in at the tick surplus tolls reserve leg overflow desk leg ↓ · named sweep ↑ (governance-named) dials backing leaves only here rewards: only here
F3.1. The system map. Every part, every flow, and the two doors. Toggle the layers to follow one kind of value at a time; click a part to jump to its section.

The parts

PlainlyThe contractIts one job
the offeringthe PourSells new tokens in governance-started offerings, always above the brim.
the reservethe ReservoirHolds the basket that backs every BRIM; value leaves through one door.
redemptionthe TapThat door. Burns BRIM, pays the pro-rata basket slice at the floor.
the splitthe WaterfallRoutes every unit of surplus above the brim: overflow, desk capital, backing, a developer share.
the stakers' shareoverflowThe stakers' leg of the Waterfall, counted unit by unit while it waits to become rewards.
the reward enginethe SpillwayReleases overflow into backed staker rewards, on a clock, under caps.
stakingthe BasinA share-based pool with three exits of differing speed and price.
the genesis allocation for rewardsthe WellPre-minted BRIM that fills reward gaps in dry spells, gradually and never off a cliff.
the deskthe MillSwaps, yield strategies, liquidity, and credit on Ripe, through Brim Adapters. Runs on protocol-owned assets only.
vestingthe DecanterEvery offering allocation and every slow exit settles here before it is liquid.
the market tollthe TollboothThe hook on the token's own pool; every swap pays a toll into the split.
governancethe BoardroomTwo boards validate every dial; a registry decides which contracts exist and which may mint.

T3.1. The parts. Plain words lead; the contract names are the ones you will see onchain.

One lock, and receipts

Every path that moves reserves or stake shares one settlement lock, which keeps a second such operation from starting before the first finishes. And every mint is sized from balances measured before and after, never from an amount someone promised. Governance is one box on this map; it gets its own section (15).

Yellow paper: § 2.

Part II

What you can do

How do I get in, get out, and stake?

04Buying in: the offering

New BRIM is sold in Dutch offerings that open at 5.00× book value and never close below 1.10×. The premium is the yield engine.

Two ways in

There are two ways to get BRIM. The market (05) quotes a price and fills what its depth allows. The offering sells a stated allocation on a stated price path, and pays a bonus for patience. The ladder in 02 shows both: the market trades between and above the brim, and the offering mints from 5.00× down to 1.10×.

An offering day

New BRIM is sold through offerings: events that governance starts and the Pour runs, each paid in one reserve asset, named when the offering is set up (tokenized Nvidia at launch), so the payment arrives in a reserve asset and is backing the moment it lands. Each offering is a Dutch auction on the price multiple over book value; the multiple counts the backing too, so 5.00× means paying 5.00 times book value, of which one part is backing and the rest is premium. The price opens at 5.00× book value and descends in a straight line over the window (one day at launch) to a 1.10× floor, the contract's own hard minimum. No sale below it is possible. Buy early and pay more for certainty; wait for a lower multiple, at the risk that the offering sells out. Every purchase is priced against the brim as it stands in that block, from a live price on every reserve asset; if any reserve asset cannot be priced, the offering refuses rather than guesses.

An offering day 1 2 3 4 5 open descend buy vest claim 5 to 30 days 80% of the payment is surplus surplus → the Waterfall 1.00× the brim 1.10×, the minimum 5.00× open close (one day) 67% 9% hour h
F4.1. An offering day. The premium falls in a straight line from 5.00× to the 1.10× minimum over the window; everything between the line and the brim is surplus, before the vesting bonus. The five steps of a purchase run along the top.

Anatomy of a sale

Because the buyer pays a premium over the brim but receives tokens backed only at the brim, every sale generates a surplus: real money above what backs the tokens actually minted, bonus included. The reserve keeps the backing first; only the surplus above it runs the Waterfall (09). That is the invariant, and the contract checks it in the transaction.

base       =  value paid / (premium × book value)                (4.1)
minted  M  =  base + vesting bonus, never beyond value paid / (1.10 × book value)   (4.2)
invariant  :  the reserve keeps ≥ M × book value from every sale  (4.3)
the running example: a purchase

A buyer pays $100 at 2.0× the brim, takes no vesting bonus, and receives 50 BRIM, released over the vesting period. $50 goes straight into the reserve as the backing for those tokens. The other $50 is surplus and runs the Waterfall in the same transaction; 09 shows where it lands and what the reserve and the brim look like after the split. The tick, a redemption, and the four-state table are in 10.

At a 5.00× fill, about 80% of the payment is surplus; at the close, 9%. That is why the offering is the yield engine at launch, before external revenue scales.

The premium funds the yield.

Anatomy of a sale buyer pays P at premium ≥ 1.10× the offering (Pour) surplus the Waterfall overflow (stakers) the desk the reserve the developers 1% backing kept ≥ M × book value the reserve (Reservoir) M tokens, vesting the Decanter claims over 5 to 30 days every sale: P above the brim, M backed at the brim, the difference is surplus
F4.2. Anatomy of a sale. The reserve always keeps at least the value backing the tokens actually minted, vesting bonus included. The true surplus above it runs the Waterfall to overflow, the desk, the reserve's own share, and the developers. Tokens vest before they are liquid.

Vesting

Every allocation vests through the Decanter, so freshly minted tokens are never liquid in the block they are born. Vesting runs 5 to 30 days at the buyer's choice, and longer vesting earns a bonus of up to 25% more tokens. The bonus can never push the effective price below the 1.10× minimum. Vesting begins when you buy. Nothing can be claimed until the cliff, which is the shortest vesting length, 5 days. At the cliff, everything accrued so far can be claimed at once, and the rest keeps releasing day by day until maturity. From the cliff on, a claim can go straight into the staked pool in the same transaction.

Vesting buy · day 0 day 20 in this example day 30 the cliff, day 5 everything accrued so far claims at once maturity the buyer's choice, day 5 to 30 100% 0 25% nothing claimable yet the rest releases day by day from the cliff on, a claim goes to a wallet or the Basin accrued claimable
F4.3. Vesting. Nothing claims before the cliff; after it, a claim can go straight into the Basin.

Bounds and budgets

Offerings are bounded by demand, by the 1.10× minimum, and by a budget the Policy Board sets per offering. They are never bounded by the reward budget that meters the Spillway (10): sales raise the brim, rewards hold it, and the two budgets are separate. An offering's terms cannot change while a window is live or scheduled; governance stops it first.

honest noteIf you need liquidity inside 5 days, use the pool, not the offering. And no door guarantees you recover a premium: the Tap pays the floor, and the pool pays whatever it quotes that day (08).

Yellow paper: § 3.

05The market and its toll

BRIM trades in its own pool. Every swap pays a toll in NVDA, never in BRIM, and the toll runs the same split as an offering's surplus.

The pool

BRIM trades in its own pool on Uniswap v4, against tokenized Nvidia (NVDA), the reserve's first asset and the pool's quote asset. The hook that runs the pool, the Tollbooth, binds that one pair; the pair is fixed at deployment, and no board can change it. The reserve can widen to other stocks while the pool stays quoted in NVDA. The pool quotes BRIM in NVDA, so a dollar price for BRIM moves with the stock as well as with the token; the dollar prices on the ladder in 02 are illustration only, and the pool never sees them. The pool charges no swap fee of its own: the toll is the only fee. Anyone can buy or sell there without touching the protocol's other doors, and for most people it is the first door they meet.

The toll

Every swap pays a toll in NVDA, never in BRIM: 5% to sell and 3% to buy at launch. The toll is the same share of what the trader pays or receives, however the order is written. Tolls accrue on the pool and settle outside the swap path: anyone can send what has accrued into the Spillway, where it enters the same Waterfall as offering surplus (09), as trading revenue. Because the toll is paid in a reserve asset, the reserve's leg of it is backing the moment it lands. Buys and sells both pay, so the pool funds yield in either direction.

The hook deploys with both tolls at zero; the launch values land through one Market Board timelock. A raise queued before a cut can never land after it: the cut cancels any raise still waiting in the queue.

Swap, toll, Waterfall protocol-owned liquidity: only the desk's adapter may add the pool · BRIM / NVDA the hook (Tollbooth) quoted in NVDA, not USD trader buy: 3% toll sell: 5% toll anyone else in NVDA, never in BRIM accrued tolls (NVDA) anyone routes the Spillway the Waterfall
F5.1. Swap, toll, Waterfall. A trade through the pool pays its toll in NVDA; the toll accrues on the pool and anyone routes it into the split. Only the desk's adapter may add liquidity.

Protocol-owned liquidity

The pool's liquidity is protocol-owned by construction. The hook admits liquidity from the desk's adapter and no one else, so a toll cannot be sidestepped by posting a position instead of a trade. Liquidity actions are queued by the Market Board behind a timelock and sized when they are queued, and execution must meet the price and minimum-output limits fixed when the action was queued.

The liveness rule

The swap callbacks read only the hook's own storage and touch only the pool manager. A failure in Brim's settlement or registries stays outside the swap: the market keeps trading, and the tolls keep accruing until someone routes them. The market still depends on what any pool depends on: the pool manager, the quote asset, the hook itself, and the chain.

Whether the pool or the Tap pays a seller more depends on depth, route, order type, gas, and what the seller wants to hold; it is a question for the trade, not for this page.

Yellow paper: § 6 (the Tollbooth row), § 10 (protocol-owned liquidity).

06Getting out: the floor

Hand BRIM to the Tap and take your slice of every asset in the reserve, in kind, less a 2% fee that stays for everyone else. No price oracle, no redemption queue, no buyer to find.

The basket, divided

Any holder can hand BRIM to the Tap and receive their pro-rata slice of the entire reserve basket, in kind, minus a fee (2% at launch) that stays in the reserve for everyone who remains. The tokens are burned before assets move. There is no queue and no buyer to find: the floor is a function anyone can call, with no market maker in between. The Tap pays 0.98× the brim, never the brim itself; the difference is what the holders who stay keep.

The basket, divided holder 1 BRIM the Tap burns first the reserve basket NVDA stock B stock C stock D the fee (2%) stays: lifts the brim a pro-rata slice of every asset, in kind no price read · no queue · no buyer to find
F6.1. The basket, divided. One BRIM in; a slice of every reserve asset out, in kind; the fee's slice stays behind and lifts the brim. No price is read on the way. The reserve opens holding tokenized Nvidia alone; the other segments are the basket it grows into as the board admits more stocks.

What redemption depends on

This is the trust layer the rest of the design leans on, and by design it is the least clever function in the protocol. Redemption needs no price oracle and no market liquidity; it hands over assets the reserve already holds. Market prices do not enter the calculation: the Tap divides what the reserve holds by the supply and pays the slice. A crashing market changes what the basket is worth. It does not change the arithmetic.

The reserve funds the floor.

The arithmetic is simple; what sits outside it is not. The Tap can be paused defensively, and the Policy Board can change the fee, never above 10% (a board bound, 15). And a reserve asset moves only if its issuer lets it (19): the Tap pays every asset in the basket or none, so one failed transfer reverts the whole redemption, burn included, until that asset moves again. Delisting does not unstick that. It only stops new deposits of the asset; what is already in the basket stays. Redemption from stake (07) goes through the same Tap and inherits the same preconditions.

Every exit lifts the brim

Every redemption raises book value for everyone left: all the BRIM handed in burns, and the payout is computed on that amount less the fee, so the fee's share of the reserve stays behind. The fee can never be set to zero. It is one of the two numbers behind the reward bound (10): no tick can pay in more than the instant exit charges, which is what makes sniping the tick a losing trade. A zero fee would switch rewards off, so the Policy Board refuses one.

Before and after: one redemption before reserve 100 · supply 100 brim 1.000 redeem 10 BRIM at a 2% fee burn 10 BRIM, pay assets worth 9.8 after reserve 90.2 · supply 90 brim 1.002 ↑ if the fee were zero reserve 90 · supply 90 brim 1.000 (no lift) the board refuses a zero fee illustrative units · all the BRIM handed in burns; the payout is computed on that amount less the fee
F6.2. Before and after: one redemption. All the BRIM handed in burns and the payout is computed on that amount less the fee, so the brim rises for everyone who stays. Beside it, what a zero fee would do, and why the board refuses one. Illustrative units.

The running example's redemption is in 10, beside the four-state table, once the sale's surplus has become rewards.

Yellow paper: § 4.

07Staking

Stake into a growing pool. Leave three ways, priced by urgency: wait for free, redeem at the floor, or rage quit and pay the patient.

A growing pool

Stakers deposit BRIM into the Basin and hold shares of a growing pool. You can deposit from a wallet, or claim a release from the Decanter and stake it in the same transaction, whether the release came from an offering or from an earlier withdrawal. Once it is staked, the three exits below are the only way out. Rewards arrive as tokens added to the pool, so the balance a share can claim grows. Your share count does not change; the pool behind it does. Brim is not a rebase. How rewards get into the pool, and how much can arrive per tick, is 10; this section is the pool and its doors.

(3,3) with a redeem button.

Three exits

Three exits, priced by urgency. Withdraw is a 7-day linear release of your BRIM through the Decanter with a 1-day cliff, and it charges no fee; a withdrawing position earns no further rewards while it releases. Redeem from stake is instant, straight through the Tap: you receive reserve assets, the basket slice for your BRIM less the 2% fee. Rage quit is instant, takes the full position, and pays out BRIM less a 50% fee. Every exit is signed with your own cap, the highest fee or the longest release you will accept, and a setting that changes after you sign cannot push past it.

The exit tree leaving the pool? yes can you wait? yes no want the basket now? yes no out this block, any cost? yes withdraw 7-day linear release 1-day cliff · free redeem from stake instant, through the Tap 2% fee rage quit · 50% fee instant, the full position half burned, half stays
F7.1. The exit tree. Can you wait? Withdraw. Want the basket now? Redeem from stake. Want liquid BRIM this block? Rage quit.
ExitYou receiveSpeedPrice
Withdrawall your BRIM, released over time7-day linear release through the Decanter, 1-day cliffno fee
Redeem from stakereserve assets: the basket slice for 0.98× your BRIMinstant, straight through the Tap2% fee
Rage quithalf your BRIM, liquid at onceinstant, full position50% fee

T7.1. Three exits. Two pay BRIM; one pays the basket.

The rage-quit split

Half of every rage-quit fee is burned; the other half stays in the pool for the stakers who remain. The last staker out burns the entire fee. When the pool empties, any residual burns for every holder. The impatient pay the patient.

The rage-quit split a position of 100 · illustrative units burned: 25 stays in the pool for the stayers: 25 paid out to the quitter: 50 the fee: 50% last staker out: the whole fee burns
F7.2. The rage-quit split. A 50% fee, half burned for every holder and half kept for the stayers. The last staker out burns it all.

Nothing stops a fast in-and-out

Capital that arrives just before a reward tick and leaves through the slow exit earns its share like anyone else. An address may take one protocol action per block, and past that nothing stops a fast in-and-out; the bounds in 10 only make instant extraction unprofitable. Mercenary liquidity is welcome, and the bounds keep it harmless. A paused Basin stops deposits and all three exits (15).

Yellow paper: § 5 (exits).

Part III

Where the yield comes from

Is the yield real, and how long does it last?

08Two ledgers

Yield lands in one of two places: your balance grows, or every token's backing grows. Every source in the protocol feeds one or both.

Two columns

Yield arrives in two ledgers. Either your balance grows, because tokens flow into the staked pool and each share represents more BRIM, or every token's backing grows, because value is banked or supply is burned and the brim rises for holders and stakers alike. Every source in the protocol lands in one of the two columns, and several land in both.

Two columns your balance grows tokens flow into the staked pool; every share is worth more offerings: overflow leg tolls: overflow leg desk sweeps: overflow leg rage quits: half stays the Well (finite, pre-minted) the brim rises value is banked or supply is burned; backing per token grows offerings: reserve leg tolls: reserve leg desk sweeps: reserve leg rage quits: half burned redemptions: the fee stays dashed: the Well, finite and pre-minted; the others recur
F8.1. Two columns. The balance grows on the left; the brim rises on the right. Six sources, each dropped where it lands; T8.1 says who pays each. The Well is drawn apart, because it is finite and pre-minted and the others are neither.

The sources

Six sources, and each has someone paying it. Three of them, offerings, tolls, and the desk's named sweeps, run the Waterfall (09): most of each becomes overflow for stakers and a slice stays in the reserve. An offering or a toll also pays a slice to the desk and a small slice to the developers, in the revenue asset; a sweep pays neither. The other three are the exits and the Well.

SourceWho pays itYour balance growsThe brim rises
Offeringsbuyers, the surplus above the brimthe overflow legthe reserve leg
Tollstraders, on every swapthe overflow legthe reserve leg
Desk sweepsthe desk's returns, from investment outside those flowsthe overflow legthe reserve leg
Rage quitsthe impatienthalf the fee stays in the poolhalf the fee burns
Redemptionsleaversthe fee stays in the reserve
The Wella finite genesis allocation, handed out, never incomethe gap below the target, and only the gap

T8.1. Six sources, and who pays each.

Leavers pay the exit fees: a redemption fee stays in the reserve, and half a rage-quit fee stays in the pool while the other half burns. Either way those who remain are better off, and every exit through the Tap lifts the brim. The Well fills a remaining shortfall below the target after organic rewards (11); it is a finite, pre-minted allocation being handed out, and this page never counts it as income. At launch the overflow leg depends on offerings filling and on trading; the floor depends on no one buying anything (01).

the running example: what a staking buyer bought

The buyer in 04 paid $100 for 50 BRIM. When the tick in 10 mints 44.9910 BRIM against that sale's surplus, the buyer's tokens are still vesting, so the reward goes to the 5,000 BRIM already staked: tokens from an offering can be staked as they are released, from the cliff on, not at the sale. The claim and the stake can be one transaction. Once staked, the buyer's claim is their share of whatever later ticks mint, under the pool cap and the era budget: the same claim any staker has. The offering sold an allocation and a price path.

Activity is the yield

Offerings, trades, and exits are the yield; the Well is a bridge, and it runs out. Each of them lands in one of the two ledgers. All overflow passes through one split (09), one tick (10), and one bound; all burn-and-bank flows compound silently into the brim.

Yellow paper: § 6.

09The Waterfall

One split, every door. Whichever way surplus arrives, the same configured shares route it to stakers, the desk, the reserve, and the developers. A desk-sourced sweep skips the desk's leg and the developers'.

One split, every door

Every unit of surplus above the brim enters the Spillway through one of three routes: an offering's surplus, a settled toll, or a sweep the desk's governance has named. The same split runs, whichever route the surplus came through. It has four legs: overflow for stakers, capital for the desk's operating sleeve, backing for the reserve, and a share for the developers who build and maintain the protocol. Under the launch configuration (18), ordinary revenue routes 90% to overflow, 5% to the desk, 4% to the reserve, and 1% to the developers. The desk leg, the reserve leg, and the developer leg move at the door, in the revenue asset; the overflow leg waits for the tick.

The developer share is paid in the asset the revenue arrived in, never in newly minted BRIM, so it can never dilute; its ceiling is 10%, enforced at the door. Until a payee address is set, that share goes to the reserve and lifts the brim instead.

the running example: the split

The $50 of surplus from the purchase in 04 runs the split, with the developers' payee set: $45.00 to overflow, $2.50 to the desk, $2.00 to the reserve, $0.50 to the developers. The desk, reserve, and developer legs move at the door; the $45.00 of overflow waits in the Spillway for the tick (10).

One split, every door offering surplus settled tolls named desk sweep the Waterfallthe split overflow: waits in theSpillway, then the Basin the desk's sleeve the reserve:lifts the brim the developers ordinary revenue 90%5%4%1% desk-sourced sweep: the desk never pays itself, and neither leg pays 96%0%4%0% stakers / desk / reserve / developers ordinary 90 / 5 / 4 / 1 · desk-sourced 96 / 0 / 4 / 0 until a payee address is set, the developers' leg accretes to the reserve
F9.1. One split, every door. Three doors, one pipe, four legs. Switch the source to see how a desk-sourced sweep routes under the same configuration.

Two source states

The desk never pays itself, and a sweep pays no developer leg either. When the desk is the source of a deposit, both legs are suppressed and fold into the stakers' share, so a desk-sourced sweep routes 96% to overflow and 4% to the reserve under the same configuration. One split, two effective outcomes, depending on the door. The configured legs are listed in 18.

Overflow is accounting

Overflow is a running count, unit by unit and per asset, of what waits in the Spillway's own vault for the tick (10). The count is in units, not dollars. If units vanish from the vault (a transfer out that was not a tick), the credit is cut to what is actually there at the next tick and never grows back on its own; if their price falls, the same units back fewer reward tokens when the tick values them. Nothing enters the reserve unpriced: an asset that cannot be priced waits in the vault, whole, until it can.

What cannot mint

Donations and stray transfers can never authorize a mint. Supported, tracked assets that arrive without passing through a listed door are swept into the reserve as backing: they lift the brim and print nothing. Anything unsupported or unpriceable stays outside reward accounting altogether. Only revenue that entered through a listed door counts as overflow, and only overflow can become a reward.

What cannot mint listed revenue offering surplus · settled tolls named desk sweeps counted as overflow may mint after the tick donations, stray transfers, unpriceable assets no mint supported and tracked: swept into the reserve as accretion mints nothing unpriceable: stays outside reward accounting
F9.2. What cannot mint. Listed revenue is counted and may mint after the tick. Donations accrete or sit outside; they never authorize a mint.

Yellow paper: § 3 (surplus), § 5 (donations), § 6, § 11 (the Waterfall row).

10The reward tick

Rewards are released hourly, by anyone, from overflow that moves into the reserve in the same transaction, under a bound that makes sniping the tick a losing trade.

One tick, in order

Rewards are released by the Spillway on a permissionless tick: roughly hourly, metered in blocks, and cranked by anyone. One tick does five things in one transaction. It measures receipts, balances before and after, never amounts promised. It moves overflow into the reserve. It mints BRIM into the staked pool under the same backing inequality as a sale, checked again when the tokens are minted. It fills any remaining gap to the target from the Well, as a transfer. And it checks both legs against the bound. A dead price feed stops the tick rather than letting it guess. A tick inside the interval sweeps donations and mints nothing. A late tick collects one interval's allowance, never a backlog.

One tick, in order 1 receipts balances read before, after 2 overflow moves into the reserve 3 mint into pool payment×supply ≥ minted×NAV 4 Well fills gap existing tokens, the gap only 5 both legs ≤ the bound one transaction · hourly · anyone may crank it
F10.1. One tick, in order. Receipts, overflow into the reserve, mint under the inequality, the Well fills the gap, both legs under the bound. One transaction, hourly, anyone may crank it.

Nothing mints unpaid.

The bound

Each tick's total inflow to the pool is bounded by the stake and by the lesser of two dials: the pool cap and the redemption fee.

total pool inflow  =  minted + Well draw  ≤  staked × min(pool cap, redemption fee)   per tick   (10.1)

The bound is not a tuning choice. It is what makes sniping the tick a losing trade: deposit just before a tick, and the most you can capture is less than the fee you pay to leave at once. At launch the pool cap, 1% of stake per tick, is the tighter of the two. The bound is a door check over two configured inputs; the door enforces it, the boards set the inputs.

Why sniping loses

Deposit just before the tick, take the most a tick can pay in, and leave through the instant exit. The exit fee is larger than the capture by construction.

Why sniping loses deposit just before the tick the tick pays at most 1% of stake leave at once: the fee is 2% 0 +1% captured −2% paid to exit net ≤ −1%: the capture never exceeds the exit fee
F10.2. Why sniping loses. Deposit just before the tick, capture at most 1% of stake, pay 2% to leave at once. The capture can never exceed the exit fee.
the running example: the tick

The tick banks the $45.00 of overflow into the reserve and mints against it at the new brim of $1.000199: 44.9910 BRIM into the staked pool. It is not 45, because the sale already lifted the brim, and the mint is priced at the brim as it stands now. The 5,000-BRIM pool's per-tick cap is 50 BRIM, so it fits. The tick's target is 1.14 BRIM, so organic rewards carry it and the Well draws nothing. The reserve holds $10,097.00 against 10,094.9910 BRIM, and the brim is unchanged at $1.000199: a backed mint moves the brim by nothing.

the running example: a redemption

Now another liquid holder, not the buyer whose allocation is still vesting, hands 100 BRIM to the Tap. All 100 BRIM burn; the payout is computed on 98 BRIM, a slice of every asset worth $98.0195 at the same accepted prices. The reserve is left with $9,998.9805 against 9,994.9910 BRIM, and the brim rises to $1.000399 for everyone who stayed.

StateReserveBRIM supplyThe brim
Before the purchase$10,00010,000$1.00
After the purchase and the split (04, 09)$10,052.0010,050$1.000199
After the tick$10,097.0010,094.9910$1.000199
After another holder redeems 100 BRIM (06)$9,998.98059,994.9910$1.000399

T10.1. The running example, four states, with the developers' payee set and the redeemer a different holder from the buyer. A sale lifts the brim, a backed mint leaves it where it is, a redemption lifts it again.

Two meters: the tick and the year

Minted rewards and Well draws are different things, even though they share the bound. Minted rewards come only from overflow that the tick moves into the reserve in the same transaction, and they are further metered by a yearly budget: reward mints in a reward era can never exceed 50% of the era's starting supply. That budget meters mints only; offerings and the Well never touch it, and burns never refill it. The Well draw mints nothing: it is a transfer of genesis-era supply (11), already counted in the brim, moving from the Well into the pool. Every tick reports three numbers separately: revenue-backed BRIM minted, Well BRIM transferred, and reserve value routed.

Yellow paper: § 5 (rewards).

11The Well

A finite, pre-minted allocation that pays only the gap organic rewards leave, so it pays most when the market is quietest. It pays toward a target, and it can never be emptied faster than its runway allows.

What the Well is, and is not

A reservoir needs a well for dry spells. At genesis, a fixed allocation of BRIM is placed in the Well. It is pre-minted, inside total supply from block one, and therefore already accounted for in the brim. Drawing on it later moves neither supply nor reserves: the brim is unchanged, to the wei, by every draw. Only the Spillway can draw from it, and no protocol path can mint it a refill; anyone may pay existing tokens in, and such a top-up is a gift to stakers.

The opposite of an emissions schedule

The usual emissions schedule pays a fixed stream, heaviest at launch, whether or not anything is happening, and it pays most into the hottest market, the one moment nobody needs it. The Well is built the other way round. It pays only the gap that organic rewards leave, so a hot week draws nothing and a dead week draws the target, within the glide. It is one allocation, sized once, and nothing prints it a refill: when it is spent it is spent, and by then the yield has either become organic or it has not. What it pays, and how fast, is arithmetic anyone can run.

The Well pays the gap, and nothing prints it a refill.

Counter-cyclical by arithmetic organic overflow Well draw (the gap only) glide cap (the Well's limit) target rate hot week: the Well idles dry week: Well fills the gap the cap bounds only the hatched piece; when it binds, the draw shrinks ticks shown are weeks apart hourly ticks →
F11.1. Counter-cyclical by arithmetic, tapered by the glide. Organic overflow pays first and the Well fills only the gap. The cap bounds the Well's piece of each bar, never the whole bar: once it falls below the gap, the hatched piece shrinks with it. The ticks shown are weeks apart. The explorer below runs the same rule under other assumptions.

The Well's size is a genesis input (17), so the chart shows the rule for whatever balance the Well holds: how a draw tapers under the glide as the balance falls. The dry year in 14 runs the same arithmetic on the running example's sheet.

The draw recipe

Governance sets one target, an annual rate on the staked pool applied per tick. Each hourly tick starts with that target for total rewards. Organic rewards count toward it first. The Well can cover the remaining shortfall, subject to its glide and to the pool's inflow bound.

target     =  staked × target rate × (tick / year)                                  (11.1)
gap        =  min(max(target − minted this tick, 0), max(inflow bound − minted, 0))  (11.2)
glide cap  =  Well balance × (tick / runway floor)                                  (11.3)
draw       =  min(gap, glide cap)          paid if draw ≥ 0.01 BRIM, else zero    (11.4)
The draw recipe 1 target = staked × target rate × (tick / year) 2 minus what organic overflow minted this tick 3 gap = min(that remainder, the inflow bound minus minted) 4 glide cap = Well balance × (tick / runway floor) 5 draw = min(gap, glide cap) paid only if ≥ 0.01 BRIM existing tokens; supply, reserves unchanged
F11.2. The draw recipe. Target, minus what organic overflow minted, capped by the glide, paid or dust.

The glide

Organic minting applies first; the Well fills only the gap. The glide is a speed limit: each tick may take at most one part in 30 × 24 of whatever is still in the Well (30 days at launch; governance can lengthen the runway behind the timelock). That is why a 30-day runway is not 30 days of full target: as the balance falls, the draws shrink, and they taper instead of stopping at a cliff. A growing pool raises the target and the inflow bound; it does not raise this drain. A draw below 0.01 BRIM is skipped.

Early is when it is deep

The target is a rate on the staked pool, and the pool is smallest at the start. So the earliest stakers are paid the full target for as long as the Well is deep against a small pool; as the crowd arrives the pool grows, the target grows with it, and the glide takes over. A higher target rate would drain the Well faster. How long the full target lasts depends on one ratio: the Well's depth against the stake it is paying. With no organic revenue at all, on the launch dials, the arithmetic says:

The Well, as a share of the opening stakeThe full target is paid, before the glide tapers it, for
50%about 46 days
100%about 98 days
200%about 172 days

T11.1. Full-target days by depth, with no organic revenue, at the 30-day runway and hourly ticks, computed by the same rule as the explorer above. Organic revenue extends every row, because the Well pays only the gap. The Well's size is a genesis input (17); the rows show what the rule does at each depth.

Counter-cyclical by arithmetic

Hot weeks draw little or nothing. Quiet weeks draw the target while the Well is deep, and less as it shallows. The target is a ceiling for the Well's contribution, and organic rewards apply first; they may carry a tick above it on their own. The rate is quoted as an annual rate per tick; because ticks compound, the realized yield on a fully paid year is higher than the nominal number, and no tick is promised to fill. The chart to watch is organic overflow against Well draws. When organic rewards cover a tick's target, the Well contributes nothing to that tick. In the running example the tick's target was 1.14 BRIM and organic rewards minted 44.9910, so the Well drew nothing; in an hour with no overflow it would draw the gap, within its glide.

Brakes and raises

Security signers can lower the target instantly and only the timelock can raise it, so a queued raise can never undo a brake. Governance sets the target and the runway parameters; the counter-cyclicality is arithmetic. The Well reports its own bounds onchain: balance, target per tick, and the most a dry tick can draw. The target is not a promise; that limit is in 19.

Yellow paper: § 7.

12The desk

The desk runs a separate sleeve of protocol-owned assets. It can borrow and it can lose; it can never touch the reserve.

A separate sleeve

The Mill is the operating desk. It manages a separately capitalized sleeve of protocol-owned assets, never the reserve, through Brim Adapters: swaps, yield strategies, liquidity, and credit. If yield-bearing stablecoin positions are used at all, they live here as a desk strategy, not in the reserve. Its capital arrives through the Waterfall's desk leg. Every action settles on receipts measured on the desk itself, names the token it expects, and carries a minimum it must achieve. The reserve sits behind a wall the desk never crosses: it holds no debt, is never borrowed against, and pays out through the Tap alone.

Two pots the reserve (Reservoir) backing assets only no liabilities exits through the Tap alone the wall the desk's vault (Mill) operating assets liabilities: borrowed principal may borrow · may lose the Waterfall named sweep: realized net profit, governance-named, timelocked desk leg reserve leg
F12.1. Two pots. The reserve holds backing and no liabilities, and exits through the Tap alone. The desk's vault holds operating assets and liabilities, may borrow, and may lose. The wall between them is never crossed; the only arrow back is a named sweep into the split.

The named sweep

The desk's flagship strategy is a credit line on Ripe (13): borrow against operating assets, and put the loan to work wherever it can earn more than the loan costs. Policy treats borrowed principal as a liability, never revenue, and permits only realized net profit to be swept: value remaining after principal repayment, accrued interest, execution costs, and realized losses. The contracts do not compute that profit; a timelocked governance action names the amount. The desk deploys, repays, and only then names a profit for the Waterfall, behind the timelock. A sweep takes no desk leg and no developer leg (09). Losses stay on the desk, and the reserve backing the floor never carries debt.

What is code, what is policy

Code enforcesPolicy decides
Only a contract listed in the Boardroom registry may drive the desk; the list holds only the boards, and governance changes it behind its timelockwhich venues the desk uses
Every action settles on receipts, names the token it expects, and carries a minimum it must achievehow much leverage, and what position size
An adapter must be listed and bound before the desk can use itwhich adapters to propose
The reserve is unreachable from the desknothing; no board can reach it short of a registry change behind its own timelock
A sweep is a named amount into the split; losses stay on the sleevewhen to name a sweep, and how much

T12.1. What is code, what is policy.

The Brim HQ team operates the desk through those boards, under each board's rules and delays, and those choices are theirs. Undecided: the sleeve's opening capital, which is a genesis input (17); after that it grows with the desk leg of every split.

Yellow paper: § 6 (the Mill row), § 8.

13The Ripe connection

Two doors connect Brim to Ripe; one wall keeps the reserve out of both.

Two doors

Brim is an independent protocol, but it launches with one deliberate ally: Ripe Protocol, an onchain lending protocol where people borrow against their tokenized stocks. The two are built around the same kind of asset, and the relationship runs through two doors.

The first is the desk's credit line on Ripe (12). The loan stays on the desk's own sleeve; only realized net profit, named by governance, comes back through the Waterfall. Ripe gains a protocol-scale borrower; Brim gains a yield engine on assets that would otherwise sit idle.

The second is genesis. On Ripe, people who stake RIPE or RIPE LP earn a juice score, and that score is what puts Ripe's most committed stakers, the Top Juicers, first in line for Brim's genesis event. The two communities are aligned from block one. Genesis itself is 17.

Two doors, one wall the reserve no debt never borrowed against the wall: neither door touches it the desk (Mill) non-backing sleeve Ripe Protocol borrow against stocks borrows against operating assets the loan: a liability, never revenue named sweep only the Waterfall juice score stake RIPE · RIPE LP genesis first in line
F13.1. Two doors, one wall. The desk borrows on Ripe against its own operating assets and returns only what governance names as realized net profit through the Waterfall; the juice score puts Ripe's stakers first in line at genesis. The reserve sits behind a wall neither door crosses.

One wall

The two protocols share no balance sheet. Ripe never touches the reserve, the reserve is never borrowed against, the desk never borrows against BRIM, and the floor does not depend on Ripe: the loan is secured by the desk's own assets, never the reserve. If the credit line loses, the loss stays on the desk's sleeve; if Ripe stops, the desk has one fewer venue and the reserve has nothing to notice.

Ripe is a venue. The reserve does not know it exists.

Yellow paper: § 8.

14The loops

Three loops make the machine reinforce itself. One net catches it when demand is gone. Each loop is the mechanics of an earlier section, read as a cycle.

Three loops and a net

The premium loop. Demand brings buyers to an offering above the brim. The premium is surplus; the stakers' share of the surplus, after the split, is overflow; the overflow mints into the staked pool; a growing pool is more reason to show up at the next offering. The offering is 04; the split is 09.

The activity loop. Trades pay the toll in both directions, so trading in either direction funds yield: buys and sells both route into the same split, to overflow and to the brim. The toll is 05.

The patience loop. Rage quits and redemptions tax urgency: half of a rage-quit fee stays for the stakers who remain and half burns for every holder, and a redemption fee stays in the reserve. Those who remain keep the retained fee, the burn shrinks the supply under everyone, and both are one more reason to stay. The exits are priced in 06 and 07.

The net. The net is not a loop. When demand is gone, the Tap pays the basket, and there is no mint-on-redeem path to amplify a fall. The net holds when the Tap is open and every reserve asset transfers (06).

Three loops and a net the premium loop demand offering above the brim stakers surplus, overflow (04, 09) the activity loop trades tolls more to trade overflow and the brim (05) the patience loop urgent exits fees and burns stay the patient keep them (06, 07) the net: the Tap pays the basket; no mint-on-redeem holds when the Tap is open and the assets transfer (06)
F14.1. Three loops and a net. The premium loop, the activity loop, and the patience loop reinforce the machine; the net beneath them pays the basket when demand is gone, when the Tap is open and the assets transfer. Inside each loop the arrows run clockwise; the step back to the top is the one people choose.

The contracts route the money. People decide whether to come back. Hot market or dead one, the same arithmetic holds; the table below sets the two side by side.

When demand is strong, the premium funds the yield. When demand is gone, the Tap pays the floor.

the running example: a dry year

Take the sheet as 10 left it: a reserve of $9,998.9805 against 9,994.9910 BRIM, the brim at $1.000399, 5,044.9910 BRIM staked, 2,000 BRIM in the Well. For the walk, assume reserve prices hold, every hourly tick runs on fresh prices, no offering fills, no swap pays a toll, no sweep lands, nothing is deposited, withdrawn, redeemed, or paid into the Well, and no setting changes. Organic rewards are zero, so each tick asks the Well for the whole target, which grows with the pool.

  • Day 0. The target is 1.15 BRIM per tick and the glide allows 2.78, so the Well pays the target in full.
  • Day 33. The Well has shallowed until its glide cap falls below the target; from here the draws taper with the balance.
  • Day 180. The draw falls under the dust line and stops, with 7.20 BRIM still in the Well.
  • Day 365. The Well has paid 1,992.80 BRIM into the pool, which ends at 7,037.79 BRIM. Supply and reserve are unchanged, so the brim is $1.000399 at both ends, and the Tap still pays 0.98× that (06).

Drop the price assumption and the brim falls with the reserve's prices; nothing in the protocol stops that (19). Neither a premium anyone paid nor a dollar figure is protected. The redemption route and the arithmetic are.

Two states

Strong demandNo demand
What paysthe premium: offering surplus and tolls become overflowthe floor: the Tap pays the basket, in kind
The Welldraws little or nothingdraws the gap up to its glide cap, and tapers as it shallows
What it depends onaccepted prices for issuance; people who keep comingthe Tap open, every asset transferable

T14.1. Two states. The same arithmetic, in a hot market and a dead one.

Yellow paper: § 6 (closing), § 9 (the synthesis paragraph).

Part IV

What you are trusting

Who can change what, and how is this not Olympus?

15Who can change what

Brim is governed and upgradeable. Three control domains, two speeds: raises wait behind timelocks, brakes act at once, and contracts can be replaced through the registry behind its own timelock.

Three domains, two speeds

Three control domains. The Policy Board holds the economic dials, the Market Board holds the pool's, and the registry holds the set of contracts and their mint rights. The registry can replace any contract behind its timelock, switch minting on or off globally, and set the token contract's own permissions; the dial table in 18 names every dial by board. The protocol is upgradeable by design: a fix or a new version is a registry change, and the bounds on this page belong to the contracts registered today.

Two speeds. Raises and value-moving actions wait behind a timelock, are validated against ceilings when proposed and again when executed, and expire if they are not executed in time. Defensive reductions act at once: pausing a department, stopping a live offering, lowering the target, lowering the tolls, delisting an asset, locking a signer. Security signers can brake but never raise. Two of these cuts, the target's and the tolls', also cancel any raise of that dial still waiting in the queue, so a raise queued before the cut can never land after it.

Three domains, two speeds the Policy Board economic dials the Market Board the pool the registry composition waits timelocked acts now brakes raise the target · change the fee, the split, the offering terms · add a reserve asset · add a signer raise the tolls · change the liquidity adapter · add or remove liquidity register or replace a contract · grant or revoke mint rights lower the target · stop an offering · pause a department · delist an asset · lock a signer lower the tolls switch minting off · pause the token · blacklist an address
F15.1. Three domains, two speeds. Across: the Policy Board, the Market Board, the registry. Down: what waits behind a timelock, and what acts at once. The Market Board's only brake is the toll cut.

What a pause stops

A signer can pause a department; only governance unpauses. A pause is not cosmetic: each one stops a specific set of actions and leaves the rest running, and some reach further than their name, since a paused Spillway or Decanter also stops offering purchases. T20.3 lists every pause department by department. The settlement lock and the ledger's records of stake and releases never pause, and the desk's risk-reducing actions stay live while the desk is paused.

Who may mint

Only two contracts hold mint rights: the offering and the reward engine, each checking the backing inequality at its own door on every mint. Mint rights are a governed setting: the registry can grant or revoke them behind its timelock, and a global mint switch sits above both. So "nothing mints unpaid" is a door check on every mint, and a list of contracts that governance maintains. The token contract also carries a pause, a blacklist, and the power to burn blacklisted balances; those powers sit in the registry's domain and are listed row by row in the authority matrix (20).

The launch trust model

At launch, governance is a multisig behind the timelocks described here, with a set of security signers who can only brake. The brim law binds what protocol actions may do; the boards' ceilings bind what a dial may be set to; the registry's timelock binds how the set of contracts may change. No single function is unstoppable, and governance can act. What waits, what acts at once, and who enforces each bound is stated above and tabulated in 20.

Yellow paper: § 2 (closing), § 11 (the floor has switches; the launch table's intro).

16Prior art

Brim borrows from five earlier designs, declines the part of each that gave way, and combines the rest under one constraint: new issuance preserves book value.

Borrowed, refused, changed

The short version is in 01; this is the long one. Brim sits at the intersection of several earlier monetary designs. Each solved a different problem, and each gave something up to do it. Brim combines selected parts of those designs under one constraint: new issuance must preserve current book value at the prices the protocol accepts.

Olympus (2021). Borrowed: premium issuance and the staking flywheel. Refused: staking rebases minted on a schedule, with no rule that each mint preserve backing per token, and a treasury "floor" that was a dashboard number with no redeem function; when the premium died, the only exit was the market. Changed: every mint must hold the brim, rewards are minted only against banked revenue, and the floor is a function anyone can call.

Terra / UST. The lesson from Terra was a backstop that pays. Refused: an endogenous backstop, where redeeming UST minted more LUNA and the exit amplified the crash it was meant to absorb. Changed: an exogenous basket and an exit in kind; there is no mint-on-redeem path.

Ampleforth. Ampleforth reached every holder by adjusting the unit: a proportional supply change, not a reward. Refused: rebasing unit balances with no reserve behind them, and nothing to redeem when demand left. Changed: shares of a growing pool, and real custody.

Reserve-style baskets. Borrowed: honest onchain redemption. Refused: the two-way mint-and-redeem arbitrage that pins price to basket NAV; holders own the basket and its yield, never a premium above it. Changed: the basket is a floor under the token, with nothing pinning the token to it.

NET (NetNet Capital Management). Borrowed: a real, onchain backing floor, with emissions capped by reserves. Refused: an exit that is a capacity-capped buyback bid just below NAV rather than a pro-rata take of the reserve, and staking yield that is still a rebase of minted supply, capped by reserves but not paid for by revenue. Changed: every mint is a paired inequality paid at the door, and the exit is the basket itself.

Borrowed, refused, changed borrowed refused changed Olympus (2021) premium issuance, staking rewards minted from thin air rewards only against banked revenue Terra a backstop that pays mint-on-redeem an exogenous basket, exit in kind Ampleforth supply adjustment to every holder rebasing units, no reserve shares of a growing pool, real custody Reserve baskets honest in-kind redemption the NAV pin a floor, not a ceiling NET a backing floor, an emission cap a capacity-capped buyback, rebased yield the exit is the basket itself the wedge: the exit is the reserve itself, priced mechanically, and the token is free to trade above its backing, not pinned to it
F16.1. Borrowed, refused, changed. What Brim takes from each predecessor, what it declines, and what it changes to make the first survive without the second.

The wedge

The synthesis is the design. Take Olympus's premium-issuance flywheel, but mint new rewards only against banked revenue, with the finite Well carrying rewards while it lasts out of pre-minted, already-backed supply. Take Reserve's honest redemption, but remove the NAV pin. There is no price target to defend and no open-ended emission schedule to sustain. Against Olympus, Terra, Ampleforth, and NET, the difference is the same: you leave with a slice of the reserve, priced mechanically, not with a bid. Against Reserve, the difference is the missing pin.

Yellow paper: § 9.

Part V

Launch

What happens at block one, and what can go wrong?

17Genesis

One event, announced by @Brim_HQ, run in tokenized Nvidia, with Top Juicers first in line. Four things about how it ends are already fixed, and everything after it runs on the rules above.

What is already fixed

Genesis is the one moment that has to establish the backing every later mint is checked against, and the whole design leans on it ending in exactly one state. Four things are fixed now, whatever the event looks like.

  1. The reserve backs the entire initial supply, the Well included. Every token that exists when the event ends, the Well's allocation among them, is inside supply and inside the brim from the first block.
  2. The token's market is protocol-owned. The pool's hook admits liquidity from the protocol's own desk and no one else, so from the first swap every trade pays its toll into the split.
  3. The Tap is open. The redeem button works from the first block, at the floor, in kind.
  4. The genesis asset is tokenized Nvidia (NVDA), and only that. The event takes in tokenized Nvidia and nothing else, the reserve opens holding it and nothing else, and the token's pool is quoted in it. That is a launch fact, not the design: the reserve is meant to be a basket of tokenized stocks, and the board admits more after genesis (15). No stablecoin sits anywhere in the reserve.
Block one how the event gets here deliberately unspecified · takes in NVDA the end state (specified) the reserve backs the entire supply reserve holders Well supply protocol-owned liquidity in the hooked pool the Tap is open
F17.1. Block one. How the event gets here is off this page; these three states are not, and the asset is tokenized Nvidia.

Genesis is open to anyone who wants to play, with no pre-sale in front of it, and after it, the only way a new BRIM ever comes into existence is through a current mint door, fully paid, at or above the brim. The Well's size and the desk's opening capital are set here too (11, 12).

What is coming

The event itself is announced by @Brim_HQ, and the Ripe juice score (13) plays an important part in it: Ripe's most committed stakers, the Top Juicers, stand first in line. What it takes in is tokenized Nvidia; the rest of its mechanics are deliberately not on this page. What this page fixes is the state it ends in, and that state is what every later mint, every tick, and every redemption is checked against.

Yellow paper: § 10.

18Launch configuration

The mechanisms above are what the registered contracts enforce today. The numbers below are dials. Every one, dated, with its bound and who enforces it.

Mechanism, not dial

The mechanisms in this paper are enforced by the contracts registered today (15); the numbers below are dials. They are governed through the Policy Board and the Market Board within the ceilings shown: raises and value-moving actions wait behind timelocks, defensive reductions act at once. "The door" means the contract that moves the money refuses anything past the bound; "the board" means the current board's validation refuses it, and a board can be replaced through the registry's own timelock. This table is dated September 2026.

The dial table

DialLaunchBoundEnforced byBoardSpeedClass
Redemption fee2%above zero, never above 10%the boardPolicytimelockedboard bound
Redemption openyesthe open flag is a dial; a Tap pause is separatethe doorPolicy; signers pausethe flag timelocked; a pause at once, and governance unpauses at onceconfigured
Reserve assetstokenized Nvidia, the first of a baskettokenized stocks; more admitted after genesis, each with a live price, never the protocol's own tokenthe door (admission); the board (the list)Policyadd timelocked; delist at onceconfigured
The pool's pairBRIM / NVDAbound into the hook; the quote asset is a reserve asset, or tolls could never settlethe doorthe registered set
Offering premium5.00× → 1.10×1.10× is the contract minimumthe doorPolicytimelockeddoor bound
Offering windowone dayat most 90 daysthe boardPolicytimelockedconfigured
Vesting5 to 30 days, bonus up to 25%bonus never above 25%; length never above 365 daysthe door (bonus); the board (range)Policytimelockedconfigured
Waterfall legs: stakers / desk / reserve / developers90 / 5 / 4 / 1desk leg never above 25%; developer leg never above 10%the doorPolicytimelockeddoor bound
Waterfall, desk-sourced sweep96 / 0 / 4 / 0the desk never pays itself; no developer leg on a sweepthe doorderived
Developer payeeset by the boardnever a protocol contract; until set, the leg accretes to the reservethe boardPolicytimelockedconfigured
Well target200% nominal APR, prorated per ticknever above 200%; lowerable at once; not a guaranteethe boardPolicy; signers lowerraise timelocked; cut at onceboard bound; not promised as an outcome
Runway floor30 days30 to 365 days, at least 10 ticksthe board (range); the door (ten ticks)Policytimelockedconfigured; a limit on the draw rate
Reward era budget50% of era-start supply per yearnever above 1000% of era-start supply; meters mints only, and the Well never touches itthe door (metered); the board (ceiling)Policytimelockedconfigured
Pool inflow cap1% of stake per tickthe lesser of its setting and the live redemption feethe doorPolicytimelockeddoor bound
Reward tickhourlynever shorter than one hourthe boardPolicytimelockedconfigured
Tolls5% sell / 3% buynever above 10% per direction; the hook deploys at zero and the launch values land through one Market Board timelockthe door (the hook)Marketraise timelocked; cut at oncedoor bound
Rage-quit fee50%never above 90%the doorPolicytimelockeddoor bound
Withdraw release7 days, 1-day cliffat most 60 daysthe boardPolicytimelockedconfigured
Price stalenessone dayfive minutes to seven daysthe boardPolicytimelockedconfigured; depends on the feed
Mint rightsthe offering, the reward engineonly registered contracts; a global switch above boththe token, via the registryregistrygrant timelocked; switch off at oncethe registered set

T18.1. The dial table, dated September 2026. The last column says what kind of claim each row is: a door bound is refused by the contract that moves the money, a board bound by the current board, and "configured" means a value governance can set within those. The full claim vocabulary is in 19 and 20.

Yellow paper: § 11 (the launch table).

19Honest limits

What the design does not claim, and for each claim it does make, what it depends on.

Eight limits

Market risk is real. The reserve is tokenized stocks; its dollar value moves with markets. The guarantee is that protocol actions never dilute, not that the number never falls.
What it means for you: a price move alone changes no quantity the reserve holds; the brim in dollars follows the stocks.
The floor has switches. A signer or governance can pause the Tap at once; only governance unpauses it. Its fee moves through a timelock, never above 10%, and registry and mint-authorization changes wait behind timelocks too. The brim law binds what protocol actions may do; it is not a claim that any single function is unstoppable.
What it means for you: a paused Tap is a closed door, and the floor behind it is unchanged; the section that lists every pause is 20.
The Well targets, it does not guarantee. Subsidized yield is bridge capital with a visible runway. A shallow Well glides below its target rather than stopping.
What it means for you: the target is a ceiling the Well aims at; what arrives depends on overflow, depth, the glide, and the inflow cap.
The desk can lose. The desk can lose operating capital on its own sleeve; it can never encumber the reserve, and what it sweeps back is named by governance, not computed by the contracts.
What it means for you: a desk loss shrinks the desk and leaves the floor where it was.
Oracles are load-bearing. Issuance and rewards price everything strictly and fail closed: if a feed dies, minting stops rather than guessing. Redemption, by design, does not depend on prices at all. Equity feeds do not update while their markets are closed. At a one-day staleness window, offerings and ticks, the Well's draw included, wait over a weekend and resume with the first fresh price; the window is a board dial.
What it means for you: a dead or stale feed pauses offerings and ticks, Well draws included; the Tap keeps paying.
Patience is priced, not enforced. Capital that arrives just before rewards and leaves through the slow exit earns its share like anyone else; the bounds only make instant extraction unprofitable. Mercenary liquidity is a customer, not an attacker.
What it means for you: the slow exit stays open to anyone; the reward bound keeps one tick's reward below the instant exit's fee.
Reserve assets have issuers. Tokenized stocks move only as their issuers allow, and the protocol cannot make one move. Because the Tap is all-or-nothing, one reserve asset that cannot move stalls every redemption until it moves again; what happens to an asset frozen for good is a question the design defers.
What it means for you: the floor is a slice of assets that live on their issuers' rails; when one of them stops, the Tap stops with it.
The token has switches of its own. The BRIM contract carries a pause, a blacklist, and the power to burn a blacklisted balance. These are Brim's own controls, separate from any issuer's. The blacklist is set by any department granted the power; the pause and the burn by governance alone; all three act at once (15, 20).
What it means for you: a blacklisted address cannot move or redeem, and no timelock stands in front of that switch.

One more precondition sits under the brim law itself: the door checks hold on every mint through the current mint doors, and which contracts are mint doors is governed (15).

The claim matrix

Every claim on this page sits in at least one of four columns, and several sit in more than one.

ClaimEnforced when callableAvailability governedExternal preconditionsNot promised
No protocol action lowers the brimthe backing inequality at every current mint doorwhich contracts are mint doors; the mint switchaccepted prices from live feedsa dollar value
Redemption in kind, pro rataburn first, then the slice of every asset; no price readthe Tap open; the fee, above zero and never above 10%every reserve asset transferable by its issuer; one failed transfer reverts the whole redemptiona dollar floor; liquidity for the assets received
The offering never mints below 1.10×the door refuseswhether an offering is open at alla strict price read of the reservean allocation at any price
Rewards per tick stay under the boundthe door check over the pool cap and the feethe pool cap and the feea rate; an APY
Rewards are backedminted only against overflow moved into the reserve in the same transactionthe reward era budget; ticks require the Spillway unpausedlive feeds for the ticka floor on rewards
The Well pays the gapthe draw recipe and the glidethe target (lowerable at once), the runway floorlive feeds for the tick; the draw is one of its steps and comes after the strict pricingthe target as an outcome; Well duration
Tolls fund yieldthe hook charges on every swap; never above 10%the toll levels; the liquidity adapterthe pool manager, the quote asset, the chaintrading volume
The desk never touches the reservethe reserve's only outlet is the Tap; the desk's vault is separatewhich contracts are registeredthe venues the desk usesdesk profit
Genesis backs the initial supplythe genesis plan (17)genesis mechanics, dates, allocation

T19.1. The claim matrix.

Stress paths

Stress paths what keeps working 1 reserve prices fall dollar book value falls the brim in reserve units is unchanged the Tap still pays the basket 2 a price feed dies strict pricing fails closed minting stops (offerings, rewards) redemption continues: no price is read 3 the Well runs shallow the glide cap falls below the target draws taper, never a cliff organic rewards continue 4 the desk loses the loss stays on its sleeve no profit, no sweep the reserve is untouched 5 a reserve asset freezes that transfer fails the Tap reverts, burn included offerings and ticks still run
F19.2. Stress paths. Five things that can go wrong, and what keeps working when they do. The fifth is the one where the Tap itself stops.

That is the whole argument. The formulas are collected in 20, the contracts are the final word, and the only genuine BRIM is the token at the address published by @Brim_HQ.

Yellow paper: § 11.

20Reference

Everything an auditor, a translator, or a researcher needs, out of the narrative's way.

Glossary

book value
reserve NAV divided by total supply; the quantity every invariant is checked against.
accepted prices
the prices the protocol's configured feeds currently accept; a stale or dead feed is not accepted, and strict reads fail closed.
the brim
book value, as the fill line: what one BRIM is backed by.
floor
what the Tap pays: book value less the redemption fee. On this page the floor is always the redemption price; the offering has a minimum and the Well has a runway, which the dial table names the runway floor.
surplus
value that arrives above the brim, from a sale, a toll, or the desk.
Waterfall
the governance-set split of surplus into overflow for stakers, capital for the desk, backing for the reserve, and a developer share.
overflow
the stakers' leg of the Waterfall, waiting for the Spillway's tick.
the offering (the Pour)
the Dutch sale of new BRIM above the brim.
the reserve (the Reservoir)
the basket that backs every BRIM; exits only through the Tap.
the Tap
redemption: burn BRIM, receive the pro-rata basket at the floor.
the Spillway
the reward engine: the tick that turns overflow into backed rewards.
the Basin
the staked pool, share-based, with three exits.
the Well
the pre-minted genesis allocation that fills reward gaps under a glide.
the Mill
the operating desk: a separate sleeve of protocol-owned assets.
the Decanter
vesting: every allocation and every slow exit settles here before it is liquid.
the Tollbooth
the hook on the token's own pool; charges the toll and gates liquidity.
Brim Adapters
the desk's connectors to venues; each is registered and bound.
the Boardroom
governance: the Policy Board, the Market Board, and the registry of validating desks.
the tick
the permissionless, hourly reward checkpoint.
the glide
the rule that a tick may draw at most the Well's balance divided by the ticks in the runway floor.
era
a reward year; gross mints in an era are capped at a share of the era's starting supply.
the quote asset
the reserve asset the token's pool is priced in and the toll is paid in; tokenized Nvidia (NVDA) at launch.
the door
the contract that moves the money and refuses anything past its bound. The offering and the reward engine are the two mint doors; the Tap is the one door out of the reserve.
(3,3)
Olympus's shorthand for the outcome where everyone stakes and everyone does better for it. Brim's version adds the exit the original never had.

Questions

Is it a rebase? No. Your share count never changes. Rewards are tokens added to the staked pool, so each share claims more. Why is there a redemption fee at all? Two reasons. It is what the holders who stay keep from every exit, and it is the bound on rewards per tick: no tick can pay in more than the instant exit charges. A zero fee would switch rewards off, so the board refuses one. What is the APY? There is no promised APY. The Well's target is 200% nominal, prorated per hourly tick, a ceiling it aims at. Because ticks compound, a year in which every tick filled would come to about 639% APY, and no tick is promised to fill. What arrives depends on overflow, the Well's depth, the glide, and the inflow cap. Who can mint? Two contracts, the offering and the reward engine, each checking the backing inequality at its door. Mint rights are granted and revoked by the registry behind a timelock, and a global switch sits above both. What do I pay with? tokenized Nvidia, at launch. An offering takes one reserve asset, named when it is set up, and the pool trades BRIM against NVDA. As the basket widens, a later offering can name another reserve asset; the pool stays quoted in NVDA. No stablecoin sits anywhere in the reserve or the pool. Is the reserve only Nvidia? No. It opens with tokenized Nvidia because the genesis event takes in one asset and the pool needs one quote asset. The design is a basket of tokenized stocks: the Policy Board admits more behind its timelock, each with a live price, and a redemption pays a slice of every asset the reserve holds. Can I add liquidity to the pool? No. Only the desk's adapter may; that is what makes the toll unavoidable. Where do donations go? Supported assets sent to the protocol go into the reserve as backing and lift the brim. They never authorize a mint.

Formula book

No.FormulaSection
2.1book value = reserve NAV / total supply02
2.2floor = book value × (1 − redemption fee)02
4.1base = value paid / (premium × book value)04
4.2minted M = base + vesting bonus, never beyond value paid / (1.10 × book value)04
4.3the reserve keeps ≥ M × book value from every sale04
10.1minted + Well draw ≤ staked × min(pool cap, redemption fee), per tick10
11.1target = staked × target rate × (tick / year)11
11.2gap = min(max(target − minted, 0), max(inflow bound − minted, 0))11
11.3glide cap = Well balance × (tick / runway floor)11
11.4draw = min(gap, glide cap), paid if ≥ 0.01 BRIM11
mint checkvalue paid × supply before ≥ minted × NAV before, at every mint door02, 10

T20.1. Formula book.

Authority matrix

ActionDomainWhoDelayCeilingCeiling enforced byTouches
Set the redemption fee, open or close redemptionPolicy Boardgovernancetimelockedfee above zero, never above 10%the boardthe Tap
Set offering termsPolicy Boardgovernancetimelocked; not while a window is livefloor premium ≥ 1.10×; bonus ≤ 25%the doorthe offering
Set the offering budgetPolicy Boardgovernancetimelockedthe ledger
Start an offeringPolicy Boardgovernanceat oncenot over a live windowthe doorthe offering
Stop an offeringPolicy Boardgovernance, security signersat oncethe offering
Set staking termsPolicy Boardgovernancetimelockedrage-quit fee ≤ 90%; release ≤ 60 daysthe door (fee); the board (release)the Basin
Set reward dials (tick, caps, target, runway floor)Policy Boardgovernancetimelocked; a brake retires a queued changetarget ≤ 200%; tick ≥ one hour; floor 30 to 365 daysthe board; the door for the ten-tick rulethe Spillway
Lower the targetPolicy Boardsecurity signers, governanceat oncelower onlythe boardthe Spillway
Set the Waterfall's legs and the developer payeePolicy Boardgovernancetimelockeddesk leg ≤ 25%; developer leg ≤ 10%; the payee is never a protocol contractthe door (legs); the board (payee)the Spillway
Add a reserve assetPolicy Boardgovernancetimelocked; needs a live pricenever the protocol's own tokenthe doorthe reserve
Delist a reserve assetPolicy Boardgovernanceat onceadmission freeze only; tracked balances staythe doorthe reserve
Add or remove a revenue doorPolicy Boardgovernanceadd timelocked; remove at oncethe Spillway
Add, remove, lock, unlock a security signerPolicy Boardgovernanceadd and unlock timelocked; remove and lock at oncethe boards
Pause a departmentPolicy Boardsecurity signers, governanceat onceany department
Unpause a departmentPolicy Boardgovernanceat onceany department
Name a desk sweepPolicy Boardgovernancetimelocked; an explicit amountthe desk, the Spillway
Recover stray tokens from a departmentPolicy Boardgovernanceat oncenever from the reserve, the Well, or any vaultthe boarda department's own balance
Move desk funds to governancePolicy Boardgovernancetimelocked; an explicit amountthe desk's vault
Raise the tollsMarket Boardgovernancetimelocked; a cut retires a queued raisenever above 10% per directionthe door (the hook)the pool
Lower the tollsMarket Boardsecurity signers, governanceat oncelower onlythe doorthe pool
Replace the liquidity adapterMarket Boardgovernancetimelocked; bound to the hook (the hook checks); listed in the adapter registry (the board checks)the door for the binding, the board for the listingthe pool
Add or remove liquidityMarket Boardgovernancetimelocked; sized when queuedone loss policythe boardthe pool, the desk
Register, replace, or disable a contractregistrygovernancetimelockedthe composition
Grant or revoke mint rightsregistrygovernancetimelockedonly registered contractsthe tokenthe token
Switch minting off or onregistrygovernanceat oncethe tokenthe token
Pause the tokenregistrygovernanceat oncethe tokenevery transfer
Blacklist an addressregistrya department granted the powerat oncethe tokenthat address
Burn a blacklisted balanceregistrygovernanceat onceonly a blacklisted addressthe tokenthat address
Set the price staleness windowPolicy Boardgovernancetimelockedfive minutes to seven daysthe boardpricing
Add a price feedprice registrygovernancetimelocked; validated livethe registrypricing

T20.2. Authority matrix. Every governed action, who may take it, on what delay, under what ceiling, and who enforces the ceiling.

What a pause freezes

Paused departmentWhat stopsWhat keeps running
the Tapredemption, including redemption from stakeeverything else; the reserve is untouched. A frozen reserve asset has the same effect on redemption without a pause: one failed transfer reverts the whole basket exit
the Basindeposits, from a wallet or straight from a Decanter claim, and all three exitsreleases already in the Decanter keep accruing and claiming to a wallet
the Decanterclaims on releases in progress, and the creation of new releases, so offering purchases and staking withdrawals fail tooexisting releases keep accruing; nothing is lost, only delayed
the offeringpurchases; starting a windowthe market
the Spillwayticks: no mints, no Well draws; revenue deposits, so offering purchases fail too, since a sale must credit its surplustolls keep accruing on the pool until routed
the desknew deployments, swaps, adding liquidity, and the named sweep to the splitwithdrawing from a strategy and removing liquidity: risk-reducing actions stay live
the ledgeroffering records, overflow credits, and reward checkpoints, so purchases and ticks fail with itstake and release records, and the settlement lock, which never pauses
the tokenevery transfer (a governance-only pause)

T20.3. What a pause freezes, checked row by row against each department's pause checks.

A change's life

Propose: a board records the change and validates it against its ceilings. Wait: the timelock runs; the change expires if not executed in time. Execute: the board validates again against the live state and applies it. Retire: a change whose nonce is stale, because a brake or another change landed first, is retired unexecuted. A queued change can execute only once.

Contract map

PlainlyContractHolds or movesAnswers
the offeringPourmints allocations into the Decanter's vault; banks backing in the reserve; hands surplus to the Spillwaythe offering window, the premium now, a purchase preview
the reserveReservoirthe basket; moves only by the Tap's instructionNAV (strict and permissive), balances
redemptionTapburns BRIM; instructs the reserve to pay the basketa redemption preview, the fee, open or paused
the reward engineSpillwayruns the Waterfall at the door; ticks; draws the Wellthe last tick, a tick preview, the Well's runway
its vaultSpillwayVaultoverflow, waiting
stakingBasinshares; deposits and exitsstaked balance, exit previews
its vaultBasinVaultthe staked pool; rewards mint here
the genesis allocationWellpre-minted BRIM; drawn only by the Spillwayits balance
the deskMillthe operating sleeve through adapterspositions
its vaultMillVaultoperating assets
vestingDecanterclaims a release, optionally straight into the Basina release, what is claimable
its vaultDecanterVaultescrowed BRIM
the market tollTollbooththe hook; accrued tolls; the liquidity gatethe tolls, a toll preview, the canonical pool
the pool adapterBrimPoolAdapterthe desk's one liquidity positionthe pool's price
configurationCharterevery dial and listthe dials
the ledgerLedgerstake shares, releases, overflow credit, eras, the settlement lockstake shares, releases, era meters
the economic boardPolicyBoardvalidates and timelocks the dialspending changes
the pool boardMarketBoardvalidates and timelocks the tolls and liquiditypending changes
the registry of boardsBoardroomwhich desks may act
the registryHqwhich contracts exist; mint rights; the mint switchmint rights, the switch
the adapter registryHarborwhich adapters the desk may use
pricingPriceDesk, ChainlinkPricesthe price walk; strict and permissive readsprices, staleness
the tokenBrimTokenBRIM; mint gated by the registry; pause and blacklistsupply, balances

T20.4. Contract map. Which contract holds what, and which one answers which number on this page.

The yellow paper (also in Chinese, Korean, and Japanese) · @Brim_HQ · Ripe

Brim is an experimental onchain protocol. It holds no customer funds, offers no accounts, and is not a regulated financial institution of any kind. Nothing here is investment advice. The reserve is tokenized stocks whose value moves with markets. Participate at your own risk.