For funds, RIAs, brokers and agent platforms. DealerFlow Terminal runs one deterministic check on every order attempt across all eight order rails, writes one ledger row with the complete trace, and rolls out shadow-first so it blocks nothing until its disagreement rate is known. The same check is offered to platforms as a validation layer over MCP and HTTP.
| It is | It is not |
|---|---|
| A deterministic pre-trade check with a closed refusal vocabulary | A signal service, a model portfolio or a source of directive calls |
| Rulebook tooling where the client writes every rule | Discretionary management — DealerFlow never takes discretion over an account |
| An audit ledger keyed to code and rulebook versions | A performance claim — we publish refusal counts, not modeled returns |
| A tenant-isolated platform with database-enforced separation | A custodian or broker — orders go to a connected brokerage account (Charles Schwab today) |
Seven US brokers now let AI agents place or draft orders (StockBrokers.com). Today the question “did the agent exceed its authority?” is often answered by people, after the fact. The Risk Desk answers it per order, before the send, in code.
Captured from the production code with sample data. Account identifiers are blurred.
Deterministic trading loops: once a rulebook is armed, it acts the same way on the same inputs, every time. No model re-reads the instruction at the moment of the order. Rulebook-driven automation is offered to institutional clients only, under written governance. Every automated order passes the same Risk Desk as a manual one — and more gates besides.
Research and desk screens. No order path.
Tickets and cards that send only on a person’s click — enforced in the database for portfolio tickets.
Rulebooks evaluate live and log every would-be order. Nothing is sent.
Per desk and per ticker — armed by the client.
A platform-level pause stops new automated fires on the equity and options desks. Closes and cancels are never blocked.
Automation on a ticker acts only where its grid is ticked. An empty grid is off — there are no implicit defaults.
A consecutive-loss streak disarms that ticker; a setup with negative measured expectancy over 20+ trades is benched until a person releases it.
On the equity desk, a ticker that is disabled or disarmed by the system gets no automated management until a person re-arms it.
Automated options entries are limited to once per ticker, per direction, per trading day — not once per window.
When long and short candidates conflict on a ticker, the arbiter removes the losing side before evaluation. Software proposes its weights; only the operator approves them.
A rulebook drafted in plain language with TAI, the DFT AI, or edited by hand, can be backtested before anyone saves it. The backtest takes the rule settings themselves and replays the signals that really fired on real one-minute prices, using the desk’s own close rules. It compares the draft with any other profiles on the same shares and dates, broken down by share, signal, day, close reason and side.
The unified Risk Desk sits above these. Each desk’s own gates stay in place underneath it — defence in depth.
| Desk | Controls already live |
|---|---|
| AFA · equity rulebooks (automated & manual) | 49 named suppression codes: switches, account, session and timeframe-window grid, daily loss cap (realised + fresh unrealised), position cap with headroom clipping, spread cap in USD and bps, earnings and trend filters, multi-timeframe alignment, opposite-position guard, loss-streak disarm, setup bench, arbiter. A funds gate is built and runs log-only by default (the broker is the final funds check); missing-data blocks on spread, earnings and trend are per-client settings. |
| AOA · options campaigns & ladder | Structure guards (no naked short, net debit only), market gate requiring both decision timeframes plus a trigger, “don’t chase”, synthetic-probability block, refusals on failed chain refresh or excessive price move, limit clamped to maximum drift from mid, once per ticker per direction per trading day for automated entries, loss cap, profit lock, kill switch that cancels opening intents. |
| 0DTE · same-day options | Central pause, the platform daily-loss cap (live mode), per-ticker and total daily ceilings under an advisory lock (an unknown broker acceptance counts as used), calendar entry cutoff, bar and chain freshness, delta band and spread-tick filters, book-depth clamp, serial clips. |
| PIS · portfolio tickets | Human-click only by database constraint, one-voice arbitration across engines, fail-closed control layer, structure guards reused from the options desk, grading of declined as well as taken suggestions. |
| Income Desk | Assemble and clear through the platform risk stack, named holds, minimum credit, refresh and price-moved refusals, do-not-manage fences, acknowledge-on-this-click overrides that are recorded. |
| C-CAT · covered calls | Six pure readiness gates where unknown never equals pass, single-use preflight tokens with every gate re-run at send, duplicate refusal, profile re-check at send, chain verdict gate. |
| Shared spine | Read-only broker guard, platform pause gate (shadow by default), account guard for cross-tenant use, quarantine and live-routing arm. |
A guardrail cannot honestly be judged by performance. It can be judged by what it refused, why, and whether the reason was sound.
Every private path is authenticated by a verified identity token; the tenant scope comes from that token, never from the request.
Account tables enable and force row-level security with explicit operator filtering.
Synthetic data is permitted only in an explicit sandbox or test environment. There is no environment switch that turns the rule off.
Nothing reaches a public channel without an approval pinned to the exact content version, plus a mechanical check for directive language.
Every release is validated on the deployed artifact, confirmed by digest in production, soaked for thirty minutes with automatic rollback, and kept out of market hours.
DealerFlow never holds client funds or securities. Orders go to a connected brokerage account.
Connect brokerage accounts on the tenant-isolated platform, or integrate the validation layer.
Your authority limits become versioned profiles; nothing is enabled by default.
Every desk evaluates and logs. Review would-blocks and disagreement with your own team.
Desk by desk, on your sign-off. Closing orders are never blocked at any stage.
No. Every rule is written and enabled by the client. Automation acts only within rulebooks the client armed, on the client’s own brokerage account, and can be disarmed per ticker, per desk or platform-wide at any time.
Private data is scoped by a verified identity token and protected by forced row-level security at the database.
Gates fail closed on unknown readings, the platform pause stops new opening orders at the spines, loss streaks disarm tickers automatically, and releases soak with automatic rollback. Closes and cancels remain available throughout.
Run every desk in shadow on your own book. The ledger shows each would-block with its evidence; your team judges the reasons before anything is enforced.
Yes — over MCP (check_order) or HTTP. Verdicts are advisory to your platform: the check sends nothing, holds nothing and writes no order of its own.
No. We publish refusal counts. Any figure we show is measured from real records; nothing is modeled for effect or fabricated.