Privacy and capability are not fixed traits of the system — they are calibrated per account to policy and KYC level. The tier a citizen holds determines both what they can do and what the state can see.
Tiers bind identity assurance to monetary capability so the two rise together under an explicit policy.
Each tier maps a level of identity assurance to a level of monetary capability — holding ceiling, velocity, eligible operations. The mapping is set by the central bank and enforced uniformly by the ledger.
A holder moves up a tier by presenting stronger evidence, and each elevation is a signed state transition, so the reason an account holds its capabilities is always reconstructable.
The thresholds that separate tiers — limits, required credentials, permitted counterparties — are policy parameters the central bank can adjust without redeploying the wallet software.
Because tiers are enforced at settlement rather than in the client, a holder cannot buy a higher-tier capability by modifying an app — the rail is the arbiter of what each tier may do.
Privacy is strongest where the policy case for it is strongest, and narrows only as value and risk rise.
At entry tiers, small-value payments can carry minimal identifying data, giving citizens cash-like privacy. As tiers rise toward larger sums, the identifying data required by policy rises with them.
Holders prove policy-relevant facts through verifiable credentials — resident, of age, screened — without revealing the underlying documents, so eligibility is checked without over-collecting personal data.
Each tier collects only the attributes its policy requires, so the system does not accumulate identity data it has no mandate to hold. Privacy is a default of the lower tiers, not an add-on.
Identity attributes stay bound to credentials and in-nation issuers rather than aggregating into a single behavioral profile, so raising a tier expands verification without building surveillance.
Supervisory visibility is a governed capability, not an ambient property of the ledger.
The identifying detail available to authorities scales with the tier: higher-value accounts carry the attribution AML and tax rules require, while entry tiers expose little by design.
Access to a holder's identifying detail beyond the tier's default is gated behind an authorized request, and the access itself is logged on the ledger, so lookups are accountable rather than silent.
Transfers crossing policy thresholds generate the structured reports supervisors require, produced from the settlement record itself rather than reconstructed from a separate reporting pipeline.
Every change to who can see what is a signed, hash-chained transition, so the boundary between privacy and oversight is not just set by policy but provably enforced and reviewable.
The tier a holder occupies parameterizes every control the ledger applies to their activity.
Holding ceilings, per-transaction caps, and daily velocity are attributes of the tier, so raising or lowering a holder's tier adjusts all applicable limits in one governed transition.
Certain operations — cross-border transfer, programmable escrow, institutional settlement — require a minimum tier, so capability is unlocked by assurance rather than granted flatly to everyone.
The central bank can retune tier parameters in response to policy — tightening in stress, loosening for inclusion — and the change propagates through enforcement without touching individual accounts by hand.
A tier's controls apply identically whether the wallet is self-custodied, hosted, or institution-held, so the assurance-to-capability contract holds no matter who signs for the account.