Consensus Is Not Governance
Why "permissionless" describes admission, not authority — and why economists keep mistaking the two
There is a category error at the centre of how protocol economies are usually analysed, and it is doing real damage. The error is the assumption that a consensus mechanism is a governance system. It is not. A consensus mechanism is a procedure for recognising which proposed states of a system count as valid. A governance system is the authority structure that determines whether the rules defining validity may themselves be changed, and on whose terms. These are different objects. Conflating them produces models that look formal but cannot answer the question economists most need to answer: under what conditions will participants commit specific investment to a rule system whose rules a coalition can later revise?
The confusion is partly a vocabulary problem. The word permissionless is doing too much work. It properly describes the admission layer of a protocol — anyone may enter, anyone may submit transactions, anyone may run validating software. It does not describe the governance layer, where rule revisions are written, classified, signalled, activated, and adopted. Once you separate these layers, the standard claim that a protocol is “decentralised because it is permissionless” collapses into something more interesting and less reassuring: a system can be open at the door and closed at the rule book, and the second is the part that determines economic behaviour.
This essay argues, plainly: consensus is not governance, admission is not authority, and the failure to distinguish these is the reason most discussions of “decentralisation” generate heat without insight. I will set out the distinction formally enough to be useful, show why it matters for investment and security, and end with what changes once the distinction is taken seriously.
1. What a consensus mechanism actually does
A consensus mechanism is a coordination procedure. Given a set of proposed updates to a shared ledger, it produces a single accepted history. The procedure varies — proof-of-work, proof-of-stake, Byzantine agreement protocols, federated voting, ordered logs — but the function is the same: select among competing candidate states under a defined rule for what counts as valid. Let Pt denote the protocol rule set at time t, and let Ct denote the consensus process that operates under those rules. The consensus process answers a narrow question: given Pt, which proposed update is the next accepted state?
It does not answer a different and prior question: who decides what Pt+1 is?
That second question is governance. Call the governance structure Gt. The two are formally distinct objects. A system can have a fully decentralised Ct — thousands of independent operators, no privileged validator, costly entry, low collusion risk — while having a highly concentrated Gt, in which a small set of maintainers, sponsors, or coalition members effectively determine whether and when Pt changes. Conversely, a system can have a fairly centralised Ct — a small validator set, perhaps a federation — while having a relatively dispersed governance process around rule revision. The two layers are independent in principle, even when they are entangled in practice.
The reason this matters economically is that participants are not investing under Ct. They are investing under the joint expectation of (Pt, Ct, Gt). A miner who buys hardware, a firm that integrates a payment rail, a developer who builds applications on top of a settlement layer, a user who holds balances — each of these actors makes a decision whose expected return depends not only on whether the consensus process correctly orders transactions, but on whether the rules under which those transactions have economic meaning will still apply tomorrow.
To say that a system is “trustless because it has consensus” is therefore to answer the wrong question. Trustlessness in the consensus layer means that participants do not need to trust any single operator to produce a correct ordering of valid transactions. It says nothing about whether participants need to trust anyone with respect to the rules that determine which transactions are valid in the first place. That second form of trust is governance trust, and consensus mechanisms do not eliminate it. They merely route around one specific trust dependency while leaving the other intact.
2. Three layers, not one
Once consensus and governance are separated, a third dimension becomes visible: mutability. Mutability is the property of the base-layer rule set itself — the question of whether Pt can be changed at all, and through what mechanism. Mutability is not the same as governance. A protocol can have governance over rule change without that governance being effective; it can also have mutable base-layer rules without any clearly identifiable governance structure, in which case the mutability is exercised through informal coordination, sponsor pressure, or implementation control by reference clients.
So we have three layers:-
Admission — denoted A — who may participate in consensus, transaction submission, validation, or development;
-
Governance — denoted G — who has effective authority to revise the protocol rule set;
-
Mutability — denoted μ — whether base-layer settlement semantics can be revised after deployment, and at what coordination cost.
The categorical claim of this essay is that A ≠ G ≠ μ. They are independent dimensions. A protocol can be open in admission, concentrated in governance, and high in mutability. It can be open in admission, dispersed in governance, and low in mutability. It can be permissioned in admission, transparent in governance, and high in mutability. The combinations matter, because the economic behaviour of participants depends on the joint configuration, not on any single dimension.
The dominant rhetoric of the field collapses these three into one word — “decentralised” — and uses that word to describe a system in which any of the three layers might be open while the others are not. The result is that two systems with radically different governance configurations can both be called decentralised, and a participant who allocates capital to either of them on the basis of that label is taking on risks the label does not represent.
This is not a philological complaint. It is an analytical complaint. If a model treats decentralisation as a single scalar — a node count, a Nakamoto coefficient, a hash distribution — it is implicitly conflating layers that need to be analysed separately. The Herfindahl index of mining concentration tells you something about Ct. It tells you almost nothing about Gt. A protocol with a beautifully diffuse hash distribution and a single repository whose maintainers determine which rule changes are merged is not, in any economically meaningful sense, decentralised in its governance.
3. The category error and what it costs
Why does the conflation persist? Partly because the early formal literature on distributed systems was built around the consensus problem, and the institutional questions came later. The Byzantine generals problem, the FLP impossibility result, the Nakamoto consensus construction — these are all results about Ct. They are sophisticated and important, but they do not address Gt. When the formal vocabulary of a field is built around one layer, the other layer tends to be treated either as exogenous or as absent. In the case of protocol economies, both errors have been common.
Treating governance as exogenous means writing models in which the rule set is fixed by assumption and the only strategic decisions concern participation in consensus. This is a perfectly legitimate modelling move when the rule set really is fixed, but it cannot be used to draw conclusions about the economic security of systems in which the rule set is mutable. The model has assumed the question away.
Treating governance as absent means writing about “permissionless” systems as if they had no authority structure at all — as if “no formal hierarchy” implied “no effective hierarchy.” Anyone who has watched the trajectory of any actually existing protocol knows this is false. Reference implementations have maintainers. Maintainers have funders. Funders have agendas. Foundations write roadmaps. Exchanges coordinate listings. Validators coordinate adoption. Sponsors classify changes as soft forks or hard forks, as bug fixes or upgrades, as routine or emergency. None of these activities is consensus. All of them are governance. The pretence that they do not exist, or that they are merely “social layer” phenomena outside the proper scope of formal analysis, is itself an analytical choice — and a costly one.
The cost is that economic actors making real investment decisions are doing so under risks the formal models do not represent. A firm that integrates a settlement rail, builds compliance infrastructure around it, trains staff, and renegotiates contracts with counterparties is making a Williamsonian asset-specific investment. The classical transaction-cost question — what protects that investment against ex post opportunism by the party with discretion to change the terms? — is precisely the question that the consensus-only framing cannot answer. It can tell you that the consensus process will order transactions correctly. It cannot tell you that the rules defining what those transactions mean will still apply when the firm needs them to.
Williamson’s central insight, in The Economic Institutions of Capitalism (1985) and earlier work, is that asset specificity transforms what looks like a market relationship into a governance relationship, and that the governance terms are part of the cost of the transaction. Protocol economies do not escape this. They reproduce it in a new register. The participant who specialises capital to a protocol’s rule set has made a specific investment, and the question of who can change that rule set is a Williamsonian governance question. Calling the system “permissionless” does not make the question go away. It conceals it.
4. Permissionless admission, governed authority
Consider what “permissionless” actually guarantees. It guarantees that no central administrator can refuse a participant’s transaction at the consensus layer, assuming the transaction conforms to the current protocol rules. It does not guarantee that the current protocol rules will continue to permit that kind of transaction tomorrow. The first is an admission property. The second is a mutability property. They are independent.
An illustration. Suppose a protocol’s current rule set permits a particular transaction format — call it format F — and a firm builds substantial infrastructure that depends on F. The firm has not been refused admission; its transactions are accepted. Now suppose a coalition of maintainers, sponsors, and validators coordinates a rule change that deprecates F, replacing it with a different format F’ that is incompatible with the firm’s infrastructure. The firm’s transactions are no longer rejected at the door; they are simply no longer valid under the new rule set. From the firm’s perspective, this is functionally equivalent to having been refused admission. The economic outcome is the same — its sunk infrastructure is stranded — but the mechanism is different. Admission was open throughout. The rules changed.
The “permissionless” framing does not capture this risk because the framing is about the door, and the loss happens through the rule book. The firm was admitted. It was not refused. It nevertheless lost the value of its specific investment because the rules under which that investment had economic meaning were revised by parties with effective authority over Pt.
Now distinguish two cases. In the first, the rule change is broadly welfare-improving — the new format F’ fixes a security flaw in F, or accommodates technical demands that F could not, or reduces transaction costs across the system. In the second, the rule change benefits the rule-changing coalition disproportionately — it advantages a particular class of validators, or a particular set of sponsors, or a particular application stack, at the expense of other participants. The first case is what the existing literature gestures at when it speaks of “upgrades” or “improvements.” The second case is what economic theory recognises as opportunistic ex post revision under specific investment, and it is not adequately addressed by any framework that treats consensus and governance as a single object.
The point is not that all rule changes are opportunistic. The point is that the framework must be capable of distinguishing the cases, and the consensus-only framework is not. To distinguish them, one needs an explicit model of who may revise Pt, on whose authority, with what coordination cost, against what accountability constraint. That is governance analysis. Consensus analysis cannot substitute for it.
5. Why this is a commitment problem, not a coordination problem
It is sometimes argued that rule change in a permissionless protocol is not really a problem because participants who object to a change can simply refuse to adopt it — they can run the old client, they can fork, they can exit. This argument treats the situation as a coordination problem. The argument is incomplete because it ignores the economics of fork costs and migration costs, which are the same Williamsonian costs that made the investment specific in the first place.
If a participant has integrated infrastructure around Pt, the cost of running an isolated old version of the protocol after the rest of the network has moved to Pt+1 is generally not symmetric with the cost of moving. The old version may lose liquidity, lose application support, lose exchange listings, lose user mindshare, lose security as operators migrate. The participant’s “choice” to remain on Pt is real but expensive, and the expense is precisely the asset specificity of the original investment. To frame this as a free coordination choice is to ignore the structure of sunk costs.
This is the structure of a classical commitment problem, in the sense familiar from Kydland and Prescott (1977) and a long subsequent literature on time inconsistency. A coalition with the discretion to change the rules later faces a temptation to do so on terms that benefit it. Forward-looking participants anticipate this and discount their investment ex ante. The result is less investment, less specialisation, less depth — not because the rule change actually occurs, but because the possibility of it is priced into participation. The participant does not need to predict that opportunism will happen. The participant needs only to recognise that nothing prevents it.
The economic logic is identical to the logic of constitutional commitment in public economics, the logic of central bank independence, the logic of vertical integration under asset specificity, and the logic of long-term contracts in the presence of relationship-specific capital. In each case, an actor with the discretion to revise terms after the counterpart has committed is in a position to extract rents, and the standard solution is to constrain that discretion through some institutional mechanism — a constitution, a charter, a contract, an integrated firm. The mechanism is what makes the commitment credible.
Protocol economies inherit this problem. They do not transcend it. The interesting question is not whether the problem exists — it does, in any system where rule change is possible and investment is specific — but what mechanisms are available to constrain it. And here the consensus-only framing is doubly unhelpful. It tells you nothing about the discretionary capacity of the rule-changing coalition, because it does not represent the coalition; and it tells you nothing about the constraints on that capacity, because it does not represent governance.
6. The governance layer in practice
Once you look for it, governance is not difficult to find in any operational protocol. The forms vary. They include:-
Reference implementation control. Most protocols have a dominant client or a small set of clients. The maintainers of those clients exercise effective authority over which proposed changes are merged, released, and tagged. Repository permissions, code review norms, and release schedules are governance instruments, not technical artefacts.
-
Funding concentration. Maintainers are paid. The entities that pay them — foundations, corporate sponsors, grant programmes, venture-funded ecosystems — exercise influence over what gets prioritised, what gets resourced, and what gets deferred. This is true even where individual decisions are formally independent.
-
Adoption authority. A rule change does not become effective merely because it is merged. It becomes effective when consensus operators run the new client. The decision of validators, miners, staking pools, and infrastructure providers to adopt a new release is a governance decision, even when each individual decision is taken independently.
-
Classification authority. Whether a change is described as a “soft fork,” a “hard fork,” a “bug fix,” or an “emergency intervention” is a governance act. The classification structures who is expected to coordinate and who can be safely ignored. Two technically identical changes can have radically different economic implications depending on how they are framed.
-
Activation design. The mechanism for activating a rule change — miner signalling, validator quorum, user-activated soft forks, hard-coded block heights, emergency hot-fixes — determines who bears the burden of dissent. A change that requires explicit opt-in is governed differently from a change that requires explicit opt-out, even when the substantive rule is the same.
-
Token voting. In systems with on-chain governance, token-weighted voting allocates rule-change authority by wealth. This is a specific governance form with its own properties, including plutocratic susceptibility, voter apathy, and capture by concentrated holders. It is not the absence of governance; it is a particular kind of governance.
-
Narrative authority. The framing of a change as routine or extraordinary, as preserving the protocol’s spirit or extending it, as conservative or progressive, is itself a governance act. It shapes what dissent looks like and what dissent costs.
None of these are consensus mechanisms. All of them are mechanisms by which Pt becomes Pt+1. A model that treats the protocol rule set as fixed, or that treats rule change as a black box outside the system, cannot represent any of them — and therefore cannot represent the economic risks and constraints they generate.
It is sometimes said that these mechanisms are “informal” and therefore not analysable. This is a misunderstanding. Informality is a feature of the mechanisms, not an obstacle to their analysis. Coase (1937) analysed the firm without supposing that internal authority within firms was formal in any contractual sense. North (1990) analysed institutions without supposing that all institutions were written down. The relevant question for institutional analysis is not whether rules are formal but whether they shape behaviour. Protocol governance, in all the forms listed above, manifestly shapes behaviour. Therefore it is analysable. Therefore it should be analysed.
7. What changes once you separate the layers
Several things change once consensus and governance are treated as distinct objects.
First, decentralisation becomes a vector, not a scalar. A system has a degree of decentralisation in admission, a degree in consensus operation, a degree in governance, and a degree in mutability. These need not be equal, and the relevant economic property is typically the minimum across the layers, not the maximum. A protocol that is highly decentralised in Ct but highly concentrated in Gt is, for the purposes of investment and commitment, governed by its Gt, not its Ct. The most concentrated effective control layer is the binding constraint. Reporting only on the least concentrated layer misrepresents the system.
Second, security becomes broader than attack cost. The standard security analysis of a consensus system asks whether the cost of mounting an attack exceeds the gain. The condition is something like αV > C, where α is the share of consensus capacity required to attack, V is the gain, and C is the direct technical cost. This is a real condition but it is incomplete, because it ignores the institutional security question: the cost of revising the rules under which transactions have meaning. A system can be secure against a 51% attack and still insecure against a coalition rule change. The institutional security condition has the form αV > C + I + K + R, where I represents capital at risk, K represents coordination cost, and R represents legal and reputational accountability. Two of these terms — K and R — are governance terms, not consensus terms. A system with low K and low R is institutionally insecure even if its consensus security is high.
Third, investment behaviour becomes explicable. Patterns that look puzzling under a consensus-only framing become natural once governance is represented. The underinvestment of certain firms in certain ecosystems, the concentration of investment in ecosystems with credibly fixed base layers, the migration of high-value applications away from systems with histories of contentious rule change, the differential pricing of equivalent technical services across protocols — all of these become predictions of a model that includes the commitment problem, rather than anomalies in a model that excludes it.
Fourth, policy becomes legible. Once governance is represented, the question of what makes a protocol’s rule set credibly stable becomes a tractable question. The answer involves the structure of the rule-changing coalition, the coordination cost of effecting a change, the accountability mechanisms — legal, reputational, fiduciary — that constrain coalition members, and the visibility of governance to participants. None of these can be addressed by tuning consensus parameters. They are governance parameters, and they require governance instruments.
Fifth, comparison across systems becomes meaningful. A comparative analysis of protocol economies that proceeds layer by layer — admission, consensus, governance, mutability — generates a typology that is both empirically grounded and analytically useful. A typology that lumps all four layers together under “decentralisation” generates noise.
8. The TCP/IP comparator
It is worth noting that the layered separation proposed here is not novel in the broader history of network protocols. The internet’s foundational protocols are routinely cited as examples of stable base-layer rules, and the citation is correct: the core semantics of TCP/IP have been remarkably stable across decades, while the application-layer ecosystem above them has evolved continuously. What is sometimes missed is that this stability is not an accident. It is the product of an explicit institutional design in which base-layer revision is constrained by a standards process — request for comments, working groups, rough consensus, deployed code — that operates separately from the operational consensus of the network itself. Routing decisions are not the same as protocol revision decisions. The two are institutionally separated.
This separation is what permits investment above the base layer without continuous exposure to base-layer revision risk. A firm building an application that relies on TCP semantics is not exposed to the possibility that the TCP specification will be rewritten next year by a coalition of router operators. The standards process is sufficiently slow, sufficiently public, and sufficiently constrained that base-layer change is rare, anticipated, and backwards-compatible where possible.
Whether the institutional arrangements around TCP/IP are optimal is a separate question. The point here is more limited: the layered separation between operational consensus and rule-revision authority is not unique to blockchain protocols, and the credibility of base-layer fixedness is an institutional achievement, not a technical property. Protocols that wish to attract specific investment in their application layers do well to take the institutional architecture seriously, not merely the consensus mechanism.
The blockchain field has often inverted this priority. Enormous attention has been paid to the consensus layer, and comparatively little to the institutional architecture of rule change. The result is a class of systems in which consensus is sophisticated and governance is improvised. The improvisation has costs, and those costs are paid by the participants who specialise capital to the system on the assumption that its rules will hold.
9. Objections
Several objections to this framing deserve direct response.
First objection: “Governance is the social layer; formal analysis should focus on the protocol layer.” This response treats the boundary between protocol and social as natural and given. It is neither. The boundary is itself an analytical choice, and the choice to draw it where the existing literature draws it has the effect of placing the most economically consequential decisions outside the scope of analysis. North (1990) and a substantial subsequent institutional economics literature have argued, persuasively, that the rules-of-the-game and the players-of-the-game are both proper objects of economic analysis. Excluding governance because it is “social” amounts to excluding institutions from the analysis of an institutional system.
Second objection: “There is no formal coalition; rule change emerges from many independent actions.” This is sometimes true at the level of any single actor’s decision. It is rarely true at the level of effective outcomes. When a particular client release becomes the de facto standard because the major exchanges, validators, and infrastructure providers adopt it, the adoption pattern is observable as a coalition outcome even if no formal coalition was declared. The economic consequence — a rule change effected through coordinated adoption — does not depend on the existence of formal organisation. Coalitions in this sense are revealed by their behaviour, not by their charters.
Third objection: “Forking provides exit, so commitment is not a problem.” Addressed above in section 5. Forks are real but expensive. The cost of forking is the asset specificity of the participant’s investment, and where that specificity is high — which is precisely where the commitment problem matters — exit is costly enough that the threat of exit does not effectively discipline opportunism. Hirschman’s (1970) treatment of exit and voice is the canonical reference here: exit is a constraint on opportunism only to the extent that it is costless or near-costless, which in protocol economies with significant integration it generally is not.
Fourth objection: “Decentralisation metrics already account for governance through proxies like client diversity and developer concentration.” Some metrics gesture in this direction, but most reduce governance to a measurable proxy that captures one dimension of it — typically client diversity — while ignoring funding concentration, sponsor influence, exchange coordination, and the more diffuse forms of effective authority. A complete metric of effective governance decentralisation would need to combine several proxies, weight them appropriately, and validate the weighting against actual rule-change episodes. This is doable. It has not generally been done.
Fifth objection: “The consensus-governance distinction is academic; it does not change practical behaviour.” The opposite is closer to the truth. Practical behaviour already reflects the distinction, even where the vocabulary does not. Investors who specialise capital to particular protocols do so on the basis of judgements about rule-change risk, not only consensus security. Application developers who choose between settlement layers do so partly on the basis of how credibly stable the base-layer semantics are. Insurance markets that have begun to price protocol risk separate consensus failures from governance-driven losses. The distinction is operative in the market. It has lagged in the formal vocabulary.
10. What the field needs
If the consensus-governance distinction is taken seriously, three lines of work follow naturally.
The first is descriptive. We need a clean comparative coding of the governance layer of major protocols, distinct from their consensus layer. Who exercises implementation authority, who funds maintenance, who classifies changes, who controls activation, who exercises adoption-critical influence. This is a tractable empirical exercise. It is also one that the field has done unevenly, partly because the vocabulary for it has not been settled.
The second is theoretical. We need formal models of investment, security, and adoption that treat the governance layer as endogenous rather than as a black box. Such models will have more state variables and more equilibrium conditions than the consensus-only models, and they will produce predictions about investment and migration that the consensus-only models cannot. The economics is not new — it is the economics of asset specificity, commitment, time inconsistency, and institutional credibility — but its application to protocol economies has been partial.
The third is institutional. We need design principles for protocol governance that are explicit about the trade-off between mutability and commitment. Mutability has option value; it permits adaptation under uncertainty, correction of errors, and response to shocks. Commitment has investment value; it permits participants to specialise capital under stable terms. The two are in tension, and the question of how to combine them is a real institutional question, not a slogan to be settled by declaring one or the other to be virtuous.
None of this requires abandoning the consensus literature. The consensus literature is correct on its own terms. The point is that its terms are narrower than the questions the field is being asked to answer. When participants make investment decisions, when regulators classify systems, when courts adjudicate disputes, when competing protocols are compared, the relevant analytical object is the joint configuration of admission, consensus, governance, and mutability — not consensus alone. The vocabulary should catch up.
11. Closing
Consensus is a procedure for ordering valid transactions under fixed rules. Governance is an authority structure for changing those rules. Admission is a property of who may enter the system. Mutability is a property of whether the rules can be changed at all. These are four distinct objects, and they need four distinct names.
The field has, for historical reasons, used a single word — “permissionless,” or sometimes “decentralised” — to gesture vaguely at all four. The consequence is that two systems with radically different governance structures can both be described in the same terms, and economic actors who allocate capital on the basis of the description are taking on risks the description does not represent. The fix is not rhetorical. It is analytical. The fix is to separate the layers, label them correctly, and analyse each on its own terms.
Doing so does not vindicate any particular protocol or condemn any other. It does something more useful. It makes the economic analysis tractable. It permits comparison. It permits prediction. It permits the formulation of policy recommendations that engage the actual mechanisms by which protocol economies allocate authority, rather than mechanisms that exist only in the marketing material.
The basic claim of this essay can be stated in a sentence: a system that is open at the door is not, for that reason, open at the rule book, and the second is the part that matters for whether participants will commit specific investment to the system. The consensus mechanism does not solve the second question. It cannot solve the second question. Solving the second question requires governance — explicit, analysable, accountable governance — and the field’s discomfort with that fact is not an argument against acknowledging it.
The economic analysis of protocols should begin from this distinction, not arrive at it as an afterthought. Until it does, the literature will keep producing models whose predictions are clean within their assumptions and silent about the questions investors, builders, and policymakers actually face. The consensus mechanism is a marvel of computer science. It is not a substitute for institutional economics. The two are different kinds of object, and protocol economies need both.
References mentioned in passing: R. H. Coase, “The Nature of the Firm,” Economica (1937); F. E. Kydland and E. C. Prescott, “Rules Rather than Discretion: The Inconsistency of Optimal Plans,” Journal of Political Economy (1977); A. O. Hirschman, Exit, Voice, and Loyalty (1970); D. C. North, Institutions, Institutional Change and Economic Performance (1990); O. E. Williamson, The Economic Institutions of Capitalism (1985).