Arbitration service

DemoThemis The most ambitious arbitration service ever made

5 min read

The simple version

DemoThemis is a bullet proof, unbuyable arbitration service. Anyone can fund the jurors and receive a ruling. When money is involved, an optional protocol escrow can execute it automatically.

Automatic Mode lets DemoThemis choose a safe court automatically; Manual Mode lets the requesting application set a custom configuration.

Problem and role

Why applications need a neutral court

From day zero, DemoThemis lets any platform offer the best dispute resolution solution to ever exist and optional escrow that both the business and its customers can trust, without first reaching the scale to build and run either itself.

Why it exists

DemoThemis gives applications a neutral court they do not control, so the application is not in conflict with the arbitration

Existing model
Broken

Dependence creates a conflict

Delegated power

You trust whoever settles the dispute

When you book an Airbnb, take an Uber, buy on eBay, order through DoorDash, or bet online, you are trusting whoever can reverse the payment if the deal goes wrong.

Conflicted control

The decision-maker is usually conflicted

An internal arbitrator works for the organization whose revenue, refund costs, largest customers, or reputation may depend on the outcome. If the jury is token weighted, token voters may also own positions affected by the ruling.

See the Polymarket token-weighted court problems
Protocol model
Fixed

Separation creates shared infrastructure

Escrow separation

Escrow changes the power

When assets are at stake, protocol escrow lets the app provide the interface without controlling the funds or outcome.

Shared scale

A shared court can compound

Many apps can use one arbiter, and the court gets better as more cases create fees, records, and evidence of juror quality.

Case lifecycle

What happens from the initial protocol request to the final ruling

DemoThemis either configures the court automatically or follows a Manual Mode route set by the requesting application. At the initial protocol request, it calculates and collects the full court fee, funding the panel before jurors are drawn.

  1. Case and fee are set

    Before the draw, the requesting application sets the case, evidence rules, court setup, result handling, and full initial fee. Automatic Mode lets DemoThemis choose the court; Manual Mode follows the route published before the case.

  2. Jurors are drawn

    World-ID humans enter one shared generalist pool. A public source of unpredictable numbers draws one panel, bound to the case. Anyone who does not assess themselves as capable of judging it can decline. The selector then runs again using the original case-bound randomness plus the next unused position. Nobody is reserved beforehand. A juror serves one case at a time. An accepted seat blocks new draws until that case resolves, so slow service costs the juror their own next draw. If an accepted case cannot seat a full panel before its fixed deadline, it unwinds instead of shrinking. The unused fee returns and no ruling is issued.

  3. Presence is checked

    After Orb verification creates the seat, a draw-bound on-device presence/continuity check confirms the enrolled human is participating now. This prevents rented jury seats; it is not a Device-only route into the jury.

  4. Votes stay private

    Receipt-free encrypted ballots let the court count the result without revealing or proving any single vote.

  5. Appeals follow fixed case terms

    Before acceptance, every case fixes a finite route and declining appeal-funding windows. Automatic Mode chooses the route; applications set the Manual Mode route. Every stage draws fresh jurors. A court can also answer that there is not enough information. The case ends without a YES or NO, and any connected escrow follows the no-ruling rule both sides accepted at the start.

  6. The ruling returns

    DemoThemis returns a final signed ruling. Connected escrow, if any, releases or refunds by rule; collusion audits can continue afterward.

Attack resistance

Protections against buying or controlling the court

Attack model

Six protections make buying the court impractical when every condition is met

To really understand how DemoThemis is bullet proof, go to the Fortify The Court chapter. It shows how Automatic Mode makes the credible attack unprofitable in proportion to governed exposure, while disclosing a separate 25% systemic-compromise stress test, and lets you test what happens when individual protections fail.

1

One juror = one human

Money can buy tokens, but it cannot mint more unique people. A verdict has to be assembled from humans, not wallets.

2

Careless voting has a cost

Jurors can be privately penalized for careless mistakes, making guessing unprofitable without giving richer people more voting power.

3

The jury cannot be rerolled

Each case gets one publicly verifiable random draw. The requesting person or application and DemoThemis must accept that panel; neither can discard it and try again.

4

Rented accounts get squeezed

A per-draw face check makes a one-time credential hard to operate remotely at the moment a vote matters.

5

Paid votes cannot prove delivery

A briber pays only for a vote they can verify. Receipt-free ballots make that proof unavailable even to a willing seller.

6

Protection is explicit

Automatic Mode chooses the least costly court that keeps the published credible attack uneconomic, caps expected corruption loss, and clears quality, formation, capacity, and funding gates. A $1,000 microcase may start with one senior juror and precommit a fresh three-juror appeal. Manual Mode follows a route set in advance. Either can govern escrow or return a signed ruling.

Juror quality

Protocol quality rewards careful judgment without public vote histories

Juror quality

How the shared court learns juror quality

DemoThemis does not treat the first majority as proof that each juror judged well. It builds the private quality record from appeal outcomes, blinded audits after reversals, and later independent confirmation when it exists.

Every case is recordedMarket outcomes, theoretically, DoorDash delivery disputes, and judgment calls all enter the same private juror-quality history.
Review overturned decisionsA juror can privately explain a difficult vote before the result. If an appeal overturns the panel, fresh auditors can separate reasonable disagreement from careless work.
Use every available checkAppeal outcomes and later real-world evidence can strengthen or correct a juror’s record.
Jurors are judged by patterns, not a few resultsA few bad results do not prove a juror is unreliable. The protocol becomes more confident as they complete more cases and changes their standing only when a clear pattern emerges.
Pay does most of the rewardCareful jurors earn more and get drawn more often, but caps stop any one juror from dominating the pool.

Bootstrap

Any application can bring demand to DemoThemis

DemoThemis does not depend on any one application for demand or funding. Any person or application can submit a well-defined case, pay the full court fee before jurors are drawn, and receive a ruling. Every completed case creates an entry in the shared private juror-quality record.

Switch to Deep dive for the mechanics and interactive stress tests behind each claim.

20 min read

Under the hood

Read straight through, or jump to the layer whose assumptions you want to inspect.

Part 1 · Problem and role

Value proposition: neutral arbitration any application can use

You never really trusted the stranger whose spare room you booked through Airbnb. You trusted the arbiter standing behind the deal. Make that arbiter unbuyable and affordable, and more apps can rely on it. Prediction markets need the same neutrality: bettors must trust the court, and token-weighted failures show what happens when it can be bought.

Booking an Airbnb from a stranger and paying before arrival looks reckless on paper. It feels ordinary because Airbnb can refund you, a card issuer can reverse the charge, and reviews punish repeat cheating. The safety comes from the arbiter behind the stranger.

Marketplaces such as eBay, gig apps such as Uber, ad auctions such as Google Ads, app stores such as Apple's App Store, and prediction markets such as Polymarket and Kalshi all outsource dispute resolution to a platform, bank, or token vote. The result can be house owned (the outcome resolution is more likely to resolve in whatever direction favors the interest of the application managing the resolution rather than what is most true or fair), slow, expensive, or buyable by the largest holders like UMA and Kleros. DemoThemis turns that hidden utility into shared, unbuyable arbitration, with optional protocol escrow if applications want us to handle escrow.

Better-than-world-class dispute resolution from day -1

From day -1, DemoThemis gives any platform better-than-world-class customer dispute resolution and optional escrow, even before it has the scale, in-house dispute operation, case history, or capital to build a system people can trust. Businesses get a neutral court they do not have to run, customers get rulings neither side can buy, and protocol escrow can hold and release funds automatically when money is involved.

One court, many apps

Build the arbiter once, share it everywhere

Any person or app can submit a well-defined case, fund its jurors, and receive an independent ruling from randomly drawn, verified humans. If assets are involved, optional escrow can execute that ruling automatically.

Airbnb · rooms
Uber · rides
eBay · goods
Google Ads · ads
DemoThemis courtfunded jurors, random panels, private votes
A signed ruling and optional automatic execution
Many apps, one shared arbiter. The court answers to none of them, which is exactly why all of them can use it.

The requesting person or application supplies the case, decision criteria, evidence rules, and juror fee. DemoThemis returns the ruling; when assets are involved, optional escrow can release or refund them by rule. Each customer replaces a private dispute-resolution system with one shared court.

The court fee

Charge a one-time court fee for each case

When a resolution request is accepted, the protocol calculates one court fee using the fee rules in force for that case: processing cost + required panel compensation + contribution to future juror rewards + capped operations charge. The requesting person or application pays it before the draw.

1

Pay follows the work

Juror pay responds to eligible supply, case volume, panel size, expected time, and complexity.

2

Operations has a ceiling

An approved, public budget is recovered only up to a hard per-case cap, never as a permanent revenue share.

3

Appeals are funded separately

Each funded appeal pays once for its new panel and delay. Any refundable appeal deposit is tracked separately from court revenue.

Every court, with or without escrow, prepays its complete work quote. Case value may determine how much protection Automatic Mode requires, but it never caps juror compensation or the court fee. An application either funds the exact quote or no case opens; every accepted quote freezes before the draw, whether the setup is Automatic Mode or Manual Mode.

Qualified supply and demand determine juror compensation under the published pricing rules. Those rules can change only between scheduled policy updates, and no application-provided budget, escrow value, or payout rule can reduce the quote for an accepted case. The rate responds to court-wide demand, eligible supply, pending workload, response time, and panel size. Time and complexity bands are recalibrated between policy updates from measured juror service, using medians so no single case can move them.

Part 2 · Attack resistance

How we make the court unbuyable

A court becomes unbuyable against practical attacks only when six protections work together: one verified human per jury seat, a single unpredictable draw, a live face check, private ballots, a court and appeal route fixed before juror selection, and a quality record that penalizes careless jury work.

Every case is requested in one of two modes. In Automatic Mode, DemoThemis picks the jury size and appeal route that keeps an attack unprofitable, then quotes the fee. In Manual Mode, the requesting application picks them itself. Both modes run the same six protections; the mode only decides who sizes the court.

To really understand how DemoThemis is bullet proof, go to the Fortify The Court chapter. Its Attack Simulator lets you raise attacker pressure, switch individual protections off, and see where capture becomes possible.

The wrong foundation

When votes are tokens, verdicts have a price

Token courts like UMA and Kleros sell the gavel to the deepest pocket. This court seats verified humans instead: one verified person per seat, a die nobody can re-roll, a face check that proves a real person is voting, and a ballot that cannot prove how it voted. Buying it means buying people, one at a time, in the dark.

In token courts like UMA and Kleros, voting weight follows the wallet, so a majority has a market price. Disputed Polymarket resolutions show the problem in practice; the evidence is in the OmenMarketMaker chapter.

That is not merely a bad implementation. If stake is voting power, the protocol works as written when the largest holder wins. An attacker reads the rule as a price list: acquire enough tokens and buy the verdict.

DemoThemis swaps the foundation to one human, one vote. Every seat is backed by a World ID that no wallet can mint twice or exchange can sell in bulk. An attacker must recruit people separately, keep them present, land them in a sealed draw, and somehow enforce their private votes. All six protocol protections apply to every funded case at once.

The draw

An application cannot see the jury before committing and paying and why it matters

If an application could see the selected jurors before committing, it could abandon an unfavourable panel and keep trying until a corrupted group was selected. DemoThemis prevents this by requiring the application to lock any escrow and pay the court fee before the jury is drawn. Once the jury is selected, the case cannot be cancelled or rerolled because of who was chosen. Starting again requires paying for a separate case, while the original case continues.

The jury is drawn using a public random number released at predetermined times, so nobody can choose when it is created or influence its result. If the random used to make the draw was dependent on the time of request then the request could influence the random number output and therefore influence the draw.

The face check

Rented jury seats cannot vote without the enrolled human

A one-time iris scan cannot stop someone renting out their phone or login later. A hundred rented credentials controlled by one operator would look like a hundred independent humans and vote like one.

Orb verification is the only way to get a jury seat. Before the seat can be drawn, in the same session, the juror enrolls a face check on their own phone, so the face is enrolled before anyone could hand the account to someone else. When the seat is drawn, the juror must pass a fresh face check tied to that case, round, wallet, and deadline. Only a pass unlocks the ballot. Device-only World ID holders cannot take a seat. A seller or renter has to bring the enrolled human back every time a vote matters, and a yearly Orb re-verification catches abandoned accounts more slowly.

World ID in the final product. Orb verification creates one jury seat per unique human, and the proof is verified on World Chain through the World ID 4 Production verifier. The face check is World's Selfie Check, used through IDKit. The juror enrolls once. Each time the seat is drawn, Selfie Check runs its returning-user camera check and DemoThemis ties the pass to the case, round, wallet, and deadline. Two parts still depend on World. Selfie Check is in beta and needs access approval, and the yearly Orb re-verification can only be enforced once World lets apps see when a person last verified at an Orb.

The privacy boundary is strict: DemoThemis never receives the scan or face template. It accepts only a short-lived, draw-bound proof that the World-ID-backed seat is present for this case now—not a name, face, reusable login, or global identity handle.

Layered anti-rental protectionEach layer makes the enrolled human return closer to the moment that matters.
  1. Identity checkOrb enrolment

    The human appears once, when the jury seat is created.

    What a renter can still doOperate it indefinitely

    The verified seat can be handed over after enrolment.

  2. Add the next layerAnnual Orb re-verification

    The enrolled human must return at least once each year.

    What a renter can still doOperate it between checks

    The unattended window can still last up to 364 days.

  3. Add the decisive layerFace check whenever drawn

    The enrolled human must return for this exact case before voting.

    What a renter can still doCannot operate the seat alone

    The check arrives with the unpredictable jury draw.

Final resultThe enrolled human must be present when the unpredictable draw happens.Mass unattended seat rentals fail at the moment they would need to vote.
The checks stack instead of replacing each other. Only the face check at the draw protects the moment a jury seat becomes valuable.

The face check prevents unattended rented seats; the encrypted ballot then prevents enforceable bribery.

The ballot

Receipt-free ballots make bought votes unenforceable

A vote buyer pays only when they can prove delivery. Commit-and-reveal fails because the juror publishes a vote hash and later opens it: the same receipt that proves honesty to the protocol proves obedience to a briber.

DemoThemis instead encrypts every ballot with a shared encryption system and lets the juror silently replace it without any public sign. This allows jurors to change their decision until voting closes for better arbitration and allows bribed voters to change their vote at any time before voting closes, which adds an extra layer of difficulty to bribing jurors.

Ballots are then added while they remain encrypted. Only the aggregate total opens, with a zero-knowledge proof that the count followed the rules; no individual ballot opens, even to tally operators. This is stronger than hiding a public vote behind an administrator. It removes the individual result anyone could sell.

Each case gives every juror a new anonymous identifier. Anyone can verify that every seat belongs to a unique, eligible human, but cannot link that juror to their activity in other cases.

What a briber can see, on purpose

The anonymous identifiers drawn for one case, so anyone can audit the draw against the public source of unpredictable numbers.
Proof that every seat is unique, eligible, and selected fairly. Draw weight is proved from a private reputation band, never a public score.
The final tally, with its proof attached.

What the protocol does not reveal

Any juror's name or face. The scans stay on the phone; a seat uses a one-case anonymous identifier.
Which way any seat voted, on any case, ever. Only the tally decrypts.
Any juror's exact penalty balance, reputation, case history, individual payment, debit, or appeal refund.
Proof of a bought vote, even from a juror trying to sell one.
The split is deliberate. The public gets one-case anonymous identifiers, aggregate accounting, and proofs that the rules were followed; it never gets the private history that could turn a penalty or payment into a vote receipt.

No administrator key is allowed. Setup must be distributed or keyless, so independent participants create the capability together without one party holding it; initialization artifacts become unusable afterward; and the sole output is an aggregate tally with a public zero-knowledge proof. A party that creates, holds, or merely promises to delete a complete key breaks the guarantee.

Privacy continues after tallying. Exact scores, penalty balances, rewards, and refunds stay inside private records whose rules can still be proved. Zero-knowledge proofs reveal only what is needed now, such as an eligible reputation band or a valid private account update, while batched totals prove the money balances. A public payment or penalty tied to a seat would recreate the receipt. One limit is plain arithmetic. A unanimous tally shows how every juror on that panel voted, and no ballot design can hide that.

Application configuration

Applications configure the case; DemoThemis chooses and protects the jury

The application requesting arbitration, like a prediction market, configures the court settings for a case before DemoThemis accepts the case: which mode to use, the value at stake, the most it will pay in fees, whether the ruling also releases escrowed funds, and how long each appeal window stays open. None of it can change afterwards. The How to Make the Court Unbuyable tab lets you set each one and watch the jury and appeal route change with it.

Part 3 · Juror quality

Protocol quality: how careful jurors earn more responsibility

Every completed case creates a private record that appeals, blinded audits after reversals, and later independent evidence can update.

DemoThemis does not grade a juror from one result or simply reward them for following the majority. Across many cases, it uses appeal outcomes, blinded audits of difficult decisions after reversals, and later evidence when available. Strong records gradually increase pay, draw rate, and earned voting responsibility; weak records reduce them. A permanent ban is the final step and occurs only when the entire 95% confidence interval falls below 70%, showing persistently poor performance rather than one bad run.

Why shared history compounds

Private history improves quality without exposing jurors

Each completed case creates two different records. The first is a signed receipt for the customer using DemoThemis, such as an application layer like OmenMarketMaker. It proves the final ruling and, when escrow is used, that the funds followed it. The second is a private grading record used only by the protocol. It records which jurors served, each juror’s private decision, whether an appeal changed the ruling, and whether later evidence supported it. No person or application can read this record; the protocol reveals only the minimum reputation band or eligibility proof needed for a future action.

The grader's paradox

Why majority agreement cannot measure judgment quality

Grade jurors on matching the majority and the safe strategy becomes guessing the room instead of reading the case. The diagram shows how a wrong consensus can produce perfect-looking scores.

  1. 1 Scoring rule

    Reward agreement

    A juror’s score rises whenever their vote matches the panel majority.

  2. 2 Incentive

    Predict the room

    Following the expected majority becomes safer than independently judging the case.

  3. 3 Panel behaviour

    Independent signals disappear

    Jurors converge on the same answer, including when the shared answer is wrong.

  4. 4 False signal

    The scores look perfect

    Agreement rises because everyone herds, not because the court identified good judgment.

The failure reinforces itselfPerfect-looking scores make the original rule appear successful, so the court keeps rewarding agreement.
The metric creates the behaviour that makes the metric look successful. High agreement can therefore hide low-quality judgment.

This is not a rare edge case. Once agreement determines careers, independent judgment adds risk but no reward. DemoThemis therefore does not use agreement with the first majority to grade jurors. It waits for stronger evidence from appeals, blinded audits after reversals, and later independent outcomes when available. The loop chapter explains how completed cases build that private record.

Appeal-triggered audit

The audit that grades overturned decisions

Most verdicts need only a vote. When the answer is not obvious, a juror may commit a private explanation with their ballot; it is opened only if an appeal overturns the panel. Its main purpose is to let jurors defend a careful decision during the audit that follows an appeal reversal.

An appeal overturning a panel is the only trigger for an audit. Two auditors drawn from the whole juror pool judge the overturned decision once, blind, from the case’s own evidence file. The seated majority decides, and a tie seats a third auditor. The winning appeal pays the audit’s fixed cost, refunded whenever an appeal fails, so the reward pool never funds the auditors and only receives. A juror whose penalty stands can fund one do-over with a returnable deposit, and after it the finding is final forever. Penalties and forfeited deposits flow to the shared juror reward pool. A missing explanation never counts against a juror, and hidden calibration files built from real past cases enforce that rule. Follow one juror, call her Maya, through the two machines below, and take a reviewer’s seat yourself.

An overturned verdict does not automatically make every juror careless. Hiding the winning side makes auditors judge the reasoning instead of copying the result.
The Audit Machine · one juror audit, start to finish
1Overturned 2Marks 3File 4You judge 5Outcome
1 · The trigger
Were the logo files delivered as promised? The jury ruled NO.OVERTURNED
An appeal overturning this decision is the only thing that triggers an audit
2 · The marks 15 jurors, waiting
3 · The blind file
One blind file
The case’s own evidence record, the decision, any notes.
Never names, never the split, never the winner.
4 · The reviewers
YOU
R2
R3
2 seats, a third on a tie
5 · The outcome
waiting
The appeal bill · paid up front New jury and delay lines, plus one more:
Set aside for the audit$22 refunded
Reviewer payWaiting for an audit. $10 a seat, plus a little overhead.
The reward pool$0 collected from penalties and lost deposits
  1. Press Trigger a Juror Audit to start. Behind the button: an appeal has just overturned the decision this jury made, so the jurors who made it are now being checked. Watch the tracker above, and note step 4: the machine stops there and waits for your verdict.
Simulates an appeal overturning this jury’s decision. The audit of the jurors follows, pausing at step 4 for your verdict.
No overturn means no audit. Nothing happens, and the $22 goes home.
Audits triggered0
Audits per overturnalways 1whatever the jury size
Reviewers per audit2, plus a third on ties
Cost per audit$222 × $10 plus overhead
Everything here runs the published audit rules. Dollar figures use the base model’s rates, and the $5 penalty and $25 deposit are illustrative numbers. With JavaScript off, this figure stands as a labeled map of the system.
The Do-over Machine · Maya’s re-check, start to finish
1The finding 2She pays 3Fresh draw 4You judge 5Outcome
1 · The finding against her
Maya’s first audit ended CARELESS. The 8 marks from it are set to stay.
8 marks, 8 queued penalties
2 · Her payment
Pays the 3 new reviewers$33 Spent, win or lose
Her refundable deposit$25 Waiting in escrow
Her own money, once, and only because she is marked
3 · Three fresh reviewers
YOU
R2
R3
None touched the case or its first audit. None are told it is a re-check
4 · The outcome
waiting
Majority of 3 decides. Then final forever
Reviewer payWaiting. $10 a seat plus overhead, from Maya’s $33.
Reward pool, from this figure$0 collects forfeited deposits
  1. Press Trigger Maya’s do-over. Her first audit ended careless, this is her one allowed re-check, and at step 4 you sit as one of the three fresh reviewers who decide it.
She pays, three fresh reviewers are drawn, and your vote helps decide her marks.
No re-check. The marks and penalties stand, and she spends nothing.
Do-overs run0
Cleared0marks erased, deposit returned
Upheld0marks stay, deposit to the pool
Up front$58$33 spent + $25 at stake
The same machine format, pointed at the re-check. One fixed case, Maya’s, judged fresh each run. Amounts are illustrative at base rates.

One court

Every case contributes to one private quality record

Every case uses the same random draw, private ballots, appeal ladder, and juror-quality system. The question and decision criteria are fixed before the draw, and every final case creates a private record that later quality evidence can update.

A market result may later provide independent confirmation. Delivery disputes and community-standard cases can contribute appeal outcomes and blinded audit findings when challenged. The available signals vary, but they all update the same private history.

Scores use appeal outcomes, audits of difficult decisions after reversals, and later independent evidence when available. No first majority becomes automatic truth.

How can this case add quality evidence?

The court does not route cases into separate accuracy systems. It records the evidence each case can provide, then updates one shared juror-quality history.

The reputation dial

Reputation is a private estimate with uncertainty

Quality findings from appeals, blinded audits, and later independent evidence form a private reputation record. Mathematically it is a beta distribution: a best estimate plus an honest error bar, not one naked percentage. An 80% record over 12 findings is therefore not treated like 80% over 140.

The system carries a 95% interval over a rolling window of the latest 50 to 150 cases. Neither the exact score nor its case history is published; a juror proves only the band or threshold needed for the current action. The table shows what that private dial may change.

What the dial movesThe ruleHow fast it bites
Draw rateScales by a privately proved reputation band, capped at a newcomer's rate so no juror dominates the draw. The largest panels, the 31 seats, require a private proof of a long case history.Continuously, from the first case
Per-case payThe juror's private share of the fee scales with the score; only the panel total is public.Continuously, from the first case
Full vote weightGranted when the interval sits clear of the line on the high side: lower bound ≥ 0.70.Earned over tens of cases
Permanent banFires only when the whole 95% interval sits below 0.70.Final, and only on confident evidence

The three-times draw cap matters because court security comes from a wide active pool, not a small class of stars. Accuracy still compounds into more work and private income, but no juror dominates selection.

Court fees fund future juror rewards

The shared juror reward pool pays periodic private rewards to jurors who prove they meet quality and recency gates. Part of each court fee contributes to this pool only while it is below its published funding target. Once the target is reached, that part of the court fee falls to zero.

An appeal can also require a refundable security bond, separate from its fee. The bond returns when the appeal succeeds; when it fails, the bond is forfeited and can add to the reward pool. Only the pool total and proof of correct distribution are public, so the reward cannot expose or bend one verdict.

Direct accountability

Private penalties make careless voting unprofitable

After all appeals are complete, the protocol charges any penalty to the juror’s private wallet. If the wallet does not contain enough funds, the juror’s World ID–linked account goes negative. Future jury earnings repay the debt first, and changing wallets cannot erase it. The penalty amount depends on current juror pay, unresolved workload, and the expected cost of errors caused by careless voting. This makes random or lazy voting unprofitable while the longer-term quality record gradually adjusts pay, draw rate, vote weight, and eventually eligibility.

One direct penalty, four longer-term consequences
40 cases
78%

Quality combines appeal outcomes, blinded audit findings after reversals, and reliable later evidence when available.

Private quality estimate
40%70% confidence line100%
Final quality finding Private debit Applied only after appeals and any triggered audit
Per-case payResponds from the first case
Draw rateNever exceeds the 3× cap
Vote weightFull only on confident evidence
EligibilityA permanent ban is deliberately last

Lenient on purpose

A permanent ban requires confident evidence of poor performance

Permanently banning a juror after one rough stretch would reward safe majority guesses. Rational jurors would avoid hard positions and follow the apparent room. A permanent ban therefore occurs only when the full interval is below 0.70, meaning the evidence is confidently and persistently poor.

Leniency at that last gate is not softness everywhere. Private pay, draw rate, vote weight, and audit-confirmed penalties respond earlier; only their aggregate transfer is public. Low effort becomes unprofitable before uncertain evidence ends a career.

When an appeal overturns a panel, an original dissenter who matched the successful appeal gains positive evidence. Jurors on the overturned side lose quality only when the blinded audit finds that their optional explanation failed to support a reasonable judgment from the original evidence. Reasonable disagreement is not treated as careless work, and no public update identifies any juror.