🇰🇭 CSB Admin Console

institutional operations — every role is a separate authority

Acting authority

On the devnet the deployer holds all roles. In production each tab's actions succeed only for the institution holding that role — try the wrong key and the chain refuses.

License a field verifier

A licence is what makes a confirmation worth something — because it can be taken away. Issuing one here also registers KYC and enables the address to transact, because all three are required and they fail in ways that look nothing alike.

Withdraw or restore

Suspension keeps the registration row. The record of who was licensed when is what a dispute over a past attestation has to be settled against, so nothing is deleted for a routine withdrawal.

Licensed verifiers

Issue a grove title

One share per verified living tree. You cannot choose the supply — it is read from the anchored record a licensed verifier confirmed, so a grove with nothing verified cannot be titled at all. The steward must be the address that actually opened the plot's chain.

Allow lists (chain-level permission)

Enter an address and check its status.

Grant

Revoke

What this is

CSB is permissioned below the contract layer. An address that is not on the txAllowList is refused by the node itself — cannot issue transaction from non-allow listed address — however well KYC'd it is. This is the tab that fixes that error.

These are not KYC. The allow list answers "may you transact at all"; KYC answers "may you hold regulated money". A developer testing contracts needs only the list. Anyone holding or sending KHRt needs an attestation from the Identity Authority tab as well.

Gas is about 1 tRIEL per ordinary transaction and roughly 100 for a contract deployment, so the 1000 default covers real use. An enabled address with no tRIEL still cannot move.

Signed by the precompile admin — the key in Acting authority above. These lists are chain configuration, not a contract role, so no other institution can change them.

Pending verification requests 0

Filed at kyc-request.html, each proven by a wallet signature. Approve registers the address on chain at the requested tier, enables it on the transaction allow list, and sends it gas — everything it needs to actually transact. The name shown is free text from the requester and never goes on chain.

AddressName givenTierAsked

Register address

Lifecycle

Address quota (paid)

Freeze / unfreeze

Confiscate (court order)

Egress gateway

Status –

Token egress policy

Tier transfer caps

Vetted system contracts

Public-good levy (KHRt)

A flat KHRt fee on each transfer sent to a fund (e.g. a hospital charity). 0 = off.

Issue KHRt

Redeem (burn own balance)

The issuer is a pluggable role: a central bank, a licensed bank consortium, or a treasury-backed entity (all placeholders) can hold it without changing the rails.

Access is self-service

Any KYC-active address activates its own scoped RPC URL at rpc-access.html by signing with its wallet — no per-user issuing, no admin step. Access is re-checked live on every request against on-chain KYC and the revoke list, so revoking KYC also cuts RPC. Use the tools here only to revoke an address, or to fetch a URL for someone who can't self-serve.

Look up a URL for an address

Revoke access

Immediately blocks that address's scoped RPC URL, regardless of KYC.

Revoked addresses

Address