Alpend, Palladium's money market on Canton Network, is non-custodial by design. Positions are controlled directly by the people who open them, and the contracts are written so that no user action depends on Palladium's own infrastructure staying online.

Protocol administration was the exception. Like every money market, Alpend has a set of privileged actions that configure how the protocol runs, and those actions sat behind one administrative key. Palladium's first deployment of Decentralization Manager changes that.

Distributed control over Alpend's administration

The first deployment governs Alpend's administrative and governance actions. Rather than one key holding full authority, those actions are exercised by a Decentralized Party: a single party identity on Canton whose signing authority is distributed across independent member nodes. An administrative action executes only once a defined threshold of members approves it.

User activity stays outside that path. Supplying, borrowing, repaying, withdrawing, and liquidations remain directly controlled by users, exactly as before, while governance protects the protocol's configuration without adding an approval step to ordinary market activity.

The scoping is deliberate. Palladium started where concentrated control carried the most consequence, and secured that first.

Shared authority in place of a single point of control

Palladium has been consistent that multi-signature was never the product the team set out to build. Threshold signing, signer coordination, and the operational process around them are real engineering work, and none of it makes a credit protocol better. Before Decentralization Manager, teams on Canton either built that layer themselves or accepted a single administrative key.

"Distributed trust and full auditability are table stakes for institutional-grade credit infrastructure like Alpend. Decentralization Manager makes that a framework the entire Canton ecosystem can build on. Adopting it was one of the easier decisions we've made."

— Akshay Sinha, Co-Founder and CTO of Palladium Labs

How the control model works

Each member of an Alpend Decentralized Party holds its own signing key in its own Canton node vault. Private keys never leave those nodes, and Decentralization Manager never holds them. When an administrative action is proposed, members confirm it independently, and execution happens only once the threshold is met.

Membership is not fixed at deployment. Members can be added or removed and thresholds can change as the protocol matures, so the governance model grows with Alpend instead of being locked in on day one. Palladium is running a small member set through testing and plans to widen the usage of Decentralization Manager after Alpend comes out of beta.

Secure a Canton application with Decentralization Manager

Tell BitSafe what you're building and find out which parts of an application belong behind threshold approval.