
Permissionless Hierarchy : A new way to look at DAOs.
DAOs are the biggest misnomer of web3. They don’t work, and no one seems to know how to make it work. Here, I present a view to challenge the way we look at DAOs to begin with. The take-away for me from 2 days of DAO discussions in Amsterdam is nobody has figured out how to manage the chaos to get anything useful done in a DAO. DAOs are today just a glorified Discord channel with no clear route to be either Decentralized (what does that even mean?) or Autonomous. “DAO” is a marketing gimmick....
Request to build - Decentralized NFT based lending protocol
A completely decentralized protocol that lets people borrow money from the treasury by producing an NFT. This is to be built on top of LooksRare, because LooksRare is decentralized and hence infinitely composable.Borrow at floor priceProduce an NFT from an NFT collection on LooksRare. The maximum amount you can borrow against the NFT is the minimum floor price of that collection over the last 30 days. You can only deposit verified collections’ NFTs - for securing the protocol. Open to any oth...
Request to build - A decentralized Audit Marketplace mechanism design
Auditing wait times on top audit firms are 9-12 months and expensive. We need something that is more participative and allows for new and yet-unproven security auditors. Here I propose a decentralized audit marketplace that turns the auditing process into a prediction marketplace.1. Select a juryA jury is usually reputed security engineers. This jury doesn’t do the audit itself, but only signs off a reported vulnerability as a real bug. There are 5 jury members selected for every audit. They ...
Founder [Questbook (YCw21)](https://questbook.xyz) Writing about things that need to be built in web3

Permissionless Hierarchy : A new way to look at DAOs.
DAOs are the biggest misnomer of web3. They don’t work, and no one seems to know how to make it work. Here, I present a view to challenge the way we look at DAOs to begin with. The take-away for me from 2 days of DAO discussions in Amsterdam is nobody has figured out how to manage the chaos to get anything useful done in a DAO. DAOs are today just a glorified Discord channel with no clear route to be either Decentralized (what does that even mean?) or Autonomous. “DAO” is a marketing gimmick....
Request to build - Decentralized NFT based lending protocol
A completely decentralized protocol that lets people borrow money from the treasury by producing an NFT. This is to be built on top of LooksRare, because LooksRare is decentralized and hence infinitely composable.Borrow at floor priceProduce an NFT from an NFT collection on LooksRare. The maximum amount you can borrow against the NFT is the minimum floor price of that collection over the last 30 days. You can only deposit verified collections’ NFTs - for securing the protocol. Open to any oth...
Request to build - A decentralized Audit Marketplace mechanism design
Auditing wait times on top audit firms are 9-12 months and expensive. We need something that is more participative and allows for new and yet-unproven security auditors. Here I propose a decentralized audit marketplace that turns the auditing process into a prediction marketplace.1. Select a juryA jury is usually reputed security engineers. This jury doesn’t do the audit itself, but only signs off a reported vulnerability as a real bug. There are 5 jury members selected for every audit. They ...
Founder [Questbook (YCw21)](https://questbook.xyz) Writing about things that need to be built in web3

Subscribe to Madhavan Malolan

Subscribe to Madhavan Malolan
Share Dialog
Share Dialog
We’ve been pondering upon how to make sure we build a truly decentralized product, community and company. It’s hard. But here I’ll share a mental model to evaluate the degree of decentralization of your system.
Your system is as decentralized as your least decentralized subsystem
But how to measure decentralization?
Balaji S had a great post (circa 2017) to measure Decentralization Retroactively, this post is about measuring Decentralization Proactively.
https://news.earn.com/quantifying-decentralization-e39db233c28e
https://news.earn.com/quantifying-decentralization-e39db233c28e
For each subsystem in your system, count the number of potential participants.
e.g.
How many bitcoin miners can exist in the world?
Maybe as many computers there are in the world? 1B
How many people can run a DB with high API availability?
Maybe as many accounts that exist on AWS? 10M
How many people can vote on a proposal?
Maybe number of people with an internet connection? 2B
Counting how many of those participants can realistically participate in the subsystem without any human’s permission?
Permission participation comes in various forms
Owning an NFT
Owning coins
Having high computation
Having an on-chain reputation
e.g. have voted previously on Snapshot
This could eventually merge into “Owning an NFT”, but right now these seem to be different.
e.g.
How many people can run a bitcoin node with > 4GH/s?
How many people can run your instance of DB with high availability? 1 (only you)
How many people can vote on proposal (and have access to full information)? Varies
D = P2/P1
Huh not too hard, that.
Another measure is
D’ = Rate of change of D over time
D’ for example has been rapidly changing for bitcoin miners. Number of ASICs has been increasing steadily in the world. When D’ is high, having a low D is kind of OK. Especially because in a lot of places in web3, technology is new but fast improving. Or, product is new, but awareness is fast growing to participate.

Let’s say you are building a decentralized software. You are now choosing a database.
How many people can run this database from a technical standpoint? Everyone who has an AWS account - maybe?
But realistically they cannot participate in the decentralized world because to run a database that is consistent with the instance you are running, they need your permission. In the sense that you need to add them to your master-slave config or you need to give them read access by adding their credentials on your DB.
So effectively only 1 participant can run this DB without your permission.
So D = 1/10M = 10^-7
Now no matter how beautifully decentralized the rest of your engineering stack is, as long as it uses a centralized Postgres DB, the decentralization score of your software can never be more than a meager 10^-7. That is because the degree of decentralization of a system is equal to the degree of decentralization of the subsystem with the lowest score.
Grants mechanisms are trying to decentralize themselves. But how decentralized are they?
Most of the grants dao are ones involving a discourse forum and some form of voting. So everyone really can see and vote on these proposals technically as long as they have internet connection. So that’s 2B people - assuming there is some form of proof of humanity.
But how much of the information & access to asking critical questions is available to anyone. This is usually a “grants committee” that is chosen by the protocol leadership. How many people realistically have access to the information that happen on calls between the grant awardee & the grants committee? Maybe 5 (the people on the committee)? Some processes also have a multisig managed by this team.
D = 5/2B = 2.5*10^-9
No matter how much of your information is published on your blog, no matter how many decentralized tools you use to manage your DAO, your process will always score a meager 2.5*10^-9 or less. Because a system is as decentralized as the most centralized subsystem.
Again, the total number of people who can vote on grants stays 2B.
Anyone can submit a proposal on Nouns as long as they own a Noun. And noun owners can vote on these proposals.
The cheapest Noun sold for 20ETH. How many people have earned more than $100,000? Probably about 100M. So technically they all will be able to participate should they care so much about voting on a Noun proposal - without needing permission from the creators of Noun or anyone else.
D = 100M/2B = 0.05
That’s a good score. Now as long as there is no other subsystem in nouns that is more centralized, it will score well.
Keep asking the question : what is the most centralized sub-system in this system?
Information asymmetry. Access to information to make decisions is not broadly available even though the processes might seem to be voting based.
URLs. Requiring people to use specific URLs to access your app, not allowing them to change it.
Unlike Uniswap, where you can access it through uniswap.org or do a swap from etherscan.org and get the exact same job done.
Not allowing people to run their own version of your API and point an app to that URL.
So, how decentralized, really, is your system?
We’ve been pondering upon how to make sure we build a truly decentralized product, community and company. It’s hard. But here I’ll share a mental model to evaluate the degree of decentralization of your system.
Your system is as decentralized as your least decentralized subsystem
But how to measure decentralization?
Balaji S had a great post (circa 2017) to measure Decentralization Retroactively, this post is about measuring Decentralization Proactively.
https://news.earn.com/quantifying-decentralization-e39db233c28e
https://news.earn.com/quantifying-decentralization-e39db233c28e
For each subsystem in your system, count the number of potential participants.
e.g.
How many bitcoin miners can exist in the world?
Maybe as many computers there are in the world? 1B
How many people can run a DB with high API availability?
Maybe as many accounts that exist on AWS? 10M
How many people can vote on a proposal?
Maybe number of people with an internet connection? 2B
Counting how many of those participants can realistically participate in the subsystem without any human’s permission?
Permission participation comes in various forms
Owning an NFT
Owning coins
Having high computation
Having an on-chain reputation
e.g. have voted previously on Snapshot
This could eventually merge into “Owning an NFT”, but right now these seem to be different.
e.g.
How many people can run a bitcoin node with > 4GH/s?
How many people can run your instance of DB with high availability? 1 (only you)
How many people can vote on proposal (and have access to full information)? Varies
D = P2/P1
Huh not too hard, that.
Another measure is
D’ = Rate of change of D over time
D’ for example has been rapidly changing for bitcoin miners. Number of ASICs has been increasing steadily in the world. When D’ is high, having a low D is kind of OK. Especially because in a lot of places in web3, technology is new but fast improving. Or, product is new, but awareness is fast growing to participate.

Let’s say you are building a decentralized software. You are now choosing a database.
How many people can run this database from a technical standpoint? Everyone who has an AWS account - maybe?
But realistically they cannot participate in the decentralized world because to run a database that is consistent with the instance you are running, they need your permission. In the sense that you need to add them to your master-slave config or you need to give them read access by adding their credentials on your DB.
So effectively only 1 participant can run this DB without your permission.
So D = 1/10M = 10^-7
Now no matter how beautifully decentralized the rest of your engineering stack is, as long as it uses a centralized Postgres DB, the decentralization score of your software can never be more than a meager 10^-7. That is because the degree of decentralization of a system is equal to the degree of decentralization of the subsystem with the lowest score.
Grants mechanisms are trying to decentralize themselves. But how decentralized are they?
Most of the grants dao are ones involving a discourse forum and some form of voting. So everyone really can see and vote on these proposals technically as long as they have internet connection. So that’s 2B people - assuming there is some form of proof of humanity.
But how much of the information & access to asking critical questions is available to anyone. This is usually a “grants committee” that is chosen by the protocol leadership. How many people realistically have access to the information that happen on calls between the grant awardee & the grants committee? Maybe 5 (the people on the committee)? Some processes also have a multisig managed by this team.
D = 5/2B = 2.5*10^-9
No matter how much of your information is published on your blog, no matter how many decentralized tools you use to manage your DAO, your process will always score a meager 2.5*10^-9 or less. Because a system is as decentralized as the most centralized subsystem.
Again, the total number of people who can vote on grants stays 2B.
Anyone can submit a proposal on Nouns as long as they own a Noun. And noun owners can vote on these proposals.
The cheapest Noun sold for 20ETH. How many people have earned more than $100,000? Probably about 100M. So technically they all will be able to participate should they care so much about voting on a Noun proposal - without needing permission from the creators of Noun or anyone else.
D = 100M/2B = 0.05
That’s a good score. Now as long as there is no other subsystem in nouns that is more centralized, it will score well.
Keep asking the question : what is the most centralized sub-system in this system?
Information asymmetry. Access to information to make decisions is not broadly available even though the processes might seem to be voting based.
URLs. Requiring people to use specific URLs to access your app, not allowing them to change it.
Unlike Uniswap, where you can access it through uniswap.org or do a swap from etherscan.org and get the exact same job done.
Not allowing people to run their own version of your API and point an app to that URL.
So, how decentralized, really, is your system?
<100 subscribers
<100 subscribers
No activity yet