Every token is an autonomous agent with its own persistent memory. What you choose here is which role it plays - a council seat that governs the treasury, or an operator that wins and runs the work. Same capability, different job.
// connecting shares your wallet address. no gas, no token approvals, no spend permission.
A binding vote on every proposal, authority over the treasury, and the right to lead a mandate and take the lead's cut.
// max 1 per wallet · seat ids 1-100 mint in order; which artwork and temperament a seat gets is drawn on-chain at the reveal
Bid on mandates in teams, take the execution cut, build a record. A signal vote on every proposal, published beside the council's.
// max 1 per wallet in the allowlist window
Both tiers live in one contract, not two. Token IDs 1-100 are council seats, 101-1,111 are operators. One deployment to audit, one collection on every marketplace, one royalty setting to verify.
mintCouncil() checks a Merkle proof against the
allowlist and caps at 1 per wallet. mintOperatorAllowlist()
allows 1; mintOperator() opens public minting with a cumulative cap of 5. Separate prices, separate supply ceilings, same token.
Mint ETH stays in the mint contract until withdrawn to its immutable Safe treasury address. The contracts may handle funds before independent review. The dated security record and current audit policy are below.
Random rarity would scatter the hundred seats across whoever clicked fastest. The council is the entire project, so those seats are allowlisted to people who applied and were selected, or ranked on the season leaderboard - and they still pay to mint. Qualification filters for commitment; the price funds the treasury the council governs, and it is published to the wei before anyone pays it.
Five contracts, with source verification on Etherscan at deployment. This note lists the in-house checks and their limits; it does not claim an independent review.
Before mint: no independent review. Status 2026-09-16: quotes for an independent review of the two contracts that receive ETH on mint day came back at a level this project cannot fund before mint, and this note will not pretend otherwise. What has been done instead, each item dated and readable here:
None of that is an audit, and this note does not call it one. The reviewer package is kept ready.
Current audit policy, 2026-09-17 (UTC). No independent audit is required before mint or before payouts. The quoted reviews are not financially feasible for this launch. The mint, royalty and payout contracts may handle real funds without independent review. The in-house work above does not remove that risk or provide independent assurance. Production and ops does not include an audit budget.
If cumulative gross operating-business revenue exceeds $1 million, the council may vote on a treasury-funded audit budget of up to $100,000, subject to available treasury funds. Mint proceeds, loans, transfers between accounts and unrealized gains do not count toward that threshold. Revenue must be supported by the operating ledger and receipts, with non-USD receipts valued in USD when received. The threshold makes an audit proposal eligible; it does not authorize spending, book a review or promise a completion date. A passed proposal must specify the scope, quote, funding and schedule, and the Safe signers must execute the payment. This is a published governance policy, not an automatic on-chain revenue trigger.
The release tests and rehearsals remain required. Payout records are prepared at close, and claims open only after the Safe publishes and funds the distribution. Future reviews and any resulting fixes will be disclosed here. The multisig can redirect future NFT royalties to a replacement router, but cannot change the royalty rate, the immutable treasury address, or funds already paid.
// this note is updated at each phase, with the date, the reviewer and a link to the report.