New Ethereum talks, every Monday. The week's conference uploads by event, in your inbox.

Loading player…

Trust Zones: Why DAOs will be the best organizations ever created by Spencer Graham | Devcon SEA

DevconTue, Oct 7, 2025, 12:00 AM

This talk introduces the theory of Trust Zones. Every Trust Zone is a unique blend of constraints, reputation requirements, and accountability measures, within which an agent can operate on behalf of an organization to further its goals. I will contend that the operational management of all organizations can be described as creating new Trust Zones and adjusting their parameters. And further, that DAOs and other onchain organizations can do this better than any other organizational form. Speaker(s): Spencer Graham Skill level: Intermediate Track: Coordination Keywords: DAO, Governance, trusted Follow us: https://twitter.com/efdevcon, https://twitter.com/ethereum, https://warpcast.com/devcon Learn more about devcon: https://www.devcon.org/ Learn more about ethereum: https://ethereum.org/ Visit the https://archive.devcon.org/ to gain access to the entire library of Devcon talks with the ease of filtering, playlists, personalized suggestions, decentralized access on Swarm, IPFS and more. Devcon is the Ethereum conference for developers, researchers, thinkers, and makers. Devcon SEA was held in Bangkok, Thailand on Nov 12 - Nov 15, 2024. Devcon is organized and presented by the Ethereum Foundation. To find out more, please visit https://ethereum.foundation/

Transcript

[Music] there will be a QR code on the right so please scan the QR code if you have any live questions for Spencer throughout his talk thank [Music] you okay everybody can hear me okay great hello uh my name is Spencer uh I spend a ton of my time thinking about organizations what they are how they work how they're structured how they should be structured and how they shouldn't be structured and today in this tiny amount of time I'm going to talk about a very or give a very very stripped down version of a framework that I've been working on to better understand all of those things and that framework is called trust zones uh every single slide that I'm going to show you has like seven slides behind it that I've stripped out so this is going to feel a little bit fast and my hope is that you just come up to me and talk to me afterwards about anything that doesn't make sense because a lot of it is going to be very very simple okay I am an agent that means I'm an organization that means I'm a human that might mean I I'm an AI agent I have a goal I cannot do all of it by myself so I delegate I delegate responsibilities and resources to some other agent this makes me a principal what does that mean that means I now have a principal agent problem a principal can't be like me I can't be sure that my agent will act in my best interest I can't be sure that my agent won't capture my resources won't fulfill my the task that I gave them in other words the principal agent problem is that I don't trust my agent 100% confidence in my agent means that I have full trust in them that is typically not the case but what techniques do I have to increase the trust in my agent to increase my confidence in my agent as a reminder trust is a principles my prediction that an agent will act in my best interest so technique number one we can constrain what the agent can do constraints are proactive physical rules restricting what agents can do they are proactive they are physical you cannot break them they are exactly what blockchains and smart contracts are really great at but con constraints don't always work creative work requires flexibility that constraints intentionally limit agents need agency to do their best work on behalf of their principles and that's often impossible to Define everything what an agent will need to do upfront but more flexibility for agents means more risk for principles like me so what do we do we can make additional rules and we can enforce them retroactively this is technique number two accountability otherwise known as retro proactive enforcement and this is the thing that this is the only tool that traditional organizations have they don't have any other capabilities accountability always requires something at stake your freedom your reputation access to Future opportunities Financial assets Dow tokens compensation all of these things can be put at stake to hold you accountable later okay technique number three we can create eligibility criteria that filter out agents that don't qualify eligibility criteria can include skill sets credentials reputation generally and also credible commitments and this ties back into accountability like I can stake something such as Dow tokens that can be slashed later or my agent can stake something and I can slash them later if they're not doing a good job so what are the techniques we have for increasing trust one is we can play with the size or limit the size of the resources that we delegate to our agents we can create constraints around what they can do with those a with those resources we can them accountable and we can apply eligibility criteria so imagine a container in that container I if I want to uh delegate responsibilities I can put them into the Container same thing with resources permissions access controls Etc I can whoops I can create constraints as a one of the ways that the container is defined and I can create a filter as an eligibility criteria that changes or that let's see if we do oh yes that um that uh allows only certain agents into the container and then I can also apply accountability mechanisms uh or Define the container with accountability mechanisms that can revoke the agent and hold them accountable if they're not meeting uh my needs or uh conforming to what I need inside the container remember in the in the container the agent has full agency they can do whatever they want within the constraints and the resource size and the uh everything that I've set up for that container inside the container the agent has my full trust so I call these containers trust zones trust zones are how principles like me can confidently delegate to agents to maximize their goals with trust zones we can also optimize uh delegation and operations within organizations because all of our techniques 012 3 4 are dials that we can turn up and down we can create the same let's see uh we can create the same level of trust with different combinations of these properties with different settings of these dials so for example with stricter eligibility criteria we can decrease the number of constraints or the strength of the constraints or with stronger accountability mechanisms we can give our agents more resources or in other words we can give our agents more agency within uh within the trust Zone within the container we can hold trust constant while optimizing for cost and other scenario specific factors traditional organizations cannot do this all they can do is do things with accountability retroactive enforcement Dows though Dows can do everything we can program trust zones with all of the with access to the entire design space of all of these techniques another word so this is what I'm going to leave you with here I just have one more minute another word for a trust zone is a role and when a principal delegates to an agent they are assigning that agent to a role when they're revoking that role they are applying accountability and finally when we Define roles on chain with smart contract we can make the best organizations that have ever been created thank you okay um we don't have any live questions rolling in so I guess we can pass around the mic in the audience if anyone has a question okay so one uh issue that I think uh impacts ability for um or I guess one of this uh agents not performing what a principal has in mind or one of these issues is um scope creep you know like the both in a such a way that um an agent's autonomy is limited because more things are expected of them or there's you know things that are expected to complete a task that ends up being outside of a scope of um things that they're authorized to do or um the not having you know the bandwidth to perform all the activities that are desired of them because of scope creep I guess yeah I would be curious to know how such a kind of reg rigid but flexible ontology um like yeah optimizes against that because it's one of the main issues obviously in Dows and our types of organizations I think it's a really big big problem and especially in traditional organizations where like your boss has all of the Power and they can just like throw more stuff at you without you having much recourse and we see a lot of that kind of in Dows but that's less like because the principle um is is like malicious and more just like weird loose lack like strange um lack of clarity what I think is really important in in Dows and in lots of organizations is that both

Automatic transcript — names and jargon may be misspelled.