Owner-approved policy (Q11=A): The 252-session expiry and bounded five-minute reconciliation contract are current under the 27 August decision record.
1. What this is
This is the automated contract that lets the pre-registered momentum sleeve go live on 15 September 2026 if every earlier gate passes. It converts the screening evidence into fixed loss, drawdown, data, reconciliation, long-only, review, sizing, expiry, and owner-rearm rules; it is not itself a graduation or trading approval.
- Positive case. The fundable $10/$10m sleeve re-derives exactly at 15.02% annual mean, 0.493 Sharpe, and −68.47% monthly max drawdown. Those unscaled results are comparison only—not a permitted graduation variant. The registered overlay reduces daily realised drawdown from −74.19% to −27.63% while improving daily Sharpe from 0.482 to 0.550.
- Only policy variant. Graduation uses the included vol-scaled 10%-target, 1.0-cap overlay; there is no variant choice. It materially reduced screening drawdown while preserving the higher daily Sharpe, but still cannot prevent an overnight gap.
- Boundary. Screening is 1998-01-01→2021-12-31 only. No row dated 2022-01-01 or later was read; the 2022-01-01→2026-08-21 lockbox remains forbidden here.
- Strict comparisons. “Worse than” means
<, not≤: H1 fires when daily return is below the negative threshold; H2 fires when high-water drawdown is below the negative threshold; a soft breach occurs when cumulative return is below its p05 band.
2. Frozen thresholds
The vol-scaled 10%-target, 1.0-cap column is the only policy variant; the unscaled column is comparison only—not a permitted graduation variant. Percentages are returns or positive loss/drawdown magnitudes. Pound cells show loss/P&L at £100, £250, £500, and £10,000 capital respectively, written policy / comparison.
| Rule | Policy: vol-scaled 10%/cap 1.0 | Comparison only—not permitted: unscaled | Multiplier | £100 policy / comparison | £250 | £500 | £10k |
|---|---|---|---|---|---|---|---|
| H1 day loss | q99.5 2.5617% → kill below −3.2022% | q99.5 7.6737% → −9.5922% | 1.25× | £3.20 / £9.59 | £8.01 / £23.98 | £16.01 / £47.96 | £320.22 / £959.22 |
| H2 max-DD | p95 18.8710% → kill below −23.5888% | p95 52.9453% → −66.1816% | 1.25× | £23.59 / £66.18 | £58.97 / £165.45 | £117.94 / £330.91 | £2,358.88 / £6,618.16 |
| Soft, 5 sessions | p05 −2.5893% | p05 −6.7019% | 1.00× | −£2.59 / −£6.70 | −£6.47 / −£16.75 | −£12.95 / −£33.51 | −£258.93 / −£670.19 |
| Soft, 10 sessions | p05 −3.5346% | p05 −9.9519% | 1.00× | −£3.53 / −£9.95 | −£8.84 / −£24.88 | −£17.67 / −£49.76 | −£353.46 / −£995.19 |
| Soft, 15 sessions | p05 −4.1335% | p05 −11.2906% | 1.00× | −£4.13 / −£11.29 | −£10.33 / −£28.23 | −£20.67 / −£56.45 | −£413.35 / −£1,129.06 |
| Soft, 21 sessions | p05 −4.9262% | p05 −13.5248% | 1.00× | −£4.93 / −£13.52 | −£12.32 / −£33.81 | −£24.63 / −£67.62 | −£492.62 / −£1,352.48 |
| Soft, 63 sessions | p05 −7.4674% | p05 −22.8204% | 1.00× | −£7.47 / −£22.82 | −£18.67 / −£57.05 | −£37.34 / −£114.10 | −£746.74 / −£2,282.04 |
| Soft, 126 sessions | p05 −9.0072% | p05 −28.3996% | 1.00× | −£9.01 / −£28.40 | −£22.52 / −£71.00 | −£45.04 / −£142.00 | −£900.72 / −£2,839.96 |
| Soft, 252 sessions | p05 −11.0978% | p05 −33.9848% | 1.00× | −£11.10 / −£33.98 | −£27.74 / −£84.96 | −£55.49 / −£169.92 | −£1,109.78 / −£3,398.48 |
One-day loss distribution. These are empirical screening losses; stationary resampling preserves this one-day marginal.
| Quantile | Policy: vol-scaled | Comparison only—not permitted: unscaled |
|---|---|---|
| q95 | 1.1436% | 3.1897% |
| q99 | 1.9887% | 6.1391% |
| q99.5 | 2.5617% | 7.6737% |
| q99.9 | 3.9003% | 11.7653% |
| Worst day | 15.3721% | 19.6362% |
One-year max-drawdown distribution. Magnitudes come from 2,000 stationary-bootstrap 252-session paths.
| Statistic | Policy: vol-scaled | Comparison only—not permitted: unscaled |
|---|---|---|
| p50 simulated max DD | 9.6590% | 25.7469% |
| p95 simulated max DD | 18.8710% | 52.9453% |
| p99 simulated max DD | 22.1166% | 62.3943% |
| Realised screening max DD | 27.6290% | 74.1937% |
- Pound convention. H1 pounds use current sleeve capital; H2 pounds in the table use the stage target for orientation, while production compares actual sleeve equity with its actual high-water mark. No FX rate is frozen here.
- H2 horizon and expiry. The simulated p95 max drawdown is a 252-session from-arm statistic, while the live high-water mark is uncapped since arm; lifetime breach probability therefore exceeds 5%. Policy v1 is valid only through session 252 and must be re-calibrated and sealed as v2 at or before session 252; without a bound v2 the controller disarms before session 253.
- Non-monetary thresholds. H3 and H4 are state predicates, so a pound translation is not applicable.
3. Kill, review, and re-arm procedure
Hard means disarm now and flatten to cash at the next regular-session open. The controller records one sealed incident before any recovery action.
- H1 — realised day loss. After each sleeve session, calculate net sleeve return after fills and costs. Fire if it is worse than −3.202155812004102%. The unscaled −9.592175927738858% threshold is comparison only—not permitted for graduation.
- H2 — high-water drawdown. Mark sleeve equity after each fill and close, maintain a monotone, uncapped high-water mark since the sealed arm event, and fire if drawdown is worse than −23.588794655631698%. The p95 calibration horizon is 252 sessions. The unscaled −66.18156941111125% threshold is comparison only—not permitted for graduation.
- H3 — any reconciliation or data failure. One bounded reconciliation attempt lasts no more than five minutes in the same session and includes two idempotent retries; any broker-versus-intended mismatch still present when that attempt ends is a reconciliation failure and fires H3. Any missing, stale, integrity-failing, or unverifiable session input receipt is a data failure and fires H3. Named examples—not an exhaustive definition—are Sharadar EOD not fresh by 07:00 ET, a price-file hash mismatch, an exchange-calendar mismatch, a missing corporate-action receipt, or an unavailable broker account snapshot.
- H4 — buying power or short. Fire on any broker rejection whose normalized reason is “insufficient buying power,” or on any observed sleeve quantity below zero. This sleeve is long-only.
- Hard action order. Atomically set
armed=false; issue idempotent cancels; wait for a broker cancel/fill watermark; resnapshot positions and fills; seal trigger, timestamps, intended and broker positions, open orders, the fixed overlay, thresholds, policy hash, and data receipt; then submit an idempotent next-open flatten whose sell quantity is clamped to the latest positive position. Resnapshot after every fill and reconcile cash and zero positions through one bounded H3 attempt. A late fill restarts the cancel/resnapshot barrier; a closed venue delays the fill but never re-arms the sleeve. - Soft review cadence. Schedule reviews after sessions 5, 10, 15, and 21 from the sealed arm event—weekly for month one—then after sessions 63, 126, and 252. At each review compare cumulative net return since arm with the vol-scaled p05 Monte Carlo envelope at that elapsed horizon; a strict breach cuts actual size to 25% of the approved target at the next open, subject to whole shares and the ADV cap, and holds it there until owner review and a sealed sizing decision.
- Consecutive reviews. “Two consecutive soft-breach reviews” means the next scheduled review also breaches; a passing scheduled review resets the consecutive count. Retire at the second consecutive breach. Only scheduled review results affect this count.
- Session 252 boundary. Conduct the final v1 review at session 252. A re-calibrated, sealed v2 must be bound by then; otherwise disarm before session 253. After 252, scheduled reviews continue every 21 sessions only under the successor policy and its resealed elapsed-horizon envelope; v1 never operates beyond its calibrated horizon.
- Owner only. Only the owner may re-arm, through a sealed approval event binding this document hash, the fixed vol-scaled overlay, ladder stage, incident cause, corrected data/reconciliation evidence, zero-short proof, and a fresh intended-position receipt. Time, a recovered process, or a successful retry cannot auto-re-arm. Retirement after two consecutive soft reviews has no automatic re-arm path.
4. Sizing ladder and gates
The ladder is 10→25→50 bp of NAV per strategy; no step is automatic. For £100,000 NAV the targets are £100, £250, and £500, inside a combined sleeve cap of £10,000.
- Sealed step. Each stage requires a separate owner approval event binding the strategy rule hash, this policy hash, the fixed vol-scaled overlay, NAV snapshot, target pounds, live price/FX snapshot, ADV evidence, whole-share order, and prior-stage review.
- Soft size. Twenty-five percent of the approved target is £25 / £62.50 / £125 at the 10 / 25 / 50 bp stages; 25% of the full sleeve cap is £2,500. “25%” is the fixed exposure after a soft breach, not a new ladder approval.
- Capacity and shares. First compute
allocated USD = allocated GBP × live GBPUSD; then per-name notional ismin(allocated USD, 0.01 × ADV USD), and shares arefloor(notional USD / live adjusted order price USD). For a $30,000-ADV name, the capacity ceiling is $300: at $10/$25/$50/$100 per share that is at most 30/12/6/3 shares. Without price and FX there is no unique whole-share count. - Gate order. Policy bound → prior stage evidence accepted → owner seal → NAV/£10k cap → 1% ADV cap → whole-share rounding → long-only/buying-power preflight → arm. Any failed gate leaves the prior stage unchanged and disarmed if it was already disarmed.
5. Derivation and reproduction
The fundable sleeve was re-derived from the audited confirm-card implementation, then risk was simulated once with fixed seeds.
- Protocol. Classification-free formation universe; unadjusted price ≥$10; trailing 20-session ADV ≥$10m with 20 observations; signal
closeadj[m−1] / closeadj[m−12] − 1; deterministic equal-count top decile with ticker tie-break; equal weight; decide at formation close, fill next-session adjusted open, exit next rebalance adjusted open; last observed adjusted close for a missing scheduled exit. - Costs. Drift-aware 10 bp per side for current-metadata Mid+ and 25 bp otherwise, including initial, rebalance, terminal, and exposure-change trades. The policy overlay uses the prior 60 completed unscaled net daily returns with a one-session lag, targets 10% annual volatility, and caps leverage at 1.0.
- Window guard. Every price SQL predicate is
< DATE '2022-01-01'; output spans 1999-01-04→2021-12-01 with 5,767 sessions. No lockbox row is queried, computed, printed, or saved. - Match. Re-derived monthly unscaled annual mean
0.1502379081907259, Sharpe0.49335114157663557, and max DD−0.6846813529798809; each relative error versus the confirm-card is exactly 0. Daily gross-to-monthly reconciliation max absolute error is1.1449174941446927e−15. - Bootstrap. Politis–Romano stationary bootstrap of each completed net return series; 2,000 paths; initial equity 1.0 included in every high-water calculation; geometric blocks with mean 21 sessions; path length 252; uniform restarts; NumPy default linear quantiles; seed
20260827; identical index paths for both series. The same paths, without re-seeding, produce the p05 envelope at 5/10/15/21/63/126/252 sessions. Vol-scaled paths resample realised net overlay returns and do not re-estimate the 60-session controller inside a path. - False-positive diagnostic. Treat the first return as session 1 of a synthetic arm, reset arm/HWM/equity/consecutive-review state every 252 observed sessions, and retain the final 223-session partial arm. Evaluate only checkpoints reached before a soft retirement. H1 is counted by day; H2 is the first from-arm crossing per synthetic arm; hard and soft mechanisms are counted independently because this is not a live replay.
- Scratch artifacts.
momentum-fundable.risk.py,momentum-fundable.risk.json, andmomentum-fundable.daily.csvare custodied under~/.local/share/tradegg/live-risk-policy/v1/(durable local, hashed below), not in this repository.lrp.ducktmpis deleted on exit. - Reproduce.
[local source path] ~/.local/share/tradegg/live-risk-policy/v1/momentum-fundable.risk.py; the script sets DuckDBmemory_limit='1.5GB',threads=2,temp_directory=.../lrp.ducktmp, andmax_temp_directory_size='3GB'before reading the sealed Sharadar DuckDB read model.
6. Historical trigger log
This is a rolling from-arm false-positive diagnostic, not a live replay or live forecast. The first screening return, 1999-01-04, is session 1 of arm 1; later synthetic arms begin at zero-based return indices 252, 504, …, 5,544, so there are 22 complete 252-session arms and one final 223-session arm. Equity, HWM, and the consecutive-review counter reset at each arm; the 5/10/15/21/63/126/252 reviews are evaluated only if reached, and review counting stops after retirement within that arm. H1 and H2 are counted independently of the soft state machine; H3/H4 are not observable in a return backtest.
| Diagnostic | Policy: vol-scaled 10%/cap 1.0 | Comparison only—not permitted: unscaled |
|---|---|---|
| H1 breach days | 12 | 15 |
| H2 first from-arm breaches | 0 | 0 |
| Hard-kill union | 12 | 15 |
| Scheduled reviews reached before retirement | 157 | 155 |
| Soft-breach reviews | 7 | 8 |
| Retirements | 1 | 1 |
- Policy H1 dates. 1999-01-13, 1999-01-21, 1999-01-22, 1999-02-10, 1999-02-17, 1999-03-24, 2001-09-17, 2005-10-06, 2015-08-24, 2016-09-12, 2017-12-05, 2020-03-12. H2: none.
- Policy soft reviews. 2008-01-24 (10, first); 2009-01-08 (252, first); 2010-02-01 (15, first); 2010-02-09 (21, second → retire); 2016-01-20 (5, first); 2016-02-11 (21, first); 2020-04-15 (63, first). The sole retirement is 2010-02-09 for the arm whose first session is 2010-01-11.
- Comparison H1 dates. 1999-01-13, 1999-04-20, 2000-03-21, 2000-03-30, 2000-04-05, 2000-04-11, 2000-04-14, 2000-04-17, 2000-04-24, 2008-10-08, 2008-10-10, 2008-10-24, 2020-03-12, 2020-03-16, 2021-03-25. H2: none.
- Comparison soft reviews. 2000-01-07 (5, first); 2001-01-08 (5, first); 2001-01-16 (10, second → retire); 2008-01-24 (10, first); 2009-01-08 (252, first); 2010-02-01 (15, first); 2016-01-20 (5, first); 2016-02-11 (21, first). The sole retirement is 2001-01-16 for the arm whose first session is 2001-01-02.
- Annualised screening rates. Over 5,767 sessions / 22.8849 252-session years, policy hard kills / soft-breach reviews / retirements were 0.5244 / 0.3059 / 0.0437 per year; comparison-only rates were 0.6555 / 0.3496 / 0.0437. These are screening diagnostics, not a live forecast.
7. What this policy does not cover
These are owned mitigations, not silent gaps. None weakens H1–H4.
- Venue outage — execution owner. The policy cannot guarantee next-open liquidity or a venue reopening. Keep the sleeve disarmed, preserve/cancel orders when reachable, reconcile all fills, and let only the owner choose a new flatten window after venue status is verified.
- Corporate-action mis-mapping — data owner. A wrong ticker/permanent-ID/action mapping can create a false intended position. Quarantine the name, stop new orders, reconcile broker and corporate-action receipts, and require a corrected sealed mapping before owner re-arm.
- Point-in-time metadata — research owner. Historical cost buckets use current
scalemarketcap; last-close exits omit unknown delisting proceeds. Keep metadata out of eligibility, retain conservative live cost/cap checks, and require an effective-dated security master before claiming this caveat is closed. - Enforcement implementation — engineering owner. This document and ledger are an executable specification, not a deployed controller. Graduation remains blocked until a tested fail-closed consumer verifies the policy/threshold hashes, persists incidents, enforces cancel/fill barriers, and proves the broker path in the dress rehearsal.
8. Hash and ledger
The ledger binds this policy without pretending a self-referential file can hash its own printed digest. Hash the final Markdown bytes after replacing only the next line with the same label and no value; the newline remains. The companion event copies that digest and binds the strategy preregistration rule hash.
- Policy document SHA-256 (self-reference line blanked): 01c2102758b44067c92715ce67613f41d6ab2ef471f86e8b097c815872b5cc0d
- Machine thresholds SHA-256:
3e512836df0ea04173186b18c89fbbe334e77d351c86a1674b5289a72945caee(UTF-8 JSON of the event’sthresholdsobject with keys sorted,,/:separators, and no ASCII escaping). - Derivation receipts: script
2544688463eec33864a33c4b3fa3a930f7b468b0e25d386a31aded8e356b6490; risk JSON6a0392896e80f0723c22d7fd6a8b37d365597c15323057789a9784432ee958e5; daily CSV2e517c7b115e48b5a20673587995faf757286648cd0871a79a7659aed2f4d50b; confirm-card JSONeb8d103bb53eab9109d52ef34877c702d066c0cfe0bcd2d5549035e4eb2c08eb. - Ledger event:
docs/research/ledger/live-risk-policy-v1.event.json; kindlive_risk_policy; versionlive-risk-policy/v1; strategy rule hashbcf45aad640b041e17f5660225976e20dacc875c536f57f86248959c948ff796. - Verification:
perl -0pe 's/^- Policy document SHA-256 \(self-reference line blanked\):.*$/- Policy document SHA-256 (self-reference line blanked):/m' docs/research/live-risk-policy-v1-2026-08-27.md | shasum -a 256