trd.fun / lab
Live lane

Live risk policy v2 — whole-share implementability draft

Updated 2026-08-30
Draft; pending owner ratification: The recommended per-name 90/90 rule remains loader-refused and cannot replace sealed policy v1 without A/B/C, Q17, final pins, and v4 engineering.
PENDING OWNER
docs/research/live-risk-policy-v2-draft-2026-08-30.md

Draft; pending owner ratification: The recommended per-name 90/90 rule remains loader-refused and cannot replace sealed policy v1 without A/B/C, Q17, final pins, and v4 engineering.

Date: 30 August 2026 Status: DRAFT — PENDING OWNER RATIFICATION · prospective only · not sealed · no trading authority

Decision boundary: Sam has not ratified this policy. It cannot replace policy v1, pass the current loader, authorize prefix-N or a canary, or authorize an order until the owner decisions, final digests, loader/executor work, tests, and amendment reseals are complete.

1 — Recommendation and unchanged controls

Recommended owner option: A — 0.90/0.90 with per-name headroom. A name without one-share headroom counts as a zero-share name inside the fraction; it is not an independent all-name failure.

V2 otherwise inherits v1's calibration, strict H1/H2/soft boundaries, H3/H4, review schedule, ladder, £10k combined sleeve cap, 1% ADV cap, and original-arm 252-session expiry. Policy rotation resets neither arm age nor the monotone uncapped HWM.

2 — Whole-share submission rule

Policy v2 is the sole proposed owner of whole-share submission semantics. For each managed name after overlay and ADV capping, but before current-position deltas and netting:

qᵢ=floor(intendedNotionalUsdᵢ/referencePriceUsdᵢ).

If headroom is below one share, qᵢ=0. The name stays in managed_names and the intended-notional denominator, and contributes zero to names_with_qty and deployed notional. An applicable positive plan passes only when both:

  • names_with_qty/managed_names ≥ chosen minimum; and
  • Σ(qᵢpᵢ)/Σ(intendedNotionalUsdᵢ) ≥ chosen minimum.

Equality passes. Truly zero-intended books record applicable:false and null fractional metrics. Kill/flatten is exempt.

Why headroom must be per-name

The frozen ALL-NAME headroom rule selects a June-2013 raw-price outlier and drives the historical minimum NAV to $2,521,437,128,668,714.50 (about $2.5e15). The pre-headroom name/deployment minimum remains approximately $881,948.56. The outlier must not be silently filtered away; headroom must fold into the per-name fraction, so a name without headroom counts as zero-share. This is the single proposed widening versus v1 plus LL-4b and therefore requires separate Q17 authority.

V2 changes no rank, weight, cap, rounding, residual-cash, or reallocation rule. Amendment v1.2 owns ranking and prefix construction; it must import the sealed v2 assessment on the selected managed set. Canary and prefix authority remain separate owner decisions.

Governance reconciliation — pending owner: amendment v1.2 retains the all-name gate in its construction text, while this policy replaces that gate with per-name headroom semantics. If both documents are sealed, policy v2's per-name assessment takes precedence at submission; the owner must explicitly confirm that precedence when ratifying them.

3 — Options arithmetic

Assumptions: 143 names, GBPUSD 1.27, overlay 0.428.

BasisPost-overlayUSD/name80/8090/9095/95
£10k cap£4,280$38.01115; £3,424129; £3,852136; £4,066
£25k hypothetical*£10,700$95.03115; £8,560129; £9,630136; £10,165
£50k hypothetical*£21,400$190.06115; £17,120129; £19,260136; £20,330
Actual £100k NAV, stage-1 £100£42.80$0.3801115; £34.24129; £38.52136; £40.66

\*Above the £10k cap. The actual ladder is £100/£250/£500. Stage 1 conditionally gives 0/143 shares at prices ≥$10.

4 — Integrity and loader boundary

The verified policy-v1 predecessor event SHA-256 is 79ac5beb21effd35a349d84dd91df693a8c27dcaddfcf50cb1713af69b85bb02. For the A-option event, canonical compact sorted-key JSON of .thresholds hashes to ade30e0aa3cd2b5cd60d2bdef52f258c38d877634c69a10a22664248a29d4248.

The prior r1 draft's declared-threshold-digest mismatch is closed in this r2-derived template. The document and raw event remain unsealed placeholders. At seal time the owner must compute the self-blanked document digest, insert it in the document and event, compute the final raw-event digest, and make that digest LIVE_LANE_RISK_POLICY_SHA256.

The current loader intentionally refuses this draft. A bounded canonical-v2 branch must validate identity, version, schema/calibration generations, rule hash, predecessor, document digest, threshold digest, every threshold and operational semantic, continuity, expiry, overlay, ladder/cap/ADV, and the chosen whole-share values. It must use a lossless jq-equivalent canonicalizer, deep-freeze the loaded policy, and refuse production v1 or unknown downgrade.

Execution planning and replay must consume LoadedRiskPolicy, not hard-coded or receipt-asserted values. Because the current plan lacks per-name intended notionals, policy v2 requires execution-plan v4, canonical per-name intended notionals and prices, and complete quantity/fraction/verdict/reason recomputation on every submit and rehearsal replay. V3 must refuse under v2.

Review disposition: r2 closes the review's event-integrity, continuity, no-widening, and replay-recomputation FIX items at specification level; its arithmetic and policy-read authority design reproduce. The remaining lines are all pending owner or implementation: choose A/B/C and Q17, supply identity/UTC, compute the final document/event pins, implement and test the canonical loader and v4 replay, then reseal amendment bindings.

5 — A-option event field map

The readable JSON below is a non-canonical field map, not the complete hashed event bytes. Its abbreviated thresholds object shows the unchanged inherited calibrations and the new sizing fields; the seal must use the complete r2 thresholds object whose canonical digest is printed above. It remains illustrative until the owner supplies identity, UTC, choices, and final digests.

{
  "type": "live_risk_policy",
  "kind": "live_risk_policy",
  "strategy": "momentum-12-1-long-only-v1",
  "version": "live-risk-policy/v2",
  "policy_schema_generation": 2,
  "risk_calibration_generation": 1,
  "calibration_inherited_from_thresholds_sha256": "3e512836df0ea04173186b18c89fbbe334e77d351c86a1674b5289a72945caee",
  "registered_at": "<OWNER_SUPPLIED_UTC_SEAL_TIME>",
  "owner": "<OWNER_IDENTITY>",
  "doc": "docs/research/live-risk-policy-v2-draft-2026-08-30.md",
  "doc_sha256": "<FINAL_SELF_BLANKED_DOCUMENT_SHA256>",
  "thresholds_sha256": "ade30e0aa3cd2b5cd60d2bdef52f258c38d877634c69a10a22664248a29d4248",
  "rule_hash": "bcf45aad640b041e17f5660225976e20dacc875c536f57f86248959c948ff796",
  "supersedes": {
    "version": "live-risk-policy/v1",
    "event": "docs/research/ledger/live-risk-policy-v1.event.json",
    "event_sha256": "79ac5beb21effd35a349d84dd91df693a8c27dcaddfcf50cb1713af69b85bb02"
  },
  "thresholds": {
    "variant": "vol_scaled_10pct_cap1",
    "permitted_for_graduation": true,
    "comparison": "strictly_worse_than",
    "h1": { "loss_quantile": 0.995, "simulated_one_day_loss": 0.025617246496032815, "multiplier": 1.25, "threshold": 0.03202155812004102 },
    "h2": { "max_drawdown_quantile": 0.95, "simulated_max_drawdown_magnitude": 0.18871035724505358, "simulation_horizon_sessions_from_arm": 252, "live_high_water_mark_uncapped_since_arm": true, "multiplier": 1.25, "threshold": 0.23588794655631698 },
    "soft_review_p05_cumulative_return": {
      "5": -0.025892826488401365,
      "10": -0.03534550594261999,
      "15": -0.04133519167052202,
      "21": -0.049262156663940765,
      "63": -0.07467429402371596,
      "126": -0.09007190691373042,
      "252": -0.11097804225132665
    },
    "operational": {
      "valid_sessions_from_arm": 252,
      "successor_policy_required_at_or_before_session": 252,
      "expiry_action": "disarm",
      "disarm_before_session_from_arm": 253,
      "continuity": {
        "arm_age_sessions_from_original_arm_inherited": true,
        "high_water_mark_since_original_arm_inherited": true,
        "policy_rotation_resets_arm_age_or_high_water_mark": false
      }
    },
    "sizing": {
      "nav_gbp": 100000,
      "strategy_ladder_bp": [10, 25, 50],
      "strategy_ladder_gbp": [100, 250, 500],
      "combined_sleeve_cap_gbp": 10000,
      "adv_fraction_cap": 0.01,
      "whole_shares": true,
      "whole_share_implementability": {
        "applicability": "plan_intends_at_least_one_positive_target",
        "target_scope": "intended_plan_target_book_before_current_position_deltas_and_order_netting",
        "flatten_and_kill_plans_exempt": true,
        "min_implementable_name_fraction": 0.9,
        "min_deployed_fraction": 0.9,
        "per_name_min_price_headroom_shares": 1,
        "headroom_semantics": "below_cutoff_name_has_zero_quantity_no_independent_all_name_gate",
        "zero_share_name_treatment": "included_in_managed_names_and_intended_notional_denominators_zero_in_names_with_qty_and_deployed_notional_numerators",
        "comparison": "greater_than_or_equal",
        "failure_action": "seal_submit_ineligible_plan_and_refuse_submission"
      }
    }
  },
  "derivation": {
    "screening_start": "1998-01-01",
    "screening_end": "2021-12-31",
    "lockbox_start_exclusive_guard": "2022-01-01",
    "bootstrap_seed": 20260827,
    "bootstrap_paths": 2000,
    "bootstrap_path_sessions": 252,
    "stationary_bootstrap_mean_block_sessions": 21,
    "overlay_vol_window_sessions": 60,
    "overlay_target_annual_volatility": 0.1,
    "overlay_leverage_cap": 1
  }
}

6 — No-widening proof

Conditionv1 + LL-4bDraft v2
H1/H2/soft equalityAccept; breach is strictly worseSame
Worse H1/H2/soft; H3/H4Refuse/disarmSame
Arm age/HWM/252 expiryPreserve/refuse at expirySame
£10k cap, ADV, long-only, flooringRefuse failureSame
Positive name fraction below chosen minimumRefuseSame
Deployment fraction below chosen minimumRefuseSame
Zero-share names but both aggregates passRefuse all-name gateAccept only if Q17 authorizes
Flat plan; kill/flattenapplicable:false; flatten availableSame
Hash/schema/policy/replay disagreementRefuse where checkedStricter refusal/recomputation
Production v1 downgrade under v2Not a v2 transitionRefuse
Unapproved prefix-N/canaryRefuseRefuse

Q17 is the sole proposed v2-accept / v1-plus-LL-4b-refuse condition.

7 — Pending owner

  • A — recommended: 0.90/0.90, per-name classifier above.
  • B: choose either 0.80/0.80 or 0.95/0.95, with identical semantics; regenerate the event and threshold hash.
  • C: reject v2; no v2-bound order.
  • Q17: separately authorize the per-name relaxation from LL-4b’s all-name rule.

OWNER QUESTION: Before the 3-Sep lockbox go, choose A, B80, B95, or C and answer Q17=YES/NO; prefix-N/canary require their separate amendment authority.

SEAL BLOCKERS REMAINING: owner identity/UTC; A/B/C and Q17; final self-blanked digest/raw-event pin; v4 loader/executor hashes, tests, and amendment reseals.

Until every blocker is closed, this document remains DRAFT — PENDING OWNER RATIFICATION and policy v1 remains controlling.

On this page 8 sections
LAB documentation describes design intent and research safeguards. It does not provide trading instructions or operational access.