Guardian provers are multisig signers who collectively serve as the higher tier in the proof hierarchy during the first couple of years after launch. These guardian provers serve a specific purpose: To act as a safety net for addressing bugs in the proving system during its early stages. Importantly, these guardian provers live outside the core protocol and can be removed from the tiered proving configuration. They cannot influence the sequencing of transactions or blocks. As the system matures and other provers prove to be reliable, the role of these guardian provers can be phased out.
While alternative mechanisms like DAO voting could manage faulty provers, such an approach would require significantly longer cooldown windows to complete the governance process. This would be unsuitable for promptly addressing critical bugs, unlike adding or removing features, which can afford a more lengthy, decentralized governance process.
Guardian provers are crucial during the initial phases of a rollup's deployment, especially if the goal is decentralization. Unlike in centralized rollups, where the chain can be paused or altered by its administrators, guardian provers offer a security layer that can address errors or vulnerabilities without undermining the network's decentralized nature.
