> This is sufficiently rare that "traditional" finance hasn't come up with a product for that. Or maybe it has, but it's just as obscure as Gnosis.
Traditional finance doesn't have an answer for this. It's not rare at all. I personally work with people from Argentina, Denmark, Canada, Serbia, Croatia, Australia and Hong Kong. It's very common to work in a fully distributed online manner, using chat products to communicate. It's very easy to meet people in online hackathons, on Discord servers, on gaming platforms, etc these days, from all over the world.
Yes, programmability is always superior to non-programmability, as it is a superset of non-programmability. After all, you could always encode whatever non-configurable properties you wanted as part of the ruleset for the contract or asset.
> It doesn't make it not esoteric. There are no tools, no way to debug, no way to revert a deployment, no way to upgrade a "contract" etc.
At this point Solidity is 7 years old. There are more than 200K developers that have learned it (50K from ETHGlobal hackathons alone: https://ethglobal.com/), 20K stars on Github, 44 million smart contracts have been deployed to ETH mainnet, 60K people watched Devcon Colombia vids a couple weeks ago (6K attended in person), 20K attended ETHDenver earlier this year, etc.
There's tons of tools:
Hardhat (https://hardhat.org/) - for JS based task running, deployment, testing, debugging, etc. Even deploys a local chain or allows you to fork a copy of mainnet locally to test against.
Foundry (https://getfoundry.sh/) - if you want to run your build/test/debug tool-chain in Solidity
WAGMI (https://wagmi.sh/) - Robust React hooks for client-side interactions with smart contracts
Ethers.js (https://docs.ethers.io/v5/) - Client side lib for interacting with Solidity primitives like 256 bit numbers
Block Explorers like https://etherscan.io/ or https://beaconcha.in/
In the pareto distribution of smart contracts, the most consequential contracts get the most eyeballs, and after they've been deployed for years without hacks, in spite of holding billions in user funds, you can be reasonably assured of their security. If not, I invite you to use your superior powers of analysis to find a bug in:
Uniswap V3: https://github.com/Uniswap/v3-core (Currently open $2.2M bug bounty plus additional $3M reward for the Universal Router and Permit2 contracts https://uniswap.org/bug-bounty)
Or Aave V3: https://docs.aave.com/developers/deployed-contracts/security..., which has been audited by ABDK, OpenZeppelin, Trail of Bits, Peckshield, and SigmaPrime (up to $250K for critical bugs: https://github.com/aave/bug-bounty).
Also, see: https://docs.openzeppelin.com/learn/upgrading-smart-contract... about upgrading smart contracts. Not always desirable, but of course, entirely possible, thanks to the proxy pattern. There's also the alternative of doing "migrations" by wrapping an asset in another contract.