Draft; pending owner ratification: The recommended per-name 90/90 rule remains loader-refused and cannot replace sealed policy v1 without A/B/C, Q17, final pins, and v4 engineering.
Date: 30 August 2026 Status: DRAFT — PENDING OWNER RATIFICATION · prospective only · not sealed · no trading authority
Decision boundary: Sam has not ratified this policy. It cannot replace policy v1, pass the current loader, authorize prefix-N or a canary, or authorize an order until the owner decisions, final digests, loader/executor work, tests, and amendment reseals are complete.
1 — Recommendation and unchanged controls
Recommended owner option: A — 0.90/0.90 with per-name headroom. A name without one-share headroom counts as a zero-share name inside the fraction; it is not an independent all-name failure.
V2 otherwise inherits v1's calibration, strict H1/H2/soft boundaries, H3/H4, review schedule, ladder, £10k combined sleeve cap, 1% ADV cap, and original-arm 252-session expiry. Policy rotation resets neither arm age nor the monotone uncapped HWM.
2 — Whole-share submission rule
Policy v2 is the sole proposed owner of whole-share submission semantics. For each managed name after overlay and ADV capping, but before current-position deltas and netting:
qᵢ=floor(intendedNotionalUsdᵢ/referencePriceUsdᵢ).
If headroom is below one share, qᵢ=0. The name stays in managed_names and the intended-notional denominator, and contributes zero to names_with_qty and deployed notional. An applicable positive plan passes only when both:
names_with_qty/managed_names ≥ chosen minimum; andΣ(qᵢpᵢ)/Σ(intendedNotionalUsdᵢ) ≥ chosen minimum.
Equality passes. Truly zero-intended books record applicable:false and null fractional metrics. Kill/flatten is exempt.
Why headroom must be per-name
The frozen ALL-NAME headroom rule selects a June-2013 raw-price outlier and drives the historical minimum NAV to $2,521,437,128,668,714.50 (about $2.5e15). The pre-headroom name/deployment minimum remains approximately $881,948.56. The outlier must not be silently filtered away; headroom must fold into the per-name fraction, so a name without headroom counts as zero-share. This is the single proposed widening versus v1 plus LL-4b and therefore requires separate Q17 authority.
V2 changes no rank, weight, cap, rounding, residual-cash, or reallocation rule. Amendment v1.2 owns ranking and prefix construction; it must import the sealed v2 assessment on the selected managed set. Canary and prefix authority remain separate owner decisions.
Governance reconciliation — pending owner: amendment v1.2 retains the all-name gate in its construction text, while this policy replaces that gate with per-name headroom semantics. If both documents are sealed, policy v2's per-name assessment takes precedence at submission; the owner must explicitly confirm that precedence when ratifying them.
3 — Options arithmetic
Assumptions: 143 names, GBPUSD 1.27, overlay 0.428.
| Basis | Post-overlay | USD/name | 80/80 | 90/90 | 95/95 |
|---|---|---|---|---|---|
| £10k cap | £4,280 | $38.01 | 115; £3,424 | 129; £3,852 | 136; £4,066 |
| £25k hypothetical* | £10,700 | $95.03 | 115; £8,560 | 129; £9,630 | 136; £10,165 |
| £50k hypothetical* | £21,400 | $190.06 | 115; £17,120 | 129; £19,260 | 136; £20,330 |
| Actual £100k NAV, stage-1 £100 | £42.80 | $0.3801 | 115; £34.24 | 129; £38.52 | 136; £40.66 |
\*Above the £10k cap. The actual ladder is £100/£250/£500. Stage 1 conditionally gives 0/143 shares at prices ≥$10.
4 — Integrity and loader boundary
The verified policy-v1 predecessor event SHA-256 is 79ac5beb21effd35a349d84dd91df693a8c27dcaddfcf50cb1713af69b85bb02. For the A-option event, canonical compact sorted-key JSON of .thresholds hashes to ade30e0aa3cd2b5cd60d2bdef52f258c38d877634c69a10a22664248a29d4248.
The prior r1 draft's declared-threshold-digest mismatch is closed in this r2-derived template. The document and raw event remain unsealed placeholders. At seal time the owner must compute the self-blanked document digest, insert it in the document and event, compute the final raw-event digest, and make that digest LIVE_LANE_RISK_POLICY_SHA256.
The current loader intentionally refuses this draft. A bounded canonical-v2 branch must validate identity, version, schema/calibration generations, rule hash, predecessor, document digest, threshold digest, every threshold and operational semantic, continuity, expiry, overlay, ladder/cap/ADV, and the chosen whole-share values. It must use a lossless jq-equivalent canonicalizer, deep-freeze the loaded policy, and refuse production v1 or unknown downgrade.
Execution planning and replay must consume LoadedRiskPolicy, not hard-coded or receipt-asserted values. Because the current plan lacks per-name intended notionals, policy v2 requires execution-plan v4, canonical per-name intended notionals and prices, and complete quantity/fraction/verdict/reason recomputation on every submit and rehearsal replay. V3 must refuse under v2.
Review disposition: r2 closes the review's event-integrity, continuity, no-widening, and replay-recomputation FIX items at specification level; its arithmetic and policy-read authority design reproduce. The remaining lines are all pending owner or implementation: choose A/B/C and Q17, supply identity/UTC, compute the final document/event pins, implement and test the canonical loader and v4 replay, then reseal amendment bindings.
5 — A-option event field map
The readable JSON below is a non-canonical field map, not the complete hashed event bytes. Its abbreviated thresholds object shows the unchanged inherited calibrations and the new sizing fields; the seal must use the complete r2 thresholds object whose canonical digest is printed above. It remains illustrative until the owner supplies identity, UTC, choices, and final digests.
{
"type": "live_risk_policy",
"kind": "live_risk_policy",
"strategy": "momentum-12-1-long-only-v1",
"version": "live-risk-policy/v2",
"policy_schema_generation": 2,
"risk_calibration_generation": 1,
"calibration_inherited_from_thresholds_sha256": "3e512836df0ea04173186b18c89fbbe334e77d351c86a1674b5289a72945caee",
"registered_at": "<OWNER_SUPPLIED_UTC_SEAL_TIME>",
"owner": "<OWNER_IDENTITY>",
"doc": "docs/research/live-risk-policy-v2-draft-2026-08-30.md",
"doc_sha256": "<FINAL_SELF_BLANKED_DOCUMENT_SHA256>",
"thresholds_sha256": "ade30e0aa3cd2b5cd60d2bdef52f258c38d877634c69a10a22664248a29d4248",
"rule_hash": "bcf45aad640b041e17f5660225976e20dacc875c536f57f86248959c948ff796",
"supersedes": {
"version": "live-risk-policy/v1",
"event": "docs/research/ledger/live-risk-policy-v1.event.json",
"event_sha256": "79ac5beb21effd35a349d84dd91df693a8c27dcaddfcf50cb1713af69b85bb02"
},
"thresholds": {
"variant": "vol_scaled_10pct_cap1",
"permitted_for_graduation": true,
"comparison": "strictly_worse_than",
"h1": { "loss_quantile": 0.995, "simulated_one_day_loss": 0.025617246496032815, "multiplier": 1.25, "threshold": 0.03202155812004102 },
"h2": { "max_drawdown_quantile": 0.95, "simulated_max_drawdown_magnitude": 0.18871035724505358, "simulation_horizon_sessions_from_arm": 252, "live_high_water_mark_uncapped_since_arm": true, "multiplier": 1.25, "threshold": 0.23588794655631698 },
"soft_review_p05_cumulative_return": {
"5": -0.025892826488401365,
"10": -0.03534550594261999,
"15": -0.04133519167052202,
"21": -0.049262156663940765,
"63": -0.07467429402371596,
"126": -0.09007190691373042,
"252": -0.11097804225132665
},
"operational": {
"valid_sessions_from_arm": 252,
"successor_policy_required_at_or_before_session": 252,
"expiry_action": "disarm",
"disarm_before_session_from_arm": 253,
"continuity": {
"arm_age_sessions_from_original_arm_inherited": true,
"high_water_mark_since_original_arm_inherited": true,
"policy_rotation_resets_arm_age_or_high_water_mark": false
}
},
"sizing": {
"nav_gbp": 100000,
"strategy_ladder_bp": [10, 25, 50],
"strategy_ladder_gbp": [100, 250, 500],
"combined_sleeve_cap_gbp": 10000,
"adv_fraction_cap": 0.01,
"whole_shares": true,
"whole_share_implementability": {
"applicability": "plan_intends_at_least_one_positive_target",
"target_scope": "intended_plan_target_book_before_current_position_deltas_and_order_netting",
"flatten_and_kill_plans_exempt": true,
"min_implementable_name_fraction": 0.9,
"min_deployed_fraction": 0.9,
"per_name_min_price_headroom_shares": 1,
"headroom_semantics": "below_cutoff_name_has_zero_quantity_no_independent_all_name_gate",
"zero_share_name_treatment": "included_in_managed_names_and_intended_notional_denominators_zero_in_names_with_qty_and_deployed_notional_numerators",
"comparison": "greater_than_or_equal",
"failure_action": "seal_submit_ineligible_plan_and_refuse_submission"
}
}
},
"derivation": {
"screening_start": "1998-01-01",
"screening_end": "2021-12-31",
"lockbox_start_exclusive_guard": "2022-01-01",
"bootstrap_seed": 20260827,
"bootstrap_paths": 2000,
"bootstrap_path_sessions": 252,
"stationary_bootstrap_mean_block_sessions": 21,
"overlay_vol_window_sessions": 60,
"overlay_target_annual_volatility": 0.1,
"overlay_leverage_cap": 1
}
}6 — No-widening proof
| Condition | v1 + LL-4b | Draft v2 |
|---|---|---|
| H1/H2/soft equality | Accept; breach is strictly worse | Same |
| Worse H1/H2/soft; H3/H4 | Refuse/disarm | Same |
| Arm age/HWM/252 expiry | Preserve/refuse at expiry | Same |
| £10k cap, ADV, long-only, flooring | Refuse failure | Same |
| Positive name fraction below chosen minimum | Refuse | Same |
| Deployment fraction below chosen minimum | Refuse | Same |
| Zero-share names but both aggregates pass | Refuse all-name gate | Accept only if Q17 authorizes |
| Flat plan; kill/flatten | applicable:false; flatten available | Same |
| Hash/schema/policy/replay disagreement | Refuse where checked | Stricter refusal/recomputation |
| Production v1 downgrade under v2 | Not a v2 transition | Refuse |
| Unapproved prefix-N/canary | Refuse | Refuse |
Q17 is the sole proposed v2-accept / v1-plus-LL-4b-refuse condition.
7 — Pending owner
- A — recommended:
0.90/0.90, per-name classifier above. - B: choose either
0.80/0.80or0.95/0.95, with identical semantics; regenerate the event and threshold hash. - C: reject v2; no v2-bound order.
- Q17: separately authorize the per-name relaxation from LL-4b’s all-name rule.
OWNER QUESTION: Before the 3-Sep lockbox go, choose A, B80, B95, or C and answer Q17=YES/NO; prefix-N/canary require their separate amendment authority.
SEAL BLOCKERS REMAINING: owner identity/UTC; A/B/C and Q17; final self-blanked digest/raw-event pin; v4 loader/executor hashes, tests, and amendment reseals.
Until every blocker is closed, this document remains DRAFT — PENDING OWNER RATIFICATION and policy v1 remains controlling.