Context
A bolt-on privacy feature looks likeif (shielded) callZcashService(): a second payment system with its own state, its own books and its own failure modes, reconciled with the first by hand.
Decision
Privacy is thezcash_ironwood venue in the one route graph. privacy: "shielded" is a constraint on the path (it must end in a shielded venue), not a separate subsystem.
Consequences
- Shielded and public payouts share every guarantee: exactly-once booking, compensation, reconciliation.
- Disclosure is built in: a viewing key per
(customer, period). - The console shows shielded balances only to the customer and key holders.
Alternatives rejected
- A separate privacy service: duplicated state and a reconciliation problem between systems.
- A private L2 or mixer: weaker disclosure semantics and no per-period audit scoping.