> For the complete documentation index, see [llms.txt](https://docs.redacted.money/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.redacted.money/protocol/system-overview.md).

# How It All Fits Together

Redacted has a few moving parts: your browser, the shared Reserve, the nodes that relay your actions, a reference screener and the governance that sets the public rules. This page explains how they fit together and who decides what, and each part has its own page, linked at the end.

{% hint style="info" %}
**Coming soon.** Sign-in, the Reserve, Spending and withdrawals work today. The node network and the rules around it roll out in upcoming updates.
{% endhint %}

## The short version

Anyone with a wallet can use Redacted, with no sign-up, KYC or identity checks, and the rules are public and the same for everyone. Every deposit is approved by the node network, and each node chooses what it checks before it approves.

New money waits about two hours before it can be used privately, so a deposit can't be matched to what you do with it a few minutes later. While it waits, the nodes can send back money they decide not to accept, which keeps the crowd you blend in with clean.

Only independent nodes decide whether a deposit is sent back, and it only ever goes back to its sender. The core contributors, the DAO and Bōheki (the DAO's safety multisig) can't turn away or send back anyone's money, and no vote or switch applies to withdrawals. Bōheki (once, for about 3 days at most) and node votes can pause all new deposits, but a pause applies to everyone at once and never singles anyone out.

## The parts

![The Redacted system map. Entry doors lead into the Reserve of private notes, and the Reserve, the Spending accounts and the Rujira products sit on THORChain. Independent nodes relay, approve and vote, each choosing its own checks, with Ozone as the reference screener, and governance sets the public rules, the upgrade timelock and the Bōheki brake](https://578094165-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FSbe8ZmgM8eAZhz3FlmfM%2Fuploads%2Fgit-blob-e04eaa615968322228761dd4bdcc0598f17cee67%2Fsystem-map.svg?alt=media)

Your browser holds the keys and proves every action. Nodes carry the proofs to the chain, can check the addresses involved and decide whether a waiting deposit is sent back. Token holders set the wider rules after the token relaunch and the DAO does until then, and the contract applies the same public rules to everyone.

Governance and safety wrap around the Reserve. Token holders (the DAO until the relaunch) set the rules and, once governance switches staking on, can back nodes with stake. Code upgrades wait 3 days in the upgrade timelock, in public, and an emergency lane that needs all three emergency signers can run a scheduled upgrade sooner. The nodes vote on five safety switches, and Bōheki is a capped brake that can pause deposits once, for about 3 days at most. None of the switches and brakes touch a withdrawal, and every code upgrade waits in public first, so you can withdraw before one runs.

## The life of your money

1. You sign in with one wallet signature, which derives your private account in your browser. There is no new seed phrase and no transaction.
2. You deposit. A node signs an approval after whatever checks it chooses to run, and the deposit then waits about 2 hours, which breaks the timing link to whatever you do next. During the wait, nodes can send it back, only to the address it came from, and you can cancel it. See [New money waits briefly](/node-network/node-network.md#new-money-waits-briefly).
3. You use your money privately. It moves from the Reserve to your Spending account and acts from there at once. Your browser proves each action, and a node picked at random carries it.
4. You bring it back. Your own money returns to the Reserve at once, including what came from your Reserve, every gain your positions make in the share you put in, and payments straight from another Redacted user's Reserve. Money someone else sends to your Spending account waits like a deposit, and a mixed return is split, so your part is back at once. Nodes confirm this (see [Returns from Spending](/node-network/node-network.md#returns-from-spending)), and during an incident or a deposit pause returns wait too.
5. You withdraw whenever you like. Withdrawals are never delayed and no vote applies to them, although a node can check the destination address first.
6. If no node is active for 7 days, the emergency exit opens by itself and you can withdraw on your own, from your own wallet. See [The emergency exit](/node-network/node-network.md#the-emergency-exit).

The diagram below shows how returns from Spending work.

![Returns from Spending. A node traces where the money came from, your own money comes back at once, money someone else sent waits like a deposit, a mixed return is split, and coins tied to known hacks or sanctions lists stay in the Spending account](https://578094165-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FSbe8ZmgM8eAZhz3FlmfM%2Fuploads%2Fgit-blob-81ef3e95bd2b7fbf604563f0ceb64025fca3f946%2Freturns-from-spending.svg?alt=media)

## Who decides what

No single group decides everything. Each has its own powers, and the contract applies the safeguards between them.

### Token holders

After the [token relaunch](/project/tokenomics.md#the-relaunch-on-thorchain), token holders decide who runs nodes. Once governance switches staking on, they stake behind the nodes they choose (see [Staking behind a node](/node-network/node-network.md#staking-behind-a-node)), and a node needs its bond to be active. Through governance they also set the bond size, remove or slash a node, and open admission to everyone. They decide the fees, the wait, code upgrades (with the 3-day delay) and the screening policy as well. Stake influences which nodes are active without being a direct election, and once admission is open anyone with the bond can run a node.

### The Redacted DAO

Until the relaunch, the Redacted DAO holds the token holders' role. It is a 2-of-3 group made up of one core contributor and two independent members.

### Nodes

Nodes run the network. They relay actions, approve deposits after whatever checks each node chooses, and send deposits back, which takes at least two nodes, or a third of the active nodes once more than six are active. They also vote on five safety switches, which are the deposit pause, the deposit cap per hour, pausing new private accounts, strict screening and incident mode. The DAO can't override those switches, and fees, bonds and code stay with token holders. The active places rotate every day, with stake deciding who holds them, so no single node is essential (see [Node rotation](/node-network/node-rotation.md)).

### Bōheki

Bōheki is a capped, 2-of-3 emergency brake. It can pause deposits or switch on incident mode, once, for at most about 3 days, and the DAO re-arms it.

### Core contributors

Core contributors build the software.

### Ozone

Ozone decides nothing. It is the reference screener, built by Redacted's core contributors, and it works only from public data. It is published as open source with the launch. Each node chooses which Ozone instance it trusts, and the node network can decide to use or add other sources. Ozone signs answers about addresses tied to known hacks or sanctions lists and can't move money, and every decision about a deposit stays with the nodes.

### You

You hold your keys. Your browser proves every action, and only your proofs can spend your notes.

### The contract

The contract applies all of this to everyone, the core contributors included. It checks every proof, accepts a deposit only with a node's approval and holds the funds in the Reserve.

For every decision and its safeguards in one table, see [Who controls what](/node-network/node-network.md#who-controls-what).

## Brakes and switches

The brakes act only on money coming in, and on everyone at once, so none of them is a decision about one person. A node vote needs two thirds of the active nodes, and at least three.

| Switch                       | Who                                                                                                    | Safeguards                                                                                                                                                                                                       |
| ---------------------------- | ------------------------------------------------------------------------------------------------------ | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Deposit pause                | A node vote, which holds until two thirds vote otherwise, or Bōheki, once and for at most about 3 days | It never touches withdrawals or Spending actions, and only the DAO re-arms Bōheki                                                                                                                                |
| Deposit cap per hour         | A node vote                                                                                            | The same safeguards                                                                                                                                                                                              |
| Incident mode (24-hour wait) | A node vote, or Bōheki                                                                                 | The same safeguards, and new money waits 24 hours instead of about 2                                                                                                                                             |
| Pause new private accounts   | A node vote                                                                                            | It applies only to creating new private accounts                                                                                                                                                                 |
| Strict screening             | A node vote                                                                                            | It refuses every fallback, so no deposit approval can rest on a node's backup copy of the lists                                                                                                                  |
| Code upgrades                | Token holders (the DAO until the relaunch)                                                             | They wait about 3 days, in public, and an emergency lane runs a scheduled upgrade at once only with all three emergency signers, who at launch are the DAO's three members. Replacing them waits the same 3 days |

## The same for everyone

The contract applies these rules to everyone, the core contributors included.

* Your notes stay yours, because only your proofs can spend them.
* A rejected or cancelled deposit goes back only to the address it came from.
* Withdrawals stay open, and no vote, pause or delay applies to them. If nodes decline a withdrawal, governance can remove them, and the 7-day emergency exit opens when no node is active at all.
* Code changes come with 3 days' notice, with the emergency lane as the one exception, which needs all three emergency signers together.
* Every node has the same chance, because the app picks the node that relays your action at random.

Only the nodes can turn a deposit away or send it back. A node turns a deposit away by not approving it, and sending a waiting deposit back takes the votes of at least two nodes, after which it goes back only to the sender. The core contributors, the DAO and Bōheki can do neither. A pause on new deposits, from Bōheki or a node vote, applies to everyone at once and is never a decision about one person.

A code upgrade is the one path that could change these rules, which is why it waits in public and why you can withdraw first.

## Go deeper

[Reserve and Spending](/using-redacted/how-it-works.md) and [How privacy works](/using-redacted/privacy.md) explain the Reserve and what stays private, and the [architecture](/protocol/architecture.md) and [the relayer](/protocol/relayer.md) cover the pieces in more detail. For screening, the wait, the bond, the brakes and the emergency exit, read [How the node network works](/node-network/node-network.md) and [Running a node](/node-network/running-a-node.md). [Compliance](/protocol/compliance.md), [Security and upgrades](/protocol/security.md), [Fees](/using-redacted/fees.md) and [Tokenomics](/project/tokenomics.md) cover screening, the upgrade delay, costs and how the network is paid for.
