From Motivational to Imperative: Strengthening Commitments with PriFi
Making commitments credible through structural design choices

Institutions have spent centuries developing ways to inspire faith in the promises they make about future conduct. Typically, these have involved incentives. However, cryptonetworks demonstrated an alternative: strengthening commitments by incorporating them into a system’s architecture.
To enter into an agreement, we need a reasonable expectation that the other party or the institution facilitating an exchange will uphold their side. However, problems regarding the credibility of such promises arise because such agreements are typically made at one moment and honoured at a later one.
Between those two points, circumstances can change. The incentives facing the promisor may be different, the people responsible for honouring the commitment may have been replaced, or an external actor may make continued compliance much more expensive than anyone anticipated when the agreement was made.
Economists have examined versions of this problem across monetary policy, political institutions, corporate contracting, and commercial exchange. Finn Kydland and Edward Prescott described the closely related problem of time inconsistency: a policy that appears optimal when announced may no longer seem so when the moment of implementation arrives. If other actors anticipate a future reversal, they may change their behaviour in advance, meaning that the risk of future defection can impose economic costs before any commitment has actually been entered into (Kydland & Prescott, 1977).
A commitment’s credibility, i.e., the likelihood that other parties will honour it, is a vital consideration when entering into agreements. Fundamental to a commitment’s credibility are the factors that might encourage a party to honour it or prevent one from breaking it if circumstances do, in fact, change. Economists categorise commitments into two grades of credibility: motivational and imperative.
This article builds on the recently published introduction to PriFi and examines how the credibility of commitments can be strengthened throughout the whole transaction supply chain.

It explains two grades of credibility, looking at historical examples of motivational credibility and the breakthrough that cryptonetworks made in terms of elevating commitments from purely motivational to imperative. The article goes on to introduce Muster, an app built with the Logos stack to visualise where privacy leaks and infrastructure dependencies exist when making onchain transactions.
Ultimately, it asks, can PriFi infrastructure and tooling bring greater assurances to other links in the transaction supply chain, just as blockchain did for transaction settlement? Learn more about how Logos infrastructure is designed to strengthen commitment across the entire transaction supply chain.
Two grades of credibility
Institutional economics outlines two grades of commitment credibility: motivational and imperative. Kenneth Shepsle distinguishes commitments in which credibility arises from incentives from those in which performance is enforced by constraints on the promisor’s subsequent discretion, an observation that Douglass North subsequently incorporated into his analysis of institutions and credible commitments (Shepsle, 1991; North, 1993).

A commitment is motivationally credible when the party responsible for performing it retains the discretion to defect but continues to prefer compliance. Reputation, future business, collateral, franchise value, contractual penalties, and legal consequences are all considered motivational assurances. The surrounding incentives make honouring the agreement more preferable than defection.
Oliver Williamson’s analysis of credible commitments in commercial exchange captures this logic. Parties to an agreement can provide greater assurances by placing valuable assets at risk through collateral and other forms of economic “hostage”. By doing so, they increase the cost of opportunistic defection (Williamson, 1983). Defection remains possible, but its economics have shifted to incentivise compliance.
By contrast, with imperative credibility, the ability to defect is constrained, removed, or subject to an enforcement mechanism that the promisor cannot simply override (Shepsle, 1991; North, 1993). The guarantee, therefore, is stronger because the set of available future actions has been narrowed, making compliance no longer a matter of preference.
We can consider motivational credibility to be rented credibility because it must be continually reproduced through favourable incentives. Conversely, we can consider imperative credibility as owned because structural constraints on future actions mitigate the extent to which the commitment depends on the promisor continuing to want the outcome they previously agreed to.
Although imperative commitments are undoubtedly a stronger form of commitment, we should not dismiss motivationally credible commitments entirely. For most of history, civilisation as we know it depended on this form of assurance, putting it among our most important institutional technologies.
The institutional achievement of motivation
To illustrate motivational credibility, we can consider the example of central-bank independence. Governments often have an incentive to pursue short-term increases in output or employment even when doing so conflicts with previously announced commitments regarding price stability. If households, lenders, firms, and wage-setters anticipate that possibility, their expectations can themselves produce an inflationary bias. Workers may demand higher nominal wages to protect their purchasing power against expected inflation, firms may incorporate higher expected costs into prices, and lenders may demand higher nominal interest rates to compensate for the anticipated erosion of the real value of repayments. Inflation expectations can, therefore, become embedded in economic decisions before policymakers have actually departed from their stated commitment. The mere expectation that policymakers may exploit future discretion can weaken the effectiveness of the commitment itself (Kydland & Prescott, 1977).
One response is institutional delegation. Kenneth Rogoff showed how appointing a central banker who places greater importance on price stability than the political authority can reduce the inflationary consequences of discretionary monetary policy (Rogoff, 1985). Central-bank independence changes who exercises discretion and the incentives under which that discretion is exercised. It does not abolish judgement; rather, it attempts to insulate judgement from particular short-term political pressures.
This is a sophisticated form of self-binding that demonstrates why motivational credibility cannot simply be reduced to trusting actors to behave themselves. Institutions can strengthen motivational commitments by separating powers, delegating authority, imposing professional norms, creating reputational consequences, and lengthening the horizon over which decision makers expect to bear the consequences of their actions.
Commercial arrangements can produce similar results. Collateral does not make default physically impossible; it makes default more expensive. Long-term contracting, warranties, bonding arrangements, and reciprocal investments mean parties have something valuable to lose if they behave opportunistically (Williamson, 1983).
While these mechanisms can be extremely effective, their limitation is narrower: the actor still retains some capacity to behave differently, while the institutions producing the desired incentives can themselves be altered, overridden, or overwhelmed. Rather than considering motivational credibility as a weak form of credibility, it’s better to understand it as credibility that’s contingent on conditions remaining consistent with those under which an agreement was made.
Bretton Woods and shifting incentives
The collapse of the Bretton Woods monetary system illustrates the importance of such contingencies. Under the post-war monetary order, currencies were pegged to the US dollar, while foreign monetary authorities could convert dollars into gold at $35 per ounce. In its mature phase, the arrangement delivered considerable monetary stability, but its operation surfaced a growing tension between the international demand for dollar liquidity and confidence in the United States’ ability and willingness to maintain gold convertibility (Bordo, 1993).
As dollar liabilities accumulated abroad relative to US gold reserves, maintaining the commitment became progressively more difficult. However, the system did not collapse at the first sign of pressure. Governments and central banks developed additional arrangements intended to support it, including coordinated interventions and measures designed to discourage conversions. Its survival for years under these pressures is evidence that the commitment possessed meaningful credibility rather than none at all (Bordo, 1993).
Eventually, however, the cost-benefit calculation changed. On 15 August 1971, President Richard Nixon suspended the dollar’s convertibility into gold for foreign monetary authorities. Although further attempts were made to preserve the fixed-exchange-rate system, Bretton Woods ultimately gave way to floating exchange rates (Bordo, 1993).
We can debate whether the decision was correct or not. However, the important point was that the commitment depended on the United States continuing to deem maintaining convertibility as preferable to suspending it. Once circumstances changed sufficiently, the promisor exercised its ability to renege on its earlier agreement.
This is a characteristic limit of motivational credibility. Defection does not require the promisor to have been dishonest when the commitment was originally made. Nor does it necessarily indicate that the later decision was irrational. Conditions can simply change enough to reverse the incentives supporting the original promise.
Swiss banking secrecy and the problem of coercion
Motivational credibility can encounter a different problem when the promisor’s preferences remain relatively stable, but an outside actor changes the incentives on its behalf. Swiss banking secrecy provides a useful illustration.
Confidentiality was not merely a matter of custom or corporate policy; banking secrecy had become a professional norm before being formalised in Swiss law in 1934, with disclosure of client information subject to significant legal sanctions. Confidentiality was subsequently reinforced through the interests of banks, employees, clients, and a financial sector whose international position was partly associated with its capacity to provide secrecy (Überbacher & Scherer, 2020).
For decades, these arrangements produced a strong commitment. Swiss institutions had legal, commercial, professional, and reputational reasons to preserve client confidentiality. However, the commitment still had to be implemented through identifiable banks, employees, and public institutions. Those actors represented points at which external pressure could be applied.
Florian Überbacher and Andreas Scherer’s study of the confrontation between US authorities and Switzerland following investigations into undeclared American assets describes this process as “indirect compellence”. US authorities could not simply rewrite the Swiss secrecy legislation directly. Instead, they could threaten Swiss banks and bankers with prosecution and exclusion from economically important relationships, thereby imposing costs that would change the incentives Swiss policymakers themselves faced. The result was an erosion of secrecy rules that had previously appeared highly durable (Überbacher & Scherer, 2020).
The commitment did not fail through ordinary commercial temptation. The organisations involved had powerful reasons to preserve it. Rather, another actor acquired sufficient leverage to make continued non-defection more expensive.
Consequently, Bretton Woods and Swiss banking secrecy reveal two different limits of motivational credibility. In the former case, the promisor’s own incentives evolved over time. In the latter, an external actor succeeded in changing them. Both cases help illustrate why motivational credibility can be described as rented. A commitment’s credibility hinges on the incentives to sustain it continuing to outweigh those to defect, regardless of future condition changes.
The economic value of commitment capacity
Commitment credibility affects the terms on which economic activity can occur. Where future behaviour remains uncertain, counterparties attempt to protect themselves. Lenders might require additional collateral, while firms might conduct more extensive due diligence, purchase insurance, employ lawyers, use escrow arrangements, or rely on specialised intermediaries. At some point, the costs associated with managing uncertainty can exceed the expected gains from exchange, and a transaction that might otherwise have been productive will not occur.
Williamson’s transaction-cost approach treats governance structures as responses to precisely these kinds of contractual hazards (Williamson, 1983; Williamson, 1996). North similarly places credible commitment at the centre of institutional arrangements capable of supporting more complex and impersonal forms of exchange (North, 1993). The value of a credible commitment can be understood partly through the hazard premium it removes.
This suggests a broader measure of institutional quality: commitment capacity. An institution’s commitment capacity is its demonstrated ability to bind its own future conduct, and the conduct of its agents, against circumstances in which deviation becomes attractive.
The quality of institutional promises is revealed when maintaining the commitment becomes costly. Cryptonetworks are significant here because they introduced a new mechanism through which that capacity can be produced.
Moving from incentive-based to architecture-based assurances
Bitcoin was explicitly designed to remove dependence on trusted third parties for the prevention of double spending. Instead of relying on an institution that promises to maintain an authoritative ledger honestly, participants independently verify transactions and the history of the network according to shared protocol rules (Nakamoto, 2008).
A node enforcing the rule set does not need to assess whether recognising an invalid transaction would be commercially advantageous, whether the party requesting an exception has sufficient political influence, or whether making the exception would preserve an institution’s reputation. If a transaction or block fails the validity conditions that the node enforces, it is rejected.
This form of imperative commitment is qualitatively different from an institutional arrangement in which an operator retains the ability to make exceptions but faces incentives not to exercise that authority. A motivational arrangement attempts to make compliance the most attractive option. A protocol attempts to make a class of non-compliant outcomes invalid. The commitment has moved, at least in part, from being based on incentives to being based on architectures.
This does not imply that Bitcoin, or cryptonetworks more generally, are perfectly immutable or free from governance changes that could undermine the commitments participants expected to be honoured. Protocols evolve, software contains assumptions and possible defects, communities disagree, and rule changes can occur through social coordination.
Primavera De Filippi and Benjamin Loveluck distinguish between governance by infrastructure, in which rules are embedded and automatically implemented through technical architecture, and governance of infrastructure, through which developers, users, miners, and other stakeholders negotiate changes to the system itself (De Filippi & Loveluck, 2016). As such, cryptonetworks do not eliminate all human decision making, but instead, relocate a lot of it. Certain forms of discretion are architecturally constrained. However, maintaining the rule set is still a governance problem.
This observation explains why protocol forks are institutionally different from other forms of defection. A change to a cryptonetwork’s rules requires participants to coordinate around a different version of the system. The change is visible to all, and participants can choose whether to adopt it, reject it, or follow a competing set of rules. That is fundamentally different from upholding an existing rule while allowing a privileged authority to exempt a favoured (or unfavoured) participant from it.
Despite this important caveat, cryptonetworks still produce a form of self-binding that no institutions before them have achieved. By elevating the quality of commitments from motivationally credible to imperatively credible, they radically constrain the discretion to defect at the architectural level.
Beyond “trustlessness”
The above caveat helps refine a word that crypto has often used imprecisely: “trustless”. Trust does not disappear from cryptonetworks. Users make assumptions about software implementations, hardware, cryptographic primitives, developers, governance procedures, interfaces, economic incentives, and the wider environment in which protocols operate.
Crypto’s more specific achievement is that some commitments no longer depend on the continuing restraint of a privileged decision maker. This raises a question fundamental to PriFi:
Can other commitments be moved from behaviour into architecture?
Discretion makes room for opportunism. An actor capable of making a beneficial exception may possess the same capacity to make a self-interested, coerced, or discriminatory one. With institutions deployed on infrastructure designed to minimise trust, we can limit discretion to defect, thus hugely reducing the cost of protecting against such defections through motivational means.
Shrinking commitment surfaces
If an attack surface describes the points through which a system might be compromised, a commitment surface describes the points at which a desired outcome still depends on another actor exercising discretion in the user’s favour. Suppose an infrastructure provider can observe users’ queries but maintains a policy prohibiting their retention or commercial exploitation. The policy may be strong, the company may have a valuable reputation to protect, and legal penalties may apply to misuse. Nevertheless, the information remains available to the operator. The protection is, therefore, substantially motivational.
PriFi attempts to shrink that commitment surface by designing systems such that the equivalent operator never receives the information in the first place. Rather than strengthening the promise governing future behaviour, the system has reduced the discretion available.
The same can be applied to a frontend capable of misrepresenting an instruction before signature, a communications service capable of observing metadata, an intermediary capable of censoring access, or an infrastructure provider capable of exploiting privileged order flow. In each case, minimising both the attack surface and commitment surface results in stronger assurances that a transaction will unfold as intended.
Consider private transaction routing. Moving an order away from a public mempool can reduce exposure to unrelated observers, thereby improving privacy. Yet, if the private routing provider itself can inspect the order, the system has introduced another form of commitment. The user must now rely on the intermediary not to trade against the information, disclose it, selectively censor it, or succumb to pressure from someone else.
Reducing the commitment surface with Logos
Credible commitment theory offers a way to understand Logos's architectural objective. Logos is designed around the premise that imperative protections should exist in the infrastructure itself rather than being reconstructed independently by each application or “bolted on” afterwards. The stack combines a locally operated runtime with privacy-preserving networking, messaging, distributed storage, blockchain infrastructure, and app modules.
Consider the difference between a cloud platform promising not to collect information about users and an architecture that removes the equivalent hosted operator from the interaction. Basecamp runs the Logos stack locally on the user’s own hardware, without requiring an account, a hosted backend, or a telemetry layer. This does not eliminate every trust assumption in the system. It does, however, alter the commitment surface by removing a central platform operator whose continued restraint would otherwise form part of the user’s security model.
A similar distinction applies to communication. Logos Messaging uses a peer-to-peer relay network without a central intermediary, combining that transport with protocols intended to support private communication and metadata protection. Again, the meaningful institutional change is not that every possible form of discretion disappears. Rather, a capability that would conventionally be concentrated in a central service provider is removed.
Elevating commitments from motivational to imperative credibility rarely consists of a single transition from “trusted” to “trustless”. More often, it involves repeatedly identifying unnecessary powers and redesigning the system so that fewer important guarantees depend solely upon somebody declining to misuse them.
Muster: Imperative commitments visualised
Muster, built with the Logos stack, provides a concrete environment for examining where coordination depends on trust, and where guarantees can instead be enforced by technical conditions. It is designed as an educational and demonstrative application for coordinating transactional activity inside private conversations, while making visible the information disclosed across the transaction lifecycle. Muster is an early-stage, unaudited app developed by Corey Petty and should not be considered production-ready software. It is under very active development, so expect its capabilities to expand in future releases.
In its current implementation, participants can coordinate and execute a privacy-preserving token transfer through an encrypted room, while Muster surfaces what information has been exposed and where the surrounding infrastructure still introduces dependencies. This makes Muster useful for thinking about the distinction between different grades of commitment, even where particular commitment mechanisms have not been implemented in the application itself yet.
Imagine that three participants jointly control an asset, but one participant technically possesses unilateral authority and simply promises not to exercise it without another actor’s approval. That promise can have motivational credibility. Reputation, contracts, legal obligations, and the expectation of continued cooperation may make unilateral action extremely unattractive. However, the underlying capability still remains.
A 2-of-3 authorisation rule changes the situation. No single participant possesses sufficient authority to satisfy the execution condition alone. The commitment that no individual will act opportunistically is, therefore, no longer secured solely by that individual’s future willingness to honour the arrangement. Unilateral execution fails the rule itself, shifting the commitment from incentive-based credibility to architecture-based credibility.
Muster asks which parts of an interaction are actually protected by the system, and which still depend on participants or infrastructure behaving as expected. Its current interface exposes the state of a private coordination room, the information that may have leaked from it, and the infrastructure involved in carrying an action through to execution. In this sense, it can be used as the basis for a broader commitment audit by making otherwise hidden dependencies visible.
The broader Logos environment extends that analysis beyond the final authorisation condition. This goes beyond whether execution can be constrained by a rule such as multisignature approval, and instead questions how much of the surrounding interaction still depends on intermediaries or infrastructure that can observe, expose, censor, or otherwise affect coordination.
Muster makes those dependencies clearly visible, helping users to understand the nature of commitment grades and distinguish between protections that currently rest on trust from those that are structurally enforced.
PriFi as the architecture of credible commitments
The history of institutional development is, in part, a history of increasingly sophisticated mechanisms for making future conduct credible. Reputation, collateral, contracts, delegated authorities, courts, and constitutional arrangements can all constrain opportunism by changing the incentives surrounding it.
Their importance should not be understated: motivational credibility enables economic coordination at an enormous scale and will remain appropriate in many contexts precisely because institutions require flexibility, judgement, and mechanisms for adapting to circumstances that cannot be specified in advance. Its characteristic limitation is nevertheless unavoidable: incentives are contingent, and conditions change.
Cryptonetworks demonstrated that commitments assumed to be always motivational can be elevated to imperative commitments. Rather than depending exclusively on an actor continuing to have sufficient reason to comply, a system’s architecture can remove or sharply constrain discretion. PriFi expands on this insight, making credibility a product of architectural designs rather than rented in exchange for ongoing incentives to honour previous agreements.
Explore Muster.
Run Muster through Logos Basecamp.
Read more transaction supply chain research.
Selected references
Bordo, Michael D. (1993), “The Bretton Woods International Monetary System: A Historical Overview”, A Retrospective on the Bretton Woods System: Lessons for International Monetary Reform (Chicago: University of Chicago Press), 3–108.
De Filippi, Primavera, and Benjamin Loveluck (2016), “The Invisible Politics of Bitcoin: Governance Crisis of a Decentralised Infrastructure”, Internet Policy Review, 5(3).
Kydland, Finn E., and Edward C. Prescott (1977), “Rules Rather than Discretion: The Inconsistency of Optimal Plans”, Journal of Political Economy, 85(3), 473–491.
Nakamoto, Satoshi (2008), “Bitcoin: A Peer-to-Peer Electronic Cash System”.
North, Douglass C. (1993), “Institutions and Credible Commitment”, Journal of Institutional and Theoretical Economics, 149(1), 11–23.
Rogoff, Kenneth (1985), “The Optimal Degree of Commitment to an Intermediate Monetary Target”, The Quarterly Journal of Economics, 100(4), 1169–1189.
Shepsle, Kenneth A. (1991), “Discretion, Institutions, and the Problem of Government Commitment”, Social Theory for a Changing Society (Boulder, CO: Westview Press).
Überbacher, Florian, and Andreas Georg Scherer (2020), “Indirect Compellence and Institutional Change: U.S. Extraterritorial Law Enforcement and the Erosion of Swiss Banking Secrecy”, Administrative Science Quarterly, 65(3), 565–605.
Williamson, Oliver E. (1983), “Credible Commitments: Using Hostages to Support Exchange”, American Economic Review, 73(4), 519–540.
Williamson, Oliver E. (1996), The Mechanisms of Governance (Oxford: Oxford University Press).