trd.fun / lab
Live lane

Live risk policy v1 — momentum 12−1

Updated 2026-08-27
Owner-approved policy (Q11=A): The 252-session expiry and bounded five-minute reconciliation contract are current under the 27 August decision record.
CURRENT
docs/research/live-risk-policy-v1-2026-08-27.md

Owner-approved policy (Q11=A): The 252-session expiry and bounded five-minute reconciliation contract are current under the 27 August decision record.

1. What this is

This is the automated contract that lets the pre-registered momentum sleeve go live on 15 September 2026 if every earlier gate passes. It converts the screening evidence into fixed loss, drawdown, data, reconciliation, long-only, review, sizing, expiry, and owner-rearm rules; it is not itself a graduation or trading approval.

  • Positive case. The fundable $10/$10m sleeve re-derives exactly at 15.02% annual mean, 0.493 Sharpe, and −68.47% monthly max drawdown. Those unscaled results are comparison only—not a permitted graduation variant. The registered overlay reduces daily realised drawdown from −74.19% to −27.63% while improving daily Sharpe from 0.482 to 0.550.
  • Only policy variant. Graduation uses the included vol-scaled 10%-target, 1.0-cap overlay; there is no variant choice. It materially reduced screening drawdown while preserving the higher daily Sharpe, but still cannot prevent an overnight gap.
  • Boundary. Screening is 1998-01-01→2021-12-31 only. No row dated 2022-01-01 or later was read; the 2022-01-01→2026-08-21 lockbox remains forbidden here.
  • Strict comparisons. “Worse than” means <, not : H1 fires when daily return is below the negative threshold; H2 fires when high-water drawdown is below the negative threshold; a soft breach occurs when cumulative return is below its p05 band.

2. Frozen thresholds

The vol-scaled 10%-target, 1.0-cap column is the only policy variant; the unscaled column is comparison only—not a permitted graduation variant. Percentages are returns or positive loss/drawdown magnitudes. Pound cells show loss/P&L at £100, £250, £500, and £10,000 capital respectively, written policy / comparison.

RulePolicy: vol-scaled 10%/cap 1.0Comparison only—not permitted: unscaledMultiplier£100 policy / comparison£250£500£10k
H1 day lossq99.5 2.5617% → kill below −3.2022%q99.5 7.6737% → −9.5922%1.25×£3.20 / £9.59£8.01 / £23.98£16.01 / £47.96£320.22 / £959.22
H2 max-DDp95 18.8710% → kill below −23.5888%p95 52.9453% → −66.1816%1.25×£23.59 / £66.18£58.97 / £165.45£117.94 / £330.91£2,358.88 / £6,618.16
Soft, 5 sessionsp05 −2.5893%p05 −6.7019%1.00×−£2.59 / −£6.70−£6.47 / −£16.75−£12.95 / −£33.51−£258.93 / −£670.19
Soft, 10 sessionsp05 −3.5346%p05 −9.9519%1.00×−£3.53 / −£9.95−£8.84 / −£24.88−£17.67 / −£49.76−£353.46 / −£995.19
Soft, 15 sessionsp05 −4.1335%p05 −11.2906%1.00×−£4.13 / −£11.29−£10.33 / −£28.23−£20.67 / −£56.45−£413.35 / −£1,129.06
Soft, 21 sessionsp05 −4.9262%p05 −13.5248%1.00×−£4.93 / −£13.52−£12.32 / −£33.81−£24.63 / −£67.62−£492.62 / −£1,352.48
Soft, 63 sessionsp05 −7.4674%p05 −22.8204%1.00×−£7.47 / −£22.82−£18.67 / −£57.05−£37.34 / −£114.10−£746.74 / −£2,282.04
Soft, 126 sessionsp05 −9.0072%p05 −28.3996%1.00×−£9.01 / −£28.40−£22.52 / −£71.00−£45.04 / −£142.00−£900.72 / −£2,839.96
Soft, 252 sessionsp05 −11.0978%p05 −33.9848%1.00×−£11.10 / −£33.98−£27.74 / −£84.96−£55.49 / −£169.92−£1,109.78 / −£3,398.48

One-day loss distribution. These are empirical screening losses; stationary resampling preserves this one-day marginal.

QuantilePolicy: vol-scaledComparison only—not permitted: unscaled
q951.1436%3.1897%
q991.9887%6.1391%
q99.52.5617%7.6737%
q99.93.9003%11.7653%
Worst day15.3721%19.6362%

One-year max-drawdown distribution. Magnitudes come from 2,000 stationary-bootstrap 252-session paths.

StatisticPolicy: vol-scaledComparison only—not permitted: unscaled
p50 simulated max DD9.6590%25.7469%
p95 simulated max DD18.8710%52.9453%
p99 simulated max DD22.1166%62.3943%
Realised screening max DD27.6290%74.1937%
  • Pound convention. H1 pounds use current sleeve capital; H2 pounds in the table use the stage target for orientation, while production compares actual sleeve equity with its actual high-water mark. No FX rate is frozen here.
  • H2 horizon and expiry. The simulated p95 max drawdown is a 252-session from-arm statistic, while the live high-water mark is uncapped since arm; lifetime breach probability therefore exceeds 5%. Policy v1 is valid only through session 252 and must be re-calibrated and sealed as v2 at or before session 252; without a bound v2 the controller disarms before session 253.
  • Non-monetary thresholds. H3 and H4 are state predicates, so a pound translation is not applicable.

3. Kill, review, and re-arm procedure

Hard means disarm now and flatten to cash at the next regular-session open. The controller records one sealed incident before any recovery action.

  • H1 — realised day loss. After each sleeve session, calculate net sleeve return after fills and costs. Fire if it is worse than −3.202155812004102%. The unscaled −9.592175927738858% threshold is comparison only—not permitted for graduation.
  • H2 — high-water drawdown. Mark sleeve equity after each fill and close, maintain a monotone, uncapped high-water mark since the sealed arm event, and fire if drawdown is worse than −23.588794655631698%. The p95 calibration horizon is 252 sessions. The unscaled −66.18156941111125% threshold is comparison only—not permitted for graduation.
  • H3 — any reconciliation or data failure. One bounded reconciliation attempt lasts no more than five minutes in the same session and includes two idempotent retries; any broker-versus-intended mismatch still present when that attempt ends is a reconciliation failure and fires H3. Any missing, stale, integrity-failing, or unverifiable session input receipt is a data failure and fires H3. Named examples—not an exhaustive definition—are Sharadar EOD not fresh by 07:00 ET, a price-file hash mismatch, an exchange-calendar mismatch, a missing corporate-action receipt, or an unavailable broker account snapshot.
  • H4 — buying power or short. Fire on any broker rejection whose normalized reason is “insufficient buying power,” or on any observed sleeve quantity below zero. This sleeve is long-only.
  • Hard action order. Atomically set armed=false; issue idempotent cancels; wait for a broker cancel/fill watermark; resnapshot positions and fills; seal trigger, timestamps, intended and broker positions, open orders, the fixed overlay, thresholds, policy hash, and data receipt; then submit an idempotent next-open flatten whose sell quantity is clamped to the latest positive position. Resnapshot after every fill and reconcile cash and zero positions through one bounded H3 attempt. A late fill restarts the cancel/resnapshot barrier; a closed venue delays the fill but never re-arms the sleeve.
  • Soft review cadence. Schedule reviews after sessions 5, 10, 15, and 21 from the sealed arm event—weekly for month one—then after sessions 63, 126, and 252. At each review compare cumulative net return since arm with the vol-scaled p05 Monte Carlo envelope at that elapsed horizon; a strict breach cuts actual size to 25% of the approved target at the next open, subject to whole shares and the ADV cap, and holds it there until owner review and a sealed sizing decision.
  • Consecutive reviews. “Two consecutive soft-breach reviews” means the next scheduled review also breaches; a passing scheduled review resets the consecutive count. Retire at the second consecutive breach. Only scheduled review results affect this count.
  • Session 252 boundary. Conduct the final v1 review at session 252. A re-calibrated, sealed v2 must be bound by then; otherwise disarm before session 253. After 252, scheduled reviews continue every 21 sessions only under the successor policy and its resealed elapsed-horizon envelope; v1 never operates beyond its calibrated horizon.
  • Owner only. Only the owner may re-arm, through a sealed approval event binding this document hash, the fixed vol-scaled overlay, ladder stage, incident cause, corrected data/reconciliation evidence, zero-short proof, and a fresh intended-position receipt. Time, a recovered process, or a successful retry cannot auto-re-arm. Retirement after two consecutive soft reviews has no automatic re-arm path.

4. Sizing ladder and gates

The ladder is 10→25→50 bp of NAV per strategy; no step is automatic. For £100,000 NAV the targets are £100, £250, and £500, inside a combined sleeve cap of £10,000.

  • Sealed step. Each stage requires a separate owner approval event binding the strategy rule hash, this policy hash, the fixed vol-scaled overlay, NAV snapshot, target pounds, live price/FX snapshot, ADV evidence, whole-share order, and prior-stage review.
  • Soft size. Twenty-five percent of the approved target is £25 / £62.50 / £125 at the 10 / 25 / 50 bp stages; 25% of the full sleeve cap is £2,500. “25%” is the fixed exposure after a soft breach, not a new ladder approval.
  • Capacity and shares. First compute allocated USD = allocated GBP × live GBPUSD; then per-name notional is min(allocated USD, 0.01 × ADV USD), and shares are floor(notional USD / live adjusted order price USD). For a $30,000-ADV name, the capacity ceiling is $300: at $10/$25/$50/$100 per share that is at most 30/12/6/3 shares. Without price and FX there is no unique whole-share count.
  • Gate order. Policy bound → prior stage evidence accepted → owner seal → NAV/£10k cap → 1% ADV cap → whole-share rounding → long-only/buying-power preflight → arm. Any failed gate leaves the prior stage unchanged and disarmed if it was already disarmed.

5. Derivation and reproduction

The fundable sleeve was re-derived from the audited confirm-card implementation, then risk was simulated once with fixed seeds.

  • Protocol. Classification-free formation universe; unadjusted price ≥$10; trailing 20-session ADV ≥$10m with 20 observations; signal closeadj[m−1] / closeadj[m−12] − 1; deterministic equal-count top decile with ticker tie-break; equal weight; decide at formation close, fill next-session adjusted open, exit next rebalance adjusted open; last observed adjusted close for a missing scheduled exit.
  • Costs. Drift-aware 10 bp per side for current-metadata Mid+ and 25 bp otherwise, including initial, rebalance, terminal, and exposure-change trades. The policy overlay uses the prior 60 completed unscaled net daily returns with a one-session lag, targets 10% annual volatility, and caps leverage at 1.0.
  • Window guard. Every price SQL predicate is < DATE '2022-01-01'; output spans 1999-01-04→2021-12-01 with 5,767 sessions. No lockbox row is queried, computed, printed, or saved.
  • Match. Re-derived monthly unscaled annual mean 0.1502379081907259, Sharpe 0.49335114157663557, and max DD −0.6846813529798809; each relative error versus the confirm-card is exactly 0. Daily gross-to-monthly reconciliation max absolute error is 1.1449174941446927e−15.
  • Bootstrap. Politis–Romano stationary bootstrap of each completed net return series; 2,000 paths; initial equity 1.0 included in every high-water calculation; geometric blocks with mean 21 sessions; path length 252; uniform restarts; NumPy default linear quantiles; seed 20260827; identical index paths for both series. The same paths, without re-seeding, produce the p05 envelope at 5/10/15/21/63/126/252 sessions. Vol-scaled paths resample realised net overlay returns and do not re-estimate the 60-session controller inside a path.
  • False-positive diagnostic. Treat the first return as session 1 of a synthetic arm, reset arm/HWM/equity/consecutive-review state every 252 observed sessions, and retain the final 223-session partial arm. Evaluate only checkpoints reached before a soft retirement. H1 is counted by day; H2 is the first from-arm crossing per synthetic arm; hard and soft mechanisms are counted independently because this is not a live replay.
  • Scratch artifacts. momentum-fundable.risk.py, momentum-fundable.risk.json, and momentum-fundable.daily.csv are custodied under ~/.local/share/tradegg/live-risk-policy/v1/ (durable local, hashed below), not in this repository. lrp.ducktmp is deleted on exit.
  • Reproduce. [local source path] ~/.local/share/tradegg/live-risk-policy/v1/momentum-fundable.risk.py; the script sets DuckDB memory_limit='1.5GB', threads=2, temp_directory=.../lrp.ducktmp, and max_temp_directory_size='3GB' before reading the sealed Sharadar DuckDB read model.

6. Historical trigger log

This is a rolling from-arm false-positive diagnostic, not a live replay or live forecast. The first screening return, 1999-01-04, is session 1 of arm 1; later synthetic arms begin at zero-based return indices 252, 504, …, 5,544, so there are 22 complete 252-session arms and one final 223-session arm. Equity, HWM, and the consecutive-review counter reset at each arm; the 5/10/15/21/63/126/252 reviews are evaluated only if reached, and review counting stops after retirement within that arm. H1 and H2 are counted independently of the soft state machine; H3/H4 are not observable in a return backtest.

DiagnosticPolicy: vol-scaled 10%/cap 1.0Comparison only—not permitted: unscaled
H1 breach days1215
H2 first from-arm breaches00
Hard-kill union1215
Scheduled reviews reached before retirement157155
Soft-breach reviews78
Retirements11
  • Policy H1 dates. 1999-01-13, 1999-01-21, 1999-01-22, 1999-02-10, 1999-02-17, 1999-03-24, 2001-09-17, 2005-10-06, 2015-08-24, 2016-09-12, 2017-12-05, 2020-03-12. H2: none.
  • Policy soft reviews. 2008-01-24 (10, first); 2009-01-08 (252, first); 2010-02-01 (15, first); 2010-02-09 (21, second → retire); 2016-01-20 (5, first); 2016-02-11 (21, first); 2020-04-15 (63, first). The sole retirement is 2010-02-09 for the arm whose first session is 2010-01-11.
  • Comparison H1 dates. 1999-01-13, 1999-04-20, 2000-03-21, 2000-03-30, 2000-04-05, 2000-04-11, 2000-04-14, 2000-04-17, 2000-04-24, 2008-10-08, 2008-10-10, 2008-10-24, 2020-03-12, 2020-03-16, 2021-03-25. H2: none.
  • Comparison soft reviews. 2000-01-07 (5, first); 2001-01-08 (5, first); 2001-01-16 (10, second → retire); 2008-01-24 (10, first); 2009-01-08 (252, first); 2010-02-01 (15, first); 2016-01-20 (5, first); 2016-02-11 (21, first). The sole retirement is 2001-01-16 for the arm whose first session is 2001-01-02.
  • Annualised screening rates. Over 5,767 sessions / 22.8849 252-session years, policy hard kills / soft-breach reviews / retirements were 0.5244 / 0.3059 / 0.0437 per year; comparison-only rates were 0.6555 / 0.3496 / 0.0437. These are screening diagnostics, not a live forecast.

7. What this policy does not cover

These are owned mitigations, not silent gaps. None weakens H1–H4.

  • Venue outage — execution owner. The policy cannot guarantee next-open liquidity or a venue reopening. Keep the sleeve disarmed, preserve/cancel orders when reachable, reconcile all fills, and let only the owner choose a new flatten window after venue status is verified.
  • Corporate-action mis-mapping — data owner. A wrong ticker/permanent-ID/action mapping can create a false intended position. Quarantine the name, stop new orders, reconcile broker and corporate-action receipts, and require a corrected sealed mapping before owner re-arm.
  • Point-in-time metadata — research owner. Historical cost buckets use current scalemarketcap; last-close exits omit unknown delisting proceeds. Keep metadata out of eligibility, retain conservative live cost/cap checks, and require an effective-dated security master before claiming this caveat is closed.
  • Enforcement implementation — engineering owner. This document and ledger are an executable specification, not a deployed controller. Graduation remains blocked until a tested fail-closed consumer verifies the policy/threshold hashes, persists incidents, enforces cancel/fill barriers, and proves the broker path in the dress rehearsal.

8. Hash and ledger

The ledger binds this policy without pretending a self-referential file can hash its own printed digest. Hash the final Markdown bytes after replacing only the next line with the same label and no value; the newline remains. The companion event copies that digest and binds the strategy preregistration rule hash.

  • Policy document SHA-256 (self-reference line blanked): 01c2102758b44067c92715ce67613f41d6ab2ef471f86e8b097c815872b5cc0d
  • Machine thresholds SHA-256: 3e512836df0ea04173186b18c89fbbe334e77d351c86a1674b5289a72945caee (UTF-8 JSON of the event’s thresholds object with keys sorted, ,/: separators, and no ASCII escaping).
  • Derivation receipts: script 2544688463eec33864a33c4b3fa3a930f7b468b0e25d386a31aded8e356b6490; risk JSON 6a0392896e80f0723c22d7fd6a8b37d365597c15323057789a9784432ee958e5; daily CSV 2e517c7b115e48b5a20673587995faf757286648cd0871a79a7659aed2f4d50b; confirm-card JSON eb8d103bb53eab9109d52ef34877c702d066c0cfe0bcd2d5549035e4eb2c08eb.
  • Ledger event: docs/research/ledger/live-risk-policy-v1.event.json; kind live_risk_policy; version live-risk-policy/v1; strategy rule hash bcf45aad640b041e17f5660225976e20dacc875c536f57f86248959c948ff796.
  • Verification: perl -0pe 's/^- Policy document SHA-256 \(self-reference line blanked\):.*$/- Policy document SHA-256 (self-reference line blanked):/m' docs/research/live-risk-policy-v1-2026-08-27.md | shasum -a 256
On this page 8 sections
LAB documentation describes design intent and research safeguards. It does not provide trading instructions or operational access.