This CGP is a temperature check to assess community support for rotating the membership of the Governance Approver multisig — removing two approvers who are stepping down and adding four new approvers — as part of the broader effort to strengthen Celo governance.
It contains no on-chain transactions. The Governance Approver multisig manages its own membership (see Verification), so the actual replaceOwner/addOwner changes are executed by the multisig itself after this signaling vote passes. The multisig will continue to require 3 signatures to issue a governance approval.
This is a signaling proposal. Because this is a community multisig, membership is linked to the individual, not their role or affiliation; roles below are given for information only.
The remaining current approvers keep their seats (ten addresses; see the final owner set under Verification).
Two current approvers are rotating out for personal reasons and will be removed from the multisig:
0xD6d48412dA0804CF88258bfDf5AaFcBe5FEd7ecC0xC85639289D4Bbb5F90e380A0f4db6B77a2F777bFIf passed, the following new approvers are added:
0x936e62E72727E47297D218c2F829ef4C36427D9A0x0a1c327FB17870488F12555e56A3a517e493cc460xF7DE62B65768a169279be74b12FaA65a22FB38D30x8eF439ee8F6905bfd2343668039d39eB2B77706eThe signature threshold is unchanged at 3. After the rotation the multisig has 14 owners (3-of-14).
No transactions. This is a signaling / temperature-check proposal; the approvers carry out a yes/no governance vote, and if it passes, the Governance Approver multisig executes its own membership changes.
N/A — see mainnet.json (empty array; no on-chain transactions).
The Governance Approver multisig has address 0x41822d8A191fcfB1cfcA5F7048818aCd8eE933d3. This can be verified by reading the approver field on the Governance proxy (0xD533Ca259b330c7A88f74E000a3FaEa2d63B7972):
cast call 0xD533Ca259b330c7A88f74E000a3FaEa2d63B7972 "approver()(address)" --rpc-url https://forno.celo.org
The members of the multisig are managed by the multisig itself, not by Celo Governance — addOwner, removeOwner, and replaceOwner are gated by onlyWallet (callable only by the multisig acting on itself via its 3-of-N submit/confirm flow). If this temperature check passes, the multisig will execute the following calls against itself to bring its membership in line with the above. The calldata is provided so signers can verify exactly what they confirm:
replaceOwner(Rob Witoff -> Javier Cortejoso)
0xe20056e6000000000000000000000000d6d48412da0804cf88258bfdf5aafcbe5fed7ecc000000000000000000000000936e62e72727e47297d218c2f829ef4c36427d9a
replaceOwner(Kobi Gurkan -> Paul Lange)
0xe20056e6000000000000000000000000c85639289d4bbb5f90e380a0f4db6b77a2f777bf0000000000000000000000000a1c327fb17870488f12555e56a3a517e493cc46
addOwner(Marcin Majchrzak)
0x7065cb48000000000000000000000000f7de62b65768a169279be74b12faa65a22fb38d3
addOwner(Pavel Hornak)
0x7065cb480000000000000000000000008ef439ee8f6905bfd2343668039d39eb2b77706e
The multisig can be inspected at any point:
celocli multisig:show 0x41822d8A191fcfB1cfcA5F7048818aCd8eE933d3
At completion, the owners should be (order is not important):
0xBE0c3B35Ec3f759D9A67c4B7c539b0D5b52A4642
0xFD74A4b05F12B9aB6020CB202aDE1BBa4Bc99aba
0x5C73151A9eDcaccBD20EBB346bd4e419CdC94da3
0xC631Eb5dE231000f96F4973ca8516d487108b2BF
0x92AD020Cde6A4e566770C603ae8315a9d7252740
0xbA4862643D476aCbC13276bd73DACa7b27bF567C
0x5caE91b0d08641249580ac89E129E8242b8335EF
0xC97d3c16BE3CBE408984cF1d7cE50D4B00c246C0
0x94A33095647Bd7f51515c6B6D3e076DA72DAd8D2
0x978727D0b401B66Cf3891AaF9a40826765469bA2
0x936e62E72727E47297D218c2F829ef4C36427D9A
0x0a1c327FB17870488F12555e56A3a517e493cc46
0xF7DE62B65768a169279be74b12FaA65a22FB38D3
0x8eF439ee8F6905bfd2343668039d39eB2B77706e
This proposal executes no on-chain transactions, so the vote itself carries no execution risk. The subsequent multisig membership changes are performed by the Governance Approver multisig and could in principle be subject to manual error; the risk is low because the multisig requires 3-of-N confirmation and the contract is the long-standing, audited Celo MultiSig. The approver multisig is nonetheless critical to the functioning of on-chain governance, so signers should verify the calldata above before confirming, and the resulting owner set against the list above.