Locked mode (an on-chain escrow contract E with exactly three spend paths, fixed destinations, no admin, no upgrade) is the single biggest departure from the auths ethos and does NOT ship until:
- a contract audit is budgeted;
- target network(s) are chosen;
- counsel reviews the money-transmitter posture of operating arbiter keys and the pinning service.
Reserved mode (shipped on dev-receipts) raises none of these; escrow_open refuses mode: locked fail-closed. Preferred outcome per the plan: reserved-mode reputational binding proves sufficient for real deal sizes and E is never built.
Locked mode (an on-chain escrow contract E with exactly three spend paths, fixed destinations, no admin, no upgrade) is the single biggest departure from the auths ethos and does NOT ship until:
Reserved mode (shipped on dev-receipts) raises none of these;
escrow_openrefusesmode: lockedfail-closed. Preferred outcome per the plan: reserved-mode reputational binding proves sufficient for real deal sizes and E is never built.