Executive Summary
The loudest debate in tokenization asks the wrong question. It pits permissioned blockchains against permissionless ones, as if institutions must pick a side. They are not picking a side. They are picking a control layer.
Large pools of regulated capital cannot touch an asset unless the issuer can prove that only eligible, screened counterparties held it. That single requirement, not ideology, decides where institutional real-world-asset (RWA) flows land first. It explains why DTCC is targeting tokenized U.S. Treasuries on the Canton Network, why JPMorgan’s Kinexys settles billions daily on a permissioned network, and why JPMorgan’s deposit token is permissioned even though it runs on Base, a public chain.
The conclusion for operators: build compliance into the asset, and the choice of chain becomes a distribution decision rather than a compliance one. That is the design Stobox Cabinet is built around.
Key Takeaways
- Institutional RWA capital flows first to environments where every counterparty is identified and screened, whether that is a permissioned chain like Canton or a permissioned token on a public chain like JPMorgan’s JPMD on Base.
- The SEC’s December 2025 no-action letter to DTC requires tokenized securities to move only between OFAC-screened, whitelisted wallets, making compliance-at-the-transfer-layer a regulatory precondition, not a preference.
- JPMorgan’s Kinexys now averages more than $7 billion in daily volume and has cleared roughly $4 trillion cumulatively, the clearest proof that permissioned rails already carry institutional-scale flow.
- The public-chain counter-case is real: on-chain RWA value sits near $33 billion, most of it on public networks, because composability and shared liquidity are hard to replicate on private rails.
- The winning architecture is convergence, not either/or: a permissioned control layer (identity, eligibility, transfer rules) deployed on whichever rail, public or permissioned, best fits the asset and its buyers.
Introduction: The Real Institutional Question
The tokenization market crossed a threshold that changes the terms of the debate. On-chain RWA value, excluding stablecoins, has moved from roughly $8 billion at the start of 2024 to the low-$30-billions in 2026. The market crossed $20B on January 11, 2026, and the acceleration followed BlackRock’s BUIDL launch in March 2024, which validated public blockchains for institutional asset managers.
That validation is real, but it obscures a second signal that matters more for anyone building infrastructure: the largest and most regulated pools of capital are choosing surveilled environments. They are not chasing open, pseudonymous DeFi. They are demanding rails where identity, eligibility, and reversibility are guaranteed before an asset moves.
The risk of ignoring this is concrete. An issuer who tokenizes a security on a fully permissionless rail with a plain transferable token has built something a regulated allocator legally cannot buy. The token works. The market does not. Understanding why is the difference between issuing an asset and issuing a tradeable one.
Why Does Regulated Capital Demand Permissioned Environments?
Regulated capital demands permissioned environments because the law holds the holder, the issuer, and the intermediary accountable for who ends up owning an asset. Anonymity is not a feature to these participants. It is a liability.
A pension fund, a bank treasury, or an insurance allocator operates under mandates that require them to know every counterparty, screen against sanctions lists, and demonstrate that ineligible parties never acquired the instrument. A permissionless environment, by design, cannot make that guarantee at the base layer. Anyone can hold an ordinary token, and anyone can receive it.
The regulatory record now makes this explicit rather than implied. The SEC staff issued a no-action letter on December 11, 2025 to the Depository Trust Company, granting relief for a three-year period to permit DTC to offer a tokenization service with respect to certain DTC-custodied assets. The conditions attached to that relief are the point. In 2026, DTC will begin instituting a preliminary base version of tokenization services under which certain securities could be represented as tokens on an approved blockchain and recorded in a DTC participant’s wallet, and these wallets must be registered with DTC, which will screen them for compliance with the requirements of the Office of Foreign Assets Control.
Whitelisted, OFAC-screened wallets are, functionally, a permissioned control layer. The blockchain underneath can be public or private. To foster innovation, the pilot avoids prescribing the use of specific blockchain technologies; instead, DTC will establish a principles-based framework through objective technology standards, and any blockchain or tokenization protocol is eligible provided it meets requirements focused on operational resilience and regulatory compliance.
Read that carefully. The regulator did not mandate a private chain. It mandated permissioned control. That distinction is the entire argument.
Where Is Institutional Capital Actually Flowing?
Institutional capital is flowing to two places: purpose-built permissioned networks like Canton, and permissioned tokens deployed on public chains. Both satisfy the same requirement through different architecture.
Canton: the purpose-built institutional rail
Canton is the clearest example of a network designed from the start for regulated participants who need privacy plus compliance. While public blockchains excel at transparency and decentralization, they often fail to deliver the confidentiality and legal finality required in institutional finance; Canton, launched in 2023, tackles this challenge as a modular network built specifically for regulated entities, enabling real-time synchronized asset movements with built-in privacy and interoperability.
The volume already running through it is not a pilot. Broadridge’s DLR processes more than $8 trillion in monthly repo volume on Canton infrastructure. And the pipeline of institutions is deep. In December 2025, DTCC, Digital Asset and the Canton Network announced a partnership to enable tokenization of DTC-custodied assets, with DTCC planning, for the first time, to enable a subset of U.S. Treasury securities custodied at DTC to be minted on the Canton Network.
DTCC has stated it planned limited production trades through its tokenization service in July 2026, followed by a broader service launch targeted for October 2026.
The institutional roster tells you who is building here. The Canton Network has seen growing activity since its 2023 launch, with major institutions including Goldman Sachs, JPMorgan, Bank of America and Citigroup participating in the ecosystem.
Permissioned tokens on public chains
The second flow is subtler and, for issuers, more instructive. JPMorgan’s Kinexys is a permissioned network in its own right. It uses a permissioned blockchain network operated by JPMorgan to record and settle transfers between participating clients. The scale is now genuinely institutional. JPMorgan’s Kinexys platform, the most advanced individual-bank tokenized deposit operation in the country, now averages more than $7 billion in daily volume and has cleared $4 trillion total.
But JPMorgan did not confine itself to a private chain. Kinexys is piloting the issuance of JPMD, a permissioned USD deposit token for live institutional payments on Base, the Ethereum Layer 2 blockchain built within Coinbase. The key word is permissioned. JPMD will be a permissioned token, eventually available exclusively to J.P. Morgan clients. This is the whole thesis in one product. JPM Coin operates on a public blockchain where only vetted counterparties transact.
That is why the deposit token deployment was a milestone. In November 2025, JPMorgan deployed its JPMD deposit token on Base, Coinbase’s Ethereum L2, marking the first time a globally systemically important bank placed real institutional dollars on a public blockchain for live payments.
The lesson: the control lives in the token, not necessarily in the chain.
The Permissioned Control Layer: A Framework
Here is the framework that resolves the debate. Call it The Permissioned Control Stack: five layers that determine whether a tokenized asset is investable by regulated capital, independent of which blockchain it runs on. It maps directly to the three-stage path of intelligence, capital readiness, and compliant tokenization.
| Layer | Question it answers | Permissioned requirement | Stage |
|---|---|---|---|
| 1. Identity | Who is this wallet? | Verified on-chain identity (e.g. ONCHAINID) | Intelligence |
| 2. Eligibility | Is this holder allowed? | KYC, accreditation, jurisdiction, sanctions screening | Capital readiness |
| 3. Transfer control | Can this move here, now? | Conditional transfers enforced at the token level | Tokenization |
| 4. Lifecycle | Can the issuer act? | Pause, freeze, force-transfer, recover | Tokenization |
| 5. Rail | Where does it settle? | Public or permissioned, chosen for distribution | Tokenization |
The insight is that layers 1 through 4 are the hard part, and they are token-level and chain-agnostic. This is exactly what compliant token standards were built to deliver. ERC-3643, also known as the T-REX standard, is designed to bring compliance to the tokenization of real-world assets, is a permissioned token that uses smart contract technology to define conditional transfer functions, and is designed to deny transactions if counterparties fail to meet compliance requirements.
Crucially, that control can travel onto a public network. The ERC-3643 protocol is an open-source suite of smart contracts enabling the issuance and transfer of permissioned tokens, with a built-in decentralized identity framework that ensures only users meeting pre-defined conditions can become token holders, even on permissionless blockchains. Adoption is already material. $28bn worth of assets have been tokenized through ERC-3643.
Stobox works within this exact stack. It backs the ERC-7943 universal RWA interface and works with ERC-3643, so eligibility is enforced at the transfer layer regardless of rail. You can see how the pieces fit in the Stobox learn library.
The Counter-Case: Why Public Chains Still Win Some Flows
The permissioned thesis is not absolute. Public chains hold a genuine advantage that permissioned networks struggle to match: shared liquidity and composability. This is where the largest single tokenized products live.
The numbers favor public rails at the aggregate level. Total distributed RWA value on public blockchains reached $31 billion as of July 2026, spread across 167 platforms and held by more than 960,000 individual holders. And the flagship institutional product chose multi-chain public deployment. BlackRock’s BUIDL, by June 2026, was deployed across eight chains including Ethereum, Solana, Polygon, Arbitrum and others, where multi-chain reach broadens access and liquidity, but each additional hop layers on bridge, oracle, sanctions-screening and finality-layer risk.
Public chains offer something a walled garden cannot: a single asset can plug into an entire ecosystem of settlement, collateral, and yield primitives. BlackRock’s BUIDL operates across eight blockchain networks, distributes daily dividend payouts, supports 24/7 peer-to-peer transfers, and is accepted as collateral on major trading venues. That reach is the composability argument, and it is real.
But the honest read comes with a caveat that cuts across both camps. Analyses of on-chain transfer data show tokenized Treasuries and private credit, the two largest segments, trade thinly, with activity dominated by mint-and-redeem cycles rather than secondary transfers; by one mid-2026 analysis, 56% of reported RWA value sits idle.
In other words, composability is a promise the market has not fully cashed. Which is why the pragmatic answer is convergence, not a purity test.
Definition: Permissioned Blockchains for Finance
Permissioned blockchains for finance are distributed ledgers, or permissioned layers on public ledgers, where participation is restricted to identified and screened parties, so that regulated institutions can transact tokenized assets while meeting KYC, sanctions, and eligibility obligations. Permissioned blockchains are distributed ledgers that are not publicly accessible and can only be accessed by users with specific permissions; unlike permissionless blockchains, they require identity verification and have a controlled level of transparency. In practice, the same control can be achieved by a permissioned token deployed on a public chain, which is why the modern institutional pattern is a permissioned control layer over the rail that best fits the asset.
How to Act on This
The right move depends on who you are. Below is the practical read by reader type, with the permissioned control stack as the lens.
If you are a CEO or issuer
Do not start with the chain. Start with the buyer. If your capital comes from regulated allocators, your token must enforce identity and eligibility at the transfer layer from day one, or the asset is unsaleable to them. That means a compliant standard, not a plain ERC-20 wrapper. Then choose the rail for distribution, not compliance. Stobox Compass issues security tokens primarily on Base, with Arbitrum and Canton also supported, so the same compliant asset can meet institutional buyers wherever they settle. Score your readiness on Stobox Compass.
If you are an asset owner
Your priority is lifecycle control. A tokenized asset that cannot be paused, frozen, or recovered is a legal exposure, not an efficiency gain. Insist on layers 3 and 4 of the control stack before issuance. The question is not “which chain,” it is “can I enforce my legal rights on-chain,” and the honest answer determines the entire structure.
If you are an investor or allocator
Read the control layer before the yield. A tokenized Treasury on a public chain with whitelisted transfers is a different instrument from a plain transferable token, even at the same APY. Ask where eligibility is enforced, who can freeze, and whether secondary transfers actually happen or the asset only mints and redeems. Use the Stobox glossary and guides to pressure-test the structure.
Frequently Asked Questions
What are permissioned blockchains for finance?
They are distributed ledgers, or permissioned layers on public ledgers, where only identified and screened parties can participate. This lets regulated institutions meet KYC, sanctions, and eligibility rules while transacting tokenized assets. The same effect can be achieved with a permissioned token on a public chain.
Why do institutions prefer permissioned environments for RWA?
Because regulated capital is legally accountable for who holds an asset. Anonymity is a liability for a pension fund or bank, not a feature. The SEC’s December 2025 no-action letter to DTC requires tokenized securities to move only between OFAC-screened, whitelisted wallets, which is a permissioned control requirement.
How does a permissioned token differ from a permissioned chain?
A permissioned chain restricts who can access the entire network. A permissioned token restricts who can hold a specific asset, even on an open network. JPMorgan’s JPMD is a permissioned deposit token issued on Base, a public chain, showing the control can live in the token rather than the chain.
Is Canton Network public or permissioned?
Canton describes itself as a privacy-enabled network built for institutional finance, combining the openness of a public network with the privacy and compliance controls institutions require. In practice it functions as an institutional rail where participants and applications operate under permissioned controls while sharing interoperable infrastructure.
Can compliant tokenization happen on a public chain like Base?
Yes. Using standards such as ERC-3643 or ERC-7943, identity, eligibility, and transfer restrictions are enforced at the token level, even on a permissionless chain. Stobox Compass issues security tokens primarily on Base with these controls, so compliance travels with the asset rather than depending on a private network.
What is the SEC no-action letter and why does it matter?
It is a December 11, 2025 letter granting DTC a three-year window to run a tokenization service for DTC-custodied assets. It matters because it makes screened, whitelisted wallets a regulatory condition, effectively endorsing permissioned control for tokenized U.S. securities. The pilot is expected to launch in the second half of 2026.
Does using a public chain sacrifice compliance?
Not if the token enforces compliance. The mistake is issuing a plain transferable token that anyone can hold. A permissioned token standard denies non-compliant transfers automatically, so a public chain can host regulated assets without sacrificing eligibility or sanctions controls.
How should an issuer choose between permissioned and public rails?
Choose based on your buyers and your distribution goals, after you have built compliance into the token. If your capital is institutional and needs privacy plus legal finality, a network like Canton fits. If you want composability and broad access, a compliant token on a public chain like Base fits. The control layer comes first; the rail is a distribution decision.
What is the biggest risk in institutional tokenization today?
Idle assets. A large share of reported RWA value trades thinly, dominated by mint-and-redeem rather than genuine secondary activity. Issuing a token does not create a market. Compliance, buyer eligibility, and real distribution matter more than the choice of chain.
