# Governance, Security & Risk

How a vote is weighted is [Staking & Governance](/staking). This chapter is the other cut: which layer may act, what the contracts must disclose, and where the house can still lose money.

## Execution & Control

Three layers. An action belongs to one of them.

### Automatic

The contract runs these without a vote and without a signer:

* **NAV** — marks and the circulating-share identity
* **Fees** — the 0 / 1% AMM split is **fixed by the hook**, not votable; fees **automatically accrue in the LP** **or** are **auto-collected to the Treasury by the contract**; belongs to **POL**; **developers take no cut**
* **Pricing** — HOLI-route TWAPs and invalidation
* **Eligible mint checks** — premium gate, quiet-period pause of staking inflation / premium issuance, pairing that does not raise circulating supply

If the check fails, the printer does not run. That is not a committee.

### Governance

<Md expr="w" /> votes the rights on [Staker Rights](/staking/rights). It picks **which pools to open**. It does **not** retune the 0 / 1% hook fee. In this layer:

* **Buyback proposal** — if HOLI is under NAV: whether to spend undeployed reserves, plus size and price cap
* **Idle-fund allocation** — when undeployed is **> 30%**, whether to put idle funds into **already-approved** pools
* **Asset admission** — pairing proposals (which Stock/HOLI books may exist)
* **Inflation** — on/off, per-period size, and interval

A vote changes the rule. It does not have to be the wallet that later clicks the swap.

### Operator / Team

The team may execute work the vote already authorized:

* **Buy stock and mint pairing HOLI into the pool** — **HOLI/Stock deployment:** only after **undeployed again > 30%** (or a **separate approval** to use reserves) **and** a <Md expr="w" /> vote passes the **specific name**, then swap into that stock and form the pool. **All newly minted HOLI enters that LP at the then market price.** See [POL Deployment](/treasury-mgmt/deployment).

The team cannot form a Stock/HOLI pool without the name vote and the undeployed **again > 30%** gate (or a **separate approval** to use reserves). It cannot allocate idle funds into already-approved pools without that allocation vote.

The **operator** may **pause** or **upgrade** the contracts after they are deployed, to handle emergencies, patch vulnerabilities, and add features.

A signer click is not "the protocol rebalanced." LP-drift policy is still open on [Rebalancing](/treasury-mgmt/rebalancing).

## Smart Contract Control

After the contracts are deployed, the **operator** can **pause** or **upgrade** them. That power is for emergencies, vulnerability fixes, and adding features. It is not a <Md expr="w" />-vote.

Live deployments should still name the operator key, the pause surface, and the upgrade path. Audits, if any, should say what they covered and what they did not.

HOLI is not immutable. Holder control does not outrun what those operator keys can do.

**Smart-contract, bridge, and multisig** risk sit in this same bucket. A bug, a bridge, or a signer set can still lose funds, stall, or capture pause and upgrade. If any HOLI or reserve path crosses a bridge, that path is a control surface.

## Main risks

Protocol-owned assets and protocol-owned liquidity do **not** remove market loss.

* **SHYT tax income.** Trading-tax income can accumulate too slowly. Phase I, the opening reserve, and any SHYT-routed HOLI mark wait on tape that may not show up.
* **RWA.** Issuer, custody, redemption, and regulation. Admission does not retire those.
* **Oracle / valuation.** A bad mark makes a clean NAV identity lie.
* **Liquidity.** IL on POL positions. Market depth can fade.
* **NAV vs exit.** Official NAV can diverge from the immediate exit value along the curve.
* **Contracts.** Smart-contract, bridge, and multisig risk. Pause and upgrade sit with the operator.
* **HOLI below NAV.** If HOLI stays under NAV long enough, premium issuance stops. There is **no** redemption until the community approves. A below-NAV buyback is a <Md expr="w" /> vote — not default NAV redemption, not a desk.
* **Governance.** A vote can still make a bad call on asset allocation or issuance parameters.

The sections below are the same list, cut by surface.

## Market Risks

* **SHYT tax income.** SHYT is the MEME spoke and, before Genesis, the tax-funded Treasury asset. Trading-tax income can accumulate too slowly. A thin tape, a violent tape, or a tape that simply does not trade enough all hit Phase I accumulation, the SHYT/HOLI pool, and any HOLI mark that routes through SHYT.
* **HOLI below NAV.** Accounting NAV is not a floor. Exit is the POL curve. If HOLI stays under NAV long enough, premium issuance stays off under the 45% gate. There is **no** redemption until the community approves a below-NAV buyback. That buyback is a [w vote](/staking/rights) on undeployed reserves, size, and a price cap. It is a market buy, not a desk, and not default NAV redemption.
* **Liquidity depth.** Early hub pools can be small. A large HOLI sell walks the V4 curve. Realized proceeds are the curve plus the 1% sell fee, not the NAV print. Market depth can fade.
* **Impermanent loss.** Full-range Stock/HOLI, USDG/HOLI, and SHYT/HOLI positions move when the two sides diverge. POL earns fees; it also takes inventory risk. Fees do not guarantee the Treasury is ahead of IL.
* **NAV vs exit.** Official NAV counts only the LP external-asset leg in <Md expr="A_t" />. That print can still diverge from the immediate exit value along the curve. What a holder can actually get is the curve, not the print.

## RWA Risks

Admitted stocks and other RWAs are not USDG. The Treasury mark is only as good as the wrapper.

* **Issuer.** Who issued the tokenized stock, what the wrapper actually claims, and whether that claim can fail.
* **Custody.** Where the underlying sits, who can freeze or seize it, and what happens to the on-chain token if the custodian stops.
* **Redemption.** Whether the wrapper can be redeemed for the underlying, by whom, at what lag, and at what discount. HOLI itself has [no NAV redemption](/nav/redemption). A stock token that cannot be redeemed is a different, extra failure.
* **Regulation.** Listings, wrappers, and venues can be restricted. An admitted name can become unlistable. Caps and pauses exist because of this, not in spite of it.

Admission is a [w-vote](/staking/rights). The vote does not retire issuer, custody, redemption, or regulatory risk. It only decides whether the house will hold that name.

## Oracle / Valuation Risks

NAV is a function of marks. Bad marks make a clean identity lie. Price construction is [Price Sources](/nav/prices).

* **TWAP.** Formal NAV uses a time-weighted on-chain price, not a one-swap spot. A window that is too short follows manipulation. A window that is too long follows a stale book.
* **Manipulation.** Thin HOLI routes can be pushed through the TWAP. Arb across routes proves the routes agree. It does not prove the price is true.
* **Illiquid pools.** If the TWAP window has too little volume, depth is below the minimum, or the HOLI route is missing, that asset's price is **not defined**. The mark is dropped from assets, and any mint or function that needs that price does not run.

Invalidation is automatic. It is still a risk: a paused mark, a missing RWA in NAV, or a printer that will not fire, because the book was too thin to trust.

## Governance Risks

<Md expr="w" /> is concentrated size × age, capped. It can still concentrate. A few long-staked wallets can set admission, inflation, idle-fund allocation, and a below-NAV buyback. A large [deposit](/staking/deposits) can knock a live position back through the 7-day cliff and zero its vote.

Governance can also just be wrong: an adverse call on **asset allocation** or **issuance parameters**, a buyback that spends reserves into a falling book, risk limits that are too loose or too tight. The [rights list](/staking/rights) is the surface area of that mistake.

The annual [management mint](/supply/management) is a known NAV-dilutive print. It is not a hidden fee, and it is not retired by a good vote.

None of those failures become a floor. Protocol-owned assets and protocol-owned liquidity do **not** remove market loss.

**NAV is not guaranteed redemption value.** There is no redemption until the community approves.
