Skip to content
Risk & safety model

Going live with real money

Planned. How one book reaches real-money trading (a checklist the system computes, a ceremony you perform, a $500 first stage, automatic demotion), and why none of it is a switch.

Who it is for
Owners & operators
Reading time
7 min read
Updated
Status
coming soon

Planned, not shipped.This page describes something that is designed but not in the console today. Nothing here is available yet unless a sentence says so.

Real-money trading is planned and not in this build. Every book trades paper today, and nothing on any , in any setting or in any deployment file can change that: the design below is what will stand between a and a live one when it ships. It replaces the older four-step ceremony described on Paper vs live with a per-book procedure. Two things will never change: the system cannot move money (no deposits, withdrawals or transfers, ever), and going live is never one click.

Who
The owner, for their own individual brokerage account only. Books you share with others stay paper.
What it is
A new, separate book marked LIVE — never a switch on an existing paper book
Before you can start
A checklist the system computes from its own records; every row must be green, and "could not measure" red
The ceremony
Sign the checklist, confirm the account, type a phrase that names the money, wait 24 hours, confirm again from a
First stage
Tiny: at most $500 of real exposure; Manual, Semi or Full is your choice, as on paper
Going back
One click, any time, from wherever the button is

What has to be true first

Paper → live readiness grows from today's thirteen-gate scorecard into the full checklist. The system computes every row from data it already holds; you cannot tick a row green, and a row it cannot measure stays red. In plain words the rows are:

  • The audit is closed. Every top-severity finding from the investment-logic audit is fixed and verified, and the protective-exit items in particular: an exit is never blocked by a day-trading rule, every position has a stop resting at the broker as a backstop, a missed heartbeat pages you.
  • Sixty paper trading days on the strategy you will trade live, with real fills. Changing the strategy (weights, , parameters) restarts the count, on purpose.
  • Evidence with error bars, not a good week. The paper track record scorecard green five days running; the paper Sharpe ratio's lower confidence bound above zero (a point estimate is not enough); the worst paper inside your 's budget; execution cost actually measured against the price at decision time; the desk's competence scores at threshold.
  • The books agree with the broker to the cent for twenty consecutive trading days.
  • Operations rehearsed: the dead-man alert, both kill modes and the on-call page drilled in the last month; a real restore from the production backup in the last five weeks.
  • You performed the ceremony (below), and nothing regressed while you waited.

Shadow first

Before any of that is green, the can be connected in shadow: a separate live reads the account, checks it is configured the way live requires (no margin, no shorting, no options, no overnight session, trade confirmations on), and reconciles it every day, and it is physically unable to place an order. Shadow is how the twenty clean reconciliation days are earned. The book shows a LIVE · Shadow band on every screen so it cannot be mistaken for paper.

The guided flow

When every row is green, Add a live book unlocks a guided flow shaped like the Connect wizard you used for paper: why and what changes → the checklist, green, with its evidence → an illustrated guide to creating live trading keys at the broker (a trading key cannot move money; the guide says what never to create) → paste and verify, after which the book sits in shadow → choose to stay in shadow or start tiny, and how it trades (Manual, Semi or Full) → the ceremony below → LIVE. You can leave and come back; it resumes where you were, and abandoning it leaves at most a shadow connection.

The ceremony

The last steps of that flow are the ceremony. Each step is recorded in the config history; each step that changes anything asks for your .

  1. Sign the checklist. Read the evidence behind each row and sign. The signature records exactly what the rows said.
  2. Confirm the account. The live Executor shows the account it detected: masked number, equity, configuration checks, key age. You type the last four digits.
  3. State the intent. Type the phrase the screen gives you; it names the money, for example TRADE UP TO $500 OF REAL MONEY IN this book. Nothing trades yet.
  4. Wait 24 hours. A countdown, cancellable with one click. At the end the checklist is computed again; any row that went red voids the ceremony.
  5. Confirm again, from a trusted device, with a second phrase. Only now does the book enter stage 1, and every notification channel says so. If you chose Manual, the first order waits in the Inbox.

No agent, script or scheduled job can perform any of these steps, and neither can whoever operates the deployment for you: they need your session, your code and your typing.

Stages

StageWhat the desk may doCap
ShadowRead the account, reconcile, check configuration. No orders.$0
TinyOrders under the autonomy mode you chose; a broker-side backstop stop on every position$500 total exposure, $250 an order, 2 orders a day, $50 stop
CappedThe same, with wider capsthe smaller of 25% of live equity and $5,000; $1,000 an order
Full postureYour posture's limits, still long-only, cash-only, regular hours, backstops onposture

Autonomy on a live book is your choice exactly as on paper: Manual, Semi or Full from the first day, chosen in the flow's "How it trades" step, with Semi and Full behind your code and a typed phrase like any loosening. What protects real money is not a tap on each order but the things that hold in every mode: the checklist, the dollar caps of the stage, the Executor's checks, the backstop stop at the broker on every position, the daily dollar loss stop that demotes the book on its own, and the Halt button.

Moving up a stage is always your decision, behind your code, after the stage's own conditions (time in stage, fills, clean reconciliation, execution cost in line with paper). Moving down is automatic and immediate: the daily loss stop, a drawdown past the stage's budget, a burst of rejected orders, execution cost out of line, any reconciliation break, a missed heartbeat during market hours, or the broker blocking the account each drop the book one stage and tell you on every channel. From Tiny, down means Shadow: exits only, no new orders, and the full ceremony to come back.

Halting a live book

Halt stays one click with no code, from the top bar and from Risk › Halts. A live book asks once, at ceremony time, which halt you want by default, freeze (cancel working orders, keep positions, leave the backstop stops resting at the broker) or (freeze, then sell out with marketable limits during the session), and offers both every time. Either way the Executor also tells the broker to block new orders on the account, so a misbehaving process cannot trade even if it wanted to; you can set the same block yourself in the broker's own app without Bellwether at all. Dropping back to Shadow is the same single click.

What it looks like

A live book carries a full-width LIVE band with the stage and the real-money exposure against its cap on every screen, phone included, and the browser tab says LIVE first. Phrases you type name the money. Every live fill, rejection, halt, demotion and missed heartbeat reaches you by push and email, and those cannot be turned down below "all" in Settings › Notifications while the book is in Tiny or Capped. Limits for a live book live where they do today, on Risk › Limits, with lower ceilings the code enforces per stage.

What stays exactly as it is

Paper remains the default everywhere, in every environment the system can be started in. Your paper book keeps running beside the live one as the reference. The keys for a live book are stored server-side, separately from every paper key, where only the live Executor can read them (see Keys and safety); the console, the API and the agents never see them. Funding is something you do at the broker (see Funding your account); the Accounts card only shows what the broker reports.

Notethe honest timeline is months, not weeks: the sixty-day clock alone runs into the new year, and it restarts whenever the strategy changes. The checklist will always say which row is holding things up.