Are you an LLM? Read llms.txt for a summary of the docs, or llms-full.txt for the full context.
Skip to content

Every player

Doré is a two-sided market. It only exists if both sides are onboarded: claim issuers who need capital, and holders who supply it. A model that maximizes protocol profit while starving either side is a spreadsheet, not a design.

So every party gets a payoff and an outside option, and the design must keep all of them at the table.

The ledger

Seventeen players over a transfer ledger. Its central property is an identity: the payoffs sum to real production margin plus external carry, minus real destruction and cost. Every internal leg cancels. Nothing is created by bookkeeping.

That identity is the basis-point echo of a kernel-level fact: over payments between named parties, cash deltas sum to zero.

Where the money is

The protocol's coordinate in that ledger is exactly the objective the ceiling maximizes — proved, not asserted. The credit loss is split the way the protection stack splits it: the write-off, what the estate returns, and what the insurer pays, rather than collapsed into a single number.

Findings that only a multi-player view produces

The profit-maximal design is infeasible. The design that earns most in the class pays holders nothing and buys no hedge. A single-agent ceiling would have crowned it.

The prior baseline starved the holder. It paid 400 basis points against a disclosed 450-point alternative — and the single-agent objective was quietly collecting the difference.

The first-loss tie was an artifact. A tranche credited with absorbing loss but never paid for it ties the optimum. Priced at its own outside option it costs 150 basis points and buys nothing, because liquidity binds before absorption does.

Holders bear loss first. The model originally paid the yield-leg holder a fixed rate, making it a creditor — while the kernel and the legal classification both make it a pro-rata share that absorbs loss ahead of the protocol. The contracts implement the share, not the coupon.

Who actually eats a bad year

Naming an absorption order is not the same as applying it. The ledger now routes the credit loss through the waterfall before anyone is paid, and the routing is bounded: the three layers together can absorb at most what was actually lost. Relief cannot be manufactured by bookkeeping any more than profit can.

Routing it changes nothing about the published ceiling. That number is a calm-scenario maximum, and in calm there is no credit loss, so every absorption leg is zero and the same design wins at the same number. This is a theorem, not an argument.

At the severe corner it changes everything. The loss there is 693 basis points, and the protocol bears none of it:

layerabsorbsnote
first-loss tranche0not bought in the optimal design
yield leg (sdrUSD)450its entire period flow
sponsor equity243the remainder
protocol0last in line, untouched here

The protocol's severe-corner payoff improves from −989 to −296, by exactly the amount absorbed above it. And the juniority holds where it matters: the yield leg is wiped to zero before the sponsor is touched, and the sponsor before the protocol.

Read this as a holder, not as the protocol. The single-agent model was charging the protocol for losses that a correctly-specified capital stack puts on holders and sponsors. It therefore overstated the protocol's downside while understating what the yield leg is exposed to. A severe year takes a holder's entire coupon and then some. That is now a theorem rather than an omission, and it is the honest version of "holders bear loss first."

Two charges remain unwired, deliberately. The market-maker retainer and the issuance fee are both zero in the calibrated environment because neither is sourced. Charging an unsourced number would be inventing one. When they are supplied, the payoff theorem gives the exact sensitivity without any remodelling.