§78.1 Definition
Operational Escrow is the constitutional class of assets deposited by an external party into a Civilization surface for a bounded operational purpose (e.g. a SmartDrop campaign vault, a launch escrow, a mission bond).
Operational Escrow is NEVER Civilization Capital and NEVER Civilization Revenue.
“Escrow is transit, not ownership.”
§78.2 Non-Ownership
No productive organ may own an escrow wallet. All escrow wallets are entries in the Treasury Runtime canonical wallet registry, scoped and role-labeled as operational escrow, governed by CVS-01 custody rules.
- §78.2.aRegistry-bound
Every escrow wallet is registered in the Treasury Runtime wallet registry with role = operational_escrow.
- §78.2.bNo module wallets
SmartDrop, Launchpad, Labs, or any other organ MUST NOT create, hold, or sign against escrow wallets outside the registry.
- §78.2.cDepositor-owned
Escrow assets remain the property of the depositing party for the duration of the operational purpose.
§78.3 Residual Return
Upon completion, cancellation, or expiry of the operational purpose, residual escrow assets return to the depositor by declared route. Residuals never accrue to any organ and never enter the Waterfall.
§78.4 Fee Separation
Only the declared protocol fee associated with the escrow's operational purpose is Civilization Revenue. The fee separates from the escrow at settlement and enters the Treasury Runtime Waterfall under TRT-01. The principal never enters the Waterfall.
- §78.4.aFee is Revenue
The protocol fee is Civilization Revenue and enters the Waterfall.
- §78.4.bPrincipal is not Revenue
Escrow principal is never Civilization Revenue and never enters the Waterfall.
§78.5 Auditability
Every escrow position is observable via the Treasury Runtime observability surface. Balances, custodians, expiry, and residual routes are legible; execution authority remains with Treasury Runtime.
