SameDeal
A signature should not survive a changed deal.
Most land-consent systems can prove that somebody signed a document. That is not the same as proving that the deal in front of us today is still the deal they agreed to.
SameDeal is a consent-integrity layer for land-use projects. It binds each community decision to the exact project boundary, compensation terms, duration, access rights, and commitments that were shown at the time. When the proposal changes, SameDeal does not blindly ask everyone to sign again. Its Consent Delta Engine determines what changed, who is affected by that change, which existing consents remain current, and which must be reviewed again.
The first use case is community consent around Indonesian land-use projects, especially plantation development and FPIC (Free, Prior and Informed Consent) workflows.
The question SameDeal answers is simple: Is today's claimed consent still consent to today's deal?
Inspiration
We started with a very ordinary failure mode: a PDF can be signed once and then become detached from the reality it was supposed to represent.
A project boundary moves. Compensation changes. A road-access promise disappears. A 20-year agreement becomes 30 years. Yet somewhere there is still an old signature that says “agreed.”
That matters in Indonesia because land conflict is not a theoretical edge case. KPA's 2025 figures, reported by Katadata, recorded 341 agrarian conflicts covering about 914,570 hectares and affecting 123,612 families across 428 villages.
The process gap is also concrete. An OECD review of infrastructure investment in Indonesia notes that public consultation can occur before exact compensation and affected areas are specified; the consultation may inform communities about a project while those exact details are determined later.
At the same time, the 2026 Indonesia National Interpretation of the RSPO Principles & Criteria requires evidence that communities can give or withhold consent, that they understand the legal, economic, environmental and social implications of operations on their land, and that affected communities can access independent advice. It also recognizes the need for formats that work for illiterate parties.
Those sources led us to a narrower problem than “solve land disputes with blockchain.” We do not think blockchain can decide who owns land or replace courts, government registries, customary law, or auditors. We want to solve one smaller but important integrity problem: keeping consent attached to the exact deal that produced it.
Research basis
- KPA 2025 agrarian-conflict figures via Katadata
- OECD — land acquisition and public consultation in Indonesia
- RSPO — Indonesia National Interpretation of the 2024 Principles & Criteria
What it does
SameDeal turns a land-use agreement into a structured, versioned Deal Packet instead of treating it as one opaque PDF.
A Deal Packet contains material facts such as:
- the project polygon and affected parcels;
- compensation and payment terms;
- project duration;
- access rights and exclusions;
- environmental or social commitments;
- the people or households whose consent is required;
- the exact version that was presented.
Each material fact becomes a committed leaf in a Merkle tree. For version v, the deal root is:
$$R_v = \operatorname{MerkleRoot}(G_v, F_v, A_v, T_v, O_v)$$
where G is geography, F is financial terms, A is access/rights, T is duration, and O is obligations or commitments.
A participant's decision is recorded against that exact root and only the scope relevant to them.
If the developer publishes a new version, SameDeal computes a deterministic set of material changes:
$$M_{v\rightarrow v+1} = \operatorname{Diff}(Deal_v, Deal_{v+1})$$
Each participant has a consent scope S_i. An existing consent stays current only when its scope does not intersect with the material changes:
$$\operatorname{Current}(c_i) \iff S_i \cap M_{v\rightarrow v+1} = \varnothing$$
In plain English: if nothing you agreed to changed, your consent survives. If something that affects you changed, your old consent stops counting for the new version.
A concrete example
Assume 37 households have completed consultation for a 102.4-hectare project.
The developer expands the boundary to 128.1 hectares. The new polygon intersects three additional household parcels.
SameDeal immediately changes the consent-coverage view from:
37 / 37 current
to:
34 current · 3 newly affected · review required
The other 34 households do not need to repeat a process that did not change for them.
Now change compensation from Rp15,000,000 per hectare to Rp10,000,000 per hectare. That financial term is relevant to every compensated household, so all 37 previous consents become non-current for the new version.
Now correct a spelling mistake in the project title. No material term changed, so no consent is disturbed.
That distinction is the core of SameDeal.
Core features for the Phase 2 MVP
1. Deal Composer + Geospatial Boundary
A project developer creates a proposal, draws the project polygon on a map, enters compensation, duration, access rights and commitments, and publishes Version 1.
2. Scoped Consent Receipt
Each affected participant sees the terms that apply to them, including the portion of land affected. They can agree, withhold consent, or request changes. The decision is tied to the exact deal root instead of a reusable generic signature.
3. Consent Delta Engine
When a new version is published, the engine compares structured terms and geospatial changes, identifies the affected consent scopes, and marks only those decisions as needing renewed review.
4. Consent Coverage Map
An auditor can see project-level status — current, affected by change, pending, or withheld — without exposing household identities publicly. The map makes the integrity state visible in seconds.
5. Delegation Check
A representative can act only for participants who have explicitly delegated authority. If somebody attempts to approve for 37 households while holding verified delegation for 8, the action is rejected for the other 29.
Why Web3
SameDeal is not using blockchain as a database replacement, and it has no token, NFT marketplace, or DAO.
The blockchain has one narrow job: make the history of deal versions and consent proofs independently verifiable by parties who do not fully trust one another.
The public proof layer stores only minimal integrity data such as:
- project identifier;
- deal-version Merkle root;
- previous root;
- material-change root;
- anonymous consent/nullifier reference;
- consent scope commitment;
- timestamp.
Names, identity numbers, land documents, phone numbers and private household information remain encrypted off-chain.
This lets an auditor verify that a current consent corresponds to the current proposal without placing people's sensitive documents permanently on a public ledger.
Privacy by design
A public chain should never become a public database of vulnerable communities.
SameDeal therefore separates proof from private evidence. The chain proves version integrity and decision uniqueness. Private identity and supporting documents remain under controlled access.
For the MVP, we will use signed participant credentials and one-time consent identifiers. If time permits during Phase 2, the privacy layer can be extended with Semaphore-style zero-knowledge group membership so a participant can prove “I am an eligible affected participant” without publicly revealing who they are.
Accessibility
A consent system fails if it only works for people comfortable reading legal PDFs.
The participant screen is intentionally plain: land affected, money offered, duration, rights kept, rights changed, accept / reject / request changes.
We also plan an audio/read-aloud mode for critical terms. This is not decorative accessibility; the current RSPO Indonesia standard explicitly discusses making processes understandable to illiterate parties and using formats such as visual or audio-visual communication.
AI, if used, will only explain an already-determined change in simpler language or another language. AI will never decide whether consent is valid. The validity decision remains deterministic and auditable.
How we will build it in Phase 2
This submission is the Phase 1 concept. We are intentionally not claiming a finished implementation before the required 24-hour build period.
Our planned architecture is deliberately small enough to finish:
Frontend: Next.js + TypeScript + Tailwind CSS
Map & geometry: MapLibre GL JS + PostGIS
Application data: PostgreSQL / Supabase
Smart contract: Solidity + Hardhat on an EVM test network
Chain interaction: viem
Integrity layer: SHA-256 + Merkle commitments
Private evidence: encrypted object storage; only hashes and proofs go on-chain
The build order is also intentional:
- Deal Composer and version model
- map polygon + affected-parcel intersection
- participant decision flow
- Consent Delta Engine
- Solidity proof registry
- coverage dashboard
- delegation check
- accessibility polish and live deployment
The hardest logic — material change classification and consent-scope intersection — will be implemented independently of the UI so it can be unit-tested with adversarial cases.
What makes SameDeal different
We are not claiming that digital consent is new. It is not.
We are also not claiming that blockchain-based consent records are new.
Our claim is narrower:
SameDeal performs consent-impact analysis when a physical-world agreement changes.
It answers:
What changed? → Who does that change affect? → Which existing consents are still current? → Which must be reviewed again?
That is different from simply timestamping a signature or storing document hashes.
It also gives us a demo that can be attacked live: move the map, reduce the compensation, remove an access promise, or attempt to represent people without delegation. The system should show exactly where the claimed consent stops being valid for the new proposal.
Target users and business model
The community should never be the paying customer.
Primary users: affected households, community representatives, independent advisers and auditors.
Paying users: plantation operators, infrastructure/project developers, certification bodies, lenders and due-diligence teams that need defensible evidence that the consent record matches the current project terms.
A realistic model is project-based SaaS for developers plus audit/API access for certification and due-diligence teams. Community participation remains free.
The first market is Indonesian plantation/FPIC workflows because the problem and compliance expectations are concrete. The protocol can later generalize to mining, renewable-energy siting and infrastructure projects where boundaries and negotiated terms can change over time.
Challenges we expect
The difficult part is not writing a smart contract. It is defining material change correctly.
A typo should not invalidate consent. A moved boundary, lower compensation, longer project duration, or removed access right probably should affect some or all participants. We will therefore keep Phase 2 classification rule-based and transparent rather than pretending an LLM can make a legal judgment.
A second challenge is privacy. A system about community rights can become harmful if it exposes identities or land details. That is why SameDeal stores only cryptographic commitments on-chain and treats private evidence separately.
A third challenge is scope. SameDeal will not decide legal ownership, resolve land conflicts, or declare that a project has legally satisfied FPIC. It is an evidence and integrity layer, not a court or regulator.
What success looks like
A judge should be able to watch one sequence and understand the whole product:
- 37 households are current on Version 1.
- We move the project boundary.
- Three newly affected households appear immediately.
- The original 34 remain current.
- We change compensation.
- All relevant consents become non-current.
- We inspect the public proof and verify which deal root each decision belongs to.
If that works live, SameDeal has done its job.
What's next
After the MVP, we would validate the change taxonomy with legal-aid, FPIC and certification practitioners instead of inventing policy rules ourselves. The next technical steps would be stronger anonymous eligibility proofs, signed third-party attestations, multilingual/offline-first community access, and export formats that auditors can integrate into existing workflows.
SameDeal is deliberately not trying to make every land dispute disappear.
It is trying to make one sentence much harder to fake:
“This is still the deal they agreed to.”
Built With
- hardhat
- maplibre
- merkle-tree
- next.js
- polygon
- postgis
- postgresql
- sha-256
- solidity
- supabase
- tailwind-css
- typescript
- viem
- web3