Encyclopedia DeFi · Entry 72
Protocol upgrades and admin powers: who can change what
In this article
At a glance
Key facts
| Fact | Detail | Source |
|---|---|---|
| Proxy | Calls can delegate to an implementation chosen by upgrade logic. | [1] |
| Roles | Different addresses can hold different privileged permissions. | [2] |
| Timelock | Authorized operations can be scheduled for delayed execution. | [2][3] |
An unchanged address can execute changed logic
A proxy receives calls and delegates execution to another implementation while using the proxy’s state. In an upgradeable design, an authorized operation can change the implementation target. Users may therefore keep interacting with the same address after behavior changes.
OpenZeppelin documents different proxy patterns, including transparent and UUPS designs. Authorization and the location of upgrade logic differ, so identifying a proxy is only the start of determining who can alter it.
Inventory the powers separately
One role may pause a market, another may change a rate, and another may grant or revoke those roles. An owner or administrative role can be more consequential than an ordinary operator role because it controls who receives powers.
For a concrete review, write down each privileged operation, its controlling address or role, and the rule for replacing that controller. Include asset-token controls and oracle controls as well as the main protocol contract.
A delay protects only the paths it governs
A timelock can require a scheduled operation to wait before execution. A multisignature threshold can require several signers. Those mechanisms change the conditions for action; they do not remove the powers themselves.
A separate emergency path, role-admin capability or upgrade authority may have different constraints. A statement that a protocol has a two-day delay is incomplete unless it specifies which operations are delayed and whether another authorized route can avoid it.
Direct answers
Questions people ask
Does verified source code mean the contract cannot change?
No. Source verification describes the code associated with a deployment. A proxy can use an upgradeable implementation, and configuration or role changes can alter behavior without replacing that address.
Inspect the evidence
The answer and key facts have stable claim links. These records retain the scope and qualification when reused.
An application’s rules can change when its design grants an administrator or governance system upgrade or configuration powers. A proxy can preserve a contract address while changing the implementation it executes. Timelocks and multiple signers constrain some actions, but their exact permissions and bypasses determine the protection.
Scope: DeFi. Verification: verified · 2026-10-02T15:08:18.373Z.
Link to this claimProxy: Calls can delegate to an implementation chosen by upgrade logic.
Scope: DeFi. Verification: verified · 2026-10-02T15:08:18.373Z.
Link to this claimRoles: Different addresses can hold different privileged permissions.
Scope: DeFi. Verification: verified · 2026-10-02T15:08:18.373Z.
Link to this claimTimelock: Authorized operations can be scheduled for delayed execution.
Scope: DeFi. Verification: verified · 2026-10-02T15:08:18.373Z.
Link to this claimRevision history
- — First publication after primary-source research and independent automated verification.
On the Know who controls the funds path · You have reached the final entry in this path.
Source register
Sources and references
Retrieval dates and locators are recorded individually.- Proxy contractsOpenZeppelin
Proxy implementation changes and the authorization requirement.
Locator: TransparentUpgradeableProxy; UUPSUpgradeable · Version / scope: OpenZeppelin Contracts 5.x · Retrieved: 2026-10-02Open source - Access controlOpenZeppelin
Ownership, roles, administrator authority and timelock limitations.
Locator: Ownership and Ownable; Role-Based Access Control; Delayed operation · Version / scope: OpenZeppelin Contracts 5.x · Retrieved: 2026-10-02Open source - How to set up on-chain governanceOpenZeppelin
Delegation, historical voting power, quorum and delayed execution.
Locator: Token; Governor; Timelock · Version / scope: OpenZeppelin Contracts 5.x · Retrieved: 2026-10-02Open source
Research and drafting use AI assistance. A separate automated review checks claims against primary sources; no external expert or named human review is implied. Publication, substantive editing, source retrieval and verification are recorded separately. This version was independently checked by an automated reviewer on 2 October 2026.
Editorial method and correctionsDegrees of Satoshi editorial project. “Protocol upgrades and admin powers: who can change what.” Published 2026-10-02; updated 2026-10-02. https://degreesofsatoshi.com/encyclopedia/protocol-upgrades-and-admin-powers/