Saltar al contenido principal

ADR 037 — Research-to-order authorization

  • Status: Accepted (2026-08-10) — ratified in chat / field ADR package (first-class module + Nautilus)
  • Related: ADR 036, principal plan

Context​

Source docs place LLMs near portfolio management and trading. Repo evidence shows a safer chain already forming:

  • Statistical promotion: PromotionPolicy (lab evidence).
  • Deterministic airlock: GateChain (alphaswarm/promotion/gate.py) — LLM-free.
  • Paper session gate: alphaswarm/trading/metadata_gate.py requiring model aspect status in {"Production","Staging"}.
  • Crossing types: StrategyPromotionRequest, OrderIntent.
  • Worker money plane: approval token + step-up + kill switch + RiskLimits inside Executor.
  • No standalone live_trading_enabled flag beyond these gates (Track D).

Decision​

Authorize research→trade as:

structured advisory (LLM/agent)
→ deterministic validation (schemas, PIT, entitlements)
→ risk (RiskLimits / pretrade / RTS6 where applicable)
→ authorization (scopes, step-up, approval tokens, HITL thresholds)
→ money plane (NativeExecutor / BotRuntime venue send)

Hard rules:

  1. OrderIntent is the sole LLM→money seam. No second agent→order path.
  2. StrategyPromotionRequest is the sole research→live crossing type.
  3. Gates remain LLM-free. LLMs may tighten limits, never raise hard limits.
  4. Reject LLMs as live execution peers (not an engine paradigm beside vectorized/live).
  5. Ray/distributed agent workflows are research-only; they must not hold venue credentials.
  6. Before live expansion, enable halt propagation and tenancy RLS per principal plan Phase 6–7.

Consequences​

  • New agent tools that emit tradeable signals must terminate in OrderIntent (or an approved synonym that translates 1:1).
  • CI/docs should treat bypass of metadata_gate / GateChain as a release blocker.
  • Optional future live_trading_enabled flag, if added, is additive documentation sugar — not a replacement for the gate chain.