Skip to content

Checking modechecking

Mode…

Limits

The limits code enforces, the independent co-signer, and why nobody can talk the agent into anything.

The model proposes · code decides

Six checks between the model and the money

Each check can only make the outcome safer. The last two trust nothing computed before them.

  1. Strict answer formatCode

    The answer must match a strict schema tied to the snapshot. An unknown market or an out-of-range number fails; after three attempts in all, nothing trades.

  2. Critic (optional)Model

    A second pass can block the decision, never change it. If it cannot run, nothing trades.

  3. Risk engineCode

    Checks every target against the launch limits and the live market: approves it, shrinks it or rejects it, and records the reason.

  4. Order planner and executionCode

    Sizes and prices orders by the venue's rules and sends each one exactly once. An unclear outcome is looked up, never sent again.

  5. Independent co-signerSeparate key

    Re-reads every vault swap, buyback and venue transfer from the compiled transaction itself, with its own price and chain reads, before adding the second signature the program requires. It refuses to sign real funds against MOCK prices.

  6. The programOn chain

    Trusts nothing off chain: it derives every destination itself, has no withdraw instruction, writes one receipt per action and enforces daily caps.

Perp orders go out from the coin's own Pacifica account once the risk engine has approved them. The co-signer and the program bound how much capital can reach that account (how capital reaches Pacifica).

Can · cannot

What the model can and cannot do

The model can

  • Read the thesis, the launch limits, the account, open positions, the cycle's markets and its own recent decisions, all as data.
  • Call read-only market-data tools on markets in the snapshot: candles, order book, funding history (at most 8 per cycle).
  • Propose the complete target book, with a short public summary and a rationale per position.
  • As the critic: block a decision.

The model cannot

  • Hold, see or use a key, or move funds. None of its tools can write anything.
  • Place, size or cancel an order. Code turns its targets into orders.
  • Trade a market outside the snapshot, or the strategy's own launch token.
  • Exceed a launch limit. The risk engine shrinks or rejects what is too large and records why.
  • Change its own settings. Venues, leverage, shorting, its model, its budget and the buyback share are fixed at launch, and no thesis mutation can change them.
  • Invent numbers. Unknown market ids and out-of-range values fail the schema.
  • Take orders from the data. Text in the thesis, market names or tool results is declared data, and every target still passes the risk engine whatever the model was told.

Prompt injection

Nobody can talk it into anything

  • Text is never an instruction. The thesis, market names and tool results reach the model as data blocks marked as data; instructions live only in the system prompt.
  • Screened before any model call. A thesis or a change request with a wallet address, a link, a request to transfer, withdraw or sign, or an override phrase (“ignore previous instructions”) is rejected outright.
  • A fooled model can still only propose. It has no tool that writes anything and no key, and every target it proposes passes the risk engine whatever it was told.

Pick one at launch

Risk levels

  • Conservative: Long only, no leverage, tight breakers.
  • Balanced: Up to 3× with shorts, moderate breakers.
  • Aggressive: Up to 5× with shorts, wide stops and breakers.
Risk levels, with Pacifica perps
LimitConservativeBalancedAggressive
Leverage, at most1×3×5×
ShortsNoYesYes
Gross exposure85%150%300%
Net exposure85%100%200%
Largest position15%25%40%
Open positions8812
Cash floor15%10%5%
Stop loss8%12%20%
Take profitOff30%Off
Drawdown breaker15%25%40%
Daily loss limit5%8%15%
Max slippage0.5%0.75%1.5%

Exposure, position and cash are shares of NAV; the drawdown breaker is measured from the high-water mark. With Solana spot alone, leverage is 1×, shorts are off and exposure is capped at what the cash floor leaves. Levels are starting points, not advice: every value can be changed under Advanced settings, within the ceilings below, and the level then reads Custom.

Protocol-wide

Ceilings no launch can pass

Leverage
≤ 10×, and each market's own maximum
Shorts
Pacifica perps only, when the launch allows them
Gross exposure
≤ 500% of NAV
Open positions
≤ 20
Position size
≤ 1% of the market's 24h volume and of its open interest
Market liquidity floors
≥ $25,000 24h volume · ≥ $15,000 open interest (perps)
Minimum order
$10 (Pacifica's minimum)
Tool calls
≤ 8 per cycle, read-only
Decision interval
1 min … 24 h (default 1 h)
Model spend
≤ $50 per day
Profit buyback share
10% … 100% of profit above the high-water mark
Borrowing outside venue margin
disabled

A coin may be stricter, never looser. The drawdown breaker closes every position (reduce-only) and pauses the agent until an operator clears it. The daily-loss limit is checked at launch, but the cycle does not report today's loss to the risk engine yet.

Vault policy: ceilings and presets

Every coin also has a vault policy: the rules hashed at launch and patched by thesis changes. The protocol validates it against these ceilings, and the launch's risk level picks the preset of the same name.

Max positions
25
Max single position
≤ 35% of NAV
Minimum cash
≥ 2% of NAV
Turnover per cycle
≤ 50%
Daily turnover
≤ 100%
Max drawdown limit
≤ 50%
Max daily loss limit
≤ 25%
Max slippage
≤ 3%
Max price impact
≤ 5%
Asset liquidity floor
$50,000
Rebalance interval
15m … 30d
Thesis length
≤ 2,000 characters
Vault policy presets
LimitConservativeBalancedAggressive
Max position10%15%25%
Min cash15%10%5%
Turnover / cycle15%25%40%
Daily turnover25%40%70%
Max drawdown15%25%40%
Max daily loss5%8%15%
Max slippage0.5%1%2%
Max price impact1%2%4%

Brakes

Breakers and pauses

  • The guardian key can pause the whole protocol or one coin (launches, the AI, execution, buybacks, thesis changes) and disable an asset. Only the admin can lift a pause or enable anything.
  • Off chain, breakers stop the same things for the protocol or for one coin. If money leaves a vault without a record, the coin's breaker engages by itself.

Paid in SOL

Changing the thesis

Anyone can pay SOL to change a coin's thesis. A change is never free-form configuration: it becomes a typed patch of at most 8 operations (a thesis amendment is at most 400 characters), applied to the current policy and re-validated as a whole, and you see it as a diff before you pay. Text is screened for instructions, links and addresses. All of the payment buys back and locks the coin.

On chain, each change must be the next version, carry an unexpired attestation, pay at least the minimum price and wait out the cooldown since the last change. No change can loosen the agent's launch settings (venues, leverage, shorting and its risk limits), and its model, budget and buyback share are fixed for good.

Can change

  • title
  • benchmark
  • objective
  • horizon
  • riskProfile
  • maxPositions
  • maxPositionBps
  • minimumCashBps
  • maxTurnoverPerCycleBps
  • maxDailyTurnoverBps
  • maxDrawdownBps
  • maxDailyLossBps
  • maximumSlippageBps
  • maximumPriceImpactBps
  • minimumLiquidityUsd
  • rebalanceIntervalMinutes
  • minimumHoldingPeriodMinutes
  • maximumHoldingPeriodMinutes

Patch operations: SET, ADD_RULE, REPLACE_RULE, REMOVE_RULE, ADD_FUNDAMENTAL_FILTER, ADD_TECHNICAL_FILTER, ADD_SENTIMENT_FILTER, REMOVE_FILTER, EXCLUDE_ASSET, UNEXCLUDE_ASSET, ADD_ALLOWED_ASSET, REMOVE_ALLOWED_ASSET, AMEND_THESIS.

Cannot change

  • schemaVersion
  • strategyId
  • quoteAsset
  • leverageAllowed
  • maximumLeverage
  • shortingAllowed
  • borrowingAllowed
  • derivativesAllowed
  • createdAt
  • version
  • agent

Not expressible at all: vault, withdrawal and executor authorities, the buyback destination, mint addresses, transfers, turning off the risk engine, and trading the coin itself.

Field names are the policy's own. Bps means basis points: 100 bps is 1%.