The word “permissioned” gets used as an insult and as a compliance checkbox, and both uses hide what it means. This article defines the term precisely, shows the model already moving real money in Canada and Japan, answers the strongest objection against it, and then asks the question sitting underneath the whole debate: how far do we actually want to disintermediate the institutions that hold our money?
Context first. Every system in the following table runs, or will run, on rails governed by named institutions under domestic law.
| Measure | Figure | Source |
|---|---|---|
| Lynx, Canada’s high value payment system: average value settled per business day | $371.9 billion | Payments Canada, 2025 |
| Interac e-Transfer transactions, 2024 | 1.4 billion | Interac year in review |
| Interac Debit transactions, 2024 | 6.6 billion | Interac year in review |
| Japan Open Chain, a permissioned Layer 1 with named corporate validators | Live since 2023 | japanopenchain.org |
| EJPY, a trust based yen stablecoin for B2B settlement on Japan Open Chain and Ethereum | Announced May 2026 | Japan Blockchain Foundation |
Most confusion in this debate comes from collapsing three separate questions:
- Who can validate transactions and write the ledger?
- Who can transact and hold assets?
- Who can read the data?
Every blockchain answers each one separately.
A permissioned Layer 1 fixes one slider and leaves the other two as design choices. Public chains fix all three at the left.
A permissioned Layer 1 restricts the first axis: validation. It can remain fully open on the other two. A bank issued stablecoin, for example, can be open for anyone to hold and to spend while running on rails validated by named institutions. When someone says a permissioned chain “defeats the purpose of blockchain,” they are usually assuming all three sliders move together when they do not.
What it keeps, and what it changes
A permissioned Layer 1 keeps the properties that made blockchains interesting to finance in the first place: one shared ledger across many institutions, settlement where the asset and the payment move together or not at all, programmability, and a cryptographic audit trail that any participant can verify independently.
What it changes is who stands behind the ledger. Validators are named institutions operating under legal agreements, in a known jurisdiction, with regulators who can call them. That allows technical settlement to be backed by enforceable legal commitments. On proof-of-work chains such as Bitcoin, confidence in finality strengthens block by block. With the appropriate legal framework, a permissioned Layer 1 can define a point after which named operators are obligated to stand behind the transfer. Technical finality is necessary but not sufficient. Legal finality is the requirement.
This is also what lets the two worlds converge instead of compete. Because validation is domestic and mirrors the institutions that already validate our payments, existing infrastructure can meet the new rails halfway. Canada’s Real Time Rail is a natural candidate to plug into rails like these once both are live. Tracey Black, who led Payments Canada through the RTR’s development, has argued Canada should prepare for a future where the RTR, stablecoins and central bank digital currencies coexist and operate in a complementary manner.
This model already moves real money
The consortium of accountable institutions is not a compromise invented to please regulators. It is how payments already work. Interac is governed by a consortium of Canadian financial institutions and processed 1.4 billion e-Transfer transactions and 6.6 billion debit transactions in 2024, per its corporate year in review. Lynx, Canada’s high value payment system, settles an average of $371.9 billion every business day and is owned and operated by Payments Canada, a membership organization. Nobody calls these systems a betrayal of payments because they are the reference model.
The same governance shape now runs on blockchain rails. Japan Open Chain, which we covered in July, is an Ethereum compatible Layer 1 live since 2023, validated by named Japanese companies under Japanese law, where bank stablecoin pilots led to EJPY, a trust based yen stablecoin announced in May 2026 for B2B settlement on Japan Open Chain and Ethereum. The Bank for International Settlements is building its unified ledger vision, including Project Agorá with Canada at the table, on exactly this premise: regulated institutions as the operators, tokenized rails as the upgrade.
Why not just a database?
The strongest objection deserves to be answered head on. If you know all the validators, why use a blockchain at all? Why not use a database?
Because a database has an owner.
Someone hosts it, someone administers it, someone can edit it. Put five competing institutions on one database and you have appointed one of them, or a third party, as the keeper of everyone else’s record. Each institution then maintains its own copy anyway, and armies of people reconcile the copies against each other. Entire back office departments exist to do that reconciliation.
Competing institutions need one shared source of truth without appointing any single member, or a foreign intermediary, as its owner. Replicating a database does not, by itself, solve that ownership problem.
A permissioned Layer 1 addresses the ownership problem that replication alone does not solve: a single record no institution controls alone, with rules independently verified by participating institutions. It combines that shared control with atomic settlement, where delivery and payment happen in one indivisible step, and shared programmability, where the logic runs on the ledger itself instead of in every member’s separate systems.
A permissioned chain gives up permissionless innovation at the validator layer, and it is weaker against its own operators colluding than a public chain is. Both points are noted, and neither is disqualifying.
Here is what the objection misses. The system we have today carries real fraud, and much of it lives in the gaps between records. A regulator currently learns what happened after the fact: institutions generate reports, data gets reconciled, money services businesses self report to FINTRAC, and the picture is assembled from pieces. Every hand-off between records is an opening. On a shared ledger, the regulator can be brought in live, seeing the same truth every participant sees, while the fraud surface of assembling the story afterward disappears. If there is one place this technology should be pushed hard, it is there.
How far do you actually want to disintermediate?
Underneath the ideology sits a real economic argument. Blockchains create efficiency by disintermediating: every intermediary removed is a fee, a delay, and a reconciliation step removed. Public chains take that logic to its end point and remove the institutions entirely.
The honest question for any financial system is where to stop.
Full disintermediation has a cost the efficiency argument rarely prices in. Lose the keys to a bitcoin wallet and no one is bringing it back. There is no branch to call, no chargeback, no ombudsman, no court order that can reach the ledger. That is the design working exactly as intended, and it demands a mindset shift, full self custody of money, that most households and most corporate treasurers have not made and may never want to make.
The dial has more than two settings. The middle one removes the cost of reconciliation without removing the safety net.
The practical question we should be asking instead is where to set the dial: which intermediaries earn their keep, and which exist only because ledgers could not be trusted across institutional lines. Reconciliation departments exist for the second reason. Deposit insurance, dispute resolution, and account recovery exist for the first. A permissioned Layer 1 is a deliberate setting of that dial: remove the reconciliation, keep the recourse.
Match the tool to the requirement
None of this is a verdict on public blockchains. They are the right tool for what they were designed to do: bearer style assets, open experimentation, and systems that must keep running where no institution can be trusted or reached. Regulated settlement has different requirements, starting with legal finality and a party who answers for failure. Requirements first, then the architecture that meets them. Skip that step and you get the current debate.
The real difference between public and permissioned is who answers when the ledger fails.
Public blockchains proved that strangers can share a ledger without trusting each other. Permissioned Layer 1s apply that proof where the participants are not strangers, and where trust was never the missing ingredient. Accountability was.
