Third-party custody
Why
When collateral rests on physical inventory, someone must exercise control over it independently of the borrower β a qualified custodian, with its own rights, its own evidence, and its own responsibility. This is never a simple text field on a warehouse: it is a full-fledged actor on the platform.
How, in the application
A custodian is represented the same way partner banks are: an identity in the shared registry, a specific qualification, validated and in force, and its own space to which its authorized users are attached. A warehouse only references the custodian that controls it β it does not "take" anything itself, it states who controls the place.
Designation and receipt, two distinct acts. Designating a custodian is an act of the guarantee's beneficiary (the institution), which checks that the designated custodian does indeed hold the required qualification. Confirming receipt is an act of the custodian itself, in its own space: it is the act by which it commits to its custody. The first never amounts to the second β designating is not receiving.
Evidence and receipts. Every notable step (receipt, inspection, executed release) produces typed, timestamped evidence, with a cryptographic fingerprint of the document. An issued receipt is never withdrawn: it can only be contradicted by a later finding, never erased.
Inspections. The custodian records its field checks with a deliberately binary verdict β compliant or negative β to prevent a nuanced result from becoming a consequence-free comment rather than an actionable verdict.
Stock releases, a three-actor chain. A release is first requested by the beneficiary, with a mandatory reason. It is then authorized or refused, but this act is reserved solely for the institution's decision-maker role β and this authorization is not the release of the collateral itself, it frees a physical outflow, nothing more. It is finally executed only by the custodian, in its own siloed space, and only if it has been previously authorized, with a release note as proof.

Safeguards
- Three facts must be verified before a custodian can act: the existence of its space, the existence of its identity in the registry, and a qualification that is validated and in force β with no exception, even for a platform administration role.
- Requesting, authorizing, and executing a stock release belong to different roles and, for execution, to an entirely distinct tenant β the same session can never request and execute.
- The custodian's application session fails explicitly rather than serving a request if the technical isolation protecting it is not in place.