More
    Real-World Asset (RWA) TokenizationPermissioned vs Public Blockchain: The Institutional Verdict

    Permissioned vs Public Blockchain: The Institutional Verdict

    Categories

    Quick verdict: for regulated institutions moving real money at scale, a permissioned network wins on governance certainty, privacy of position data, and capital treatment under current bank rules — but a public chain wins on secondary market reach, composability with outside liquidity, and long-run vendor independence. Most large asset managers and banks end up running both, using a permissioned ledger for the parts of a trade that require known counterparties and a public chain for the parts that need broad distribution. The choice is rarely permissioned or public; it is which layer of a given workflow needs which property.

    That answer sounds like a dodge until you look at what institutions have actually built. JPMorgan settles intraday repo on a private, permissioned ledger it controls end to end. BlackRock’s tokenized Treasury fund lives on public Ethereum, with mirrored shares on five additional public networks. Franklin Templeton runs its money market fund shares on Stellar and Polygon, both public. Goldman Sachs, Deutsche Börse, and a growing bench of banks settle through Canton, a network that is technically public in its topology but permissioned at the level of who can read any given transaction. None of these firms picked one architecture and walked away from the other. They picked the architecture that matched the specific job — custody, settlement, distribution, or reporting — and are increasingly running more than one at once.

    Permissioned and Public Chains, Side by Side

    A permissioned blockchain restricts who can operate a validating node, who can submit transactions, and often who can even read the ledger’s contents. Consortium members are vetted, identified, and typically bound by a membership agreement before they get write access. Hyperledger Fabric, Corda, Quorum-derived networks, and JPMorgan’s Kinexys platform all fall into this category. Governance sits with a known set of institutions, and changes to the rules of the network happen through a negotiated process among members rather than through open-source consensus among anonymous participants.

    A public blockchain — Ethereum, Solana, Avalanche’s C-Chain, the various layer-2 rollups sitting on top of Ethereum — lets anyone run a validator or send a transaction, subject only to the protocol’s own rules and whatever gas fee the network charges. Nobody needs permission from an operator to join. Security comes from economic incentives (staking, proof-of-work, or a hybrid) spread across a large, often global and pseudonymous, set of participants rather than from a membership list. Canton Network sits in an unusual middle position: its base layer is open to anyone who wants to run a “synchronizer,” but transaction data is only visible to the parties actually involved, which gives it some of the confidentiality institutions want from a permissioned system while keeping the topology public.

    The practical distinction that matters to a treasury desk or a fund administrator is not philosophical. It is operational: who can see your position, who can freeze or reverse a transaction, how fast a trade becomes irreversible, and what a banking regulator will say about the capital you have to hold against an asset that lives on one network versus the other.

    Governance and Validator Control: Who Actually Runs the Ledger

    On a permissioned network, governance is a contract, not a protest. Kinexys Digital Payments, the platform formerly known as Onyx, is operated by JPMorgan itself — there is exactly one validating entity that matters, and disputes get resolved the way disputes at any bank get resolved: through the institution’s own legal and operational chain of command. Canton’s validator set is larger and more diverse, drawn from named institutions including Goldman Sachs, Deutsche Börse, Cboe Global Markets, BNP Paribas, Broadridge, and several trading firms, but it is still a closed, identified list that can add or remove members by agreement. If a validator misbehaves, there is a real-world entity to sue, sanction, or expel.

    Ethereum’s validator set looks nothing like that. More than a million active validators secure the network, the large majority of them anonymous or pseudonymous, running client software with no membership agreement and no central operator to call when something goes wrong. That scale is exactly what gives public chains their censorship resistance and their appeal to anyone who does not want a single counterparty able to unilaterally freeze a position — but it also means there is no help desk. If a smart contract has a bug, the network will still faithfully execute it.

    Validating Participants, By Network (log scale)

    Illustrative counts of independent entities or nodes that can validate transactions

    Kinexys (JPMorgan, single operator)

    1 entity

    Canton Network validators

    ~30 named

    Ethereum active validators

    1M+

    Bar widths are log-scaled to show order-of-magnitude difference, not a linear count.

    For an institution, more validators is not automatically better. A bank running a repo desk generally wants a small, identified, contractually accountable validator set so it knows exactly whose servers are holding the truth about who owns what. A capital markets platform trying to reach the widest possible pool of buyers wants the opposite: a large, neutral, unkillable network that no single participant, including the platform operator, can shut down.

    Settlement Finality, Throughput, and Operational Risk

    Finality is the point at which a transaction cannot be reversed short of an extraordinary, coordinated intervention. Permissioned networks built for institutional settlement generally target near-instant, deterministic finality: a small set of known validators sign off on a block, and once that signature threshold is met, the transaction is done. Kinexys and Canton both operate on this model, with settlement typically confirmed in a couple of seconds.

    Ethereum’s finality is probabilistic in a different sense. A transaction is included in a block within roughly twelve seconds, but full economic finality — the point at which reversing it would require an attacker to destroy a large fraction of staked ETH — takes about two epochs, or somewhere close to fifteen minutes, following the Dencun-era consensus rules. Layer-2 rollups add another wrinkle: an optimistic rollup transaction feels instant to the end user but is not truly final on the base layer until its seven-day fraud-proof challenge window closes, unless the user trusts a sequencer’s soft confirmation.

    Time to Settlement Finality (log scale)

    Dashed line marks the traditional T+2 equity settlement benchmark for reference

    Permissioned chain (Canton, Kinexys)

    ~2 sec

    Ethereum L1 economic finality

    ~15 min

    Optimistic rollup withdrawal window

    ~7 days

    Traditional T+2 equity settlement (~172,800 seconds) is shown for scale, not as an equivalent workflow.

    Throughput follows a similar pattern. A permissioned network sized for a specific consortium’s repo book does not need to process the entire planet’s transaction volume, so it can be tuned for the workload it actually serves, often thousands of transactions per second within the consortium. Public layer-1 chains have to share capacity across every application running on them, which is exactly why so much institutional public-chain activity has migrated to layer-2 networks that inherit Ethereum’s security while executing transactions off the congested base layer.

    Privacy, Data Disclosure, and Regulatory Capital Treatment

    This is the criterion that most often decides the argument in a bank’s risk committee, because it is the one with an actual rulebook attached. Under the Basel Committee’s cryptoasset prudential standard, finalized in December 2022 and phased in from 2025, tokenized traditional assets that meet strict classification conditions can qualify for Group 1a treatment — meaning a bank holds capital against them roughly as it would against the underlying, untokenized asset. The standard also directs supervisors to assess “infrastructure risk,” and networks that are open to permissionless participation, without documented risk mitigants around validator behavior and settlement finality, are the ones examiners scrutinize hardest before granting that preferential treatment. A permissioned ledger with a known validator set and contractual recourse is simply an easier conversation to have with a prudential regulator than an open network run by anonymous stakers, even when the two networks behave identically from a technical standpoint.

    Europe took a parallel but distinct approach. The DLT Pilot Regime, Regulation (EU) 2022/858, has applied since March 2023 and lets market operators run trading and settlement infrastructure on distributed ledgers — permissioned or public — inside defined size limits: roughly €500 million in admitted share value and up to €1 billion for bonds and other debt instruments per venue, with an overall market value cap near €6 billion that triggers a mandatory transition plan once a platform edges toward €9 billion. The regime does not mandate permissioned architecture, but nearly every live DLT Pilot venue to date has chosen one, precisely because it is simpler to demonstrate the access controls and record-keeping supervisors expect.

    Public chains are not shut out of privacy entirely. Canton achieves sub-transaction privacy on a technically public network by only revealing transaction details to parties who are actually involved, a model that regulators evaluating the DLT Pilot and similar sandboxes have found more workable than a fully transparent ledger like base Ethereum, where every wallet balance and trade is visible to anyone who wants to look. Still, for a market maker or a pension fund, broadcasting position sizes to the entire internet in real time is rarely acceptable, and this remains the single biggest reason large, sensitive trades gravitate toward permissioned or privacy-layered infrastructure rather than a plain public ledger.

    Interoperability, Secondary Liquidity, and Exit Options

    Here the advantage flips. A tokenized fund living only on a permissioned, single-bank ledger is only as liquid as the counterparties that bank chooses to onboard. A tokenized fund living on Ethereum can, at least in principle, be held, transferred, or pledged as collateral by anyone with a compatible wallet and the right eligibility credentials, and it can plug into a much larger existing base of custodians, exchanges, and DeFi lending markets without a separate integration project for each one. BlackRock’s decision to mirror its BUIDL fund shares across five additional public networks beyond Ethereum — Aptos, Arbitrum, Avalanche, Optimism, and Polygon — was explicitly about reaching investors and platforms that were already active on those chains rather than asking them to bridge into a single closed venue.

    Public-chain interoperability also reduces vendor lock-in. A fund issued on a bank-operated permissioned ledger is dependent on that bank’s continued participation, pricing, and roadmap. A fund issued through an open standard on a public chain can, in theory, be supported by any custodian or transfer agent that adopts the same token standard, which is a meaningfully different risk profile for an asset manager thinking in decades rather than quarters. Central bank digital currency pilots illustrate the opposite end of the spectrum well: wholesale CBDC platforms built as permissioned ledgers, such as Project mBridge, deliberately trade that openness away in exchange for tighter control over settlement finality and compliance checks among a fixed group of central and commercial banks — a reasonable trade for cross-border wholesale payments, but not a model built for retail-adjacent secondary trading.

    The cost of that openness on public chains is exposure to the network’s own volatility — gas fee spikes during congestion, smart contract risk in the token standard itself, and the reputational tail risk of sharing infrastructure with unrelated, sometimes disreputable, activity happening on the same base layer. Institutions weighing interoperability against control are really weighing a wider pool of future counterparties against a narrower, more predictable set of known ones today.

    Permissioned vs Public: The Head-to-Head Comparison

    CriterionPermissioned ChainPublic Chain
    Validator controlKnown, vetted, contractually accountable membersOpen, large, often anonymous global set
    Settlement finalitySeconds, deterministicMinutes (L1) to days (rollup withdrawal)
    Position privacyRestricted to counterparties by defaultFully transparent unless a privacy layer is added
    Bank capital treatmentEasier path to preferential Group 1a treatmentFaces added infrastructure-risk scrutiny
    Secondary liquidity reachLimited to onboarded consortium membersOpen to any compatible wallet or venue
    Vendor lock-in riskHigher — tied to the operating institutionLower — open standard, multiple custodians
    Representative examplesKinexys, Canton, Project mBridgeBlackRock BUIDL, Franklin Templeton BENJI

    Worked Example: Settling the Same $50 Million Position Two Ways

    Consider a fixed-income desk that needs to move $50 million of short-duration exposure overnight to manage a liquidity gap. Two paths are available.

    Path one runs through a permissioned repo platform modeled on JPMorgan’s Kinexys design. The desk’s collateral and cash legs are represented as tokens on the bank’s private ledger. Because both counterparties are already onboarded members with signed legal agreements in place, the trade settles atomically in a couple of seconds, the position never appears on any public ledger, and the bank’s own capital desk already has a signed-off internal model for how much capital to hold against it. The tradeoff is that the desk can only do this trade with other institutions already inside that same permissioned network — if the natural counterparty for tonight’s liquidity need banks somewhere else, this rail is not available.

    Path two involves a tokenized Treasury fund share, structured the way BlackRock’s BUIDL or Franklin Templeton’s BENJI shares are structured, held on a public chain. The desk can pledge or transfer that token to essentially any custodian or counterparty that recognizes the token standard, without a bilateral integration project, and the transaction is visible on a public block explorer for anyone who wants to verify it independently. Settlement on the base layer takes roughly fifteen minutes to reach full economic finality, or is available near-instantly if both sides accept a soft confirmation with counterparty risk in the interim. The desk’s compliance team, meanwhile, has to document how it satisfies KYC and eligibility screening for a token that a counterparty could, in theory, later transfer onward to a wallet nobody has vetted — a control gap that permissioned rails close by design.

    Neither path is objectively better. A desk doing frequent, large, relationship-based repo trades with a stable set of counterparties gets more value from the permissioned rail’s speed and privacy. A desk that needs to reach the widest possible buyer pool for a security, or that wants a fallback custodian relationship independent of any single bank, gets more value from the public rail’s openness — accepting slower base-layer finality and public visibility as the price of that reach.

    When Each Option Wins

    Permissioned infrastructure tends to win when the trade involves a small, stable set of known institutional counterparties; when position confidentiality is a hard requirement rather than a preference; when a bank’s own capital and risk models already exist for that architecture; and when the use case is intraday liquidity, wholesale settlement, or a regulated market venue operating inside a defined sandbox like the EU’s DLT Pilot Regime.

    Public infrastructure tends to win when the goal is distribution to the broadest realistic pool of eligible investors; when the asset needs to interoperate with custodians, exchanges, or lending markets the issuer does not control; when long-term independence from any single technology vendor matters more than short-term settlement speed; and when transparent, independently verifiable record-keeping is itself a selling point, as it increasingly is for tokenized fund shares marketed partly on the strength of on-chain auditability.

    Common Mistakes Institutions Make Choosing Between Them

    • Treating “permissioned” as a synonym for “compliant.” A permissioned network still needs its own KYC, sanctions screening, and audit trail built into the application layer — access control alone does not satisfy a regulator.
    • Assuming a public chain is automatically disqualified from bank balance sheets. Group 1a treatment under the Basel standard is available to public-chain tokenized assets that meet the classification conditions; the bar is documentation and risk mitigation, not the label “public” itself.
    • Picking the network before defining the legal wrapper. The token is a representation of a legal claim, not a substitute for one. Firms that select infrastructure first and bolt on the legal structure afterward routinely have to re-platform.
    • Underestimating key management differences. Permissioned networks often centralize recovery options through the operator; public-chain self-custody puts key loss risk squarely on the holder, which changes the operational playbook for a treasury team used to bank-mediated recovery.
    • Ignoring the interoperability question until it becomes urgent. An asset issued on one permissioned ledger with no bridge strategy can become difficult to move if a new counterparty or custodian only supports a different network.
    • Conflating “public” with “anonymous counterparties.” A public settlement layer can still sit underneath a fully permissioned, whitelisted transfer function at the token contract level — the base chain and the access-control layer are separate design decisions.

    Practical Checklist Before Choosing a Chain Architecture

    • Map every party who legally needs to see position and transaction data, and every party who explicitly must not.
    • Confirm which capital treatment your prudential regulator will apply, and get that confirmation in writing before building anything.
    • Decide whether the asset’s value comes primarily from broad distribution or from tight counterparty control, and let that answer drive the network choice rather than the reverse.
    • Test settlement finality under realistic network congestion, not just in a quiet sandbox environment.
    • Document a key-recovery and business-continuity plan appropriate to the custody model you are actually using.
    • Build the token’s transfer restrictions and eligibility checks at the smart contract or ledger-rule level, regardless of whether the base chain is public or permissioned.
    • Plan an interoperability or bridging strategy before launch, not after the first counterparty asks for one.
    • Revisit the choice annually — regulatory capital treatment and network maturity are both moving targets in this market.

    Key Takeaways

    • Permissioned chains offer known validators, fast deterministic finality, and an easier path through current bank capital rules.
    • Public chains offer broader secondary liquidity, lower vendor lock-in, and independently verifiable transaction history, at the cost of slower base-layer finality and default transparency.
    • The Basel Committee’s cryptoasset standard and the EU’s DLT Pilot Regime both shape — but do not strictly mandate — the permissioned-first pattern seen among most bank-led tokenization projects to date.
    • Networks like Canton show the binary is already blurring, combining a technically public topology with transaction-level privacy.
    • Most sophisticated institutions run both architectures for different legs of the same overall workflow rather than committing to a single one.

    Frequently Asked Questions

    Is a permissioned blockchain more secure than a public one?

    Security depends on what you are protecting against. A permissioned chain reduces the risk of anonymous bad actors joining as validators, but it concentrates trust in the operator and its named members, so a compromise or collusion among a small validator set can do more damage than on a network secured by a million independent validators. Public chains distribute that risk more widely but expose more of the transaction data by default.

    Can a public blockchain satisfy bank capital requirements under the Basel cryptoasset standard?

    Yes, if the tokenized asset meets the classification conditions for Group 1a treatment, including redemption rights and legal enforceability equivalent to the underlying asset. Supervisors apply extra scrutiny to infrastructure risk on permissionless networks, which in practice makes the approval process longer, but the standard does not categorically exclude public chains.

    Why do banks like JPMorgan use a permissioned chain instead of Ethereum for repo settlement?

    Repo trades on Kinexys involve a known set of institutional counterparties who need instant, private, legally certain settlement many times a day. A permissioned ledger the bank operates directly gives it deterministic finality in seconds and keeps position data out of public view, both of which matter more for that workflow than the broad interoperability a public chain would offer.

    What is the DLT Pilot Regime and does it require a permissioned network?

    The DLT Pilot Regime is an EU framework, in force since March 2023, that lets market operators run trading and settlement infrastructure on distributed ledgers within defined size limits, roughly up to €1 billion per venue for bonds and other debt instruments. It does not mandate permissioned architecture, but nearly every live venue under the regime has chosen one for easier compliance demonstration.

    Is Canton Network permissioned or public?

    Canton is best described as a hybrid: its validating infrastructure is open to any institution willing to run a synchronizer node, which makes it public in topology, but transaction details are only visible to the parties actually involved in a given trade, giving it privacy characteristics closer to a permissioned system. This middle position is a big part of why banks including Goldman Sachs and Deutsche Börse chose it for tokenized fund settlement.

    References

    • Basel Committee on Banking Supervision: “Prudential treatment of cryptoasset exposures” (Standard d545, finalized December 2022).
    • European Union: Regulation (EU) 2022/858 on a pilot regime for market infrastructures based on distributed ledger technology.
    • Bank for International Settlements Innovation Hub: Project mBridge technical and policy documentation.
    • BlackRock and Securitize: USD Institutional Digital Liquidity Fund (BUIDL) product disclosures and multi-chain expansion announcements.
    • Franklin Templeton: OnChain U.S. Government Money Fund (BENJI) prospectus and network expansion filings.
    • JPMorgan: Kinexys Digital Payments platform documentation (formerly Onyx).
    • Digital Asset: Canton Network technical architecture and validator participant disclosures.
    • Ethereum Foundation: Consensus layer specification on finality and validator participation.

    David Kim
    David Kim
    David Kim is a fintech product lead and personal finance writer who helps readers make smarter choices about the tools in their wallets and phones. Raised in Vancouver and now living in New York City, David studied Computer Science at UBC and later earned an MBA focused on product innovation. He’s shipped budgeting apps, savings automations, and fraud-prevention features used by millions—experiences that make his writing unusually practical about how money tech really works behind the scenes.David’s articles sit at the intersection of usability, security, and behavioral design. He reverse-engineers paywalls, compares fee structures, and explains why certain interfaces nudge you to spend—or save—more than you intended. He’s especially good at teaching readers to build a personal “tool stack” that integrates cleanly: a primary bank and backup, rewards without debt traps, savings buckets with real names, and alerts that matter.He also writes about digital safety for everyday users: why two-factor authentication is non-negotiable, how to spot synthetic-identity scams, and the simple routines that cut risk without turning you into your family’s full-time IT department. His tone is friendly and nonjudgmental, anchored by checklists and screenshots that lower the barrier to action.Outside of work, David is a weekend photographer who loves street scenes and rainy sidewalks. He plays mediocre but enthusiastic piano, roasts his own coffee beans, and has a soft spot for thrifted mid-century desk lamps. He believes good tools should disappear into the background and that the best budgeting app is the one you actually open.

    LEAVE A REPLY

    Please enter your comment!
    Please enter your name here

    Recent Posts

    More
      Cross-Chain Bridge Risk in Tokenized Assets Explained

      Cross-Chain Bridge Risk in Tokenized Assets Explained

      0
      Quick answer: Cross-chain bridge risk is the possibility that a tokenized asset moved between blockchains stops being backed one-to-one by the collateral it's supposed...
      Gold Token vs Gold ETF The 2026 Head-to-Head Comparison

      Gold Token vs Gold ETF: The 2026 Head-to-Head Comparison

      0
      A head-to-head comparison of gold-backed tokens like PAXG and Tether Gold against physical gold ETFs like GLD, IAU, and SGOL — covering custody, cost, liquidity, taxes, and retirement-account eligibility.
      Tokenized Commodity Warehouse Receipts How the Market Works

      Tokenized Commodity Warehouse Receipts: How the Market Works

      0
      Quick Answer A tokenized commodity warehouse receipt is a blockchain-recorded claim on a specific, physically stored lot of a commodity, most often copper cathode, aluminum,...
      Trade Finance on Distributed Ledgers eBLs and Smart LCs Explained

      Trade Finance on Distributed Ledgers: eBLs and Smart LCs Explained

      0
      Quick Answer Trade finance on distributed ledgers replaces paper documents and courier-based letter-of-credit processing with electronic bills of lading and rule-encoded smart contracts that banks...
      Tokenized Invoice Finance How On-Chain Receivables Work

      Tokenized Invoice Finance: How On-Chain Receivables Work

      0
      Quick Answer Tokenized invoice finance converts an approved but unpaid invoice into a blockchain-recorded claim that outside investors can fund directly, usually through a pool...

      More From Author

      More

        Collateral Mobility Tokenization: Closing the Intraday Liquidity Gap

        A margin call does not wait for a settlement cycle. When a clearinghouse recalculates exposure at 11 a.m. and demands another few hundred million...

        Asset Location Strategy: A Guide for Multi-Account Investors

        Quick Answer Asset location means deciding which account holds a given investment, not how much of it you own. The short version for most multi-account...

        Cross-Chain Bridge Risk in Tokenized Assets Explained

        Quick answer: Cross-chain bridge risk is the possibility that a tokenized asset moved between blockchains stops being backed one-to-one by the collateral it's supposed...

        Gold Token vs Gold ETF: The 2026 Head-to-Head Comparison

        A head-to-head comparison of gold-backed tokens like PAXG and Tether Gold against physical gold ETFs like GLD, IAU, and SGOL — covering custody, cost, liquidity, taxes, and retirement-account eligibility.