# Protocol upgrades and admin powers: who can change what

An application’s rules can change when its design grants an administrator or governance system upgrade or configuration powers. A proxy can preserve a contract address while changing the implementation it executes. Timelocks and multiple signers constrain some actions, but their exact permissions and bypasses determine the protection.

Evidence: [Proxy contracts](https://docs.openzeppelin.com/contracts/5.x/api/proxy); [Access control](https://docs.openzeppelin.com/contracts/5.x/access-control)

Canonical: https://degreesofsatoshi.com/encyclopedia/protocol-upgrades-and-admin-powers/
Published: 2026-10-02
Substantively modified: 2026-10-02
Independently verified by an automated reviewer: 2026-10-02T15:08:18.373Z

AI-assisted research and drafting with a separate automated source-verification pass; no external expert or named human review is implied.

## Key facts

- **Proxy:** Calls can delegate to an implementation chosen by upgrade logic. ([Proxy contracts](https://docs.openzeppelin.com/contracts/5.x/api/proxy))
- **Roles:** Different addresses can hold different privileged permissions. ([Access control](https://docs.openzeppelin.com/contracts/5.x/access-control))
- **Timelock:** Authorized operations can be scheduled for delayed execution. ([Access control](https://docs.openzeppelin.com/contracts/5.x/access-control); [How to set up on-chain governance](https://docs.openzeppelin.com/contracts/5.x/governance))

## An unchanged address can execute changed logic

A proxy receives calls and delegates execution to another implementation while using the proxy’s state. In an upgradeable design, an authorized operation can change the implementation target. Users may therefore keep interacting with the same address after behavior changes.

OpenZeppelin documents different proxy patterns, including transparent and UUPS designs. Authorization and the location of upgrade logic differ, so identifying a proxy is only the start of determining who can alter it.

Evidence: [Proxy contracts](https://docs.openzeppelin.com/contracts/5.x/api/proxy)

## Inventory the powers separately

One role may pause a market, another may change a rate, and another may grant or revoke those roles. An owner or administrative role can be more consequential than an ordinary operator role because it controls who receives powers.

For a concrete review, write down each privileged operation, its controlling address or role, and the rule for replacing that controller. Include asset-token controls and oracle controls as well as the main protocol contract.

Evidence: [Access control](https://docs.openzeppelin.com/contracts/5.x/access-control)

## A delay protects only the paths it governs

A timelock can require a scheduled operation to wait before execution. A multisignature threshold can require several signers. Those mechanisms change the conditions for action; they do not remove the powers themselves.

A separate emergency path, role-admin capability or upgrade authority may have different constraints. A statement that a protocol has a two-day delay is incomplete unless it specifies which operations are delayed and whether another authorized route can avoid it.

Evidence: [How to set up on-chain governance](https://docs.openzeppelin.com/contracts/5.x/governance); [Access control](https://docs.openzeppelin.com/contracts/5.x/access-control)

## Questions

### Does verified source code mean the contract cannot change?

No. Source verification describes the code associated with a deployment. A proxy can use an upgradeable implementation, and configuration or role changes can alter behavior without replacing that address.

Evidence: [Proxy contracts](https://docs.openzeppelin.com/contracts/5.x/api/proxy); [Access control](https://docs.openzeppelin.com/contracts/5.x/access-control)

## Claims and scope

### protocol-upgrades-and-admin-powers-quick-answer

An application’s rules can change when its design grants an administrator or governance system upgrade or configuration powers. A proxy can preserve a contract address while changing the implementation it executes. Timelocks and multiple signers constrain some actions, but their exact permissions and bypasses determine the protection.

Scope: {"collection":"defi","dataAsOf":null,"blockHeight":null}

### protocol-upgrades-and-admin-powers-fact-proxy

Proxy: Calls can delegate to an implementation chosen by upgrade logic.

Scope: {"collection":"defi","dataAsOf":null,"blockHeight":null}

### protocol-upgrades-and-admin-powers-fact-roles

Roles: Different addresses can hold different privileged permissions.

Scope: {"collection":"defi","dataAsOf":null,"blockHeight":null}

### protocol-upgrades-and-admin-powers-fact-timelock

Timelock: Authorized operations can be scheduled for delayed execution.

Scope: {"collection":"defi","dataAsOf":null,"blockHeight":null}

## Sources

- [Proxy contracts](https://docs.openzeppelin.com/contracts/5.x/api/proxy) — OpenZeppelin. Proxy implementation changes and the authorization requirement. Locator: TransparentUpgradeableProxy; UUPSUpgradeable. Retrieved: 2026-10-02.
- [Access control](https://docs.openzeppelin.com/contracts/5.x/access-control) — OpenZeppelin. Ownership, roles, administrator authority and timelock limitations. Locator: Ownership and Ownable; Role-Based Access Control; Delayed operation. Retrieved: 2026-10-02.
- [How to set up on-chain governance](https://docs.openzeppelin.com/contracts/5.x/governance) — OpenZeppelin. Delegation, historical voting power, quorum and delayed execution. Locator: Token; Governor; Timelock. Retrieved: 2026-10-02.

## Revision history

- 2026-10-02: First publication after primary-source research and independent automated verification.

## Cite this entry

Degrees of Satoshi editorial project. “Protocol upgrades and admin powers: who can change what.” Published 2026-10-02; updated 2026-10-02. https://degreesofsatoshi.com/encyclopedia/protocol-upgrades-and-admin-powers/
