# Architecture Explorer

> A durable map of a protocol's actors, controllers, and upgrade authority — derived from deployed bytecode and reconciled against replayed traces.

Platform

A durable map of who controls what in a protocol — actors, controllers, and upgrade authority — derived from deployed bytecode and on-chain state, and versioned alongside the review it supports.

Multisig 0x4f…9c11

controls VaultV2proxy

controls FeeRouterproxy

controls Oracleproxy

One principal controls three upgradeable contracts.

Architecture Explorer showing a controller resolved from an on-chain admin slot

The model

## Authority, resolved from the chain

The Explorer reads the storage slots that actually hold authority on a pinned fork, then classifies each controller it finds — externally owned account, multisig, timelock, governance, or contract. Controllers that appear across several contracts collapse into a single principal, so concentration is visible instead of implied.

- Reads: storage slots on a pinned fork
- Source: optional; verified ABIs enrich the map
- Resolves: actors, controllers, upgrade authority
- Output: a revisioned map with immutable snapshots

On Solana

## The explorable graph is an EVM capability

On Solana (SVM) the same questions — signer required, PDA ownership, upgrade authority — are answered by the Scanner as graded findings.

- Unit: a program and the accounts it touches
- Source: Rust, read and analyzed; no Anchor toolchain, so nothing is compiled
- Authority: not a storage slot — an account's owner is a program; who must sign is a per-instruction privilege
- Evidence: compute units, logs and account diffs; SARIF export

Illustrative detector view of Solana program authority, not an available Explorer graph. A table shows the accounts a detector reads: the program and its program-data account, both owned by the BPF loader, with upgrade authority held by a single keypair; and a vault PDA owned by the vault program, which signs by derivation rather than with a key. Alongside it, the authority checks that ship as graded findings: missing signer on authority, PDA owner not verified, upgrade authority is a single key.

Review

## Rules that run, and paths you can follow

Structural rules run over the graph and surface the shapes that matter in a review — a single key behind an upgrade, authority that concentrates on one principal, a path from an external caller to a privileged function. Each result is a route through the model you can walk, not a severity label.

### Versioned

The map is a revisioned document with immutable snapshots and an audit trail, so a review can cite the exact architecture it was performed against.

### Reconciled

Replay a transaction on the fork and its real execution is compared against the model — edges confirmed, unexpected, or never observed.

### Shared

Developers and auditors read the same map alongside the same fork, findings, and contract context.

## Map the protocol before you review it

Open a target and the architecture is built from what is deployed.

[Launch app](https://app.trilocore.ai/) [Back to the platform](https://trilocore.com/platform/)

---

[Canonical HTML version](https://trilocore.com/platform/architecture-explorer)
