Status: Kept current, 12 September 2026. This is the mechanism's §19 in one place: every question that needs a person, the assumption taken in their absence, why that assumption is the conservative one, what would replace it, and what the public site says while it holds. An assumption is never promoted to a fact on the site; the site says *not decided*, *not passed*, *not deployed*, and this page says why the work went on anyway.
| # | Open question | Assumed, for now | Why this and not the other way | What replaces the assumption | What the site says meanwhile |
|---|---|---|---|---|---|
| A1 | G01 — pilot, hold, change a candidate, or stop? | Hold. Stay in simulation and rehearsal; deploy nothing with real assets. | Two things stand in the way of a pilot and neither is a matter of code: the eligibility question (A3) has no answer, and the current wrapper for A held about ten tokens in all at the blocks read — one lot of ten units would be the whole wrapper. Holding costs nothing and forecloses nothing. | A written gate decision by the people the mechanism names, after A3 and A6. | Every gate *in research*, none passed; NOT_DEPLOYED; the front page's stage line. |
| A2 | C09 — independent review and audit | Not reviewed. Treat the prototype as unreviewed, however many tests pass. | Tests written by the author find what the author thought of. The invariant suite and the recorded runs are what a reviewer starts from, not what they conclude. | A named reviewer's report on a named commit, findings closed and re-run. | "Unaudited, unreviewed, undeployed" wherever the contract is mentioned; the self-review is filed as a self-review (REVIEW.md). |
| A3 | G2 — is a Curb series contract (and are its receipt holders) an eligible holder under each issuer's rules? | No, until an issuer says yes. The technical fact that AAPLon and wAAPLx move for an arbitrary address on a fork is not eligibility. | Both issuers document jurisdiction and investor-status restrictions and one documents that eligibility still applies when a contract holds the token. Assuming *yes* would be exactly the claim the blueprint forbids. | A written answer from each issuer, or a legal review naming the rule under which the contract may hold and holders may claim. | Component statuses *not determined*; "eligibility is not a fork question"; ADR-003 proposes the access design that would apply if the answer were yes. |
| A4 | O01 — who are the signers? | Nobody. No operator exists; in every rehearsal the operator is a throwaway local account. | An operator with authority over stops and permits is exactly what should not be improvised. | Named signers, a multisig with the proposed quorum, published on the site. | "No signer has been appointed, no multisig exists, and no key is held"; the policy is a proposal. |
| A5 | R04 / B02 — is there demand, and do people understand the offer? | Unknown, and not assumed either way. No interview result is invented. | Demand invented on paper is the one input that would make every other assumption look safer than it is. | Ten to fifteen interviews against the baseline of two tokens in a wallet, scored with the guide; a comprehension test of the in-kind, fixed-lot, nontransferable offer. | "User need against the baseline is not validated: no interviews have been held." |
| A6 | R05 — the real units per lot and the cap | Illustrative only: 10 and 20 units, 1,000 lots, as the simulation shows. | The right figures depend on A3, on B's decimals (18, now read) and on the wrapper's size; guessing them would put a number on the site that looks like configuration. | The method in ADR-006 applied on a dated day, reviewed. | Every unit figure labelled illustrative; a deployment record refuses to be sent without a named reviewer. |
| A7 | Which wrapper, and what if it stays this small? | The current wrapper (v2) is the unit, as the issuer's own document says; the raw token is not a candidate because it rebases. If the wrapper stays this small, A1 stays *hold*. | The issuer says the legacy wrapper is unwrap-only and the vault rate is not a price; a series that held the raw token would carry the corporate-action multiplier into its ledger. | The wrapper growing, or a decision to build the rebasing handling into a future series. | The wrapper's size beside the *market offer* status, dated by block. |
| A8 | Ondo's API key | Not needed for the address. The candidate address for B comes from the issuer's own product page; the API's refusal stays on the record as a refusal. | The product page is the issuer's publication for the asset, the same record the API would give, without an example being promoted to fact. | A key, which would add the API's answer beside the page's and remove the refusal. | The API source shows ACCESS_DENIED; the page source shows the record. |
| A9 | A public deployment | None. The tool exists and refuses an unreviewed record; no key exists. | A deployment is the one action here that cannot be taken back. | A1 decided as *pilot*, then the deployment plan. | NOT_DEPLOYED, and the wallet flow does not appear. |
| A10 | The token: does CURB exist, and what is it for? | It does not exist. What it is for is no longer assumed: the token record is decided — the product owner, 12 September 2026 — prepaid credit for services that exist, priced in dollars (US$20.00 to open a key, US$0.05 a call, US$0.10 a delivery), with its terms, its proceeds split and its order of work. No supply, allocation, vesting, buyback or fee share is assumed, and none was decided. | A launch is a marketing step, not a source of facts; the mechanism's §16 says there is no basis yet for anything but payment for services. Building the services and the gate first means a launch sells something that works. | The token deployed and read from the chain; the desk deployed from a reviewed record. The decision on the function, the prices, the terms and the chain (Robinhood Chain, the desk's own) was taken on 12 September 2026. | /services and /api/credits say NOT_CONFIGURED; every figure that depends on a rate says there is none. |
| A11 | The rate: where does a CURB price come from? | From a pool the chain profile can read, at a block — or from nowhere. Until a pool exists the price list stays in dollars and no CURB amount is quoted. A bonding-curve period before a pool is a period with no conversion. | A price typed in by hand, or read from a launchpad's page, is a rate the desk did not read; the market capitalisation shown is price × supply at the same block, which the reader can check. | The pool's address recorded from the chain in CURB_CREDITS; a second source kind added to the reader if the pool is not a constant-product pair. | "No rate — no token exists, no desk is deployed and no pool is read." |
| A12 | The launchpad's terms | Not known and not assumed. Whatever the launchpad takes, allocates or vests is stated on the day it exists, from the chain. | The desk publishes the proceeds' budget as shares of *net* proceeds precisely because the gross is not known. | The launchpad's mechanics read on chain after the launch; the token record's proceeds table filled with figures. | The token record says the terms are not assumed; the services page says nothing about a launchpad. |
How the register is used
- —Every line's *what the site says meanwhile* is checked against the pages when the register changes; the site never states an assumption as a fact.
- —When a person replaces an assumption, the line is edited to say who, when, and what they decided, and the decision record it belongs to is moved from *proposed* to *decided*.
- —Work that does not depend on the open question goes on — as it did: the whole path from a reviewed record to a holder's own wallet has been rehearsed without a single assumption being promoted.