Hive  /  Energy  /  Primer
A working note, not a pitch

For a senator, an ISO chief engineer, or an IPP CFO: a quiet note on receipt-shaped market messages.

We owe you the same honesty you'd want from anyone standing across the table on a forty-year asset. We're a small team. We don't assume we know more about how PJM, CAISO, ERCOT, MISO, NYISO, ISO-NE, SPP, or the EU Network Code regions run than the people who built them. Here's what we noticed over the last 18 months, what we think we can honestly contribute, and three questions we'd like this room to push back on. If we're wrong about any of it, tell us. If we're right about any of it, we'd like the chance to prove it on one signed receipt before anyone changes anything else.

FERC 2222 aligned EU Network Code DR CAISO 2026 capacity reform PJM dispatchability rules Offline verifier · no ISO callback RFC 8785 / Ed25519
Read the category brief Back to Energy overview Request a pilot conversation
01 What changed in the last 18 months

Four clocks started ticking at once.

Four regulatory deadlines have moved in the last six quarters. None of them require a new market message. But all four assume one already exists.

Where What moved What it asks for
FERC 2222 Implementation deadlines now binding across PJM, CAISO, NYISO, ISO-NE, MISO, SPP. DER aggregations participate in wholesale markets through an aggregator the ISO settles against. A way to settle thousands of DER assets behind one aggregator without trusting a single XML envelope. The aggregator is on the hook for the chain.
EU Network Code on Demand Response The EU Network Code framework on Demand Response is moving from consultation toward implementation, with national TSOs working out how aggregators interface with balancing markets. A cross-border evidentiary surface where a German aggregator and a French TSO can verify the same flex obligation without trading PDFs.
CAISO 2026 capacity reform CAISO is rebuilding the resource-adequacy framework. Capacity is being redefined around what a resource can actually do under stress, not what it nameplates. A capacity attestation that references its own measurement window and test method, not a PDF certificate that loses its context the day it's signed.
PJM dispatchability rules PJM has tightened capacity-performance rules and is leaning harder on dispatchability evidence after recent winter events. A dispatch instruction and a meter window that share the same parent_ref, so the capacity-performance audit is a verifier run, not a forensic month.

None of these four changes asks for a new market. All four assume there's a court-grade record behind every market action. Today, that record is a PDF. We think tomorrow it should be a signed receipt.

02 What we noticed

Every settlement gets pieced back together after the fact.

Spend a week with the settlement team at any ISO or any IPP and you'll see the same pattern everywhere. A market run produces an XML file. A meter system produces a CSV. A scheduling system produces a PDF. A dispatch system produces a log. When a number gets disputed, someone pulls all four together by hand, reconciles them, and writes a memo defending the answer. That memo becomes the official record.

The chain gets rebuilt after the fact. We think the chain should be the message itself. The honest framing.

That's not a knock on the people doing the rebuilding. It's just describing the real problem they have to solve. The XML gets trusted because of the pipe it arrived on. The PDF gets trusted because of the cover letter. The CSV gets trusted because of the meter contract. None of these four things can prove itself. And none of them survive the moment someone disputes the pipe, the cover letter, or the contract.

03 What we think we can credibly contribute

Receipt-shaped market messages.

Here's what we think we can honestly offer: one signed receipt per market action, in four shapes, each one a standard JSON file the ISO can check offline. We're not trying to replace market clearing. We're not trying to replace scheduling. We're not trying to replace settlement. We just think the message behind each of those actions should be a receipt instead of a PDF or an XML file. Four building blocks. One verifier. One open standard. The same file the IPP holds onto, the ISO checks, the aggregator signs on top of, and a regulator can still read five years later without ever calling us.

SEU

Standard Energy Unit.

Power · Capacity

One kilowatt of qualified capacity over a commitment period. Backed by a signed capacity certificate with measurement window and test methodology referenced.

SMU

Standard Megawatt Unit.

Megawatt-Hour · Delivered

One MWh of dispatched and meter-verified energy delivery. Pairs a dispatch receipt with a revenue-grade meter-data receipt. Court-grade evidentiary chain.

SAU

Standard Ancillary Unit.

Ancillary · ISO Market

One MW of regulation, spinning reserve, non-spin, ramping, or frequency response. Replaces XML market messages with a signed bid receipt the ISO can verify offline.

SFU

Standard Flexibility Unit.

Flex · Virtual Power Plant

One kilowatt-hour of forward demand-flex obligation. Atomic unit of VPP and DR market participation. ISO counter-signs; curtailment chains to dispatch with parent_ref.

A small admission. The receipt cryptography is real, and you can verify it offline today. We have an open verifier and an open canonicalization rule. The part that touches public payment rails, routing the bearer instruments to mainnet, is still in simulation. The public rail we use is USDC on Base. Anything heavier than that, we call it what it is: a permissioned, issuer-controlled settlement network. We want to be straight about what's in production and what's still simulated. The receipt is in production. The rail is not.

04 Three questions we would like the room to push back on

If any of these is the wrong question, tell us.

These are the three questions we would put in front of an ISO chief engineer, an IPP CFO, a VPP aggregator CEO, or a FERC counsel and ask to be argued out of. We do not think we know the answers. We think we know the questions.

Is offline verification of a bid receipt a credible substitute for ISO trust-of-pipe?

Today an ancillary-services bid is trusted because of the TLS pipe it arrived on and the market-participant credential at the other end. If the same bid is a signed JSON body with an Ed25519 signature against a registered issuer DID, the ISO can verify the bid without trusting the pipe. The pipe still carries the message. The trust moves from the pipe to the signature. Is that a credible substitution, or are there reasons of operational risk we have not thought through?

Does FERC 2222 settlement get easier or harder if every DER asset emits a signed flex receipt instead of an aggregator XML?

The aggregator model places the wholesale settlement on the aggregator and expects an XML roll-up of DER behavior to flow up to the ISO. If instead each DER asset emits an SFU at the moment of curtailment, and the aggregator counter-signs the roll-up, the chain from device to ISO is verifiable end-to-end. The aggregator is no longer the only evidentiary surface. Does that make settlement disputes easier to close, or does it move the dispute to a place that is harder to close?

If a meter and a dispatch sign the same parent_ref, what audit work goes away?

A delivered MWh today is two artifacts: a dispatch instruction in one system, a revenue meter reading in another. The reconciliation is human. If both reference the same parent SEU or SAU, the SMU is a single receipt that points to both. The capacity-performance audit, the settlement re-run, and the after-the-fact dispute all collapse into a verifier pass. We are interested in which audit functions you would be willing to retire on that basis, and which you would never retire regardless of how clean the chain looks.

05 What we are not

A short list of things we do not propose to do.

To save time in the briefing, here is a short list of things we do not propose to do, in case any of them came up before we did.

We are not a market clearing engine. We do not propose to clear day-ahead, real-time, capacity, or ancillary markets. The ISO clears. We sign the inputs and outputs.

We are not a settlements platform. We do not propose to issue invoices, manage shortfall charges, or run uplift allocation. The ISO settles. We provide the evidentiary chain settlement leans on.

We are not an ISO replacement. The market participant credential is still the ISO's. The tariff is still the ISO's. The clearing is still the ISO's. We are an attestation layer that sits over the systems already in production.

We are not a SCADA system. We do not control breakers. We do not move set-points. We do not dispatch units. We sign what other systems did.

06 Closing

One signed receipt before anyone changes anything else.

If we are wrong on any of it, we want to be told. If we are right on any of it, we would like the chance to prove it on one signed receipt before anyone changes anything else.

The receipt cryptography is real today. The verifier is open. The four primitives are locked. The mainnet rail is still in simulation, and we say so plainly. We'd like to keep this conversation small and specific, starting with one workflow: one capacity test, one ancillary bid, one delivered MWh, or one flex obligation. Configuration comes after that. Your questions come before it.

Private by design. Hive does not store your prompts. Every request is already receipted by a one-way SHA-256 fingerprint, not the words. Proof, not surveillance.