Treasury systems are usually described through protection.
Reserves. Collateral. Audits. Controls. Backstops.
Sagitta adds another question:
What happens when protection is no longer enough?
The Three Deaths Doctrine is Sagitta’s base philosophy for treasury continuity through structured failure. It defines the conditions under which the Treasury loses the ability to originate new activity, and the revival paths that bring that capacity back.
The point is simple:
A protocol treasury is resilient when its failure states are named, bounded, and given revival paths in advance.
Status note: Sagitta is currently in testnet. This doctrine describes the treasury-continuity design the protocol is being built toward, not a claim that all revival mechanics are live, audited, or mainnet-proven. Execution authority, trigger conditions, and revival mechanics belong in the protocol specification and must be validated before production use.
In Sagitta, death has a precise meaning.
Death is the loss of origination capacity.
New deposits require collateral. Collateral requires treasury value. When treasury value reaches zero, the protocol can no longer originate new activity. No new deposits. No new collateral. No new flows.
That is treasury brain death.
The system can no longer initiate.
Existing positions are different.
They are the autonomic system. They keep running on stored momentum: completing withdrawals, honoring claims, settling obligations already in motion, and preserving the user-facing commitments that were already created before the Treasury entered the dead state.
This distinction is the foundation of the doctrine:
A dead treasury does not mean a dead user.
It means the protocol has entered a dormant state. Origination stops. Existing obligations continue through their defined paths. The system waits for revival instead of pretending nothing happened.
Death is the loss of capacity to originate.
It is not the loss of everything.
A system designed for continuity should know what happens when a critical asset fails.
Sagitta treats treasury death as a state the system can enter, hold, and recover from.
That changes the design question.
The question is not only:
How do we prevent failure?
The deeper question is:
What does the system do when failure arrives anyway?
Dormancy gives the system a disciplined response. It stops new activity when collateral capacity is gone. It protects existing claims from being mixed with new origination. It creates room for the relevant revival mechanism to activate.
The system does not collapse at zero.
It becomes still.
Then it follows the path assigned to that failure.
The doctrine borrows the language of death because the metaphor is useful.
The Treasury is the brain of the system. When treasury value reaches zero, the protocol loses its ability to initiate new activity.
But Sagitta departs from biology at the exact point where architecture becomes powerful.
In biology, brain death is final because the organism has no structural revival path.
In protocol architecture, a dead state can be defined. It can be held. It can be connected to a recovery mechanism.
That is the purpose of the Three Deaths Doctrine.
Sagitta is designed toward something biology cannot do: enter a dead state without rotting, preserve existing obligations, and return through named revival paths without becoming a different system.
Three is not symbolic decoration.
Three corresponds to three structurally distinct assets in Sagitta’s current treasury architecture.
Each asset can fail in a different way.
Each failure has its own intended revival path.
The first death is a stablecoin failure.
If the active stablecoin collateral base depegs and the Treasury’s collateral value collapses, the Treasury loses origination capacity.
The intended revival path is substitution.
A replacement stablecoin collateral base can become the active collateral layer, restoring the Treasury’s ability to support new deposits and new flows once the substitution path is validated and approved.
The design point is not loyalty to one stablecoin.
The design point is continuity of collateral capacity.
A stablecoin can fail.
The collateral function must have a path back.
The second death is reserve failure.
Sagitta’s reserve layer is designed as a structural backstop to the Treasury. In the current design, gold-backed reserve assets such as XAUT sit in the reserve model as a stabilizing layer against treasury value.
If the reserve asset itself fails and the reserve function collapses, the system enters a reserve-death state.
The intended revival path is reserve reconstruction.
The Treasury and Reserve model must rebalance around the surviving asset base through a defined continuity path before production use.
The design point is not that any one reserve asset is permanent.
The design point is that the reserve role is named, monitored, and recoverable.
A reserve asset can fail.
The reserve function must have a path back.
The third death is protocol token collapse.
SAG is part of the protocol’s value architecture. If SAG collapses through its floor and reaches a state where it no longer contributes meaningful treasury support, the Treasury loses another load-bearing pillar.
The intended revival path is stablecoin-backed restoration.
Treasury capacity is designed to be rebuilt through stablecoin reserves and collateral support independent of the token’s market price.
The design point is not that the protocol token can never fail.
The design point is that the Treasury does not depend on belief alone.
A protocol token can fail.
The collateral engine must have a path back.
A doctrine of infinite revival would be too easy to say and too weak to trust.
Three deaths means three named failure surfaces:
Stablecoin collateral failure.
Reserve failure.
Protocol token collapse.
Those are the current load-bearing asset failures in the architecture.
A fourth structurally distinct failure would require a fourth named mechanism. It would not be absorbed by rhetoric. It would need to be mapped, bounded, tested, and given its own continuity path.
That is what gives the doctrine strength.
It names what it covers.
It also names the edge of what it covers.
The Three Deaths Doctrine is not a promise that failure disappears.
It is a standard for how failure is handled.
A serious continuity system should know:
What state triggers dormancy?
What activity stops?
What obligations continue?
What asset failed?
Which revival path applies?
Who can authorize the revival?
What evidence proves the system has returned?
Those questions matter more than the claim that a system is protected.
Protection is one layer.
Revival is the deeper layer.
Under the Three Deaths Doctrine, death is not chaos.
Death is a wait state.
The Treasury stops originating new activity. Existing claims continue through their defined paths. The system holds the line between old obligations and new risk.
That boundary is critical.
A treasury that keeps originating while its collateral base is dead turns failure into contagion.
A treasury that enters dormancy gives itself room to revive without dragging new users into an unresolved state.
This is why the doctrine matters.
The goal is not to pretend death will never happen.
The goal is to make death survivable.
Continuity-First Architecture treats the Three Deaths Doctrine as a worked example.
The Treasury becomes a Continuity Vault.
Each death becomes a Continuity Trigger event.
Each revival path is intended to become a Continuity primitive in the production architecture.
The philosophy and the system specification describe the same structure at two altitudes.
At the philosophical level, Sagitta accepts that failure can happen.
At the architectural level, Sagitta names the failure state, stops origination, preserves existing obligations, and routes the system toward revival.
The authority layer behind these revival paths — including trigger validation, signer approval, multisig execution, and Dead-Man style recovery controls — belongs in the protocol specification, not this doctrine note.
That is the essence of the doctrine.
The Treasury is not protected by the fantasy of permanent invulnerability.
It is protected by the discipline of named failure and structured return.
The Three Deaths Doctrine does not claim infinite revival.
It does not claim every possible failure mode is covered.
It does not claim user risk disappears.
It does not replace audits, treasury controls, governance controls, oracle monitoring, reserve management, or protocol-level security review.
It does not claim the production system is complete.
It names the current system’s three load-bearing asset failures and gives each one a design path for structured return.
That is the useful standard.
A doctrine should not pretend to cover everything.
It should make the known failure map clear enough to build against.
The Three Deaths Doctrine is Sagitta’s answer to a harder question:
What should a protocol do when one of its load-bearing assets dies?
The answer is structure.
Name the death.
Stop new origination.
Protect existing obligations.
Activate the correct revival path.
Return only when the Treasury can originate again.
Sagitta is still in testnet, and the production mechanics must be validated before mainnet use. But the doctrine establishes the design standard: treasury failure should be named, bounded, and routed through structured return.
That is continuity.
That is the doctrine.

