Fig. 01 · Clients, control plane, execution legs, observers and books. One engine per concern serves every lane.
The layers
Route planner (packages/routing)
Route planner (packages/routing)
Turns a request (corridor, purpose, privacy, source, destination, environment) into an ordered list of legs by searching a graph of venue/asset positions. It rejects any payout not funded from the Tempo hub and any collection that does not land on it, and it is the only place privacy is decided: a shielded payout must end in the
zcash_ironwood venue. Routing →Saga engine (packages/saga)
Saga engine (packages/saga)
Runs a plan as durable steps in Postgres. Each leg has
forward and optional compensate. Steps retry with backoff, a lease keeps one worker per saga, and a failure compensates completed steps in reverse order. Failures after money has left Corridor’s control stop at manual_review instead. Saga →Legs (packages/legs and chain packages)
Legs (packages/legs and chain packages)
Each leg kind (
tempo.transfer, across.bridge, partner.payout, near.swap, zcash.shieldedBatch, …) moves value on one venue and returns the ledger entries that describe what it did. Legs are idempotent: before sending, they look for the movement by its reference. Chains & partners →Ledger (packages/ledger)
Ledger (packages/ledger)
Double-entry, append-only journal on Postgres. Postings balance per asset, accounts can be flagged no-overdraft, and each external movement is booked exactly once through a unique
(venue, external_ref). Ledger →Observers and reconciliation (packages/recon)
Observers and reconciliation (packages/recon)
Observers turn chain logs, partner webhooks and viewing-key scans into one
Observation shape. The matcher joins them with ledger entries on the external reference, and a vault check compares each vault’s on-chain balance with the books. Reconciliation →Treasury console (apps/console)
Treasury console (apps/console)
The operator’s view: hub balances, venues, sagas with explorer links, pre-funding forecast, reconciliation, shielded batches with FROST approvals, and auditor disclosure exports. Console →
Design principles
Privacy is a venue, not a feature
Shielded payouts are a path through the same graph into
zcash_ironwood, booked in the same ledger, reconciled by the same matcher.The hub is enforced, not suggested
Every dollar is settled, held and reconciled on Tempo. The planner refuses anything else.
One reference, every chain
A 32-byte reference rides in each chain’s native memo field, so no indexer is needed to reconcile.
Book from the chain
Gas, funding and deliveries are booked against the log or output that proves them, never against what the code intended.