Limits
The limits code enforces, the independent co-signer, and why nobody can talk the agent into anything.
The model proposes · code decides
Six checks between the model and the money
Each check can only make the outcome safer. The last two trust nothing computed before them.
Strict answer formatCode
The answer must match a strict schema tied to the snapshot. An unknown market or an out-of-range number fails; after three attempts in all, nothing trades.
Critic (optional)Model
A second pass can block the decision, never change it. If it cannot run, nothing trades.
Risk engineCode
Checks every target against the launch limits and the live market: approves it, shrinks it or rejects it, and records the reason.
Order planner and executionCode
Sizes and prices orders by the venue's rules and sends each one exactly once. An unclear outcome is looked up, never sent again.
Independent co-signerSeparate key
Re-reads every vault swap, buyback and venue transfer from the compiled transaction itself, with its own price and chain reads, before adding the second signature the program requires. It refuses to sign real funds against MOCK prices.
The programOn chain
Trusts nothing off chain: it derives every destination itself, has no withdraw instruction, writes one receipt per action and enforces daily caps.
Perp orders go out from the coin's own Pacifica account once the risk engine has approved them. The co-signer and the program bound how much capital can reach that account (how capital reaches Pacifica).
Can · cannot
What the model can and cannot do
The model can
- Read the thesis, the launch limits, the account, open positions, the cycle's markets and its own recent decisions, all as data.
- Call read-only market-data tools on markets in the snapshot: candles, order book, funding history (at most 8 per cycle).
- Propose the complete target book, with a short public summary and a rationale per position.
- As the critic: block a decision.
The model cannot
- Hold, see or use a key, or move funds. None of its tools can write anything.
- Place, size or cancel an order. Code turns its targets into orders.
- Trade a market outside the snapshot, or the strategy's own launch token.
- Exceed a launch limit. The risk engine shrinks or rejects what is too large and records why.
- Change its own settings. Venues, leverage, shorting, its model, its budget and the buyback share are fixed at launch, and no thesis mutation can change them.
- Invent numbers. Unknown market ids and out-of-range values fail the schema.
- Take orders from the data. Text in the thesis, market names or tool results is declared data, and every target still passes the risk engine whatever the model was told.
Prompt injection
Nobody can talk it into anything
- Text is never an instruction. The thesis, market names and tool results reach the model as data blocks marked as data; instructions live only in the system prompt.
- Screened before any model call. A thesis or a change request with a wallet address, a link, a request to transfer, withdraw or sign, or an override phrase (“ignore previous instructions”) is rejected outright.
- A fooled model can still only propose. It has no tool that writes anything and no key, and every target it proposes passes the risk engine whatever it was told.
Pick one at launch
Risk levels
- Conservative: Long only, no leverage, tight breakers.
- Balanced: Up to 3× with shorts, moderate breakers.
- Aggressive: Up to 5× with shorts, wide stops and breakers.
| Limit | Conservative | Balanced | Aggressive |
|---|---|---|---|
| Leverage, at most | 1× | 3× | 5× |
| Shorts | No | Yes | Yes |
| Gross exposure | 85% | 150% | 300% |
| Net exposure | 85% | 100% | 200% |
| Largest position | 15% | 25% | 40% |
| Open positions | 8 | 8 | 12 |
| Cash floor | 15% | 10% | 5% |
| Stop loss | 8% | 12% | 20% |
| Take profit | Off | 30% | Off |
| Drawdown breaker | 15% | 25% | 40% |
| Daily loss limit | 5% | 8% | 15% |
| Max slippage | 0.5% | 0.75% | 1.5% |
Exposure, position and cash are shares of NAV; the drawdown breaker is measured from the high-water mark. With Solana spot alone, leverage is 1×, shorts are off and exposure is capped at what the cash floor leaves. Levels are starting points, not advice: every value can be changed under Advanced settings, within the ceilings below, and the level then reads Custom.
Protocol-wide
Ceilings no launch can pass
- Leverage
- ≤ 10×, and each market's own maximum
- Shorts
- Pacifica perps only, when the launch allows them
- Gross exposure
- ≤ 500% of NAV
- Open positions
- ≤ 20
- Position size
- ≤ 1% of the market's 24h volume and of its open interest
- Market liquidity floors
- ≥ $25,000 24h volume · ≥ $15,000 open interest (perps)
- Minimum order
- $10 (Pacifica's minimum)
- Tool calls
- ≤ 8 per cycle, read-only
- Decision interval
- 1 min … 24 h (default 1 h)
- Model spend
- ≤ $50 per day
- Profit buyback share
- 10% … 100% of profit above the high-water mark
- Borrowing outside venue margin
- disabled
A coin may be stricter, never looser. The drawdown breaker closes every position (reduce-only) and pauses the agent until an operator clears it. The daily-loss limit is checked at launch, but the cycle does not report today's loss to the risk engine yet.
Vault policy: ceilings and presets
Every coin also has a vault policy: the rules hashed at launch and patched by thesis changes. The protocol validates it against these ceilings, and the launch's risk level picks the preset of the same name.
- Max positions
- 25
- Max single position
- ≤ 35% of NAV
- Minimum cash
- ≥ 2% of NAV
- Turnover per cycle
- ≤ 50%
- Daily turnover
- ≤ 100%
- Max drawdown limit
- ≤ 50%
- Max daily loss limit
- ≤ 25%
- Max slippage
- ≤ 3%
- Max price impact
- ≤ 5%
- Asset liquidity floor
- $50,000
- Rebalance interval
- 15m … 30d
- Thesis length
- ≤ 2,000 characters
| Limit | Conservative | Balanced | Aggressive |
|---|---|---|---|
| Max position | 10% | 15% | 25% |
| Min cash | 15% | 10% | 5% |
| Turnover / cycle | 15% | 25% | 40% |
| Daily turnover | 25% | 40% | 70% |
| Max drawdown | 15% | 25% | 40% |
| Max daily loss | 5% | 8% | 15% |
| Max slippage | 0.5% | 1% | 2% |
| Max price impact | 1% | 2% | 4% |
Brakes
Breakers and pauses
- The guardian key can pause the whole protocol or one coin (launches, the AI, execution, buybacks, thesis changes) and disable an asset. Only the admin can lift a pause or enable anything.
- Off chain, breakers stop the same things for the protocol or for one coin. If money leaves a vault without a record, the coin's breaker engages by itself.
Paid in SOL
Changing the thesis
Anyone can pay SOL to change a coin's thesis. A change is never free-form configuration: it becomes a typed patch of at most 8 operations (a thesis amendment is at most 400 characters), applied to the current policy and re-validated as a whole, and you see it as a diff before you pay. Text is screened for instructions, links and addresses. All of the payment buys back and locks the coin.
On chain, each change must be the next version, carry an unexpired attestation, pay at least the minimum price and wait out the cooldown since the last change. No change can loosen the agent's launch settings (venues, leverage, shorting and its risk limits), and its model, budget and buyback share are fixed for good.
Can change
- title
- benchmark
- objective
- horizon
- riskProfile
- maxPositions
- maxPositionBps
- minimumCashBps
- maxTurnoverPerCycleBps
- maxDailyTurnoverBps
- maxDrawdownBps
- maxDailyLossBps
- maximumSlippageBps
- maximumPriceImpactBps
- minimumLiquidityUsd
- rebalanceIntervalMinutes
- minimumHoldingPeriodMinutes
- maximumHoldingPeriodMinutes
Patch operations: SET, ADD_RULE, REPLACE_RULE, REMOVE_RULE, ADD_FUNDAMENTAL_FILTER, ADD_TECHNICAL_FILTER, ADD_SENTIMENT_FILTER, REMOVE_FILTER, EXCLUDE_ASSET, UNEXCLUDE_ASSET, ADD_ALLOWED_ASSET, REMOVE_ALLOWED_ASSET, AMEND_THESIS.
Cannot change
- schemaVersion
- strategyId
- quoteAsset
- leverageAllowed
- maximumLeverage
- shortingAllowed
- borrowingAllowed
- derivativesAllowed
- createdAt
- version
- agent
Not expressible at all: vault, withdrawal and executor authorities, the buyback destination, mint addresses, transfers, turning off the risk engine, and trading the coin itself.
Field names are the policy's own. Bps means basis points: 100 bps is 1%.