Every function in the chain — holding the asset, keeping the register, introducing buyers, taking the money — is something a named party is authorised to do in a named place. Technology changes how these are performed. It does not change that they must be performed by someone permitted to perform them.
Custody is the clearest dividing line in the whole field, and the test is simple. If a firm can move an asset without the owner’s signature, it has custody of that asset, whatever the product calls itself. If it cannot — because the only key that authorises a movement is held by the owner — it does not.
Where a firm does have custody, three obligations follow almost everywhere: the assets are held separately from the firm’s own, they are recorded so that each client’s share is identifiable, and there is a plan for returning them if the firm becomes insolvent. Meeting these is what a custody licence attests to.
This is why the custodial and non-custodial parts of a product should never be blurred on the same screen. A user who cannot tell which of their holdings someone else can move has not been given the information that matters most.
No licence is needed to publish software that lets someone hold their own asset, because nothing is being held for them. The trade-off is real: lose the key, lose the asset, and no operator can reverse it.
Convenient, recoverable, and regulated. Client assets segregated, reconciled and protected on insolvency. This is a licensed activity in essentially every serious jurisdiction.
A common and workable design: the holder keeps their own keys for the asset, and a regulated partner holds the money. It only works if the boundary is visible in the interface.
Names and boundaries differ between jurisdictions, but the functions are consistent. A tokenized offering that reaches the public usually needs most of this list, assembled from several firms.
There is no global authorisation. A firm permitted to provide custody in one country is, by default, not permitted to provide it in another, and serving a customer resident elsewhere may require a permission in that customer’s country rather than the firm’s own.
The result is that cross-border products are assembled from locally licensed parties, connected by contract. Most of the engineering difficulty in this field is the connecting, and most of the legal difficulty is deciding which party is responsible at each hand-off.
Sets company law, insolvency treatment, whether the ledger can be the register, and what must be filed publicly.
Sets whether they may be offered the interest at all, what must be disclosed to them, and which regulator hears their complaint.
Sets what it may do and for whom. A partner’s licence is not a licence you hold; it is a licence you are relying on, and the scope of that reliance is worth writing down.
A software layer can build the contracts, keep the record, enforce the restrictions and present all of it through one interface. It can shorten a process from months to days. It cannot hold client assets without a custody permission, cannot be the register where that role is reserved, cannot introduce an offering without the relevant authorisation, and cannot make an investor eligible who is not.
That is not a limitation to be worked around. It is the shape of the field, and designs that acknowledge it early tend to reach production; designs that discover it late tend to be rebuilt.
The honest summary for anyone planning an issuance: assemble counsel in the vehicle’s jurisdiction, a custodian, a registrar or transfer agent, a licensed distributor if the offering reaches beyond people you already know, and a payment institution for the money leg. Then choose the technology.