Wholesale CBDC Sample Application Workflow

After you install and configure the sample wholesale CBDC application, you can use it in scenarios where a system owner (a central bank) and participant organizations (other financial institutions) interact in an interbank market.

The sample application supports eleven roles, or personas. Each role has a different interface and set of operations that support the entire workflow of token management in the wholesale CBDC scenario.

Central Bank Roles

  • Central bank administrator: Configures tokens and organizations; creates wallets and CBDC accounts; sets limits, purposes, groups, and roles.
  • Central bank creator: Requests token creation and transfers the created value to a central bank issuer.
  • Central bank issuer: Issues value to participants and returns value for retirement..
  • Central bank manager: Approves or rejects creation, issuance, transfer, and retirement requests.
  • Central bank retirer: Submits retirement or burn requests.
  • Central bank auditor: Reviews network activity, balances, pending requests, and history without changing data.

Financial Institution Roles

  • Financial institution administrator: Manages participant wallets, accounts, application groups, status, and limits.
  • Financial institution manager: Approves or rejects transfers for the participant organization.
  • Financial institution officer: Deposits value to the central bank and transfers value to permitted users.
  • Financial institution user: Transfers value to permitted recipients.
  • Financial institution auditor: Reviews participant/organization activity without changing data.

Onboarding

After you install and configure the application, you prepare users, wallets, CBDC accounts, and ledger roles. Complete the following steps before you run token operations.

  1. The central bank administrator logs in first. Select the bootstrap wallet that was granted the Token Admin Besu role when the smart contract was initialized. This is the initial administrative entry point even before a CBDC account exists.
  2. The central bank administrator verifies the organization registry. Register or review the founder and participant organizations, confirm the founder sequence, and verify the organization order and display values. For more information, see Central Bank Administrator.
  3. The central bank administrator initializes the token and creates the initial accounts. Create wallets and CBDC accounts for central bank personas and for the financial institution administrators who will administer participating organizations. Select the correct wallet, application group, and account limits.
  4. Each participating organization is deployed and configured. Use the same one-click or local deployment process for the participant application. One-click deployment uses the Oracle Blockchain Platform configuration; local deployment requires manual configuration.
  5. The financial institution administrator logs in for the participant organization. Load or create the organization’s wallets, then create manager, officer, user, and auditor accounts using the permitted application groups and limits.
  6. The central bank administrator synchronizes manager roles. After each financial institution manager account is created, use the Account Actions > Sync Roles command on that account to apply its Escrow ledger role. Application groups control workspace access; ledger roles control contract operations.
  7. Each persona logs in and verifies access. Select the intended wallet when more than one is available, confirm the correct workspace opens, and verify that permitted and restricted actions match the assigned application group and ledger role. Use the persona sequence in the following table.
  8. After all persona configuration and access checks are complete, follow the application workflow to work with the wholesale CBDC token life cycle.

Persona Sequence

Sequence Persona Responsibility Information
1 Central bank administrator Completes central bank, organization, wallet, account, and role setup. Central Bank Administrator
2 Financial institution administrator Sets up participant wallets and accounts. Financial Institution Administrator
3 Central bank creator Submit requests to create tokens. Central Bank Creator
4 Central bank manager Approves or rejects creation requests. Central Bank Manager
5 Central bank issuer Issues value to participants and returns value for retirement. Central Bank Issuer
6 Financial institution manager Approves or rejects participant transfers. Financial Institution Manager
7 Financial institution officer Deposits and transfers value. Financial Institution Officer
8 Financial institution user Transfers value to permitted recipients. Financial Institution User
9 Central bank retirer Submits retirement requests after value is returned. Central Bank Retirer
10 Central bank auditor Reviews central bank activity and history. Central Bank Auditor
11 Financial institution auditor Review participant organization activity and history. Financial Institution Auditor

Application Workflow (Token Life Cycle)

After deployment and setup, the personas in the scenario engage in the following tasks as part of the complete token life cycle.

  1. The central bank creator requests token creation. The request remains pending and does not yet credit the creator.
  2. The central bank manager approves or rejects the creation request. Approval credits the creator; rejection does not.
  3. The central bank creator transfers approved value directly to the central bank issuer. This transfer has no additional approval step.
  4. The central bank issuer transfers directly to the central bank retirer to return value for retirement, or submits a distribution to a financial institution officer. The officer distribution is held for central bank manager approval; rejection releases the hold.
  5. The financial institution officer transfers to the central bank issuer, another financial institution officer, or a financial institution user. Each officer transfer is held for financial institution manager approval; rejection releases the hold.
  6. A financial institution user transfers to a permitted financial institution officer or user. Each user transfer is held for financial institution manager approval; rejection releases the hold.
  7. The central bank retirer submits a burn request after receiving value. The central bank manager approves or rejects the request. Approval removes the value from circulation; rejection leaves the burn incomplete.
  8. The central bank auditor reviews central bank and financial institution activity available to its audit scope. The financial institution auditor reviews their own institution’s activity. Both use operation IDs and final history states to reconcile the sequence.

After each request or decision, refresh the sender, recipient, manager, and auditor views as applicable. Confirm the final status and balance before submitting another operation.