Home / Blogs /

Permissioned Access, Public Execution: A New Architecture for Tokenized Securities

Permissioned Access, Public Execution: A New Architecture for Tokenized Securities

by Oscar Jofre | Sep 18, 2026 | AskOscar, Broker-dealers, Capital Markets, Capital Raising, Private capital markets, Security Token

For years, discussions about blockchain in capital markets have tended to begin with a false choice: permissioned or permissionless.

Permissionless blockchains offer interoperability, broad ecosystem access, transparency, and the ability for assets and applications to move across open networks. Permissioned systems offer something equally fundamental to regulated financial markets: the ability to know who is participating, determine what they are authorized to do, enforce the rights attached to an asset, and maintain accountable records of what occurred.

Securities markets need both.

The U.S. Securities and Exchange Commission's September 17, 2026 Innovation Exemption makes that distinction especially important. The temporary framework permits certain Tokenized Securities Venues, or TSVs, to experiment with tokenized NMS stocks through permissioned Automated Market Maker (AMM) liquidity pools. At the same time, the relevant distributed-ledger applications must be public and auditable and deployed on public, permissionless distributed ledgers. The SEC describes the arrangement as allowing tokenized securities to trade in a permissioned environment while the Commission evaluates a longer-term regulatory framework.

At first glance, those ideas can appear contradictory.

They are not.

They point toward an architecture that may become increasingly important as securities move onchain: Public chain transaction infrastructure combined with permissioned regulatory control.

A Blockchain Does Not Know Whether a Securities Transaction Should Happen

A blockchain is very good at answering certain questions.

Did a transaction occur?
Which wallet signed it?
What state did the smart contract reach?
Has consensus been achieved?

Those are valuable capabilities. But a regulated securities transaction raises a different class of questions.

Who controls the wallet?

Is that person or entity permitted to hold the security?

Has identity been verified?

Are KYC, AML, sanctions, jurisdictional, investor-eligibility, or other requirements satisfied?

Does the seller actually have an unencumbered position available for transfer?

Is the security subject to an issuer restriction, holding period, freeze, court order, corporate action, or transfer-agent requirement?

If the security is represented simultaneously on multiple networks, has some portion of that position already been committed somewhere else?

And, ultimately, who is recognized as the owner of the security after the transaction?

Putting a security on a blockchain does not make those questions disappear. In many cases, tokenization makes answering them consistently across systems even more important.

That is why permissionless chain transactions do not require permissionless securities.

The Security and Its Execution Environment Are Different Things

The SEC's January 2026 staff statement on tokenized securities made another important point: the ownership record for a tokenized security may be maintained in whole or in part through one or more crypto networks, and different architectures can connect blockchain records with an issuer's or transfer agent's master securityholder file.

This suggests a useful way of thinking about tokenization. A security should not be defined by the blockchain on which one representation happens to exist. A share of a company remains a share of that company whether a transaction is initiated through a conventional broker-dealer system, an alternative trading system, an API, a permissioned blockchain, Ethereum, Solana, or another future network.

The execution environment can change. The legal rights, ownership constraints, compliance state, and regulatory history of the security must remain coherent.

This distinction is at the heart of KoreInside's architecture.

The Twin Model

KoreInside's Twin technology starts with a KoreToken, a canonical digital representation of the security within KoreChain, KoreInside's permissioned blockchain infrastructure.

The KoreToken is more than a token that can be transferred from one address to another. It functions as the security's canonical regulatory twin.

It can be associated with the security's identity, ownership state, permitted holders, transfer restrictions, issuer conditions, corporate actions, freezes, regulatory requirements, transfer-agent controls, and other attributes that determine whether a transaction may occur.

A corresponding representation of that same security can then operate within an external blockchain ecosystem such as Ethereum, Solana, Base, or another network.

That external representation is the execution twin. The two are joined.

The public-chain token does not become an independent security with an independent compliance universe simply because it exists on another blockchain. Its ability to transact remains connected to the canonical regulatory state represented through KoreToken and KoreInside's compliance infrastructure.

This allows the security to benefit from the reach and composability of public blockchain ecosystems without duplicating or fragmenting its regulatory identity.

Put simply: The security can travel. Its compliance does not.

Real-Time Authorization Matters

That connection cannot merely be conceptual. For a regulated security, authorization needs to be contemporaneous with the proposed transaction.

Consider an investor who wants to transfer 100 tokenized shares through a public-chain venue. Before the transaction is submitted for execution, the transaction intent can be sent to KoreInside and checked synchronously against the current KoreToken state.

KoreInside can determine in real time whether the investor and wallet remain authorized, whether the shares are available, whether the recipient is eligible, whether applicable restrictions are satisfied, and whether another transaction has already committed or reserved the same position.

If the transaction is permitted, the relevant quantity can be reserved against the canonical state and a single-use cryptographic authorization returned for the public-chain transaction.

The public smart contract does not need to reproduce the entire securities compliance framework. It needs to be able to verify that KoreInside has authorized this transaction, involving this security, these participants, this quantity, on this network and venue.

Once the public blockchain validates and records the transaction, the resulting transaction evidence flows back through the Twin architecture. The reserved state can then be committed. If the transaction fails or expires, the reservation can be released.

This is an important distinction from simply issuing a reusable credential or periodically updating a whitelist. Securities state can change continuously. Authorization should reflect the state that exists when the transaction is actually proposed.

One Security Across Many Networks

This architecture also addresses one of the less discussed problems in tokenization: fragmentation. Imagine that the same security can operate on Ethereum, Solana, Base, a permissioned institutional network, an ATS connected through an API, and an issuer's own platform.

An Ethereum-based venue may know what happened to the security on Ethereum, but not what happened to that same security on Solana, an ATS, or another connected platform. 

Without a common securities state, the market can begin to create disconnected representations of what is legally one asset.

KoreToken provides a common reference point.

If an investor owns 500 shares and 100 are committed to a transaction on Ethereum while another 200 are committed elsewhere, the canonical state can know that only 200 remain available. A transaction request arriving through an ATS or another blockchain can be evaluated against the same position.

Ethereum does not need to understand Solana.

Solana does not need to understand the ATS.

The ATS does not need to understand either blockchain.

They need to understand a common authorization protocol.

That is a fundamentally different approach from trying to make every network directly synchronize with every other network.

Identity Becomes Infrastructure

The same reasoning applies to identity.

A blockchain address is not a person, institution, broker-dealer, fund, transfer agent, custodian, or regulated entity. It is an address.

In regulated capital markets, the relationship between the wallet and the participant matters.

KoreID is designed to provide that persistent identity and permissioning layer: connecting verified individuals and entities with wallets, regulatory attributes, eligibility, and ongoing compliance status without requiring personally identifiable information to be exposed publicly on the blockchain.

A participant may eventually have multiple wallets across multiple networks and interact with multiple venues. The identity should not have to be rebuilt independently inside every ecosystem.

The market needs verified identity and permissions to travel across platforms, without requiring the underlying personal information to travel with them. 

That distinction becomes increasingly important if tokenized securities begin moving across otherwise unrelated financial and blockchain systems.

From "Which Chain Wins?" to "How Do the Chains Work Together?"

Much of the blockchain industry continues to be organized around competition among networks. Each chain seeks to attract developers, applications, issuers, users, assets, and liquidity into its own ecosystem. That competition has driven considerable innovation, but it has also produced increasingly fragmented islands of technology and liquidity. For capital markets, however, the objective should not be to force every security and every participant onto the same island. It should be to make those ecosystems interoperable while preserving a common regulatory state for the security. 

This changes the question from “Which chain wins?” to “How can a security operate safely across whichever chains succeed?” 

Different networks may ultimately be useful for different purposes. Public chains may offer large ecosystems and liquidity. Permissioned networks may provide stronger governance and privacy characteristics. Institutional networks may optimize for financial-market participants. Conventional systems will continue to exist because much of the world's financial infrastructure will not migrate simultaneously.

A durable capital-markets architecture therefore should not require one technology to win.

It should allow the security's regulatory identity and rights to remain persistent while execution occurs through whichever environments are appropriate.

That is the role KoreInside sees for KoreChain, KoreToken, KoreID, and its Unified Cross-Chain Interoperability, and the broader KoreInside infrastructure.

Not another isolated blockchain, but a regulatory control plane across blockchains and conventional capital-market systems.

What the SEC's Experiment May Teach the Market

The Innovation Exemption is deliberately temporary. The SEC describes it as a bridge toward durable rulemaking and an opportunity to learn from actual market experimentation rather than prematurely establish a permanent technological model.

That makes the next several years important.

The industry's challenge is no longer simply proving that securities can be represented by tokens. That has already been demonstrated.

The harder questions are now becoming operational:

  • How do regulated assets move between ecosystems without losing their regulatory context?
  • How do markets permit self-directed, potentially self-custodied activity while maintaining identity and eligibility controls?
  • How do issuers and transfer agents preserve authoritative ownership records?
  • How do corporate actions follow a security across networks?
  • How do we prevent cross-chain duplication or inconsistent state?
  • How can regulators and regulated intermediaries understand what occurred without forcing every market participant onto the same technology stack?

Those are infrastructure questions.

And solving them is what will determine whether tokenization becomes merely another format for securities or a genuine modernization of capital markets.

At KoreInside, our view is that the answer will not be permissioned or permissionless.

It will be permissioned where trust, identity, rights, and regulatory authorization