Permissions + Threat Notes
HISTORICAL - describes the abandoned tournament / forecast-AMM design
This page documents the pre-migration architecture (TournamentManager,
matchday-gated trading, on-chain ForecastMarket AMM). None of it exists in the
current system: tournaments were replaced by instant 1v1 prestige-ladder
battles, prediction markets are off-chain parimutuel in non-redeemable in-game
currency, and the contract suite is Charter v2 + the Uniswap v4 venue. For
current rules see the Platform Rules page; for current architecture see the
repo's docs/architecture/ and my-dapp-contracts/docs/ARCHITECTURE.md.
- Privileged actions should be owned by a multisig with clear operational SOPs.
- A dedicated
Guardianrole should be able to pause both token and forecasting flows during incidents. - Backend signer compromise is a critical risk; treat automation keys as production-tier secrets.
- MEV and slippage risk exists across all three AMM domains; enforce user slippage bounds and monitor sandwich patterns.
- Oracle risk primarily affects fallback forecast resolution and TWAP-dependent checks; deterministic
TournamentManagerresults are preferred. - Document pause criteria, incident runbooks, and all privileged-call audit trails.