ADR 037 — Research-to-order authorization
- Status: Accepted (2026-08-10) — ratified in chat / field ADR package (first-class module + Nautilus)
- Related: ADR 036, principal plan
Context
Source docs place LLMs near portfolio management and trading. Repo evidence shows a safer chain already forming:
- Statistical promotion:
PromotionPolicy(lab evidence). - Deterministic airlock:
GateChain(alphaswarm/promotion/gate.py) — LLM-free. - Paper session gate:
alphaswarm/trading/metadata_gate.pyrequiring model aspect status in{"Production","Staging"}. - Crossing types:
StrategyPromotionRequest,OrderIntent. - Worker money plane: approval token + step-up + kill switch +
RiskLimitsinsideExecutor. - No standalone
live_trading_enabledflag beyond these gates (Track D).
Decision
Authorize research→trade as:
structured advisory (LLM/agent)
→ deterministic validation (schemas, PIT, entitlements)
→ risk (RiskLimits / pretrade / RTS6 where applicable)
→ authorization (scopes, step-up, approval tokens, HITL thresholds)
→ money plane (NativeExecutor / BotRuntime venue send)
Hard rules:
OrderIntentis the sole LLM→money seam. No second agent→order path.StrategyPromotionRequestis the sole research→live crossing type.- Gates remain LLM-free. LLMs may tighten limits, never raise hard limits.
- Reject LLMs as live execution peers (not an engine paradigm beside vectorized/live).
- Ray/distributed agent workflows are research-only; they must not hold venue credentials.
- Before live expansion, enable halt propagation and tenancy RLS per principal plan Phase 6–7.
Consequences
- New agent tools that emit tradeable signals must terminate in
OrderIntent(or an approved synonym that translates 1:1). - CI/docs should treat bypass of metadata_gate / GateChain as a release blocker.
- Optional future
live_trading_enabledflag, if added, is additive documentation sugar — not a replacement for the gate chain.