After Issuance: The Book of Record Problem

Blog
July 30, 2026

A tokenized security can move onchain but the question remains: who’s allowed to own it?

Our article “What Tokenized Assets Need to Become Market Infrastructure” made the case that tokenization is the starting point, and that the market gets built after issuance. Before an asset can move between wallets, settle, be serviced or become collateral, the market needs a definition of who owns it and under what conditions that ownership can change.

This source of truth: the Book of Record.

What the Book of Record Actually Decides

Acting as a securities register, it defines a hierarchical sequence of ownership, from user to issuer:

General Eligibility. Whether the potential holder is permitted to own this specific security/has a verified identity, their investor classification, jurisdiction, accreditation. Passing KYC once does not make an investor eligible for every asset, as each issuer sets its own conditions.

Permissions/Restrictions. Taken further, is this transfer allowed to this receiver? Lockups, holder caps, jurisdictional limits, transfer windows. These are the conditions the register enforces before a transfer clears, not after.

Issuer controls. Freeze, forced transfer, recovery of a lost wallet, mint and burn. The controls a regulated issuer and its appointed agents retain across the life of the asset.

Servicing state. Which corporate actions such as distributions, redemptions, splits, and to whom.

None of these are or can be answered by holding a token. They are answered by the record behind it. A tokenized security needs more than a token contract. It needs a record behind it that the market can use to answer and validate each, consistently.

What Breaks When the Record Is Fragmented

Today, the token and the record generally live in different systems, and once the asset gets onchain, that record gets copied across venues.

For example, a fund is distributed through more than one platform. Bonds are held by investors across different custodians. The asset connects to secondary venues, reporting systems, and collateral applications. Each environment needs the same sequence of understanding of who can own what. If each platform and venue derives the rules from its own copy, an error can get amplified.

The consequences compound with each derivation:

A transfer that looks valid in one venue's copy violates the master register, because eligibility changed and the copy was stale.

A corporate action gets applied in one environment and not another, leaving one group of holders of the same security in inconsistent states.

An application or platform behaves too conservatively, leading to thin liquidity

Any or all of these is the cost of getting assets onchain without a unified record layer.

As private-market transactions already take days to weeks to process against offchain registers, tokenization that leaves the register offchain doesn't remove that cost. It ultimately adds a potentially out of date reconciliation layer on top of it.

"A fund's ownership legally exists in a single register, and everything an issuer does ie paying distributions, processing redemptions, meeting regulatory obligations depends on that register being accurate. The moment an asset moves somewhere the register can't see, that link breaks.That's why most tokenized funds still prevent assets from leaving the platform where they were issued: it's the simplest way to ensure the issuer can continue servicing them. When every venue reads from the same shared register, distributions stop being a reconciliation exercise and become a native function.At that point, issuers no longer need to confine assets to a single platform, and true distribution becomes possible."  - Daniel Coheur CEO & Co-founder at T-REX

Why the Problem Grows After Issuance

For onchain assets, every new venue, custodian, application and reporting system that touches the newly issued asset needs the same answers as alluded to above: who owns it, whether they are eligible, is the transfer allowed, and which issuer actions have been applied (in real time). If each answers from its own copy, tokenization has only produced a new layer of fragmentation rather than removing an old one.

This is why the bottleneck has moved.

With tens of billions in tokenized funds and Treasuries onchain, and more than $32 billion in cumulative value across ERC-3643 implementations, we’re now seeing that post-issuance utility has not kept pace, and as it grows, may face compounding fragmentation as assets spread across markets.

Because of this the proposition of a Book of Record becomes market infrastructure at the point where all approved environments reference the same, unified record, instead of maintaining their own.

Until then, every step adds a reconciliation problem.

What a Shared Record Requires

Issuers, custodians and venues will, of course, use different environments and their own operational nuances for different reasons, whether it be distribution, settlement, overarching degrees of custody, reporting nuances, or liquidity constraints. However along the way, those separate environments must still be able to resolve against one authoritative record.

The record needs to also be authoritative in the legal sense, too, not only in the technical one. An onchain register becomes authoritative when a licensed party operates it under the same obligations that govern any securities register.

Thus, this is the problem T-REX is being built to solve, stated briefly:

ERC-3643 provides the open token standard, carrying identity, eligibility and issuer controls at the token level.

ONCHAINID connects verified investors and reusable credentials to wallets, so eligibility travels with the holder.

T-REX Ledger designed to be the shared record layer, the reference approved networks resolve against, such that each environment retains its own settlement while working from the same ownership and compliance state.

The distinction matters: distributed settlement is fine, and probably inevitable. What cannot be distributed is the truth of who owns what and who is allowed to trade it.

Portable investor identity also affects whether applications and institutional assets can interact across different environments.

Heslin Kim, CBO & Co-founder at Zenith, shared his perspective on why portable investor identity matters for multi-venue capital markets:

"The biggest long-term opportunity unlocked by verifiable but private identification is the ability to open global distribution to entirely new customer demographics in ways that were previously impossible, while still embedding strong consumer protections.Without a reusable, portable investor identity (exactly what ONCHAINID + ERC-3643 gives us), every new venue, chain, or application forces repeated KYC, re-whitelisting, and eligibility renegotiation.That friction doesn’t just slow institutions; it locks out vast pools of potential participants who could otherwise access tokenized products safely and compliantly.

The costs compound:

- Issuers and transfer agents remain trapped in repetitive onboarding loops instead of expanding distribution into new investor segments and geographies.

- Liquidity stays fragmented because the same (or newly eligible) investor cannot move seamlessly across tokenized offerings and DeFi venues.

- For Zenith specifically, it constrains the flywheel we’re building: bringing battle-tested EVM/SVM applications natively onto Canton so they can compose atomically with institutional assets. Every extra identity hurdle reduces the chance that both traditional banks and previously underserved or retail-adjacent demographics can participate under consistent protections.

Over the next decade, this missing primitive is the difference between closed pilot programs and a cohesive, liquid, multi-venue capital market that can reach global audiences while preserving the consumer safeguards institutions and regulators require."

What’s Possible

When approved environments resolve to one authoritative record, the operational picture inverts.

A transfer can be checked for eligibility and permission before it happens, not corrected after. A transfer agent works from one ownership record instead of reconciling several. A corporate action is applied once and reflected everywhere that references the record. A holder's verified identity travels with them rather than being re-established at each venue. An application references the same eligibility state instead of maintaining a disconnected, conservative copy.

The book of record stops being a cost the market absorbs at every step and becomes the layer the market coordinates around.

That is the shift underneath "after issuance."

Not a better representation of an asset that still depends on another system to confirm what it is, but a record the market can build on directly: once the record is authoritative, all things follow.