How Anchor Ledger's permission model actually works: per-chain approval mechanics, on-chain verification instead of trusting a wallet app's word, and the two-cluster isolation rule behind non-custodial trading permissions.
When you link a wallet you set an Approval Cap. That number is written into the on-chain approval itself — the delegate address Anchor Ledger controls literally cannot move more than that amount, because the chain won't allow it. Revoking is a transaction you sign yourself; once it confirms, the authority is gone.
Before a wallet is marked linked, the server queries the chain directly for the real current allowance. A wallet app reporting "success" is not proof — mobile wallet confirmations have reported the wrong amount before. If on-chain state doesn't match, linking fails rather than silently trusting a client-reported success.
Solana handles deposits and withdrawals; Tron is where trade execution happens. A single transaction can't reference two different blockchain clusters at once, so any feature touching two chains gets two fully separate code paths and connections — structurally, not as an afterthought.
Related: Security · Why Anchor Ledger doesn't custody your funds.