Pending runbook: The path from a pre-registered confirmed paper win to funded money names existing artifacts only and grants no authority.
Date: 4 September 2026 Status: RUNBOOK — PENDING OWNER · prospective only · not sealed · no trading authority
Authority boundary: this runbook grants nothing. It names the artifacts, thresholds and rituals that already hold authority, and marks every undecided threshold as OWNER DECISION PENDING against the document that asks the question. No step here authorizes an order, a seal, a lockbox opening, or a movement of money.
1. Purpose and the two binding sentences
This runbook exists so that, when a pre-registered paper programme produces a confirmed win, the path to funded money is already written and needs no second planning round. It is a reading order over sealed artifacts, not a new authority.
Two sentences bind everything below, quoted verbatim from the repository:
- Paper-first (2026-08-30): "im going to paper trade for a long time and only put money in when we have confirmed wins on paper trades." (source:
docs/research/prereg-amend-v1.3-fractional.md#status) - No date: "No live date exists." (source:
docs/research/prereg-amend-v1.3-fractional.md#status)
The owner mandate that commissioned this runbook (relayed 2026-09-04, not itself a repository artifact) is: "Paper now, real-money path prepared. Drive to a running, pre-registered paper programme … AND draft the funding-gate runbook (0.80/0.80 gate, broker readiness) so a confirmed win can be funded without a second planning round. No real money."
Two constants are already fixed and are used throughout: QGATE = 0.80/0.80 and QPAPERNAV = £430,000, the intended first-live NAV (source: docs/research/prereg-amend-v1.3-fractional.md#status).
2. What "a pre-registered confirmed win on paper" must show
Every row must hold at the same sealed endpoint of one unbroken attempt. Any single failure emits paper_attempt_failed, voids the attempt and starts the next one; there is no within-attempt retest (source: docs/research/prereg-amend-v1.3-fractional.md#graduation-preconditions-and-ratification).
| Criterion | Threshold | Source doc / section | Who verifies | Artifact path | ||
|---|---|---|---|---|---|---|
| Pre-registration sealed BEFORE the paper run | Amendment v1.3-r4 is owner-ratified 2026-08-31 but NOT YET SEALED; every seal blocker closed, criteriaHash final, paper origin loaded and deterministic attempt 1 recorded before F0 | (source: docs/research/prereg-amend-v1.3-fractional.md#status, #pins-and-seal-blockers) | Sam seals; Fable checks the blocker list | docs/research/prereg-amend-v1.3-fractional.md plus the 21 owner-sealed pins | ||
| Attempt start not operator-timed | T=max(M,N) over the LL-5 merge commit and the NAV seal; F0 is the first month-end formation whose close is at or after the first session opening after T | (source: docs/research/prereg-amend-v1.3-fractional.md#enumerated-paper-attempt-calendar) | executor computes; Fable reads | paperAttemptId receipt | ||
| QGATE — implementable-name fraction | ≥ 0.80 | (source: docs/research/prereg-amend-v1.3-fractional.md#construction-paper-sizing-and-sealed-inputs) | executor at plan seal | sealed plan receipt; refusal code implementability_name_below_0_80 | ||
| QGATE — deployed-notional fraction | ≥ 0.80 | (source: docs/research/prereg-amend-v1.3-fractional.md#construction-paper-sizing-and-sealed-inputs) | executor at plan seal | sealed plan receipt; refusal code implementability_deployed_below_0_80 | ||
| Minimum paper duration | N = 3 countable formation-to-formation intervals in ONE unbroken attempt; an interval is countable iff P_buy+P_sell ≥ 0.50 × sealed stage notional; no-trade intervals neither count nor fail, so elapsed time may exceed a quarter | (source: docs/research/prereg-amend-v1.3-fractional.md#enumerated-paper-attempt-calendar, #receipt-computable-monthly-tests) | executor seals; Fable reads | per-interval month receipts plus paper_no_trade_interval/v1 | ||
| Per-interval execution quality | each defined R_buy, R_sell, R_all ≥ 0.99; CostBp ≤ 25; every ShortfallBp_f ≤ 100; complete evidence | (source: docs/research/prereg-amend-v1.3-fractional.md#receipt-computable-monthly-tests) | executor | month receipt | ||
| Realized-return limb (one shot) | R_real > 0 at the sole endpoint E3, net of costs, with NAV₀ = £430,000 × sizing_approval.gbpUsdSnapshot and R_cash := 0 | (source: docs/research/prereg-amend-v1.3-fractional.md#graduation-preconditions-and-ratification) | independent Codex reviewer replays | live-lane-daily-nav-reconciliation/v1 receipts | ||
| Shadow-tracking limb | ` | Rreal − Rshadow | ≤ 0.0075 — a 75 bp band, i.e. 3 × 25 bp` | (source: docs/research/prereg-amend-v1.3-fractional.md#graduation-preconditions-and-ratification) | independent Codex reviewer replays | frozen shadow ledger inputs |
| No external flows | every daily-NAV receipt seals unexplainedCashMovementUsd; any nonzero residual voids the attempt as external_flow_detected, with no waiver | (source: docs/research/prereg-amend-v1.3-fractional.md#graduation-preconditions-and-ratification) | Fable reads; Sam confirms no transfers | daily-NAV receipts | ||
| Kill-rule history clean | zero sealed H3/H4-class codes (invalid_risk_state, long_only_violation, reconciliation_failure, data_failure, h4_short_or_buying_power); every below_p05_cumulative_return soft breach carries its sealed cut/retire policy-path receipt by the interval terminal | (source: docs/research/prereg-amend-v1.3-fractional.md#graduation-preconditions-and-ratification) | Fable plus independent Codex reviewer | risk-decision and policy-action receipts | ||
| Live kill thresholds still calibrated | H1 fires below −3.202155812004102% day loss; H2 below −23.588794655631698% high-water drawdown; scheduled soft reviews at sessions 5/10/15/21/63/126/252; policy v1 is valid only through session 252 and disarms before session 253 without a sealed v2 | (source: docs/research/live-risk-policy-v1-2026-08-27.md#3-kill-review-and-re-arm-procedure, #2-frozen-thresholds) | Fable reads; only Sam re-arms | policy sha 01c2102758b44067c92715ce67613f41d6ab2ef471f86e8b097c815872b5cc0d | ||
| Reconcile authority green | every countable interval carries submit/fill/reconcile, completed-session NAV/daemon and policy-action receipts; absence fails the interval | (source: docs/research/prereg-amend-v1.3-fractional.md#enumerated-paper-attempt-calendar) | Fable via the CLI status and evidence commands | live-lane-artifacts receipt chain | ||
| Incidents resolved | each incident carries an incident_resolution/v1 with an admissible resolution_code and a passing sealed proof predicate by close(E_k); only hard_kill_flatten may become unresolvable, and only after a terminal hard-action receipt | (source: docs/research/prereg-amend-v1.3-fractional.md#receipt-computable-monthly-tests) | executor validates at seal time | incident_resolution/v1 receipts | ||
| Lockbox untouched | the lockbox and rule hash bcf45aad640b041e17f5660225976e20dacc875c536f57f86248959c948ff796 remain untouched; LOCKBOX-H1 and LOCKBOX-H2 must each be a one-shot PASS computed on data from 2022 onward, with both verdict receipt SHA-256s on the graduation receipt; no paper field enters them and no recomputation is allowed | (source: docs/research/prereg-amend-v1.3-fractional.md#status, #graduation-preconditions-and-ratification) | Sam only | lockbox_h1_verdict_receipt_sha256, lockbox_h2_verdict_receipt_sha256 | ||
| One-shot candidate statistics (momentum prefix-N) | annualized net-active mean > 0; DSR ≥ 0.95 at N = 53; fixed 15-split PBO ≤ 0.20; any miss is REFUSED forever | (source: docs/research/prereg-amendment-v1.2-canary-prefix-n-2026-08-30.md#5-one-shot-post-opening-test, docs/research/prereg-amend-v1.3-fractional.md#execution-trial-corporate-actions-and-authority) | independent Codex reviewer | trial-53 verdict receipt | ||
| Registered lockbox falsifiers (per candidate) | momentum: lockbox net excess > 0 and ≥ 50% of the screening 4.87%/yr, Newey–West t ≥ 2, at least 3 of 5 years positive, DSR ≥ 0.95; GP/A: net excess > 0 and ≥ 50% of +2.83%/yr, t ≥ 2, at least 3 of 5 years positive, DSR ≥ 0.95 — conjunctive, no retry | (source: docs/research/prereg-momentum-12-1-long-only-v1-2026-08-27.md#4-falsifier-pre-committed-lockbox-gates--any-miss--refused-no-fix-and-retry, docs/research/prereg-gross-profitability-long-only-v1-2026-08-28.md#4-falsifier-pre-committed-lockbox-gates--any-miss--refused-no-fix-and-retry) | Sam opens once; Codex reviewer replays | preregistration rule hashes | ||
| Wave-9 family-wise significance (Wave-9 candidates only) | DSR raw N = 84, clustered effective N = 14, 14 family clusters, Holm α = 0.10, Benjamini–Hochberg α = 0.10, CSCV ten blocks choose 5 of 10, reporting exact_implemented_row_set, research window ends 2021-12-31 | (source: lib/live-lane/sweep/index.ts#Wave9Corrections) | independent Codex reviewer | wave9-batch-corrections/v2 plus wave9-batch-receipt/v2 seals |
The Wave-9 declaration under scripts/__fixtures__/wave9-sweep-definition/wave9-sweep/DECLARATION-2026-08-31.md is the synthetic trial-9999 test fixture: it "is never a research artefact and grants no production or trading authority" (source: scripts/__fixtures__/wave9-sweep-definition/wave9-sweep/DECLARATION-2026-08-31.md#wave-9-synthetic-publication-fixture). Do not cite it as the sweep's registered declaration.
Statistical honesty, stated once. At N = 3 the realized-return limb is near a coin flip: under the registered screening approximation P(PASS_return | registered edge) = 60.83% and P(PASS_return | zero edge) = 50.00%, and 80% power at one-sided α = 0.05 needs 246 monthly intervals (source: docs/research/prereg-amend-v1.3-fractional.md#graduation-preconditions-and-ratification). A pass is machinery fidelity plus a pre-registered profit sign — never evidence of an edge.
3. Broker and executor readiness checklist (paper mirror to live)
- Fractional authority. Exactly
live-fractional-authority/v1, event typeowner_sealed_live_fractional_authority, non-fixture, owner-sealed, minimum $1 notional, quantity precision 9 decimals, mixed-mode snakecase, variant `marketdayregularsession_open/v1; raw bytes externally pinned and loader-bound to an explicit broker origin (source:docs/research/prereg-amend-v1.3-fractional.md#execution-trial-corporate-actions-and-authority; codelib/live-lane/risk/fractional-authority.ts, precision constant inlib/live-lane/reconcile/receipt.ts`). - The pin is code, not data.
LIVE_FRACTIONAL_AUTHORITY_OWNER_SHA256is a code-reviewed pin updated in the same reviewed change as the owner seal; replacing event bytes alone cannot re-authorize the gates, and the fixture pin is accepted only on the fixture-only, loopback, test-runtime loader path (source:lib/live-lane/risk/fractional-authority.ts). - The 0.80/0.80 gates live in policy, not in the authority. The authority event carries
minimum_implementable_name_fractionandminimum_deployed_fraction; their values come from the separately pinned policy and construction (source:docs/research/prereg-amend-v1.3-fractional.md#execution-trial-corporate-actions-and-authority). - Canary and prefix-N (amendment v1.2, still DRAFT). One deterministic whole-share OPG limit order in the first ranked candidate priced at no more than £100, canonical next-open unwind, broker quantity reconciled to zero, then a fresh H1–H4
continue; anything else permanently refuses stage 2 for that opening. Trial 53 is bound to a 67-row ledger with SHA-256b14715abd0c980362c70ec5fc1978f8f6d38c2980b9835eebeee2261d8e8a203and raw/effectiveN = 53(source:docs/research/prereg-amendment-v1.2-canary-prefix-n-2026-08-30.md#3--rank-proof-and-canary-lifecycle,#2--ledger-and-trial-accounting). - NAV event. The planner reads
navSnapshotGbp,gbpUsdSnapshotand timestamps from the owner-sealedsizing_approval, rejects an age over one completed session, and refuses unless attempt-seal equity equals £430,000 × gbpUsdSnapshot USD. FX 1.27 is diagnostic-only, never a planning input (source:docs/research/prereg-amend-v1.3-fractional.md#construction-paper-sizing-and-sealed-inputs). - Ladder. Each strategy starts at 10 bp of NAV and steps 10 → 25 → 50 bp only through separate sealed owner approvals, inside the combined sleeve cap of £10,000, the 1% ADV cap and whole-share rounding; a soft breach cuts to 25% of the approved target (source:
docs/research/live-risk-policy-v1-2026-08-27.md#4-sizing-ladder-and-gates). - Entrypoints, by name only. CLI
scripts/live-lane.mjswith commandsrefresh,simulate-window,plan,submit,reconcile,resume,drill,rehearsal-receipt,live-graduation,status,preregister,run,validate,evidence, and flags--ledger,--out,--store-root,--paper,--live,--owner,--event-id,--at,--sizing-approval-event,--lockbox-opened-event-hash,--unlock-event-id,--rehedge-from-plan-hash,--seed,--replications,--cost-multiplier,--database,--duckdb-bin,--fixture-first-date. Supervisorscripts/live-lane-daemon.mjswith--ledger,--outand--interval(default 30 seconds, orLIVE_LANE_DAEMON_INTERVAL_SECONDS); fixture-era commands are loopback-only. Reconcile authority is thereconcilecommand pluslive-lane-daily-nav-reconciliation/v1, whosenetOfCosts=trueandbrokerMode=paperbinding must equal the attempt (source:scripts/live-lane.mjs,scripts/live-lane-daemon.mjs,lib/live-lane/reconcile/index.ts). - Paper-mirror and attestation rituals, by name only.
scripts/provision-alpaca-paper-mirror-gateways-v1.mjsprovisions thepaper_mirror_runtime_gatewayandpaper_mirror_admin_gatewayroles, taking the administrator URL only from the environment and writing generated passwords once to a private caller-selected file, never to output.scripts/attest-first-hour-operational-deployments-v1.mjsproducesfirst-hour-operational-deployment-evidence/v1over the scheduler, producer and verifier lanes, with runtime tokens supplied only through the environment (source: those two script headers). - "Owner-sealed", operationally. An owner-identified, UTC-stamped event appended to the trial ledger, hash-bound to the document SHA-256, rule hash, policy SHA-256 and account/origin, reproduced independently by its verifying consumer, and — where a code pin exists — landed in the same reviewed change. Prose, an option letter, or a passing test seals nothing (source:
docs/research/prereg-amend-v1.3-fractional.md#pins-and-seal-blockers;docs/research/edge-deep-dive-2026-08-29.md#q13q16--owner-authority). - What must never be in git. Broker keys, database URLs and attestation tokens (environment only, per the two ritual scripts); the durable risk-derivation scratch artifacts custodied outside the repository (source:
docs/research/live-risk-policy-v1-2026-08-27.md#5-derivation-and-reproduction); lockbox rows and any post-2021 price data used to compute them (source:docs/research/prereg-momentum-12-1-long-only-v1-2026-08-27.md#2-exact-rule-frozen).
4. The funding ritual, step by step
Roles: Sam is the owner and the only person who seals, re-arms, opens the lockbox, handles credentials or moves money. Fable does orchestration, read-only verification and integration. Codex reviewer is an independent read-only reviewer who did not write the code under review.
- Confirm the attempt is live and clean. Run the CLI
statuscommand (Fable, read-only). Evidence: the status snapshot JSON with zero pending hard actions and a broker snapshot that matches the sealed refresh authority (source:scripts/live-lane.mjs). - Prove interval coverage. For each of the three countable intervals, show formation/plan, terminal-coverage, submit/fill/reconcile, completed-session NAV/daemon and policy-action receipts; absence fails the interval (Fable) (source:
docs/research/prereg-amend-v1.3-fractional.md#enumerated-paper-attempt-calendar). Evidence: the receipt chain under the--outdirectory. - Recompute the monthly tests from receipts.
R_buy,R_sell,R_all,CostBpand everyShortfallBp_fare recomputed, never read from stored verdicts (Codex reviewer) (source:docs/research/prereg-amend-v1.3-fractional.md#receipt-computable-monthly-tests). Evidence: a replay that reproduces the sealed month receipts byte-for-byte. - Evaluate both return limbs once at
E3.R_real > 0and|R_real − R_shadow| ≤ 0.0075(Codex reviewer) (source:docs/research/prereg-amend-v1.3-fractional.md#graduation-preconditions-and-ratification). Evidence: the daily-NAV receipt atclose(E3)and the frozen shadow replay. Either FAIL ends the attempt — do not look for an alternative endpoint. - Prove no external flow. Every daily-NAV receipt's
unexplainedCashMovementUsdis exactly zero (Fable verifies; Sam confirms that no deposit or withdrawal happened) (source:docs/research/prereg-amend-v1.3-fractional.md#graduation-preconditions-and-ratification). - Prove risk-control integrity. No sealed H3/H4-class code in the attempt, and every soft breach carries its sealed cut/retire receipt (Fable plus Codex reviewer) (source:
docs/research/prereg-amend-v1.3-fractional.md#graduation-preconditions-and-ratification). - Statistical validity — lockbox verdicts.
LOCKBOX-H1andLOCKBOX-H2must already be one-shot PASS verdicts. Hard stop: opening the lockbox is an irreversible one-shot owner ritual, and as of 2026-09-04 the standing ruling is that the lockbox stays sealed; only Sam may change that (source:docs/research/prereg-amend-v1.3-fractional.md#graduation-preconditions-and-ratification). - Owner graduation event. Sam seals graduation with the
live-graduationcommand plus--ownerand--event-id, carrying both lockbox verdict receipt hashes and bindinglive-risk-policy/v1by its document SHA-256 before any live order exists (source:scripts/live-lane.mjs;docs/research/prereg-momentum-12-1-long-only-v1-2026-08-27.md#5-live-contract-if-it-passes). - Separate live-origin load. Live stays blocked until one attempt passes both return limbs, both lockbox verdicts PASS, a separate owner graduation and live-origin load occur, and corporate-action refusal remains armed (Sam) (source:
docs/research/prereg-amend-v1.3-fractional.md#pins-and-seal-blockers). Hard stop: loading live broker credentials is a credential operation — Sam only, never an agent. - Broker readiness. Complete the fractional-authority owner seal with its reviewed pin update, provision the paper-mirror gateway roles, and produce the deployment attestation, with every secret supplied only through the environment (Sam runs; Fable reviews output that contains no secret) (source: section 3 above). Hard stop: the provisioning script writes to a database, so it is a destructive or irreversible database action and requires Sam in the loop.
- Seal the NAV event. Sam seals
sizing_approvalat £430,000 with a contemporaneousgbpUsdSnapshot; the planner refuses if attempt-seal equity does not equal£430,000 × gbpUsdSnapshotor if the approval is older than one completed session (source:docs/research/prereg-amend-v1.3-fractional.md#construction-paper-sizing-and-sealed-inputs). - Fund, at stage 1 only. Money moves only by Sam's own action, into a book that starts at 10 bp of NAV under the sealed ladder and the £10,000 combined sleeve cap, with each later step needing its own sealed approval (source:
docs/research/live-risk-policy-v1-2026-08-27.md#4-sizing-ladder-and-gates). Hard stop: the amount funded, and whether one passing attempt is enough to fund at all, are owner decisions — see section 5. - Keep the kill lane armed. From the first live order, H1–H4, the soft-review cadence and the session-252 expiry apply unchanged; only Sam may re-arm after a hard action, through a sealed approval event (source:
docs/research/live-risk-policy-v1-2026-08-27.md#3-kill-review-and-re-arm-procedure).
5. Open owner decisions that the ritual depends on
Each bullet's source tag names the document that asks the question, so the owner can answer it in place.
- Policy v2 thresholds — OWNER DECISION PENDING. Choose A
0.90/0.90with per-name headroom, B0.80/0.80or0.95/0.95, or C reject the gate; separately choose all-name versus per-name/fractional headroom and answer Q17. The stated deadline was 3 September 2026 and has passed with the document stillDRAFT — PENDING OWNER RATIFICATION(source:docs/research/ll4-multi-strategy-ledgers-2026-08-29.md#pending-owner;docs/research/live-risk-policy-v2-draft-2026-08-30.md#7--pending-owner;docs/research/edge-deep-dive-2026-08-29.md#policy-v2-fix-first-review). Until it is sealed, policy v1 remains controlling andQGATE = 0.80/0.80is the paper-side gate the preregistration already fixes. - Precedence between amendment v1.2 and policy v2 — OWNER DECISION PENDING. v1.2 keeps the all-name gate in its construction text while v2 replaces it with per-name headroom; if both are sealed, v2's per-name assessment takes precedence at submission and the owner must confirm that explicitly (source:
docs/research/prereg-amendment-v1.2-canary-prefix-n-2026-08-30.md#4--prefix-n-construction;docs/research/live-risk-policy-v2-draft-2026-08-30.md#2--whole-share-submission-rule). - Q13–Q16 — OWNER DECISION PENDING. Canary lifecycle, prefix-N authority, trial 53 with its one-shot test, and the "final hash-pinned policy v2 plus fail-closed v3 executor only" condition (source:
docs/research/prereg-amendment-v1.2-canary-prefix-n-2026-08-30.md#9--pending-owner-ratification-and-seal-blockers). - Amendment v1.3 seal — OWNER DECISION PENDING. QGRAD is ratified but the amendment is unsealed: owner identity and UTC, the £430,000 NAV/account/origin, all 21 manifest values, the final
criteriaHash, the LL-5a–LL-5f merges and rehearsal, and attempt 1 recorded beforeF0all remain open (source:docs/research/prereg-amend-v1.3-fractional.md#pins-and-seal-blockers). - Multi-strategy prerequisites — OWNER DECISION PENDING. Seal
capital-priority/v1and the strategy ranks; choose momentum's opening shadow cash versus reserve; forbid or allow same-open sale proceeds in available cash; confirm that H1/H2 preserves surviving strategies after selective cleanup; decide whether actual broker fees enter shadow NAV (source:docs/research/ll4-multi-strategy-ledgers-2026-08-29.md#pending-owner). - How much to fund, and after how many confirmed wins — OWNER DECISION PENDING. No document fixes a funding trigger or a funded amount. The preregistration fixes what one passing attempt proves and fixes
QPAPERNAV= £430,000 as the intended first-live NAV, and the standing owner sentence puts money in only on "confirmed wins" in the plural — the count, the cadence and the sum are the owner's (source:docs/research/prereg-amend-v1.3-fractional.md#graduation-preconditions-and-ratification,#status). - Lockbox and overlay — RULED 2026-09-04. The lockbox stays sealed, and the ML overlay is paper-only and labelled as such. The ruling is recorded here because steps 7 to 9 depend on it; it was relayed on 2026-09-04, is not yet a sealed repository event, and amends no preregistration.
6. Non-goals — what this runbook does not authorize
- It does not authorize a live order, a live-origin load, a broker credential operation, or any movement of money.
- It does not seal, ratify or amend anything: not amendment v1.2 or v1.3, not policy v2, not
capital-priority/v1, not a NAV or sizing approval. - It does not open the lockbox, re-run a one-shot test, repair a refused verdict, or create an alternative endpoint for a failed attempt.
- It does not change a threshold. Every number above is quoted from a sealed or drafted document and carries its source; where a document leaves a threshold open, this runbook says OWNER DECISION PENDING rather than choosing.
- It does not grant Wave-9, the ML overlay, or any unregistered candidate a paper or live path; each needs its own pre-registration, and the ML overlay remains paper-only and labelled.
- It is not evidence of an edge. A passing attempt demonstrates machinery fidelity, risk-control integrity and a pre-registered profit sign at
N = 3— nothing more (source:docs/research/prereg-amend-v1.3-fractional.md#graduation-preconditions-and-ratification).