What has to be true for a tokenized asset to become a functioning financial instrument rather than just a record on a chain?
I keep arriving at the same answer from different directions. Tokenization creates value only when the legal claim, the operational records, and the financial utility stay aligned. Protocol architecture can reduce friction, share liquidity, and automate execution. It cannot manufacture enforceability, a defensible price, a correction path, or an executable balance sheet.
Token issuance mechanics are largely solved: standards, transfer restrictions, compliance hooks, distribution logic. Of the tokenization concepts I've worked through with clients, most never reached implementation, and almost none died on a technical question. They died on securities classification, a land registry that won't recognize the transfer, cross-border mismatch, transfer restrictions that make the instrument unsellable, or economics worse than the incumbent's. The work starts before the contract: what is the enforceable right, who owes it, under which law? Get that wrong and the token points at nothing.
Nor is a production system the token contract. It's custody, compliance and identity, policy enforcement at the transfer level, valuation inputs, and off-chain/on-chain reconciliation. That last one is where designs quietly bend: register and chain can drift apart in ordinary business, so the system must define which record is authoritative, who detects the mismatch, and who closes it.
This is why banks reach meaningful issuance first. Not because they're more innovative, but because they already hold the licenses, clients, and operational machinery that startups otherwise have to build before issuance. The same advantage can then produce cash islands: tokenized deposits that move beautifully inside one institution and connect to nothing outside it. Fragmentation on better rails.
Which is where DeFi earns its place. Not fractional ownership, which legal structures and investment platforms provided long before blockchains, but post-issuance utility: trading, collateral, borrowing, composability. An asset you can pledge and finance without selling is a different economic object than one you can merely subdivide. Nor does this require flattening risk into one pool: shared liquidity can coexist with asset-specific risk parameters, oracle configuration, and eligibility rules, reducing the cross-subsidy between borrowers posting assets with materially different risk profiles.
What architecture cannot supply on its own is an economically defensible price. Permissioned AMM infrastructure solves compatibility and onchain eligibility enforcement well: eligibility checked inside the pool rather than only at the frontend, the right to trade separated from the right to provide liquidity. It does not solve price formation, correction capacity, or the capital that makes markets. Once eligibility is enforced in the pool, the allowlist becomes market structure, deciding who may correct a stale quote and who may hold inventory. And productive inventory is not automatically executable: balances routed to a vault can earn carry, but when a trade arrives, market accounting, vault accounting, and the issuer register must be reconciled. Three records, each internally correct, breaking at the seams.
None of which makes venue choice irrelevant; it places venue selection downstream of instrument and market structure rather than upstream of them. AMM, RFQ, order book, auction, and primary redemption are execution roles matched to the instrument, the order, and the market state. A frequently updated valuation with hedgeable exposure and a two-way primary facility supports one configuration; a quarterly appraisal behind a closed reference market supports another. Continuous execution is not continuous liquidity.
For secondary markets specifically, the organizing idea is that liquidity is somebody's balance sheet, and balance sheets are rational. A 2025 BIS working paper on US tokenized real-estate platforms documents increased trading after natural-disaster declarations, attributing the advantage to platform buyback mechanisms and flagging a trade-off with higher platform insolvency risk. That is its finding, for its model and sample. My architectural reading, as interpretation rather than result: buyback-supported liquidity remains available only while the supporting balance sheet can keep providing the backstop. Credible continuous liquidity is bounded by the weakest non-substitutable capacity in the settlement and correction path, not by headline value locked.
What would change my mind
The claim worth testing isn't that liquidity requires capital. That's definitional. It is my causal ranking: that instrument structure, eligibility regime, redemption path, and reference-price process carry more weight than venue design. So falsify it this way. Hold those four constant, change only the execution venue, and show it repeatedly producing durable competitive depth, independent quoting, and resilience through closures, redemption delays, and stress, without continuing issuer or platform subsidy. Across instruments, not once. If that holds, venue design carries more causal weight than I give it, and my sequencing is wrong.
The framework is complete enough to use on a live mandate: identify the enforceable claim and the reconciliation owner; then ask who forms the price, who can correct it, and whose balance sheet is executable when the trade arrives. Comparative production evidence on permissioned secondary-market quality remains thin, and should keep being tested against real markets rather than announced intentions.