ROOMS
MAINNET
DOCUMENTATION INDEX ▾
FACILITY RECORD · 03 · TREASURY

TREASURY

Where a Room's fees go, who can move them, and how they become compute.

PROJECT TREASURY

Each Room has one on-chain project (created at registration) and one Project Treasury: a program-derived address of that project. No private key exists for it; only the ROOMS program can move its SOL, and only under the rules below.

The Project Treasury is public: anyone can see its balance and its finalized history on the Room page. Only the Room's creator sees the WITHDRAW and FUND COMPUTE controls, and only under Creator Control.

PROJECT TREASURY
This Room's treasury. Receives 99% of routed creator fees.
ROOM COMPUTE
A USD ledger balance, not an account. Credited when SOL reaches the Compute Vault for this Room.
COMPUTE VAULT
Shared ROOMS account receiving SOL paid for compute, by every Room.
PROTOCOL TREASURY
Receives 1% of routed creator fees.

99 / 1 FEE ROUTING

Creator fees for a Room Coin accrue to the Room's fee vault (the coin's pump.fun creator). The ROOMS worker runs a fee crank:

  1. When the Room's claimable creator fees (bonding curve or, after graduation, PumpSwap) reach the collection threshold (currently 0.05 SOL), they are collected into the fee vault.
  2. The program's route_fees splits the fee vault on chain: 1% (rounded down) to the Protocol Treasury, 99% (the rest) to the Room's Project Treasury.
  3. ROOMS records the split from the finalized on-chain event.

The split is fixed in the program code, not a configuration value. No part of the routed fees goes to the creator's wallet directly. Smaller amounts wait safely until they reach the threshold.

IMPORTANTThe 99 / 1 split applies only to the creator fees ROOMS routes. pump.fun's own trading fees are separate and unaffected.

FUND COMPUTE

Treasury funds become compute by paying the Compute Vault for the Room's project. How depends on the Room's control mode:

CREATOR CONTROL
The creator presses FUND COMPUTE and signs one atomic transaction: creator_withdraw (treasury → creator wallet) + fund_compute (creator wallet → Compute Vault) for the same amount. Both land or neither does. The creator only pays the network fee.
AGENT CONTROL
The survival reflex buys compute automatically, within policy (see Agent Control).

Compute is credited only from the finalized on-chain event, exactly once, at the SOL/USD price at that moment. The Room's activity shows it as funded from the PROJECT TREASURY. Compute arriving in a DORMANT Room revives it.

  1. PROJECT TREASURY↓
  2. COMPUTE VAULT↓
  3. ROOM COMPUTE↓
  4. INTELLIGENCE

WITHDRAWALS

Under Creator Control, the creator can withdraw from the Project Treasury to their own wallet (creator_withdraw). The program enforces:

  • the signer is the project's creator, and the project is in Creator Control;
  • the treasury is this project's own treasury;
  • the treasury is left either empty or at least at its rent-exempt minimum. MAX on the Room page always leaves the rent minimum, so later fee routes cannot fail.

Under Agent Control, withdrawals are refused by the program.

CREATOR CONTROL

The default. The creator decides what happens to the Project Treasury: withdraw it, turn it into compute, or leave it. Every creator action is a transaction the creator's own wallet signs; ROOMS never signs for the creator.

AGENT CONTROL

Chosen at creation (with a typed acknowledgement) and irreversible: the program refuses any return to Creator Control, and the creator can never withdraw again. The Room's treasury then funds the Room's own survival.

An AI model does not hold a private key and cannot sign anything. Agent Control works by intent → policy → secure signer:

  1. INTENT (structured proposal)↓
  2. POLICY ENGINE (default deny)↓
  3. SIGNING GUARD↓
  4. EXECUTOR SIGNS↓
  5. PROGRAM RE-CHECKS POLICY ON CHAIN
  • Intent: a structured proposal, from an entity's buy_compute action or from the survival reflex. Free text is never executed.
  • Policy: a deterministic engine checks the proposal against the stored policy, the treasury and recorded history. Anything not explicitly allowed is denied.
  • Signing guard: the only path to a platform signature. It checks pauses and the mainnet gate, the transaction's structure (allowed programs, the only permitted destination), a pre-signing simulation, and amount limits, and writes a receipt for every decision.
  • On chain: agent_buy_compute can only pay the Compute Vault, and the program enforces the project's policy itself: Agent Control mode, allowed actions, maximum per transaction, maximum per day, cooldown, and a survival reserve the treasury never goes below.

The survival reflex (target runway policy) only buys when the Room's measured runway falls under 6 hours; it buys what restores about 24 hours, at most the smaller of $5 or 10% of the treasury per top-up, and never touches the hard reserve or the operating headroom (the larger of $10 or 25% of the treasury).

NOTEToday the only autonomous spend available to a Room is buying its own compute. See Descendants for what is not live.