Governance Rules
Voting covers how you vote: get Voting Power, verify once, pick Adopt or Reject. This page covers what happens around your vote — the rules that decide whether a proposal passes, how fast it can pass, and what the community can change about those rules.
The short version: not every proposal is equally dangerous, so not every proposal follows the same rules. OhShii sorts proposals into two lanes, and the dangerous lane costs more participation, more time, and more visibility.
ONS and SONS — the two kinds of DAO
Section titled “ONS and SONS — the two kinds of DAO”There are exactly two kinds of DAO on OhShii, and they never overlap.
- ONS — OhShii Network System. The ecosystem DAO, one for the whole platform. You vote in it with Voting Power from locked OHSHII. It governs the OhShii platform itself: the launcher canisters, the OhShii Locker, the pool manager, and the OHSHII ledger, index and pool. It also directs the OhShii treasury.
- SONS — Standalone OhShii Network System. A campaign DAO, one per token. A token gets one in one of two ways: by running an LGE, or by importing a token that already exists and never had one. Either way you vote in it with Voting Power from locked tokens of that campaign, not with OHSHII, and it governs only that token: its own proposals, treasury, liquidity position and canisters.
The distinction that matters: a SONS is autonomous. Once a campaign completes, only that campaign’s own holders govern it — ONS cannot, and neither can OhShii. ONS is not a parent DAO with authority over campaign DAOs; it governs the platform, they govern themselves.
Every token governed by a SONS is a utility and governance token: it exists so its holders can vote on that project. OhShii is neutral infrastructure and time-boxed escrow — it does not vet or endorse projects, and a creator who presents theirs as anything else has breached the terms of use the platform operates under.
Everything below applies to both kinds: each DAO holds its own copy of these rules and changes only its own.
Two lanes: Normal and Critical
Section titled “Two lanes: Normal and Critical”Every proposal is automatically classified as Normal or Critical the moment it is created. You never choose the lane — it is derived from what the proposal actually does.
| Normal | Critical | |
|---|---|---|
| Voting window | 3 days, fixed | 7 days, fixed |
| Quorum needed at the deadline | 250,000 VP and 15 voters | 350,000 VP and 20 voters |
| To pass | more Adopt VP than Reject VP — a tie rejects | ≥ 65% of the participating VP must be Adopt |
| Can it close early? | Never | Only under a much higher bar — see below |
| Guardian veto | No | Yes — and it is overridable |
| If quorum isn’t reached | Expires with no effect | Expires with no effect |
What makes a proposal Critical
Section titled “What makes a proposal Critical”Critical is anything that can change code, control, or the rules themselves:
- upgrading the code of any canister the DAO controls — its token’s ledger, index and archives, another dapp it governs, or its own governance canister;
- upgrading a frontend (asset canister);
- batch upgrades — a whole ledger suite, or an ordered set of dapp canisters, in a single proposal;
- appointing, replacing, or removing the guardian;
- dangerous operations on the DAO’s own governance canister — adding or removing a controller, restoring or deleting a snapshot;
- changing the voting parameters themselves;
- custom calls and HTTPS outcalls the DAO composes itself — the target canister, method, or URL is unconstrained, so these always run in the Critical lane;
- a set of high-impact operations that would otherwise look routine: treasury or balance withdrawals, removing liquidity, transferring an LP position, changing locks on the OhShii Locker, deleting a campaign, and edits to the ecosystem token’s own metadata.
Everything else is Normal: motions and signals, campaign information updates, routine administrative executions, topping up canisters with cycles the DAO already holds.
Immediate execution — and why Normal proposals never use it
Section titled “Immediate execution — and why Normal proposals never use it”“Immediate execution” (or early close) means a proposal is decided before its deadline, as soon as the outcome is beyond doubt. It sounds like a convenience feature. It is also the classic way a governance system gets rushed, so OhShii restricts it heavily.
Normal proposals never close early. They always run their full 3 days, even at 100% Adopt. The window is already short; letting a fast, well-coordinated group close it in the first hours would decide things before the rest of the community had a realistic chance to look.
Critical proposals may close early — but only through a much narrower door. All of these must be true at once:
- ≥ 75% of the participating VP is Adopt, and
- at least 450,000 VP has voted, and
- at least 30 unique voters have voted, and
- the guardian has cast an Adopt vote.
That last condition is the point of the design. Critical proposals are exactly the ones the guardian can veto, and the veto only works while a proposal is still open — so an early close would race the brake. Requiring the guardian’s own Adopt vote means the brake was consulted before the shortcut was taken. When a DAO has no guardian set, this gate simply doesn’t apply.
Early rejection is symmetric — at ≤ 25% Adopt with the same VP and voter bars — and has no guardian gate, because rejecting early can never push a change through.
Guardian-removal proposals can never close early at all. They run a hard 7-day window no matter what, and the guardian may not vote on its own removal.
One small exception, for completeness: a guardian-created Normal proposal may choose a shorter window, down to a floor of 1 day. It cannot shorten a Critical proposal, cannot shorten a removal, and cannot skip any threshold — it only affects how long a routine proposal it created stays open.
The guardian: a brake the community can override
Section titled “The guardian: a brake the community can override”Each DAO can have a guardian. Its only power over an outcome is a veto on Critical proposals, and that veto is deliberately not final.
Where the guardian comes from
Section titled “Where the guardian comes from”The first guardian is not elected — it is set when the DAO is created, and the community takes over from there:
- A campaign DAO (SONS): the creator chooses the guardian at creation, when setting up the LGE or importing an existing token. If they don’t pick anyone, it defaults to the creator’s own principal. It can be any principal — including a canister ID — except the anonymous principal and OhShii’s own infrastructure principals, which are rejected. See LGE Launch and Imported DAO for the creator’s side of this.
- While the LGE is still running, that choice is not yet in force: the emergency role is held by the ecosystem DAO’s guardian. The creator’s chosen guardian takes effect when the campaign DAO becomes autonomous at completion.
- The ecosystem DAO (ONS) has its own guardian, changed only by a Critical
SetGuardianproposal. - From then on, only a vote can change it. There is no operator switch and no creator override: the guardian principal is written once at creation and afterwards only an approved governance proposal can replace or remove it. Appointing or replacing a guardian runs in the Critical lane on every OhShii DAO: the full 7-day window, the Critical quorum, and the 65% bar. A removal also runs the fixed 7-day window and can never be decided early, but it is deliberately judged at the ordinary quorum — taking the brake out must never be harder than putting it in.
How the veto works
Section titled “How the veto works”- The guardian vetoes a still-open Critical proposal. The proposal moves to Vetoed — it is not cancelled.
- A 24-hour override round opens automatically. This is a second, independent ballot: you can vote in it even if you already voted in round 1.
- The override succeeds if it reaches ≥ 80% Adopt of the participating VP, with 700,000 VP and 50 unique voters. If it does, the proposal is Approved and executes. If it doesn’t, the veto stands and the proposal is Rejected.
Details worth knowing about the override round:
- Direct votes only. Delegated votes do not cascade into an override round — overriding a veto is a decision you make yourself.
- Fresh personhood check. Each override voter passes a live World ID re-attestation, so dormant verifications can’t simply be re-mobilised to flip a veto.
- One veto per proposal. A proposal that has been vetoed cannot be vetoed again.
- No early close in this round — it runs its full window and the timer decides.
And the limits on the role itself:
- It can only veto — it cannot change a vote, rewrite a tally, alter the anti-replay records, or change any DAO-voted parameter.
- It has no discretionary path to the treasury: it cannot withdraw funds or choose a recipient. Its only fund-related power is an idempotent recovery that returns tokens stuck in a pool back to the DAO’s own treasury, to a destination fixed in code.
- Removing it is hardened: a fixed 7-day window, never early, and the guardian cannot vote on its own removal. It may veto its own removal — but that only opens the override round, where the community completes the removal at the override supermajority (and where the guardian again cannot vote).
- It is not a permanent seat. Whoever the creator picked at launch holds the role only until the DAO votes otherwise — the role belongs to the DAO, not to the person who set it up.
The net effect is bounded by design: a guardian acting badly can delay a Critical proposal by one override window. It cannot permanently block one, and it cannot pass one on its own.
What each DAO can change by vote
Section titled “What each DAO can change by vote”The ecosystem DAO changes these with a voting-parameters proposal (Critical lane); a campaign DAO changes its own copy with a configuration proposal. Neither can change the other’s.
| Parameter | Current default | What it controls |
|---|---|---|
| Minimum lock duration | 45 days | how long a lock must run before it earns any VP |
| VP cap per person | 36,000 | the ceiling on one identity’s total Voting Power |
| Normal quorum | 250,000 VP + 15 voters | participation needed to decide a Normal proposal |
| Critical quorum | 350,000 VP + 20 voters | participation needed to decide a Critical proposal |
| Critical approval | 65% | Adopt share needed for a Critical proposal at its deadline |
| Critical early close | 75%, 450,000 VP, 30 voters | the early-close bar (plus the guardian’s Adopt vote) |
| Voting windows | 3 days Normal · 7 days Critical | how long each lane stays open |
| Guardian minimum window | 1 day | floor for a guardian-created Normal proposal |
| Minimum VP to propose | 10,000 | stake needed to create a proposal |
| Proposal fee · rejection cost | 30,000 · 25,000 tokens | the fee, and what is withheld if the proposal is rejected |
| Veto-override bar | 80%, 700,000 VP, 50 voters, 24 h | what it takes to override a guardian veto |
| (Ecosystem DAO only) LGE tier limits, tier VP thresholds, Guest fee | see LGE Participation | purchase economics, not vote weight |
| (Campaign DAO only) identity-verification requirement, minimum lock amount, minimum stake to propose, fee recipient, excluded countries | set at creation | that campaign’s own participation rules |
The floors — what a vote can never do
Section titled “The floors — what a vote can never do”Tuning is bounded so a DAO cannot vote itself into a broken state, even by accident:
- Quorums and minimum-voter counts can never be zero — “nobody has to show up” is not a valid setting.
- Approval percentages must stay between 1 and 99 — no 0% and no unreachable 100%.
- Voting windows must be greater than zero and stay ordered: guardian-minimum ≤ Normal ≤ Critical.
- The veto-override quorum, voter minimum, and window can never be zero (a campaign DAO additionally has a 1-day floor on the override window). This is what keeps a veto from ever becoming an instant, unoverridable kill.
What is fixed in code
Section titled “What is fixed in code”These change only through a canister upgrade — which is itself a Critical proposal, voted on-chain, with a WASM hash anyone can reproduce and check before voting:
- the Voting Power formula (
√tokens × months) and the built-in 36,000 ceiling enforced by the lock canister; - which categories are Critical;
- the decision rules themselves — a tie rejects, Normal never closes early, a Critical early approval requires the guardian’s Adopt vote;
- the guardian guardrails — who may hold the role, the 7-day removal floor, and the ban on voting for one’s own removal;
- the anti-abuse limits — rate limits, delegation caps, and the cycle floors that keep the canister operable under load.
Why it is built this way
Section titled “Why it is built this way”Each rule above exists because of a specific, ordinary failure mode. Read the design as a set of answers.
“Someone accumulates a large position and takes control.” Voting Power is not linear in stake. It grows with the square root of the amount and linearly with lock duration, and it is capped per identity at 36,000 — a ceiling that applies to the sum of all your locks, so splitting one identity’s stake across many locks gains nothing. Weight has to be earned by time-locking, so decisive control cannot be assembled quickly, and it cannot be bought in proportion to size.
“…so they split the position across many wallets.” That is exactly why the proof-of-personhood gate exists. Quadratic Voting Power without Sybil resistance is actually weaker than linear voting — an attacker just splits one wallet into many and walks around the square root. The two features only work as a pair, which is why OhShii ships both: World ID or DecideID, verified once, counting on every OhShii DAO. Participation in a launch is bounded on the same axis: at most 50 distinct unverified (Guest) participants per LGE while the gate is active.
“A risky upgrade gets pushed through on a quiet weekend.” It lands in the Critical lane: a fixed 7-day window that no amount of enthusiasm shortens, a higher quorum in both VP and distinct voters, a 65% bar, and no early close unless the guardian has itself voted Adopt.
“Then lower the bar first, and push it through afterwards.” The parameter-setter is itself Critical, the thresholds are snapshotted when each proposal opens, and the floors above cap how far any value can be moved. There is no cheap path to a weaker rule.
“A harmful proposal still reaches quorum.” That is what the overridable veto is for — a brake that buys the community a 24-hour, well-publicised second look, at a bar that is deliberately reachable so a veto can only ever delay.
“The guardian itself is the problem.” The seat starts with the creator’s choice, but it does not stay theirs: removal is the hardened path — 7 days, never early, no self-vote, freeze-resistant, and overridable if the guardian vetoes its own exit — and the correct sequence is remove first, then appoint. The community always keeps the last word.
“A delegate quietly builds a bloc.” Liquid Democracy is bounded so delegation represents without amplifying: one hop only (no chains), a principal is either a delegate or a follower but never both, each delegated vote is cast with the follower’s own capped VP, delegates are capped at 500 followers, followers can leave at any time and can always outvote a pending delegated vote — and the veto-override round doesn’t accept delegated weight at all.
Compared with a stake-weighted DAO
Section titled “Compared with a stake-weighted DAO”OhShii and stake-weighted DAO frameworks — the SNS among them — solve the same problem with different trade-offs, and the stake-weighted model’s strengths are real: it is simpler, well established, battle-tested, and in the SNS’s case natively integrated with the NNS. If that is what a project needs, it is a strong choice.
OhShii optimises for a different property — resistance to a capital-driven takeover — and pays for it with more moving parts:
- Voting Power that is not linear in stake, so accumulating tokens does not accumulate control proportionally;
- a per-identity cap, so there is a ceiling no bankroll clears;
- proof-of-personhood at the voting gate, which is the piece that turns quadratic Voting Power from Sybil-farmable into whale-resistant;
- layered Critical thresholds plus an overridable guardian brake, with the threshold-setter locked behind the Critical lane;
- autonomy from day zero, verifiable as an on-chain controller change rather than a promise.
The load-bearing difference is that most of this is structural, not a setting: the formula and the personhood pairing are fixed in code, the tunable numbers sit behind hard floors, and loosening any of it is always a high-bar, on-chain, publicly visible governance decision — never a quiet configuration change.
Honest limits
Section titled “Honest limits”Worth stating plainly, because a governance page that only lists strengths isn’t useful:
- A large, identity-verified, well-coordinated coalition can still win votes. Governance is majoritarian by design. These mechanisms raise the cost of capture and remove the cheapest single-actor routes; they do not make a legitimate-looking supermajority impossible.
- The identity gate inherits its providers’ strength. Proof-of-personhood relies on two independent third parties. Using either is enough, and only a DAO vote can turn the gate off on the ecosystem DAO — but its Sybil resistance is ultimately theirs.
- The guardian is a genuine trust assumption, bounded by the override path, the removal hardening, and the fact that votes, tallies and parameters are walled off from it — but it is not zero-trust.
- The numbers on this page are current settings, not permanent guarantees. The authoritative description of the system is the code and the reproducible WASM hash of the deployed canisters.
Related
Section titled “Related”- Voting — Voting Power, verification, and how to cast a vote.
- Liquid Democracy — following a delegate, and the limits that keep delegation from concentrating.
- Voting Hotkey — voting from a second principal without moving your locks.
- Why OhShii — the plain-language case for the whole model.
- Governance & Capture Resistance — the technical companion: threat model, mechanisms, and the full honest-limits list.