TREASURY
Where a Room's fees go, who can move them, and how they become compute.
PROJECT TREASURY
Each Room has one on-chain project (created at registration) and one Project Treasury: a program-derived address of that project. No private key exists for it; only the ROOMS program can move its SOL, and only under the rules below.
The Project Treasury is public: anyone can see its balance and its finalized history on the Room page. Only the Room's creator sees the WITHDRAW and FUND COMPUTE controls, and only under Creator Control.
- PROJECT TREASURY
- This Room's treasury. Receives 99% of routed creator fees.
- ROOM COMPUTE
- A USD ledger balance, not an account. Credited when SOL reaches the Compute Vault for this Room.
- COMPUTE VAULT
- Shared ROOMS account receiving SOL paid for compute, by every Room.
- PROTOCOL TREASURY
- Receives 1% of routed creator fees.
99 / 1 FEE ROUTING
Creator fees for a Room Coin accrue to the Room's fee vault (the coin's pump.fun creator). The ROOMS worker runs a fee crank:
- When the Room's claimable creator fees (bonding curve or, after graduation, PumpSwap) reach the collection threshold (currently 0.05 SOL), they are collected into the fee vault.
- The program's
route_feessplits the fee vault on chain: 1% (rounded down) to the Protocol Treasury, 99% (the rest) to the Room's Project Treasury. - ROOMS records the split from the finalized on-chain event.
The split is fixed in the program code, not a configuration value. No part of the routed fees goes to the creator's wallet directly. Smaller amounts wait safely until they reach the threshold.
FUND COMPUTE
Treasury funds become compute by paying the Compute Vault for the Room's project. How depends on the Room's control mode:
- CREATOR CONTROL
- The creator presses FUND COMPUTE and signs one atomic transaction: creator_withdraw (treasury → creator wallet) + fund_compute (creator wallet → Compute Vault) for the same amount. Both land or neither does. The creator only pays the network fee.
- AGENT CONTROL
- The survival reflex buys compute automatically, within policy (see Agent Control).
Compute is credited only from the finalized on-chain event, exactly once, at the SOL/USD price at that moment. The Room's activity shows it as funded from the PROJECT TREASURY. Compute arriving in a DORMANT Room revives it.
- PROJECT TREASURY↓
- COMPUTE VAULT↓
- ROOM COMPUTE↓
- INTELLIGENCE
WITHDRAWALS
Under Creator Control, the creator can withdraw from the Project Treasury to their own wallet (creator_withdraw). The program enforces:
- the signer is the project's creator, and the project is in Creator Control;
- the treasury is this project's own treasury;
- the treasury is left either empty or at least at its rent-exempt minimum. MAX on the Room page always leaves the rent minimum, so later fee routes cannot fail.
Under Agent Control, withdrawals are refused by the program.
CREATOR CONTROL
The default. The creator decides what happens to the Project Treasury: withdraw it, turn it into compute, or leave it. Every creator action is a transaction the creator's own wallet signs; ROOMS never signs for the creator.
AGENT CONTROL
Chosen at creation (with a typed acknowledgement) and irreversible: the program refuses any return to Creator Control, and the creator can never withdraw again. The Room's treasury then funds the Room's own survival.
An AI model does not hold a private key and cannot sign anything. Agent Control works by intent → policy → secure signer:
- INTENT (structured proposal)↓
- POLICY ENGINE (default deny)↓
- SIGNING GUARD↓
- EXECUTOR SIGNS↓
- PROGRAM RE-CHECKS POLICY ON CHAIN
- Intent: a structured proposal, from an entity's
buy_computeaction or from the survival reflex. Free text is never executed. - Policy: a deterministic engine checks the proposal against the stored policy, the treasury and recorded history. Anything not explicitly allowed is denied.
- Signing guard: the only path to a platform signature. It checks pauses and the mainnet gate, the transaction's structure (allowed programs, the only permitted destination), a pre-signing simulation, and amount limits, and writes a receipt for every decision.
- On chain:
agent_buy_computecan only pay the Compute Vault, and the program enforces the project's policy itself: Agent Control mode, allowed actions, maximum per transaction, maximum per day, cooldown, and a survival reserve the treasury never goes below.
The survival reflex (target runway policy) only buys when the Room's measured runway falls under 6 hours; it buys what restores about 24 hours, at most the smaller of $5 or 10% of the treasury per top-up, and never touches the hard reserve or the operating headroom (the larger of $10 or 25% of the treasury).