{
  "$schema": "https://degreesofsatoshi.com/encyclopedia/schemas/article-v1.json",
  "schemaVersion": "1.0.0",
  "id": "protocol-upgrades-and-admin-powers",
  "canonical": "https://degreesofsatoshi.com/encyclopedia/protocol-upgrades-and-admin-powers/",
  "collection": "defi",
  "title": "Protocol upgrades and admin powers: who can change what",
  "description": "Understand proxy upgrades, roles and timelocks, and learn how to describe a protocol’s concrete powers without assuming all contracts are immutable.",
  "aliases": [
    "administrative powers",
    "smart contract upgrade"
  ],
  "dates": {
    "published": "2026-10-02",
    "modified": "2026-10-02",
    "verified": "2026-10-02T15:08:18.373Z",
    "dataAsOf": null
  },
  "authorship": {
    "publisher": "Degrees of Satoshi editorial project",
    "process": "AI-assisted research and drafting with a separate automated source-verification pass; no external expert or named human review is implied."
  },
  "quickAnswer": {
    "text": "An application’s rules can change when its design grants an administrator or governance system upgrade or configuration powers. A proxy can preserve a contract address while changing the implementation it executes. Timelocks and multiple signers constrain some actions, but their exact permissions and bypasses determine the protection.",
    "claimId": "protocol-upgrades-and-admin-powers-quick-answer",
    "sourceIds": [
      "proxy",
      "access"
    ]
  },
  "keyFacts": [
    {
      "label": "Proxy",
      "value": "Calls can delegate to an implementation chosen by upgrade logic.",
      "sourceIds": [
        "proxy"
      ],
      "id": "proxy",
      "claimId": "protocol-upgrades-and-admin-powers-fact-proxy"
    },
    {
      "label": "Roles",
      "value": "Different addresses can hold different privileged permissions.",
      "sourceIds": [
        "access"
      ],
      "id": "roles",
      "claimId": "protocol-upgrades-and-admin-powers-fact-roles"
    },
    {
      "label": "Timelock",
      "value": "Authorized operations can be scheduled for delayed execution.",
      "sourceIds": [
        "access",
        "governance"
      ],
      "id": "timelock",
      "claimId": "protocol-upgrades-and-admin-powers-fact-timelock"
    }
  ],
  "prerequisites": [
    "what-is-defi",
    "governance-tokens"
  ],
  "sections": [
    {
      "id": "proxy",
      "heading": "An unchanged address can execute changed logic",
      "paragraphs": [
        "A proxy receives calls and delegates execution to another implementation while using the proxy’s state. In an upgradeable design, an authorized operation can change the implementation target. Users may therefore keep interacting with the same address after behavior changes.",
        "OpenZeppelin documents different proxy patterns, including transparent and UUPS designs. Authorization and the location of upgrade logic differ, so identifying a proxy is only the start of determining who can alter it."
      ],
      "sourceIds": [
        "proxy"
      ]
    },
    {
      "id": "permissions",
      "heading": "Inventory the powers separately",
      "paragraphs": [
        "One role may pause a market, another may change a rate, and another may grant or revoke those roles. An owner or administrative role can be more consequential than an ordinary operator role because it controls who receives powers.",
        "For a concrete review, write down each privileged operation, its controlling address or role, and the rule for replacing that controller. Include asset-token controls and oracle controls as well as the main protocol contract."
      ],
      "sourceIds": [
        "access"
      ]
    },
    {
      "id": "delay",
      "heading": "A delay protects only the paths it governs",
      "paragraphs": [
        "A timelock can require a scheduled operation to wait before execution. A multisignature threshold can require several signers. Those mechanisms change the conditions for action; they do not remove the powers themselves.",
        "A separate emergency path, role-admin capability or upgrade authority may have different constraints. A statement that a protocol has a two-day delay is incomplete unless it specifies which operations are delayed and whether another authorized route can avoid it."
      ],
      "sourceIds": [
        "governance",
        "access"
      ]
    }
  ],
  "faq": [
    {
      "question": "Does verified source code mean the contract cannot change?",
      "answer": "No. Source verification describes the code associated with a deployment. A proxy can use an upgradeable implementation, and configuration or role changes can alter behavior without replacing that address.",
      "sourceIds": [
        "proxy",
        "access"
      ]
    }
  ],
  "claims": [
    {
      "id": "protocol-upgrades-and-admin-powers-quick-answer",
      "articleSlug": "protocol-upgrades-and-admin-powers",
      "statement": "An application’s rules can change when its design grants an administrator or governance system upgrade or configuration powers. A proxy can preserve a contract address while changing the implementation it executes. Timelocks and multiple signers constrain some actions, but their exact permissions and bypasses determine the protection.",
      "sourceIds": [
        "source-16bb921e662a5173",
        "source-56dd3f4220f6fea2"
      ],
      "sourceLocators": [
        {
          "sourceId": "source-16bb921e662a5173",
          "locator": "TransparentUpgradeableProxy; UUPSUpgradeable"
        },
        {
          "sourceId": "source-56dd3f4220f6fea2",
          "locator": "Ownership and Ownable; Role-Based Access Control; Delayed operation"
        }
      ],
      "scope": {
        "collection": "defi",
        "dataAsOf": null,
        "blockHeight": null
      },
      "qualification": "",
      "evidenceStatus": "documented",
      "verification": {
        "status": "verified",
        "method": "independent automated source review",
        "checkedAt": "2026-10-02T15:08:18.373Z",
        "reviewer": "automated independent verification",
        "notes": [
          "Read OpenZeppelin transparent/UUPS proxy authorization and access-control/timelock operation. Same address with different delegated implementation is supported; delay protects only constrained paths.",
          "Source verification, upgrade permissions and configuration authority remain separate. The QA does not turn verified code into a promise of immutability."
        ]
      }
    },
    {
      "id": "protocol-upgrades-and-admin-powers-fact-proxy",
      "articleSlug": "protocol-upgrades-and-admin-powers",
      "statement": "Proxy: Calls can delegate to an implementation chosen by upgrade logic.",
      "sourceIds": [
        "source-16bb921e662a5173"
      ],
      "sourceLocators": [
        {
          "sourceId": "source-16bb921e662a5173",
          "locator": "TransparentUpgradeableProxy; UUPSUpgradeable"
        }
      ],
      "scope": {
        "collection": "defi",
        "dataAsOf": null,
        "blockHeight": null
      },
      "qualification": "",
      "evidenceStatus": "documented",
      "verification": {
        "status": "verified",
        "method": "independent automated source review",
        "checkedAt": "2026-10-02T15:08:18.373Z",
        "reviewer": "automated independent verification",
        "notes": [
          "Read OpenZeppelin transparent/UUPS proxy authorization and access-control/timelock operation. Same address with different delegated implementation is supported; delay protects only constrained paths.",
          "Source verification, upgrade permissions and configuration authority remain separate. The QA does not turn verified code into a promise of immutability."
        ]
      }
    },
    {
      "id": "protocol-upgrades-and-admin-powers-fact-roles",
      "articleSlug": "protocol-upgrades-and-admin-powers",
      "statement": "Roles: Different addresses can hold different privileged permissions.",
      "sourceIds": [
        "source-56dd3f4220f6fea2"
      ],
      "sourceLocators": [
        {
          "sourceId": "source-56dd3f4220f6fea2",
          "locator": "Ownership and Ownable; Role-Based Access Control; Delayed operation"
        }
      ],
      "scope": {
        "collection": "defi",
        "dataAsOf": null,
        "blockHeight": null
      },
      "qualification": "",
      "evidenceStatus": "documented",
      "verification": {
        "status": "verified",
        "method": "independent automated source review",
        "checkedAt": "2026-10-02T15:08:18.373Z",
        "reviewer": "automated independent verification",
        "notes": [
          "Read OpenZeppelin transparent/UUPS proxy authorization and access-control/timelock operation. Same address with different delegated implementation is supported; delay protects only constrained paths.",
          "Source verification, upgrade permissions and configuration authority remain separate. The QA does not turn verified code into a promise of immutability."
        ]
      }
    },
    {
      "id": "protocol-upgrades-and-admin-powers-fact-timelock",
      "articleSlug": "protocol-upgrades-and-admin-powers",
      "statement": "Timelock: Authorized operations can be scheduled for delayed execution.",
      "sourceIds": [
        "source-56dd3f4220f6fea2",
        "source-5ae9ea0050b20bf7"
      ],
      "sourceLocators": [
        {
          "sourceId": "source-56dd3f4220f6fea2",
          "locator": "Ownership and Ownable; Role-Based Access Control; Delayed operation"
        },
        {
          "sourceId": "source-5ae9ea0050b20bf7",
          "locator": "Token; Governor; Timelock"
        }
      ],
      "scope": {
        "collection": "defi",
        "dataAsOf": null,
        "blockHeight": null
      },
      "qualification": "",
      "evidenceStatus": "documented",
      "verification": {
        "status": "verified",
        "method": "independent automated source review",
        "checkedAt": "2026-10-02T15:08:18.373Z",
        "reviewer": "automated independent verification",
        "notes": [
          "Read OpenZeppelin transparent/UUPS proxy authorization and access-control/timelock operation. Same address with different delegated implementation is supported; delay protects only constrained paths.",
          "Source verification, upgrade permissions and configuration authority remain separate. The QA does not turn verified code into a promise of immutability."
        ]
      }
    }
  ],
  "sources": [
    {
      "id": "proxy",
      "label": "Proxy contracts",
      "publisher": "OpenZeppelin",
      "url": "https://docs.openzeppelin.com/contracts/5.x/api/proxy",
      "locator": "TransparentUpgradeableProxy; UUPSUpgradeable",
      "note": "Proxy implementation changes and the authorization requirement.",
      "version": "OpenZeppelin Contracts 5.x",
      "checkedAt": "2026-10-02",
      "recordId": "source-16bb921e662a5173",
      "contentSha256": null
    },
    {
      "id": "access",
      "label": "Access control",
      "publisher": "OpenZeppelin",
      "url": "https://docs.openzeppelin.com/contracts/5.x/access-control",
      "locator": "Ownership and Ownable; Role-Based Access Control; Delayed operation",
      "note": "Ownership, roles, administrator authority and timelock limitations.",
      "version": "OpenZeppelin Contracts 5.x",
      "checkedAt": "2026-10-02",
      "recordId": "source-56dd3f4220f6fea2",
      "contentSha256": null
    },
    {
      "id": "governance",
      "label": "How to set up on-chain governance",
      "publisher": "OpenZeppelin",
      "url": "https://docs.openzeppelin.com/contracts/5.x/governance",
      "locator": "Token; Governor; Timelock",
      "note": "Delegation, historical voting power, quorum and delayed execution.",
      "version": "OpenZeppelin Contracts 5.x",
      "checkedAt": "2026-10-02",
      "recordId": "source-5ae9ea0050b20bf7",
      "contentSha256": null
    }
  ],
  "related": {
    "articles": [
      "decentralized-autonomous-organizations",
      "smart-contract-audits",
      "defi-composability"
    ],
    "dossiers": [],
    "wallets": []
  },
  "revisionHistory": [
    {
      "date": "2026-10-02",
      "kind": "published",
      "summary": "First publication after primary-source research and independent automated verification."
    }
  ],
  "citation": "Degrees of Satoshi editorial project. “Protocol upgrades and admin powers: who can change what.” Published 2026-10-02; updated 2026-10-02. https://degreesofsatoshi.com/encyclopedia/protocol-upgrades-and-admin-powers/"
}
