- Per-pool state and isolation, so one pool’s failure cannot touch another
- Three tranche tokens
- A transfer allowlist on every token, controlling who may hold them
- The loss waterfall
- The first-loss floor and ratio caps, checked on every deposit
- Receivable records and repayment routing
What each one is actually for
Note what the third and fifth have in common with
the four controls: they are checks, not covenants. The pool
cannot enter an invalid state rather than being punished afterwards for having done
so.