> ## Documentation Index
> Fetch the complete documentation index at: https://docs.grapl.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Security and authority

> Local administrator powers, tested boundaries and requirements before public funds.

The local protocol has unit, integration, fuzz, invariant and transaction smoke coverage. Those checks establish local behavior, not an external audit or production readiness.

## Who can do what?

| Actor or role | Power and limitation |
| - | - |
| Default admin | Grants/revokes roles and unpauses; can assign itself mint, burn or service privileges |
| Pauser | Pauses its module; cannot unpause without admin authority |
| GEM minter | Mints within lifetime cap; intended assignment is SwapRewards |
| GEM benefit burner | Can burn a holder's GEM; intended reserve assignment checks consent, but admin can reassign it |
| Reserve funder | Deposits accounted GRAPL with receipt checks; no arbitrary withdrawal |
| Approved benefit service | Consumes its holder-approved allowance and receives the GRAPL debit |
| Authorized rewards router | Trusted to report real execution and pay the fee |
| Registry factory | Adds immutable schedules; cannot rewrite existing entries |
| LP creator | Withdraws its position at or after the declared unlock time |
| Local randomness operator | Chooses game outcomes; unsuitable for production |

<Warning>
  A malicious approved benefit service can consume allowances granted to it. A
  malicious administrator can assign a different burner. Consent checks in the
  legitimate reserve do not remove these trust assumptions.
</Warning>

All local roles use a disposable unlocked Anvil account. No production signers or timelock delays have been chosen. Timelocked governance and separate emergency pausing are proposals.

## Failure and pause behavior

Pausing relevant registry, GEM, reserve or rewards modules can revert the entire trading path. This is not an isolated reward suspension. Exhausting lifetime issuance is different: swaps and fees can continue without new GEM.

LP withdrawal remains subject to its own immutable unlock time. A game pause blocks entries but permits existing requests to fulfill. There is no game timeout or automatic refund if the operator stops responding.

## What local checks cover

<AccordionGroup>
  <Accordion title="Launch and swap boundaries">
    Authorized initialization, registered pool identity, immutable schedules,
    actual caller binding, exact-input settlement, deadlines, minimum output,
    maximum fee, partial fills and atomic rollback.
  </Accordion>

  <Accordion title="GEM and reserve accounting">
    Nontransferability, bounded issuance, replay protection, consent, donation
    immunity, funding maturation, reference ceilings and lifetime-cap behavior.
  </Accordion>

  <Accordion title="Prize delivery">
    Worst-case inventory locks, insufficient inventory rollback, authorized
    single fulfillment, token transfers and fulfillment during pause.
  </Accordion>
</AccordionGroup>

Fees and caps do not solve wash trading or Sybil activity. A bounded direct GEM reference benefit says nothing about promotional prize profitability. No anti-scam guarantee follows from fixed supply or removing a bonding curve.

## Before public deployment

Public operation requires approved registration and economic policies, secure randomness and recovery, governance, chain-specific checks, adversarial token testing, gas bounds, static analysis, expanded fork testing, independent audit, monitoring and incident procedures. See [supported chains](/reference/supported-chains) for the network evidence required.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.