Owner-ratified; not yet sealed: Fractional execution remains non-authoritative until the LL-5 chain, paper-NAV event, and merge-time rule/pin hashes close the seal blockers.
STATUS: RATIFIED BY OWNER 2026-08-31 — NOT YET SEALED. Seal blockers: LL-5 chain merged to main; the £430,000 paper-NAV event; rule/pin hashes recorded at merge. Binding 2026-08-30 decisions: “just build the fractional stuff now and keep for sep 15th date”; “im going to paper trade for a long time and only put money in when we have confirmed wins on paper trades.” Binding 2026-08-31 QGRAD direction: “profit criterion and as short as possible”. QGATE=0.80/0.80; QPAPERNAV=£430,000, the intended first-live NAV. No live date exists. v1.2 grants no authority; lockbox and rule hash bcf45aad640b041e17f5660225976e20dacc875c536f57f86248959c948ff796 remain untouched ([prereg](./prereg-momentum-12-1-long-only-v1-2026-08-27.md:11)).
Construction, paper sizing, and sealed inputs
The 2026-08-30 Alpaca paper Assets measurement (56.7% fractionable; NYSE 78%, NASDAQ 50%) is a non-research operational exception: it may choose fractional versus whole-share mechanics, never ranks, returns, thresholds, or verdicts. Mixed mode has distinct hash fractionalConstructionVariantSha256=<FINAL_AT_LL5_MERGE>; parent-rule authority is insufficient.
For post-overlay, post-1%-ADV-cap allocation aᵢ and sealed positive price pᵢ:
fractionable=true: qᵢ=floor((aᵢ/pᵢ)×10^9)/10^9 when aᵢ≥$1, else 0
fractionable=false|unknown: qᵢ=floor(aᵢ/pᵢ) when aᵢ≥$1, else 0Unknown is whole-share-or-zero; no shorts or redistribution. A fresh buy <$1 becomes zero; a positive rebalance-buy delta <$1 retains prior reconciled quantity and is excluded from fill denominators; reductions/closes sell exact nine-decimal quantity. Policy conflict on retention refuses.
Paper uses max((stageBp/10000)×paperNavUsd×overlay,$1×eligibleNames), subject to cap; $1×names is allocation, not deployment. Both QGATE fractions must be ≥0.80. Books span 69–234 names: 143 illustrative, 234 March-2021 binding. At £10k, diagnostic 1.27 FX/0.428 overlay gives Stage-1 $5.4356 and $143/$234 floors 26.31×/43.05×. The $546,728.98/£430,495.26 threshold is screening-only on those diagnostics ([review](../../.handoff-durable/fractional/review-amend-v13-r2.md:22)). At £430,000 they give $233.7308 before the $234 floor; plans use sealed contemporaneous overlay/FX.
Each plan seals prior-session unadjusted SEP close/manifest, ranks/eligibility/ADV20, 1% cap, overlay, Asset/CA, account/origin, and sizing approval. Asset/CA is post-close and ≤18h old; full refresh runs 09:25–09:29 ET at start,+15s,+45s, without partial reuse. Rank order is preserved; maps serialize UTF-8 permaticker ascending.
Target-set lineage proof (LL-5 code obligation). Every sealed execution plan carries signalFormationPlanEventHash, the formation receipt hash from which its target set derives ([current field](../../lib/live-lane/execution/plan.ts:955)). Validation loads that receipt, recomputes the canonical ordered target set, and requires byte-equality with the targets supplied to createSizingAggregate; missing receipt, hash mismatch, recomputation failure, or target/weight difference refuses before sizing or plan sealing. Direct createSizingAggregate.targetSets input without this proof is inadmissible. LL-5b implements the proof and LL-5f adds an acceptance test that mutates one ticker/weight and proves refusal, plus a canonical-match PASS test.
Actual NAV/FX source. The planner reads navSnapshotGbp, gbpUsdSnapshot (USD/GBP), and timestamps from owner-sealed sizing_approval ([loader](../../lib/live-lane/execution/plan.ts:410)); rejects age over one completed session ([freshness](../../lib/live-lane/execution/plan.ts:877)); and uses that FX ([conversion](../../lib/live-lane/execution/plan.ts:919)). Broker /v2/account equity is separate USD evidence ([NAV path](../../scripts/live-lane.mjs:661)). FX is owner-sealed ledger data; 1.27 is diagnostic-only. Attempt-seal equity must equal £430,000×gbpUsdSnapshot USD or refuse.
construction_refused="none" only if no failure applies; otherwise first applicable code wins and all codes are sealed in this precedence: authority_or_origin_invalid, construction_or_input_hash_mismatch, snapshot_unavailable_or_stale, corporate_action_unresolved, invalid_or_untradable_asset, retained_position_policy_conflict, implementability_name_below_0_80, implementability_deployed_below_0_80, order_or_reconciliation_failure.
Execution, trial, corporate actions, and authority
Fractional orders are idempotent market/DAY at 09:30 ET; whole-share legs may remain OPG. Broker VWAP is the paper fill; manifest-pinned adjusted open is audit-only. Trial 53 requires seal-time ledger maximum 52, sealed row count/SHA-256, and raw/effective N=53. Both variants use adjusted open, frozen 10/25-bp costs, next-open horizons, zero auction edge, DSR ≥0.95, active net >0, and fixed 15-split PBO≤0.20 ([PBO](../../.handoff-durable/prereg-amend-v1.2-r3.md:52)). One run; replay must reproduce hashes.
CA source is complete paginated Alpaca announcements, linked cash/CIL, and pre/post positions. Only none, canceled_with_broker_evidence, or final_reconciled releases; pending/unknown/unrecognized, changed evidence, duplicate/missing evidence, ambiguous successor, or residual cash/quantity refuses. Paper cannot prove paper/live parity; future live begins with CA refusal armed ([memo](../../.handoff-durable/fractional/fractional-feasibility.md:15)).
LL-5a authority remains exactly live-fractional-authority/v1, owner_sealed_live_fractional_authority, non-fixture, owner-sealed, minimum $1, precision 9, mixed-mode snakecase, variant `marketdayregularsession_open/v1`; raw bytes are externally pinned and loader-bound to explicit origin ([authority](../../lib/live-lane/risk/fractional-authority.ts:146)). The 0.80/0.80 gates live in the separately pinned policy/construction.
Enumerated paper-attempt calendar
Let M be the LL-5 merge commit's committer timestamp, N the NAV-seal event's sealed_utc, and T=max(M,N); the commit hash/timestamp and NAV-event hash/UTC are attempt fields. On the sealed NYSE calendar let S1=min{s:open(s)>T} and F0=min{f∈monthEndFormations:close(f)≥close(S1)}. Thus F0 follows at least one full trading session after the later sealed timestamp and is not operator timed. paperAttemptId=hash(counter,M,N,F0,calendarHash,criteriaHash).
Any 4–11 September receipts are rehearsal-only and never count toward an attempt.
At interval terminal E_k, any failure automatically emits paper_attempt_failed; that receipt both voids attempt n and triggers n+1, whose identity and start are fixed as hash(n+1,failureReceiptHash,nextFormation(E_k),calendarHash,criteriaHash) and nextFormation(E_k). Append delay cannot move the start; no intervening seal exists. Attempts are never omitted or renumbered. There is no cap. Attempt ≥3 starts automatically, but execution requires an owner paper_attempt_review referencing all failures; its timing cannot shift the window and it cannot change criteria. criteriaHash is immutable in v1.3; any change requires a new amendment, and the counter continues across versions.
Accepted residual: attempt start timing. The owner chooses when to merge LL-5 and seal NAV, hence F0; with a realized-return gate this can affect PASS probability. It remains an accepted, disclosed ex-ante choice—not evidence—because the pinned commit/NAV hashes make F0 immutable and the endpoint cannot be re-selected.
Every interval requires formation/plan and terminal coverage receipts; absence fails. A countable interval also requires submit/fill/reconcile, completed-session NAV/daemon, and policy-action receipts; absence fails.
N=3 countable formation-to-formation intervals—one nominal calendar quarter and three exercised monthly rebalances—is the minimum operational horizon: below it the initial, intervening, and terminal cycles cannot collectively expose the corporate-action, position/cash-drift, reconciliation, and no-trade paths. No-trade intervals still do not count, so elapsed calendar time may exceed a quarter. This is an operational floor, not statistical evidence.
Receipt-computable monthly tests
For side s∈{buy,sell}, eligible orders E_s exclude below_minimum_buy_retained; planned_qty is the absolute eligible delta. Monthly reference_price_usd is, by definition, the matching plan receipt's sealed deltas[].referencePrice sizing field ([plan field](../../lib/live-lane/execution/plan.ts:1046)). Sealed fields are side,planned_qty,reference_price_usd,filled_qty,fill_price_usd,commission_usd,fee_usd,disposition and lineage hashes.
P_s=Σ(E_s planned_qty×reference_price_usd); Q_s=Σ(E_s fills filled_qty×reference_price_usd)
R_buy=Q_buy/P_buy; R_sell=Q_sell/P_sell; R_all=(Q_buy+Q_sell)/(P_buy+P_sell)
IS_f=filled_qty×(fill_price_usd-reference_price_usd) for buy;
filled_qty×(reference_price_usd-fill_price_usd) for sell
G=Σ_f filled_qty×fill_price_usd; CostBp=10000×(Σcommission_usd+Σfee_usd+ΣIS_f)/G
ShortfallBp_f=10000×[(fill_price_usd/reference_price_usd)-1] buy;
10000×[1-(fill_price_usd/reference_price_usd)] sellFill price enters only cost/shortfall. An interval is countable iff P_buy+P_sell ≥ 0.50×sealed_stage_notional_usd; otherwise seal paper_no_trade_interval/v1, which neither counts nor fails. E3 is the close endpoint of the third countable interval, not the third candidate calendar interval. Every intervening no-trade interval remains inside the session window close(F0)…close(E3); its equity evolution is included in both realized and shadow paths. For a countable interval require each defined R_buy,R_sell,R_all≥0.99; a side-zero denominator is PASS-vacuous. G=0 gives CostBp=0 PASS-vacuous; require CostBp≤25, every ShortfallBp_f≤100, and complete evidence.
Incident taxonomy is the construction enum above plus the already-enumerated fractional, risk, refusal, disarm, and hard-action lane codes. incident_id is exactly the id of the originating refusal/disarm/hard-action receipt. A resolution is incident_resolution/v1 carrying resolves_incident_id=incident_id and one resolution_code from: refusal_condition_cleared, flatten_complete, position_reconciled, cash_reconciled, data_restored, authority_restored, policy_action_complete, submission_reconciled, corporate_action_final_reconciled, synthetic_drill_complete. It is unresolved at E_k iff no such receipt has sealed_at≤close(E_k); the month receipt seals the lookup result and resolution hash. “Same incident” means equal incident_id, with no other identity rule.
The closed classes below cover the lane's current implementability refusals, risk decisions, and hard-action triggers ([risk decisions](../../lib/live-lane/risk/index.ts:192), [open strings](../../lib/live-lane/risk/hard-action.ts:61)). Every proof also requires incident_class, account/origin, and policy hashes equal the originating receipt.
| Incident class | Admissible resolution code(s) | Required sealed proof predicate |
|---|---|---|
implementability_refusal | refusal_condition_cleared | new_plan_hash; same formation; implementability.passed=true; both metrics ≥0.80 |
submit_refusal | submission_reconciled | plan_hash,submit_hash,broker_orders_hash; intended client IDs occur exactly once and are terminal |
authority_refusal | authority_restored | later owner-sealed authority_event_hash; account/origin/policy bindings equal |
data_failure | data_restored | refresh_receipt_hash,manifest_hashes,fresh_through; complete, fresh, and equal plan inputs |
position_drift | position_reconciled | reconciliation_receipt_hash; expected/actual symbol quantities and plan/submit lineage equal |
cash_drift | cash_reconciled | receipt seals expected/actual cash and cash_tolerance_usd; absolute difference ≤ criteria-bound tolerance |
corporate_action_pending | corporate_action_final_reconciled | all action_ids are final_reconciled; CA, cash, and position receipt hashes present/equal |
hard_kill_flatten | flatten_complete; none after terminal proof failure | incident/disarm/flatten hashes linked; cancellations terminal, final orders/positions empty, two consecutive zero snapshots |
daemon_non_continue | policy_action_complete, authority_restored, flatten_complete | heartbeat/lease/action hashes present; action matches sealed soft_review/disarm/hard_kill decision |
rehearsal_lineage_failure | refusal_condition_cleared | rehearsal hash and expected/actual lineage hashes present/equal; canonical validator PASS |
synthetic_drill | synthetic_drill_complete | drill/incident/disarm/flatten/state hashes linked; completed=true; twoConsecutiveZeroSnapshots=true |
An invalid proof leaves an incident unresolved. Only hard_kill_flatten becomes UNRESOLVABLE for that attempt, and only after a sealed terminal hard-action receipt proves cancellation/flatten verification exhausted without the table predicate; it then has no admissible resolution code. No other class may carry unresolvable=true. LL-5 code obligation: replace authoritative open-string trigger/reasons with this incident_class enum; seal-time validation rejects unknown/absent classes, inadmissible class/code pairs, or failed predicates.
Graduation preconditions and ratification
Machinery fidelity: 3 countable intervals in one unbroken attempt pass schedule, formulas, 0.80/0.80, and incident resolution.
RISK-CONTROL INTEGRITY (control correctness, not return): no sealed H3/H4-class code—invalid_risk_state, long_only_violation, reconciliation_failure, data_failure, h4_short_or_buying_power—occurs during the attempt; every below_p05_cumulative_return soft-band breach has the exact sealed cut/retire policy-path receipt by interval terminal. day_loss_limit/drawdown_limit actions and paper returns remain telemetry; occurrence is not a graduation predicate, though prescribed handling must be complete.
REALIZED-RETURN TEST (one shot per attempt). For any session s, Equity_close(s) is the unique sealed live-lane-daily-nav-reconciliation/v1.endingNavUsd whose date=s and whose brokerAccountIdHash, brokerOrigin, and brokerMode=paper equal the attempt ([receipt](../../lib/live-lane/reconcile/index.ts:132)); its required netOfCosts=true binds actual costs into return. NAV₀ is the sealed paper-NAV value £430,000×sizing_approval.gbpUsdSnapshot ([authority fields](../../lib/live-lane/execution/plan.ts:410)).
R_cash:=0
R_real=[Equity_close(E3)−Equity_close(F0)]/NAV₀−R_cash; PASS_return iff R_real>0
R_shadow=[ShadowEquity_close(E3)−NAV₀]/NAV₀−R_cash; PASS_track iff |R_real−R_shadow|≤0.0075No cash/risk-free benchmark is sealed in the preregistration or live-risk policy; they define absolute net and equal-weight comparisons instead ([prereg](./prereg-momentum-12-1-long-only-v1-2026-08-27.md:23); [policy](./live-risk-policy-v1-2026-08-27.md:7)). Therefore the owner-visible paper convention is R_cash:=0: paper cash earns nothing, and the identical shadow convention leaves tracking unchanged.
External-flow prohibition. Deposits and withdrawals are forbidden from close(F0) through close(E3). The activity reader seals only DIV|DIVNRA|CIL ([activity enum](../../lib/live-lane/execution/alpaca.ts:88)); therefore each daily-NAV receipt must also seal endingCashUsd and unexplainedCashMovementUsd := endingCashUsd−priorEndingCashUsd−signedOrderCashUsd−dividendCashUsd−cashInLieuCashUsd, with every RHS amount recomputed from sealed order/dividend/CIL receipts and signed order cash including sealed fees. Any nonzero residual voids the attempt as external_flow_detected; there is no Flow adjustment or waiver.
Frozen shadow. Start cash at NAV₀ and positions empty. At every countable formation execute exactly the sealed plan deltas[] quantities at deltas[].referencePrice (formation snapshot price), without fill data, charging its sealed costRateByTicker (10/25 bp per side). Mark positions each session using that session's same-binding daily-NAV markPricesUsdByTicker; cash earns R_cash=0. Apply live-lane-corporate-action-adjustment/v1 and live-lane-dividend-attribution/v1 receipts ([adjustment](../../lib/live-lane/corporate-actions/index.ts:42), [dividend](../../lib/live-lane/corporate-actions/index.ts:84)) in sealed chain order, including linked dividend/CIL cash. A skipped/no-trade formation holds quantities unchanged but continues daily marking. At close(E3) mark to market without liquidation. All inputs are sealed receipts, so replay is byte-for-byte. Current daily-NAV v1 lacks endingCashUsd and markPricesUsdByTicker; LL-5 must add complete, finite-positive price fields and validate their account/origin/mode binding before seal.
The horizon band is 75 bp of NAV: N×25 bp=3×25 bp, allowing the entire sealed monthly all-in cost budget to be mis-estimated in every countable interval while tracking still passes. Both limbs must PASS at the sole endpoint E3; either FAIL emits paper_attempt_failed, publishes the reason, increments the counter, and automatically restarts. No within-attempt retest or alternative endpoint exists.
POWER DISCLOSURE. Registered screening reports 6.75% annual net mean and Sharpe 0.55 ([screening](./free-look-battery-2026-08-27.md:53); [prereg](./prereg-momentum-12-1-long-only-v1-2026-08-27.md:24)). With RF=0, iid-normal monthly inputs are μ=0.0675/12=0.5625% and σ=(0.0675/0.55)/√12=3.5428%. Thus P(PASS_return|μ)=Φ(√3μ/σ)=60.83%; P(PASS_return|μ=0)=50.00%. A one-sided α=0.05 test reaches 80% power only at ceil(((z₀.₉₅+z₀.₈₀)σ/μ)²)=246 monthly intervals (20.5 years). This approximation ignores tails/autocorrelation and does not model tracking power. At N=3 the sign test is near coin-flip and cannot confirm an edge; pre-registration prevents endpoint peeking, nothing more.
STATISTICAL VALIDITY: separately named LOCKBOX-H1 and LOCKBOX-H2, computed once using ≥2022 data at the sealed historical opening under their preregistered hashes, must both be PASS. The graduation receipt must carry lockbox_h1_verdict_receipt_sha256 and lockbox_h2_verdict_receipt_sha256, each resolving to that one-shot PASS. No paper field enters them; no recomputation or repair is allowed.
Paper Sharpe and drawdown remain telemetry; paper P&L affects graduation only through the sealed test above.
OWNER RATIFICATION — QGRAD (verbatim): QGRAD — Ratify the deterministic enumerated-attempt rule (3 countable formation-to-formation intervals; sub-50% no-trade intervals neither count nor fail; no attempt cap; attempt 3 and later require an owner review event that cannot amend criteria), the receipt formulas and tolerances, and the machinery-fidelity, risk-control-integrity, realized-return, and statistical-validity preconditions above? I ratify the one-shot R_real>0 profit rule and 75-bp shadow-tracking band at N=3, knowing that under the registered normal screening approximation (μ=0.5625%, σ=3.5428% monthly), P(PASS_return|registered edge)=60.83%, P(PASS_return|zero edge)=50.00%, and 80% power at one-sided α=0.05 requires 246 months. N=3 cannot confirm an edge; pre-registration prevents endpoint peeking, nothing more. I ratify that the attempt start is fixed at F0 by my own merge/seal timing and is not re-selectable.
Pins and seal blockers
Every digest uses its repository hash domain, is independently reproduced, and is included in the indicated owner seal:
| Artifact | Producer | When computed | Verifying consumer | Owner-sealed |
|---|---|---|---|---|
fractionalConstructionVariantSha256=<FINAL_AT_LL5_MERGE> | LL-5 integrator | final merge | planner | y |
fractionalInputSchemaSha256=<FINAL_AT_LL5_MERGE> | schema build | final merge | input loader | y |
fractionalReceiptSchemaSha256=<FINAL_AT_LL5_MERGE> | schema build | final merge | receipt validator | y |
fractionalRefusalEnumSha256 | schema build | final merge | refusal resolver | y |
candidateReturnSpecSha256 | trial author | trial seal | trial evaluator | y |
calendarHash | calendar compiler | attempt creation | attempt scheduler | y |
criteriaHash=<FINAL_AT_AMENDMENT_SEAL> | amendment compiler | amendment seal | attempt/graduation validators | y |
sizingApprovalRawSha256 | owner authority writer | NAV seal | planner/scheduler | y |
formationLineageProofSha256=<FINAL_AT_LL5_MERGE> | LL-5b build | final merge | sizing/plan validators | y |
shadowReturnSpecSha256=<FINAL_AT_LL5_MERGE> | LL-5 build | final merge | return/graduation validators | y |
dailyNavReconciliationSchemaSha256=<FINAL_AT_LL5_MERGE> | LL-5 build | final merge | NAV/shadow validators | y |
externalFlowProhibitionPredicateSha256=<FINAL_AT_LL5_MERGE> | LL-5 build | final merge | attempt validator | y |
lockbox_h1_verdict_receipt_sha256 | lockbox evaluator | one-shot opening | graduation validator | y |
lockbox_h2_verdict_receipt_sha256 | lockbox evaluator | one-shot opening | graduation validator | y |
fractionalAuthorityRawSha256 | authority writer | final merge | authority loader | y |
riskPolicySha256 | policy compiler | final merge | risk engine | y |
executorManifestSha256 | LL-5 build | final merge | CLI preflight | y |
pboSpecSha256 | trial author | trial seal | PBO evaluator | y |
caSpecSha256 | CA schema build | final merge | CA gate | y |
ledgerDigestSha256 | ledger registry | attempt/trial seal | registry verifier | y |
amendmentSelfSha256 | amendment compiler | amendment seal | seal loader | y |
The document self-hash blanks only its own value and chains predecessor 84198caeaf294eabc4edcd4596497a68a3e471ac631db5f46f2d7a04a0c6751b.
- Amendment v1.3-r4 SHA-256 (self-reference line blanked):
<FINAL_SHA256>
SEAL BLOCKERS: owner identity/UTC and revised QGRAD; £430,000 NAV/account/origin; all 21 manifest values/consumers; final criteriaHash, shadowReturnSpecSha256, daily-NAV schema with endingCashUsd/markPricesUsdByTicker, R_cash=0, and external-flow prohibition predicate; final attempt/failure/no-trade/review/incident-resolution/return schemas; LL-5b target-set lineage proof plus LL-5f mutation/PASS tests; closed incident_class enum, class/code mapping, and seal-time predicate validator replacing open strings; LL-5a–LL-5f merged and rehearsed; paper origin loaded and deterministic attempt 1 recorded before F0. Live remains blocked until one attempt passes both return limbs, LOCKBOX-H1/H2 PASS, separate owner graduation/live-origin load, and CA refusal remains armed.