I used to assume proving investor eligibility meant revealing the identity behind it. Looking closer at Citadel changed that assumption.
The flow starts with a credential — a license — issued by a trusted License Provider. The provider checks the user off-chain, signs the relevant attributes, publishes an encrypted license, and registers it in a Citadel contract. Later, the user can generate a zero-knowledge proof showing they own a registered, provider-signed license — without revealing their wallet key, their personal attributes, or even which exact license produced the proof.
What actually shifted my thinking is this: a regulated service can now receive cryptographic evidence that an eligibility check happened, without the investor's full identity ever touching the chain. But Citadel doesn't decide who gets admitted. The service provider still chooses which License Providers it trusts, which attributes satisfy its rules, and whether a session is expired, revoked, or reusable.
So the proof makes credential ownership private and verifiable — but the meaning assigned to that credential still lives at the application level, in the hands of whoever issues and interprets it.
Does Citadel actually remove identity exposure from access control, or does it just relocate the most important trust decision to the provider issuing and interpreting the credential?

#dusk $DUSK @Dusk