Unit 13 of 22 · Intermediate

One desk, three clocks

The short version

A trading desk needs three kinds of decision running at three different speeds, and Kestrel makes that literal. A strategist — a frontier model, event-driven, a few times a day — sets the frame: the day's Plan, thesis, and View. A watcher — small, fast, cheap, every few seconds — manages the armed book inside that frame. A deterministic runtime fires armed Plans at the tick and admits, but never trusts, either tier: every action both author passes through the same fail-closed admission Gate, so a weak or even adversarial watcher cannot exceed its mandate. Intent flows down the cascade and veto flows up from the Gate. The work itself rides a durable Operation — one canonical intent that survives wakes and boundaries without changing its identity — which is the wake, plan, grade cadence you actually operate. This unit teaches why the desk is split by speed and why the runtime, not any model, keeps authority.

A desk needs three decisions at three speeds

A trading desk makes three kinds of decision, and they run at three different clocks. Framing the day is slow, expensive judgment. Managing a live position is fast and frequent. Firing an order at the tick has to be instant. No single brain is good and cheap at all three, so Kestrel makes the desk literal across two model tiers and a deterministic floor:

TierClockCostJob
Strategist (frontier model)a few times a daydollarssets the frame: the day's Plan, thesis, and View
Watcher (small, fast model)every wake, secondspenniesmanages the armed book inside the frame
Deterministic runtime + Gatemicroseconds~freefires armed Plans; admits, never trusts, both tiers

The strategist is not on a schedule — it is event-driven. It authors the frame at the open, re-frames on a shock or a regime break, and answers when the watcher escalates. Everything in between belongs to the cheaper clocks. The desk reference covers the full architecture; this unit teaches the two rules that hold it together.

Intent flows down. Veto flows up.

The tiers do not invent a private protocol to talk to each other. They speak the same four statements you already know, read at the boundary between tiers:

  • A Plan is standing authority — the strategist arms it, the runtime fires it fire-then-inform, the watcher manages inside it.
  • A View is the lean screen the watcher reads on every wake.
  • A Wake, read at the tier boundary, is the escalation channel: a watcher-authored wake means "wake the strategist."

So intent flows down the cascade — the strategist's frame becomes the watcher's boundaries becomes the runtime's armed reflex. And veto flows up — when the watcher reaches the edge of its thesis, it does not guess and seize new authority; it escalates, spending a frontier call, never an unbounded action.

The runtime keeps authority — the safety keystone

Here is the property the whole design rests on. Every action the watcher authors passes the same fail-closed admission Gate as any other agent — the same budget clamp, the same never-naked and bounded-risk checks. The watcher authors above the determinism line exactly like the strategist, and its turn crosses into the Gate, never around it.

The consequence is structural, not a matter of trust: a weak, mis-prompted, or even adversarial watcher cannot exceed its mandate. The worst a bad watcher can do is trade badly inside its envelope — which the Grade will punish. It can never trade outside it, which the Gate makes impossible by construction. Said plainly: the watcher buys judgment; the runtime keeps authority. You get to admit a cheap, fast model to the hot seat precisely because admitting it costs you nothing you did not already bound.

One durable Operation across the whole cadence

The wake, plan, grade cadence is not a series of disconnected events. The work rides a durable Operation — the control-plane's single unit for one canonical agent intent. An Operation survives boundaries — a free-tier edge, a settlement, a retry, a provider callback — without changing its identity or repeating work already done. It is not an Episode and never a fifth statement kind; it is the through-line that makes "resume where I left off" true across every wake and boundary. That durable spine is the cadence you actually operate a seat on.

See it in kestrel

Run an event session — exactly the kind that makes an event-driven strategist re-frame and hand a live book to the watcher:

npx kestrel.markets sim fomc-rate-decision-whipsaw

That runs a deterministic simulation over a generic index session — managed licensed data, no wall time, no signup, no card — and prints a certified proof URL. Point the CLI back at the proof and it recomputes the whole record on your own machine, byte for byte:

npx kestrel.markets certify https://kestrel.markets/proof/art_d29415f0cf502f4a218a9cba

Keep it one command away: drop the kestrel.markets MCP server into your client and the next session is already wired up — no account in between.

Recompute it

Every claim in this unit recomputes from a certified proof — no account, no card.

/proof/art_d29415f0cf502f4a218a9cba
Keep readingWho may sign, and the worst case in dollars