Governance
Upgradeability and recovery
What can change, what cannot, and how holders are protected.
The hybrid model
Escrow and leg tokens are immutable. Policy modules (SeriesPolicy, BackstopPolicy, OracleAdapter, TradingCalendar) are upgradeable behind UpgradeGovernor.
Module swaps with grace
A replaced module applies only to series created after the swap; live series keep the module they were created with unless the change is a recovery.
Which contracts can and cannot be upgraded in place
| Contract | Upgradeable |
|---|---|
| BarrierCore | No |
| BarrierLegs | No |
| Policies, oracle, calendar | Yes (UUPS) |
| Token engine | Yes (UUPS) |
| BERRIER | No |
Core replacement path
A fix to BarrierCore means a new core for new series. Old series run to settlement on the old core.
Recovery unwind
If a series can never settle (for example its Stock Token is permanently frozen), governance can unwind it: each side receives back exactly what it deposited, less coupons already paid.
Storage-layout policy
Append-only storage, gaps reserved, checked in CI.
Known limitations
Governance is concentrated until veBERRIER is widely distributed.