Derivation, without a chain to write to
- 01
Get a transaction
on-chainEither a real transfer submitted to Stellar testnet from a disposable demo account, or one of the flows shipped with this repository. No wallet and no funded account of your own, either way.
or start from a shipped flow
Shipped flows were never observed on a live network. The ones marked refused are declined somewhere in the pipeline on purpose — a simulator that can only succeed is not evidence about anything.
- 02
Observe it
on-chainRead back into an observable flow: through Soroban RPC for a testnet hash, from the repository for a shipped one.
- 03
Derive the boundary
computed locallyThe minimum context rule and policy set that permits exactly that flow, composed from audited OpenZeppelin primitives.
- 04
Try to exceed it
computed locallyAdjacent transactions, one mutated dimension each. Every one must be refused.
- 05
Read the policy
computed locallyThe exact policy configuration that was derived, and the unsigned payload.
- 06
Ask whether it could be installed
computed locallyWhat Limen derives and what an OpenZeppelin smart account can hold are different languages. Lowering either translates the boundary or refuses it and names the constraint.