A Frame is one instant of the screen
If the View is live video of the market, a Frame is one fully specified still: a single materialized instant of a View, the typed bundle of values the agent reads on one wake. And the atom of a Frame is the Field — one value together with the provenance it was derived under. The screen reference lists the exact contract; this unit teaches how to read a Frame the way an agent must, which comes down to reading the tags.
Every Field carries one of six provenance tags
Nothing above a raw observation goes unattributed. Each Field wears exactly one of six tags, so the agent always knows how much to trust a number and where it came from:
| Tag | Meaning |
|---|---|
[OBS] | an observed market datum — a quote, a trade |
[CALC] | a deterministic transform of OBS — VWAP, range, realized vol |
[DETECTOR] | a named pattern detector's output, versioned |
[MODEL] | a model output — a fair value, a regime claim; must carry its receipt and confidence |
[POLICY] | a configured platform decision — budgets, zoom, what was omitted |
[UNKNOWN] | explicitly unavailable — rendered, never guessed |
Each value also carries a source watermark like src=SPX:vwap@120 — where it
came from and the engine sequence it was derived at. That sequence is an
ordinal, never a wall clock, which is what lets a run replay byte-for-byte and
keeps dates off the record path. The discipline is strict: a [MODEL] field
without its receipt and confidence is refused at construction. The agent never
has to wonder whether 5081.30 is something the market printed or something a
model imagined — the tag says which.
UNKNOWN is a value, not a gap
The most important tag is [UNKNOWN]. When a value is genuinely not knowable yet
— the day's range-to-go before the day has run, a cause the feed cannot see — the
screen renders it as an explicit UNKNOWN, and never fills the gap with a
plausible number. The reason is a hard principle: a token-efficient wrong number
is worse than an expensive right number. A guessed value looks exactly as
authoritative as a real one and quietly poisons every decision downstream.
Refusing to guess is the honest move.
SHOCK measures; it does not editorialize
When a violent move fires the SHOCK frame, the screen zooms to one-second buckets
and delivers measurements — how far, how fast, whether the move synced across
correlated instruments, how bid presence collapsed. What it will not do is tell a
story. The interpretation field reads, in effect, omitted; agent must classify,
and the cause reads [UNKNOWN] because the feed does not know it. Classifying a
shock is the agent's judgment, and the platform never launders an opinion into
the Frame.
Degraded is fail-closed
The same honesty governs failure. When the canonical feed goes stale, the screen
does not improvise an alternate price. It marks the anchor [UNKNOWN], omits the
panes that depended on it, de-arms the Wakes and Plans that needed it, and
schedules a full resync — telling the agent exactly what it cannot see and what
has been stood down. A screen that would rather show nothing than show a guess is
the perception-side twin of the fail-closed parser.
See it in kestrel
Run a session with a genuine volatility shock and watch the SHOCK frame and the degraded posture in action:
npx kestrel.markets sim s-p-500-etf-pandemic-volatility-crashThat runs a deterministic simulation over a generic broad-ETF session with a real volatility spike — managed licensed data, no wall time, no signup, no card — and prints a certified proof URL. Point the CLI back at the proof and it recomputes the whole record on your own machine, byte for byte:
npx kestrel.markets certify https://kestrel.markets/proof/art_66d7dda7f0466f69c123463cKeep it one command away: drop the kestrel.markets MCP server into your client and the next session is already wired up — no account in between.