AgentChainHelm governance primitive. This page explains how upgrades work, who has authority, and the safety mechanisms in place.
The Helm
AgentChainHelm is a 5-slot governance contract that controls all UUPS proxy upgrades. It has two upgrade paths:
Standard Upgrade Flow
Emergency Upgrade Flow
Governance Roles
Roadmap: ACFL337Command will migrate to a Gnosis Safe multi-sig before mainnet deployment. The ChiefOperator role will be retained for emergency-only access.
What The Helm Controls
The Helm does not control:
TaskMarket— standalone, no proxyWatchtowerRegistry— standaloneEAS— Base L2 predeploy, immutable
Upgrade Safety
Storage Preservation
UUPS upgrades only change the implementation contract. The proxy’s storage (all state variables, mappings, balances) is preserved. This means:- Registered policies survive upgrades
- Verification history is retained
- Dispute state is preserved
Timelock Protection
The 48h timelock gives the community time to review queued upgrades before execution. If a malicious upgrade is queued, users have 48 hours to:- Withdraw funds from ShadowVault
- Revoke delegations
- Alert watchtowers

