# bookd: day-one $BOOKD utility and launch economics

Decision draft, 3 October 2026 UTC. **Use $BOOKD as required service-capacity collateral from the first activated business, while keeping calls and subscription costs funded in dollars.** A fiat or USDC customer receives a sponsored token bond; an owner may instead supply their own bond. The token is part of access enforcement and operator authorization. Customers do not need to speculate, manage a wallet, or pay telephony bills in a volatile asset.

The confirmed identity is lowercase **bookd**, `bookd.bot`, proposed `@BookdBot`, lime/ink, a **b + check** mark, “Your next job, bookd.” and “Real work. Onchain rails.” Those cues come from the associated brand thread retrieved by the coordinating agent; this analysis does not repeat unavailable details or imply that the domain/handle has been purchased. $BOOKD being mandatory from day one supersedes the previous plan's optional-token/later-launch recommendation.

**Recommendation:** Base; native Clanker V4's **100,000,000,000 BOOKD origin supply**, with the numeric mechanics below. Clanker availability does not make custom vesting, live billing, or incident arbitration implemented. The source product is a trades receptionist, booking and crew-coordination service. BOOKD holders receive no claim on merchant job revenue, bookd equity, or SaaS cash flows.

## 1. Required day-one mechanics

### Business capacity bond

Each standard activated business requires **2,500,000 BOOKD** in an escrow record associated with a random tenant identifier. The business's paid/trial entitlement must also be current. Holding a wallet balance alone never grants access.

`active = sufficient deposited BOOKD AND current funded entitlement AND no withdrawal pending AND authorized operator`

The standard bond permits one business tenant and the configured standard call-concurrency tier. It does not guarantee a throughput level that has not passed load testing. Booking, crew access, transcripts and support remain part of the paid product; staffing limits and approved usage budgets still apply. Neither calls nor bookings put customer data onchain.

**Sponsored route:** card or USDC subscriptions fund the ordinary service. A segregated capacity reserve supplies the tenant's BOOKD bond. The sponsor owns these tokens and receives them back after offboarding. The customer has no token redemption claim, no hidden custody responsibility and no additional wallet setup. Payment itself is insufficient: the server must verify the actual bond and the settled billing grant before activation.

**Owner route:** an owner deposits the same units from a wallet. After disabling new dispatch and completing a seven-day withdrawal cooldown, the depositor withdraws the **same token units**, subject to the contract's stated rules. The implemented reference permits one bounded review extension; the launch default is at most three additional days, without confiscation or repeated extensions. There is no guaranteed dollar return, loan, staking interest or forced price-based top-up. A replacement bond belongs to the new depositor; changing merchant ownership cannot redirect the existing depositor's refund. Same features and same SaaS price; do not manufacture an annual yield through a subscription discount.

Contract authorization must distinguish tenant administration, depositor ownership and funding authority. A billing administrator cannot appropriate a customer's deposit. Sponsor withdrawals return to the restricted reserve rather than an unrestricted treasury trading wallet. Enforce one active registry assignment per bond; prevent the same deposit from counting for multiple businesses.

**Why a finite token?** It gives the product a common, transferable capacity collateral asset, shared by businesses and operators, and bounds how much capacity an operator can register. It is critical by protocol design. It is not technically necessary to run a telephone service: a centralized non-token database could implement similar allocation rules. Treasury-funded bonds also do not produce guaranteed external purchases. Useful access mechanics and speculative price demand are different claims.

### Operator capacity and performance

The first-party bookd operator must post **100,000,000 BOOKD per complete block of 100 assigned standard tenant slots**. A paid tenant is assigned to an operator with enough registered bonded capacity. At 101 assignments the operator needs 200m BOOKD, or a second qualifying operator. Expired/inactive tenant assignments still occupy slots until removed. This is a discrete authorization ceiling, not a claim that 100 businesses all consume the same compute.

The tested local reference now implements operator capacity and consent in `BookdOperatorCapacityEscrow`, and combines it with the tenant's funded/bonded status in `BookdServiceActivation`. It checks the same immutable token in both escrows. Partial deposits grant only complete 100-slot blocks; requesting operator exit immediately disables composite access. Withdrawal follows the configured seven-day cooldown and requires removal of every assignment. Operators can remove their own assignments without registrar permission. No challenge extension or slashing exists in this capacity escrow. Production must use one canonical registry and enforce the composite gate and the remaining paid usage budget server-side. Later independent operators must also pass actual operational qualification: token ownership cannot authorize a stranger to receive private recordings or calendar credentials.

For accountable performance, the proposed separate operator contract allows a disclosed penalty after a substantiated incident and appeal. Example policy: at most **1% of the deposited operator bond per upheld incident**, at most **10% in a 30-day epoch**, a seven-day appeal window and a 30-day operator exit delay while unresolved cases exist. Incident identifiers are hashes of private evidence; no transcript or telephone number goes onchain. No automatic slash based on an unauthenticated call report, failed booking alone, or token price.

**Implementation boundary:** required operator capacity collateral and composite activation are implemented and tested references; they are undeployed. Neither escrow has administrator seizure or performance slashing. The separate performance contract, incident reserve settlement and adjudication process remain specified integrations. Describe operator tokens as refundable capacity collateral until those additional mechanisms are reviewed and integrated. Initial adjudication would be disclosed first-party/independent reviewer governance, not decentralized consensus. This report does not claim a live arbitrator or production contract.

Incident compensation is paid only from a funded **USDC service-credit reserve**, not from assumed sales of slashed BOOKD. Slashed tokens cannot guarantee dollar compensation. A representative published cap is 20% of that month's subscription for an eligible incident, subject to the policy's per-month and aggregate funded limits. Freeze new benefit commitments before issuing unfunded promises.

### Usage and payment

Fiat and Base USDC settle identical dollar-priced subscriptions into one server entitlement ledger. BOOKD may also be accepted as a payment input: obtain a short-lived executable swap quote, enforce a customer-approved maximum token amount and minimum USDC output, and grant usage from **USDC actually received**. A frontend quote or signature alone does not activate service. Failed, late, replayed or insufficient settlements create no duplicate entitlement.

Avoid a thin-pool spot oracle for pricing subscriptions or collateral. Do not require a recurring fixed-unit BOOKD burn: a price spike would raise a merchant's operating cost without raising the platform's dollar cost. Neither token holding nor bonding creates perpetual free minutes. Every call still consumes a funded usage allowance.

## 2. Supply, allocations and vesting

Clanker V4 fixes origin supply at **100B with 18 decimals**. Its Superchain bridge has privileged crosschain mint/burn mechanics; say “100B origin supply; no arbitrary administrator mint,” not “the contract has no mint function.” A custom reference ERC-20 can mirror supply in local tests but must not become a second public BOOKD asset. Publish Base chain ID and the verified canonical Clanker token address as identity.

| Allocation | BOOKD | Supply | Restriction and purpose |
| --- | ---: | ---: | --- |
| Initial token liquidity | 25,000,000,000 | 25% | Verified Clanker LP/locker configuration; publish fee beneficiaries and withdrawal rights |
| Sponsored business capacity | 25,000,000,000 | 25% | Restricted capacity vault; deposits/returns only for eligible sponsored tenants; supports 10,000 standard bonds |
| Operator capacity reserve | 15,000,000,000 | 15% | Restricted operator vault; capacity/performance collateral; not a free trading wallet |
| Team and long-term builders | 15,000,000,000 | 15% | 12-month cliff, then 48 months linear; no accumulated 25% cliff dump |
| Ecosystem integrations | 10,000,000,000 | 10% | Three-month cliff, then 36 months linear; approved integration grants and capacity pilots, no automatic per-booking emissions |
| Operating treasury | 5,000,000,000 | 5% | Six-month cliff, then 36 months linear; declared budgets, timelock and recipient restrictions |
| Early contributor distribution | 5,000,000,000 | 5% | Up to 500m after the native minimum lock and verified claims; remaining 4.5B linear over 12 months |
| **Total** | **100,000,000,000** | **100%** | No discretionary inflation schedule |

Vesting starts are measured from the canonical token deployment timestamp; “12-month cliff then 48 months” means a 60-month total schedule. Core team release after the cliff is approximately **312.5m BOOKD per month**, not a 3.75B immediate cliff release. Actual contracts must use seconds/defined dates rather than ambiguous calendar-month arithmetic.

**Native deployment limits matter.** Clanker permits at most 90% outside LP, a maximum of ten extensions, one native vault allocation per token, a native vault lock of at least seven days, and a native airdrop lock of at least one day. Extension addresses must be approved by the factory owner. This allocation uses 75% outside LP, but seven labels do not mean seven native vaults can be configured.

A candidate native-compatible route is one airdrop allocation whose fixed Merkle recipients are predeployed reviewed reserve/vesting contracts. Those recipients claim only after the one-day lock and apply their own restrictions. The airdrop's root/admin mutability, receiver claim authorization, factory allowlist and exact bytecode must be checked before this becomes a deployable allocation. An arbitrary custom allocation-router extension cannot simply be injected. Do not send all 75B to a freely controlled multisig and call the schedule enforced vesting.

**Day-zero bridge inventory:** if 100 pilots must have active bonds immediately, buy **350m BOOKD** through the approved dev-buy/market path: 250m for tenant bonds and 100m for their operator. These are tokens purchased from the LP allocation, not an extra mint or an unlocked vault allocation. When restricted capacity allocations become claimable, retain the bootstrap inventory in the same restricted reserve and reconcile both holdings transparently.

At the example genesis, the economic breakdown is **24.65B available market tokens + 350m bonded bootstrap tokens + 75B locked allocation = 100B**. Once 500m verified early-contributor tokens are released, available market supply could reach **25.15B**, before other releases or new purchases. This is an economic free-float model, not a promise about a data aggregator's circulating-supply classification. Sponsored and first-party operator tokens remain treasury-controlled restricted inventory even though they are in escrow.

## 3. Capacity demand and adoption limits

| Active standard tenants | Tenant bonds | Required operator bonds | Combined bonded BOOKD | Origin supply |
| ---: | ---: | ---: | ---: | ---: |
| 100 | 250m | 100m | 350m | 0.35% |
| 500 | 1.25B | 500m | 1.75B | 1.75% |
| 1,000 | 2.5B | 1B | 3.5B | 3.5% |
| 10,000 | 25B | 10B | 35B | 35% |
| 20,000 | 50B | 20B | 70B | 70% |

The sponsored reserve can support 10,000 standard tenants at the original threshold, plus the small bootstrap inventory. More customers require returned inventory, transparently purchased collateral, additional self-funded bonds, or a new tier announced before commitment. Operator reserve capacity separately supports 15,000 tenants. Tokens sitting in internal reserve are not evidence of customer demand or a price floor.

With all 100B available for collateral and one fully utilized operator, fixed original rules have an exact **28,560-tenant theoretical ceiling** after rounding operator blocks upward. Retaining 25B of market liquidity reduces this ceiling to **21,400**; fragmented partly filled operator blocks can reduce it further. This is a real design constraint. Any future threshold/tier change uses a new reviewed registry/contract for **new commitments**, is published at least 30 days in advance and passes a timelock; the current reference's thresholds are immutable, so grandfather existing fully funded bonds. Do not silently change thresholds in response to price or require owner margin calls. Track actual capacity and funded sponsor headroom before promoting unlimited scale.

Forced merchant token purchases would add price, wallet, accounting and exit friction to a simple trades SaaS. Default sponsorship avoids those steps. Owned bonds offer control over the collateral and eventual withdrawal, rather than a promised investment return. Test sponsored versus optional owner-supplied conversion and support burden; do not equate token wallet connections with retained paying businesses.

## 4. Dollar-funded unit economics

These are **planning assumptions, not provider quotes or observed cohorts**: all-in telephone/voice/AI cost $0.08/minute baseline, $0.18 stress; SMS $0.013/segment; allocated hosting/support $24/business-month; card + Stripe Billing collection 3.6% + $0.30. Call transfers, simultaneous legs, audio model changes, number rental, taxes, fraud and human support may change costs. Stress contribution below excludes acquisition, central payroll, tax and development.

Proposed standard test offer: **$199/month, 500 call minutes and 300 SMS segments; $0.35 additional minute and $0.03 additional SMS segment**, with a disclosed prepaid spend limit. Same operating features for every payment route. This deliberately changes the source site's unlimited/no-usage-fee terms. If preserving 600 included minutes is important, use a provisional **$229** price instead. At $199/600, adding the 5% funded benefit budget lowers stress contribution to about 23.0%, below the proposed 30% gate.

Reserve **5% of actually collected service revenue**: 2% for eligible incident credits, 2% for verified customer acquisition, 1% for bounded trial/integration benefits. This is an expense/reserve commitment, not a distribution to holders. Cash balances, commitments and payouts must reconcile; unused balances stay segregated. Do not calculate budgets from token treasury mark-to-market value or unpaid annual invoices.

Let `M = call minutes`, `S = SMS segments`, `c = minute cost`:

`R = 199 + 0.35 × max(0, M − 500) + 0.03 × max(0, S − 300)`

`C = M × c + S × 0.013 + 24 + 0.036 × R + 0.30`

`contribution after benefits = R − C − 0.05 × R`

| Monthly usage | Collected revenue | 5% funded budget | Baseline contribution after budget | Stress contribution after budget |
| --- | ---: | ---: | ---: | ---: |
| 300 min / 100 SMS segments | $199 | $9.95 | $132.29 / 66.5% | $102.29 / 51.4% |
| 500 min / 300 SMS segments | $199 | $9.95 | $113.69 / 57.1% | $63.69 / 32.0% |
| 600 min / 300 SMS segments | $234 | $11.70 | $137.68 / 58.8% | $77.68 / 33.2% |
| 1,000 min / 300 SMS segments | $374 | $18.70 | $233.64 / 62.5% | $133.64 / 35.7% |
| 3,000 min / 900 SMS segments | $1,092 | $54.60 | $722.09 / 66.1% | $422.09 / 38.7% |

At 100 full-allowance paid businesses, revenue is **$19,900/month**, baseline cost **$7,536.40**, stress cost **$12,536.40**, and funded benefits **$995**. Contribution after the reserve is **$11,368.60 baseline / $6,368.60 stress**. Each month the incident reserve receives $398, referral budget $398 and trial/integration budget $199. These are operating projections, not bookd traction.

Seed the segregated incident pool with an illustrative **$10,000 USDC** before promising credits. A maximum 20%-of-monthly-plan credit is $39.80 per standard tenant; 100 simultaneous eligible claims would need $3,980. Initial cash covers that case without selling BOOKD. A large outage, refund/cancellation surge or depleted reserve can still exhaust it; publish limits and pause new funded commitments when coverage fails.

A bounded 14-day pilot with **150 minutes / 50 SMS segments** costs about **$24.65 baseline / $39.65 stress**, assuming $12 allocated support for half a month and no payment fee. One hundred such pilots require **$2,465–$3,965**, plus setup/acquisition. Reserve that cash before issuing trial grants. The old 60-day, 600-minute/month promise is not carried over silently; trials must show their actual funded allowance and duration.

## 5. Token-price and liquidity stress

Use a balanced full-range benchmark of **25B BOOKD + $100,000 USDC** solely for an inspectable liquidity model. Initial spot is $0.000004/BOOKD, implied origin-supply value $400,000, and combined pool asset value $200,000. **These are not a launch valuation target, token floor or confirmed Clanker pool balances.** Clanker's real concentrated-liquidity ranges, token pairing, hook/LP/protocol fees, counterasset depth and dev-buy path must be simulated. A token-only pool position does not contain $100,000 of stable liquidity merely because a starting price was configured.

| Price scenario | BOOKD price | Owner's 2.5m-token bond | Operator's 100m bond | Effect |
| --- | ---: | ---: | ---: | --- |
| 90% fall | $0.0000004 | $1 | $40 | Capacity rules unchanged; token penalty deterrence weakens; funded USDC remains the credit source |
| Model starting spot | $0.000004 | $10 | $400 | Sponsor bridge of 350m tokens has approximately $1,400 spot value before actual execution |
| 10× price | $0.00004 | $100 | $4,000 | Self-funded acquisition costs rise; sponsored existing deposits do not need top-ups |
| 100× price | $0.0004 | $1,000 | $40,000 | New market-funded bonds could become prohibitive; stop unfunded sponsor commitments rather than promise cheap inventory forever |

For a fee-free constant-product model, `k = x × y`, token-sale USDC output is `y × Δx / (x + Δx)`, and post-trade price is `k / (x + Δx)²`.

Selling 2.5B BOOKD (10% of modeled LP tokens) returns approximately **$9,090.91**, an average execution price 9.1% below initial spot; post-trade price falls 17.4%. Selling 10B returns approximately **$28,571.43** and lowers spot by 49.0%. A $10,000 buy receives approximately **2.273B BOOKD**, average price 10% above starting spot and ending spot 21% higher. Real fee/slippage and concentrated liquidity can worsen execution. The treasury therefore cannot count its full marked token inventory as spendable dollar runway.

Provisional cash requirement for this particular modeled configuration is **$100,000 real stable liquidity + ~$1,420 bootstrap tokens at modeled impact + $10,000 incident reserve + $3,960 stressed pilot funding = ~$115,380**, before deployment review, engineering, legal/operational setup, gas, exchange fees, acquisition or central operating runway. Launch with a smaller pool only after publishing the thinner-liquidity model and adjusting limits. No unbacked treasury valuation may replace the required cash.

## 6. Reward fraud and treasury controls

Pay no token reward simply because an AI says a job was booked. The source product cannot verify an invoice or merchant revenue; fake jobs, repeated calls and referral farms would exploit that event. Calendar-confirmed is not paid/completed.

For the optional acquisition budget, an example cap is **$30 of actual funded value** after a distinct business completes onboarding, settles its first two invoices, retains service for 60 days and passes duplicate/related-party/chargeback checks. At 100 standard subscribers, a $398 monthly pool funds **13 such rewards ($390)**, not unlimited $30 promises. Reserve the reward when admitting an offer; use a waitlist when the remaining funded balance is insufficient. Pay USDC or purchase/quote BOOKD within the same cash ceiling. Never infer a future guaranteed token quantity from a dollar reward.

Protect with verified business/number/domain, payment identity and tenant controls; exclude self-referrals and materially related businesses; one accepted claimant per business; manually review suspicious networks; hold rewards through the stated dispute period; keep reversible pending balances before final transfer. Incident claims need provider evidence, idempotent event IDs and reviewer conflict controls. Reward/sponsor accounting must be publicly auditable in aggregates without exposing customer PII.

Use separate reserves for liquidity, sponsored capacity, operator collateral, operating cash and incident credits. A multisig plus delayed administrative changes reduces unilateral control but does not make the operator trustless. Publish admins, upgrade/seizure rights, LP fee recipients, reserve restrictions, vesting recipients, next releases and wallet balances. No automatic buyback, revenue-share yield, APY, permanent free service or claim that bond returns track a dollar price.

## 7. Production gates and what to measure

Day-one token criticality requires a **real canonical token, real funded escrow, real verified fiat/USDC billing events, authorized operator capacity and server enforcement**. A working local contract/demo is concrete implementation evidence but is not a live launch. Do not advertise production activation while these paths are mocked. Sign in with ChatGPT, if approved, links identity/permissions and cannot replace paid voice-provider funding.

Before activation: simulate the exact Clanker factory and approved extensions; verify 100B allocation arithmetic and Merkle recipient proofs; review each reserve/vesting/escrow bytecode; establish wallet/admin roles, appeals/exit policy, provider load tests and cash reserve funding. If performance slashing is omitted from the first release, remove slashable-contract claims and ship capacity enforcement plus funded incident credits honestly.

Pilot gates: provider-derived cost/minute and concurrent legs; at least 30% stress contribution after the benefit reserve; renewal/retention and canceled trials; available sponsored-seat inventory; entitlement/bond reconciliation lag and outage behavior; incident reserve coverage; referral cost per retained business and duplicate rate; own-bond versus sponsored conversion and support cost. React to failures by adjusting future allowances, deployment size and budgets, rather than changing existing token promises.

## Evidence and provenance

The source operating features and conflicting unlimited-price claims were read from `source-audit.md` and `launch-plan.md`; unit-cost assumptions are deliberately inherited planning inputs, not supplier contracts. The user explicitly required bookd and $BOOKD day one. The coordinating agent retrieved the linked private brand conversation and provided the confirmed cues above. Clanker constraints were checked by the identity research agent against official V4 source and SDK 4.2.18, including contract revision `b004c2edda29fa282a16d5d1441a26484f70b37f`; raw evidence is in `bookd-sources/`. Token/cash tables were calculated with exact decimal arithmetic. No supply was minted, no pool funded, no assets acquired and no live merchant activated in this research.

Primary reference entry points: https://clanker.gitbook.io/documentation/sdk-reference/v4.md ; https://github.com/clanker-devco/v4-contracts ; https://docs.base.org/build-on-base/accept-payments/charge-on-a-schedule ; https://docs.stripe.com/billing/subscriptions/overview . Current factory addresses, approvals and actual swap/pool configuration require deployment-time verification.


## Provider-cost update

The current provider review is reflected in the scenario table above: use 3.6% + $0.30 for Stripe card plus Billing and $0.013 per US SMS segment as a planning input. At 500 voice minutes and 300 segments, contribution after the 5% funded-benefits reserve becomes **$113.69 / 57.1% baseline** and **$63.69 / 32.0% stress**. These are assumptions, not observed costs. One hundred full-allowance subscribers produce modeled **$11,368.60 baseline / $6,368.60 stress** contribution; trial estimates with 50 SMS segments become $24.65 / $39.65. Carrier, registration, number and gateway costs require actual account quotes. [Primary provider research](provider-setup.md).
