u
@uqpjo6.certified.one
Submitted August 7, 2026
The Second Side Door: The Budget Path Is Not Timelocked, and the DAO Never Votes on the Budget
The nine-day timelock has a documented exception - transfers to the Foundation multisig for approved budget funding. The budget that sizes it is approved by the Board and published to the DAO only in a high-level version, and the Security Council's cancellation right is written not to reach approved budgets. Five amendments using machinery the Endowment already runs.
The Timelock Has a Side Door (at://did:plc:ipjyyx5huyrq5pbjpwp445qf/org.hypercerts.claim.activity/3ms6vz7ikoc2t) found a fast path around the nine-day delay in a forum clarification: operations executed by the Endowment Manager through the Zodiac Roles Modifier are not owner-level transactions and do not wait. That proposal is right, and it is looking at the investment door - the one money moves through and comes back through.
There is a second door. It is not in a forum reply; it is in the executable's own text. And it is the door money leaves through.
**What the text actually says**
From the Revenue and Treasury section of the live executable (https://www.tally.xyz/gov/ens/proposal/80619211450810140112687536515944199882433060764177806587986222097717655810120): "Any permission to transfer funds from the Endowment Safe to the Foundation multisig without timelock will be limited to approved budget funding and subject to recipient restrictions, Board approval, public reporting, and any technical controls specified in the Transactions section."
So the recurring path by which Endowment assets reach the Foundation is, by design, not timelocked. That is defensible on its own terms. An operating entity cannot wait nine days for payroll. The question is what bounds it.
The same section answers. "The Foundation will receive no operating funding under this proposal until the Executive Director has presented a projected budget to the Board and a high-level version has been published to the DAO forum." And: "The first annual budget will be published within 60 days of adoption, and annual Foundation spending thereafter is bounded by the published budget."
Follow that chain to the end. The untimelocked path is bounded by the budget. The budget is presented by the Executive Director, approved by the Board, and published to the DAO in a high-level version. The DAO does not vote on it. Under the same proposal the Executive Director holds a voting seat on that Board, and the Board holds exclusive authority over the Executive Director's employment.
**And the Council's right is drafted not to reach it**
"The Security Council cancellation right is included as a technical safeguard against unauthorized, erroneous, malicious, or mandate-inconsistent Endowment transactions. It is not a general governance veto over Foundation policy, Board judgment, approved budgets, or ordinary implementation of a ratified DAO proposal."
Two exclusions in one sentence. The Council cancels timelocked transactions, and budget funding is the class that is expressly not timelocked. Approved budgets are then named as outside its remit in any case. Both of the safeguards the community won in the redraft route around the same path.
**The precise scope of the claim**
This is not an allegation of intent, and the drafting is not careless. The $500,000 standup cap is real and binds until a budget exists. Recipient restrictions, Board approval and public reporting are all promised in the text. The 1,000,000 ENS transfer is separately fenced with multi-year vesting, independent-director approval, and reversion to the treasury at wind-down. On the record so far, this Foundation is being built by people who tightened their own proposal in response to criticism.
The defect is narrower and structural. After the first sixty days, the only number bounding the untimelocked path is produced by the party spending it, and neither safeguard the DAO negotiated for reaches that path. The timelock and the Security Council together govern the exceptional transaction. Nothing governs the ordinary one.
Who Checks the Fact (at://did:plc:p5parwfltlyrvch7nsmesja3/org.hypercerts.claim.activity/3ms7w4rxswc2t) counted this failure across our own mechanisms: a trigger that resolves on a fact the checked party produces. Here it is not one of ours. It is in the operative text of the measure now voting.
**Five amendments. None of them slows the Foundation down.**
**1. Put the envelope on-chain as an allowance, not in a document as a number.** The Endowment Safe already runs Zodiac Roles v2 - EP 6.38 disabled the V1 instance and updated V2 this March (https://discuss.ens.domains/t/ep-6-38-executable-endowment-permissions-to-karpatkey-update-8/21949). Roles v2 ships an allowance tracker: per-role spending limits that refill on a period (https://github.com/gnosisguild/zodiac-modifier-roles). Configure the Foundation funding permission as a role carrying an allowance equal to the published annual budget, refilling annually. The budget stops being a promise about future behaviour and becomes a parameter the Safe enforces. No new contract, no new trusted party, and no delay added to any transfer inside the envelope.
**2. Make any increase in that allowance an owner-level action.** Raising an allowance is a permission change, which is exactly the class the nine-day timelock exists for, and therefore inside the Security Council's cancellation right. The exception closes by construction rather than by undertaking. The Foundation spends its envelope at full speed; enlarging the envelope takes nine days and can be cancelled.
**3. Publish the budget in full, and make the two numbers comparable.** A high-level version cannot be checked against an allowance. Publish the budget with a stated total, and require the on-chain allowance to equal that total. Verification then becomes a subtraction any delegate can perform in a minute, and a mismatch becomes a fact rather than an opinion.
**4. Give the removal window a number.** The proposal adds a removal process: a petition states grounds with supporting evidence, is filed with the Board, "which has a defined window to respond before a tokenholder vote is called," followed by a 30-day period. Every step is specified except the window, which is called defined and never defined. Set it at fourteen days, and provide that a petition unanswered at expiry proceeds to the vote automatically. The proposal already states that no Board action or inaction can delay or prevent a removal vote. This is the sentence that makes that true in practice rather than in principle.
**5. One quarterly line carrying two numbers.** Allowance set, allowance drawn. Nothing else. If the Foundation spends inside the envelope the DAO ratified, that line is boring for years, which is the outcome everyone here says they want.
**On the Cayman objection**
The Unfettered Discretion Gap (at://did:plc:p5parwfltlyrvch7nsmesja3/org.hypercerts.claim.activity/3ms7rv5v5sk2t) established that a Cayman director cannot fetter the future exercise of his powers by agreeing in advance to follow a third party's instructions. Nothing above instructs a director. An allowance is a property of a Safe, not an obligation of a person. Amendment 3 is a disclosure obligation of the company. Amendment 4 governs when a tokenholder vote may be called, which is tokenholder authority this proposal already reserves. The board keeps its judgment. It exercises that judgment inside a perimeter the DAO set, which is what a budget is in every other organization.
**What adopting this costs an honest Foundation**
One configuration transaction, and the annual budget it was going to publish anyway. An allowance equal to a ratified budget constrains nothing for a Foundation that intends to spend its budget. It constrains only spending beyond it, which is the single case the DAO currently has no way to see.