Unit 12 of 22 · Intermediate

What happened vs how good it was

The short version

The Blotter is the record of what happened in a run — every order, fill, position change, and settlement — laid out as a byte-stable projection of the session's event Bus. It is not a second ledger written alongside the trade; it is regenerated deterministically from the Bus by a pure projector, so the same run yields the same Blotter, byte for byte, on any machine. That is why it is trustworthy in a way a hand-kept trade log never is: there is nothing to forge, drift, or forget, because it is derived, not authored. The Blotter answers what happened; the Grade — a separate, judged verdict computed over one or more Blotters — answers how good it was. This unit separates the two and shows why a regenerable projection, not a written log, is the evidence a run can stand on.

The Blotter is derived, not written

A run produces one authoritative stream of events — the Bus: every wake, every authored decision, every order the runtime placed, every fill it saw, every position and settlement. The Blotter is what happened, read straight off that Bus.

The word doing the work is projection. The Blotter is not a second book that some process writes in parallel with the trade — a parallel writer is exactly what drifts, double-counts, or quietly disagrees with reality. Instead a pure projector folds the Bus into the Blotter deterministically: same Bus in, same Blotter out, byte for byte, on any machine, every time. There is no second source of truth to reconcile, because there is no second writer.

That is the whole trust argument. A hand-kept trade log is an assertion — you take the keeper's word that it matches what happened. A Blotter is a consequence — regenerate it from the Bus and it is identical or it is wrong, and either way there is nothing to take on faith.

The Blotter is not the Grade

Two different questions, two different artifacts, kept structurally apart:

  • The Blotter records what happened — the orders, fills, positions, and settlement, as a byte-stable projection of the Bus.
  • The Grade records how good it was — a judged verdict computed over one or more Blotters by the open judge, date-blind so hindsight can't leak in.

The Grade reads Blotters; it never rewrites them. Keeping them separate is what lets a stranger recompute your verdict: they replay your Bus to the same Blotter, then run the same open judge to the same Grade, and never once trust your summary of either.

A worked example

Run a generic index session — call the instrument IDX. Across the session the Bus records the day's wakes and, if a plan armed, the order it placed at the tick, the fill the runtime actually saw, and the position carried into settlement. Project that Bus and you get a Blotter: bought 1 IDX contract at the recorded fill, held to close, settled at the marked price. Nothing in that Blotter is opinion. Re-project the same Bus tomorrow, on a different machine, and it is the same bytes — which is precisely why the Grade computed over it means something.

See it in kestrel

Every hosted run mints a certified receipt, and the Blotter is inside it. Run one over a generic index scenario — deterministic, managed data, no wall time, no signup, no card:

npx kestrel.markets sim fomc-rate-decision-whipsaw

That prints a proof URL. The Blotter it carries is not the server's say-so: recompute it on your own machine and watch the tool re-project the Bus locally and assert the bytes match the hosted result:

npx kestrel.markets certify https://kestrel.markets/proof/art_66d7dda7f0466f69c123463c

For the anatomy of that receipt — signatures, roots, the open judge — read evidence. Keep it one command away: drop the kestrel.markets MCP server into your client and the next run opens where this one left off, no account in between.

Recompute it

Every claim in this unit recomputes from a certified proof — no account, no card.

/proof/art_66d7dda7f0466f69c123463c
Keep readingOne desk, three clocks