Ownership Module

ARCOS → Module → Ownership Module

Developer Overview

ARCOS

ARCOS is infrastructure that makes NFTs programmable and operational — not just a pointer to an owner, but a governed system for what can be done with a digital asset, by whom, and under what rules.

It’s organized as a set of Modules, each governing one domain of an asset’s behavior.


Module — The Generic Infrastructure

A Module is a governed state machine:

One domain of state, owned by exactly one authority, changed only through defined transitions, reachable by anything else only through MAS.

Every Module is built from the same nine pieces. The pieces are fixed; what fills them is domain-specific.

1. Governed State

The only thing ever actually stored.

A fixed, named set of fields representing real facts about the asset. Nothing else is stored anywhere else.

2. Authority

Who can legitimately cause the state to change.

Authority is never stored as its own fact — it is computed live from Governed State, every time it is checked.

3. Transition

The finite, named set of ways Governed State is allowed to change.

Every Transition follows the same order:

Authority check → Invariant check → Write → Log

A failure at either check means nothing is written, not even partially.

4. Invariant

The rule that decides whether a specific change is valid, given that the caller already passed the Authority check.

Identity asks: who?
Invariant asks: is this particular change okay right now?

5. History

A permanent, append-only record of every Transition attempt — success or failure.

Failures are kept exactly like successes. Nothing is discarded.

6. Lifecycle

Lifecycle is not stored.

It is a live read over History, answering:

Given everything recorded so far, what stage is this asset in right now?

7. Recovery / Failure

Failure is what any ordinary Transition becomes when its Invariant does not pass.

Recovery is a specific Transition gated by a second, independent Authority, kept in reserve for when the primary Authority is lost.

8. Capabilities

Capabilities are never stored.

They are named patterns read from Governed State, measured against Authority.

A capability is a description of the state, not a separate fact about it.

9. MAS — Module Activation System

MAS is the only path between Modules.

No Module calls another directly.

If one Module’s state answers a question another Module needs, the second queries it through MAS instead of holding its own copy.


Ownership Module — The Applied Instance

The Ownership Module is Module filled in for one domain:

Who owns a digital asset, and what that ownership actually lets them do.

Governed State

Five fields:

  • Shares

  • Possession

  • Use

  • Benefit

  • Version

Nothing else is stored.

Authority — Authority Root

The Authority Root is the strict majority of Shares, recomputed live on every check.

If Shares change, Authority changes automatically.

Nothing needs to be separately updated.

Transitions

The current Ownership Module defines:

  • mint

  • delegateUse

  • revokeUse

  • moveToCustody

  • returnFromCustody

  • splitShares

  • mergeShares

  • setGuardians

  • recoverOwnership

Invariants

Examples:

  • Use cannot be granted if already committed elsewhere.

  • Shares must sum to 100.

  • A Rental cannot be revoked before its term ends.

History

Every Transition attempt — pass or fail — is permanently logged in the Ledger.

Lifecycle

Lifecycle is derived from the Ledger:

Genesis → Active → Encumbered → Fractured → Suspended → Recovered

Recovery / Failure

Recovery is gated by guardian quorum, not Shares-majority.

This creates a second, independent Authority for recovery when the primary Authority is lost.

Failure is simply what appears in the Ledger when an ordinary Invariant does not pass.

Capabilities

Four current patterns are read from the five fields rather than stored separately:

  • Delegation

  • Rental

  • Custody

  • Shared Ownership


MAS in Practice

Settlement — payment/consideration for a Rental — was deliberately kept outside Ownership.

It has a different authority and a different lifecycle.

Ownership therefore does not store a price field. Instead, its Invariant queries Settlement through MAS when it needs that information.


Current Status — What Needs Work

Ownership Module today governs Rights only.

Possession, Use, Benefit, and Shares are all Rights — what a holder is entitled to do.

What is currently missing is the representation of what a holder owes while holding something.

This is one of the areas I want developers to review and challenge.


Live Demo

The Ownership Module has a live, interactive demo with no wallet or blockchain required.

It walks through:

  • Governed State

  • Authority Root

  • Every Transition

  • Invariant pass/fail

  • History

  • Lifecycle

  • Recovery

All using one NFT:

Sunset #7

GitHub:


Looking for Developer Review

I’m looking for developers who can review the Ownership Module, challenge the architecture, identify what is missing, and suggest improvements.

If you find the direction interesting and want to contribute beyond the review, I’d also like you to join me in building the Ownership Module.

ARCOS is currently solo-built — it’s just me — and there is no funding yet.

The goal is to build this together as open infrastructure for the future of NFTs / Digital Assets.

The question

What should the future of NFT ownership look like?

ERC ownerOf() → Ownership Module → Governed Ownership for Digital Assets