Authorize new capital, capped at the exact permitted amount.
The verifiable pre-trade authorization layer for autonomous capital
Already have a trading agent?
Add Profit Engine Governor.
Keep custody. Keep control.
PE Governor evaluates each submitted order intent against your rules, coordinates portfolio capacity across agents, and returns a short-lived signed authorization for the exact permitted amount. Your executor verifies it; PE Governor never takes custody or places the order.
PE Governor by Solarly.
Decision verdicts
Cut an existing managed position. Never exceed the returned amount.
A hard rule failed. Do not act on this candidate again.
Temporary blocker or unselected this cycle. Stand down and re-ask.
A deterministic decision, rendered live
This card is produced by the same pure policy the paid endpoint runs, from the example request below. Identical input always yields an identical decision hash.
Permitted amount
$25,000.00
selected: cand_spot_btc_01
- cand_spot_btc_01rank 1ALLOCATE
- cand_eq_msft_02rank 2HOLD
- Request hash
- request a2a7c6d765b6ef70214374eef0f1ad0fc4276c754b69030219ecdad05ab6e468
- Decision hash
- decision 855dec83616b3c4363d24707604abf566e092ca8f4e67f7d5bff77007729bd68
Risk checks (observed vs limit)
- portfolio_state_fresh15 / 120PASS
- portfolio_state_not_future0 / 5PASS
- reconciliation_currenttrue / truePASS
- kill_switch_clearfalse / falsePASS
- daily_loss_budget400 / 5000PASS
- max_drawdown1.8 / 8PASS
How it works
1. Propose
Your agents emit up to 50 candidates on a common bus: lane, asset, side, requested notional, caller-supplied maximum loss and expected net edge, evidence status and expiry.
2. Govern
PE Governor applies one pure policy: state freshness, reconciliation, kill switch, evidence, loss budgets, reserve, notional caps and concurrency — then ranks and picks at most one winner.
3. Obey
Capital moves on your terms. Same request in, byte-identical decision out, with SHA-256 hashes of the canonical request and decision for audit.
Foundational control for autonomous capital
A deterministic authorization layer that makes agent decisions bounded, auditable, and portable across your execution stack.
Tamper-evident policy receipts
Every response binds the canonical request and decision with SHA-256 hashes, the policy version, timestamp, exact permitted amount, and observed-versus-limit checks. Replays remain byte-identical.
Portfolio-wide governance
Evaluate up to 50 candidates from multiple strategies against one fresh, reconciled portfolio snapshot. Loss, drawdown, reserve, notional, concurrency, and kill-switch rules apply before at most one winner is selected.
Machine-native payment
Pay the published, risk-banded price per decision in USDC on Base through the Coinbase Business checkout flow, or use prepaid credits. Idempotency prevents duplicate logical purchases.
Enforcement starts in your execution adapter
PE Governor returns the authorization; your adapter verifies and obeys it before placing an order. Coinbase does not currently enforce PE decisions at the venue, and payment never changes the verdict.
Read the install policySigned authorizations your executor can verify
Every governed allocation carries a short-lived, cryptographically signed authorization bound to its exact intent and the portfolio's latest submitted risk state.
Verifiable policy proofs
The signature covers the canonical proof payload: issuer, key id, verdict, exact permitted amount, candidate, strategy, lane, full scope, request hash, decision hash, portfolio-state hash, the durable price quote and expiry. Fetch the public key once and verify offline.
Atomic cross-agent reservations
Concurrent agents in the same tenant and portfolio contend for one aggregate risk ledger. A winning candidate only becomes executable if the reservation is granted; otherwise the verdict is downgraded to HOLD.
Risk-banded pricing
The price of a decision scales with capital at risk — the largest requested notional or maximum loss in the request. The quote is deterministic and hash-bound. Payment buys evaluation, never a verdict.
Deterministic price per decision
Capital at risk is max(requestedNotionalUsd, maximumLossUsd) across submitted candidates. One credit unit equals 0.05 USDC.
| Capital at risk | Price (USDC on Base) | Credit units |
|---|---|---|
| up to $1,000 | 0.05 USDC | 1 |
| up to $10,000 | 0.10 USDC | 2 |
| up to $100,000 | 1.00 USDC | 20 |
| up to $500,000 | 5.00 USDC | 100 |
| above $500,000 | 10.00 USDC | 200 |
The same price applies to ALLOCATE, REDUCE, REJECT and HOLD. There is no subscription.
Verify before you execute
Your execution adapter must verify the payload hash, the signature, the issuer and key id, the validity window, the live reservation token, every expected hash, and that the order matches the authorized intent and exact amount. Consume each authorization once in a durable store, and refuse any order not covered by a live authorization.
import { verifyAuthorizationForOrder } from "./pe-authorization";
// 1. Fetch and cache the published Ed25519 verification key (kid + issuer).
const { issuer, keys } = await (await fetch("/api/pe/v1/keys")).json();
// 2. Gate every order on a live, exactly matching authorization.
const check = await verifyAuthorizationForOrder({
proof: decision.proof, // returned with every 200
publicKeyBase64Url: keys[0].x,
order: {
candidateId, strategyId, assetId, lane, side, reduceOnly,
amountUsd: decision.allocationAmountUsd, // must equal permittedAmountUsd exactly
tenantId, portfolioId, agentId, ownerId, accountScope,
},
expected: {
issuer,
keyId: keys[0].kid,
policyVersion: decision.policyVersion,
requestHash: decision.audit.requestHash,
decisionHash: decision.audit.decisionHash,
portfolioStateHash: decision.proof.payload.portfolioStateHash,
quoteHash: decision.priceQuote.quoteHash,
reservationFencingToken: decision.proof.payload.reservation.fencingToken,
},
// Durable single-use store: ONE atomic operation, never has() then add().
replayStore: {
consumeIfUnused: async (id) => {
const { rowCount } = await db.query(
"INSERT INTO used_authorizations (id) VALUES ($1) ON CONFLICT DO NOTHING",
[id],
);
return rowCount === 1; // false => already consumed
},
},
});
if (!check.valid) throw new Error(check.reason); // never place the order
placeOrder(decision.allocationAmountUsd);Hold portfolio capacity for the whole execution window
OptionalVerifying a signed authorization offline stays sufficient on its own. If you want more, claim it: PE Governor then holds that authorization's share of aggregate capacity until your adapter reports the outcome, so a second agent cannot spend the same room twice.
AUTHORIZED
Issued with the decision and already holding capacity for its short validity window.
CLAIMED
Your adapter bound a secret claim key and now owns the outcome. No other caller can transition it.
COMMITTED
The adapter acted. Capacity stays held, because committed capital is at work until you reconcile.
RELEASED
The adapter stood down without acting. Capacity returns immediately.
EXPIRED
Nobody reported back in time. Capacity returns on its own, with no cleanup call needed.
// Optional. Offline verification of the proof is still sufficient.
const { authorizationId } = decision.lifecycle;
const claimKey = crypto.randomUUID() + crypto.randomUUID(); // >= 32 chars, keep it
const claim = await fetch(`/api/pe/v1/authorizations/${authorizationId}/claim`, {
method: "POST",
headers: { "x-pe-claim-key": claimKey },
});
if (!claim.ok) return; // someone else owns this authorization
try {
await placeOrderWithYourOwnExecutor(intent); // PE Governor never does this
await fetch(`/api/pe/v1/authorizations/${authorizationId}/commit`, {
method: "POST",
headers: { "x-pe-claim-key": claimKey },
});
} catch {
// stand down and give the capacity straight back
await fetch(`/api/pe/v1/authorizations/${authorizationId}/release`, {
method: "POST",
headers: { "x-pe-claim-key": claimKey },
});
}Lifecycle state is bookkeeping of your own policy. Committing records that your adapter acted; PE Governor still never places, routes, or settles an order.
Install the policy once
Wire the call ahead of any allocation at or above the owner threshold. Stop on REJECT or HOLD, and never exceed a REDUCE amount.
# Install once, obey always.
BEFORE any allocation >= OWNER_THRESHOLD_USD:
decision = POST /api/pe/v1/governor # same-origin; production clients resolve it against https://governor.solarly.ai
if decision.decision in ("REJECT", "HOLD"):
stop() # no order, no retry loop
if decision.decision == "REDUCE":
size = min(intended_size, decision.allocationAmountUsd)
if decision.decision == "ALLOCATE":
size = decision.allocationAmountUsd # never more
execute(size) # execution is 100% yoursRequest and response payloads
{
"schema": "pe-governor-request.v1",
"requestedAt": "2026-08-11T22:30:00.000Z",
"ownerId": "owner_demo",
"portfolio": {
"asOf": "2026-08-11T22:29:45.000Z",
"reconciliationCurrent": true,
"killSwitchEngaged": false,
"equityUsd": 250000,
"cashAvailableUsd": 90000,
"grossNotionalUsd": 120000,
"dailyNotionalUsedUsd": 30000,
"realizedLossTodayUsd": 400,
"drawdownPct": 1.8,
"openPositions": [
{
"assetId": "ETH-USD",
"lane": "SPOT",
"notionalUsd": 20000,
"managed": true
}
]
},
"constraints": {
"capitalReserveUsd": 25000,
"installThresholdUsd": 1000,
"maxCandidateNotionalUsd": 25000,
"maxPositionNotionalUsd": 40000,
"maxPortfolioNotionalUsd": 200000,
"maxDailyNotionalUsd": 75000,
"remainingLossBudgetUsd": 3000,
"maxDailyLossUsd": 5000,
"maxDrawdownPct": 8,
"maxConcurrentPositions": 12,
"maxConcurrentPositionsPerLane": 6,
"maxPortfolioStalenessSeconds": 120,
"minimumEdgeBpsByLane": {
"EQUITIES": 25,
"SPOT": 30,
"FUTURES": 40
}
},
"candidates": [
{
"candidateId": "cand_spot_btc_01",
"sourceLane": "SPOT",
"strategyId": "carry_basis_v3",
"assetId": "BTC-USD",
"side": "BUY",
"reduceOnly": false,
"requestedNotionalUsd": 30000,
"maximumLossUsd": 1200,
"expectedNetEdgeBps": 85,
"evidenceStatus": "READY",
"createdAt": "2026-08-11T22:28:00.000Z",
"expiresAt": "2026-08-11T22:40:00.000Z",
"metadata": {
"venue": "primary",
"confidence": 0.71
}
},
{
"candidateId": "cand_eq_msft_02",
"sourceLane": "EQUITIES",
"strategyId": "gap_fade_v2",
"assetId": "MSFT",
"side": "BUY",
"reduceOnly": false,
"requestedNotionalUsd": 12000,
"maximumLossUsd": 900,
"expectedNetEdgeBps": 40,
"evidenceStatus": "READY",
"createdAt": "2026-08-11T22:27:10.000Z",
"expiresAt": "2026-08-11T22:45:00.000Z"
}
]
}{
"schema": "pe-governor-decision.v1",
"policyVersion": "pe-governor-policy-1.0.0",
"generatedAt": "2026-08-11T22:30:00.000Z",
"decision": "ALLOCATE",
"selectedCandidateId": "cand_spot_btc_01",
"allocationAmountUsd": 25000,
"reasons": [
"ALLOCATION_PERMITTED"
],
"portfolioChecks": [
{
"check": "portfolio_state_fresh",
"status": "PASS",
"observed": 15,
"limit": 120
},
{
"check": "portfolio_state_not_future",
"status": "PASS",
"observed": 0,
"limit": 5
},
{
"check": "reconciliation_current",
"status": "PASS",
"observed": true,
"limit": true
},
{
"check": "kill_switch_clear",
"status": "PASS",
"observed": false,
"limit": false
},
{
"check": "daily_loss_budget",
"status": "PASS",
"observed": 400,
"limit": 5000
},
{
"check": "max_drawdown",
"status": "PASS",
"observed": 1.8,
"limit": 8
}
],
"candidates": [
{
"candidateId": "cand_spot_btc_01",
"decision": "ALLOCATE",
"allocationAmountUsd": 25000,
"rank": 1,
"expectedAfterCostProfitUsd": 212.5,
"reasons": [
"SIZE_CONSTRAINED_BY_LIMITS",
"ALLOCATION_ELIGIBLE"
],
"riskChecks": [
{
"check": "evidence_ready",
"status": "PASS",
"observed": "READY",
"limit": "READY"
},
{
"check": "candidate_unexpired",
"status": "PASS",
"observed": "2026-08-11T22:40:00.000Z",
"limit": "2026-08-11T22:30:00.000Z"
},
{
"check": "maximum_loss_bounded",
"status": "PASS",
"observed": 1200,
"limit": 30000
},
{
"check": "remaining_loss_budget",
"status": "PASS",
"observed": 1200,
"limit": 3000
},
{
"check": "install_threshold",
"status": "PASS",
"observed": 30000,
"limit": 1000
},
{
"check": "lane_minimum_edge_bps",
"status": "PASS",
"observed": 85,
"limit": 30
},
{
"check": "capital_reserve",
"status": "PASS",
"observed": 65000,
"limit": 0
},
{
"check": "max_candidate_notional",
"status": "BLOCKED",
"observed": 30000,
"limit": 25000
},
{
"check": "max_position_notional",
"status": "PASS",
"observed": 40000,
"limit": 40000
},
{
"check": "max_portfolio_notional",
"status": "PASS",
"observed": 80000,
"limit": 200000
},
{
"check": "max_daily_notional",
"status": "PASS",
"observed": 45000,
"limit": 75000
},
{
"check": "lane_concurrency",
"status": "PASS",
"observed": 1,
"limit": 6
},
{
"check": "portfolio_concurrency",
"status": "PASS",
"observed": 1,
"limit": 12
},
{
"check": "permitted_size_usd",
"status": "PASS",
"observed": 25000,
"limit": 30000
}
]
},
{
"candidateId": "cand_eq_msft_02",
"decision": "HOLD",
"allocationAmountUsd": 0,
"rank": 2,
"expectedAfterCostProfitUsd": 48,
"reasons": [
"ALLOCATION_ELIGIBLE",
"NOT_SELECTED_THIS_CYCLE"
],
"riskChecks": [
{
"check": "evidence_ready",
"status": "PASS",
"observed": "READY",
"limit": "READY"
},
{
"check": "candidate_unexpired",
"status": "PASS",
"observed": "2026-08-11T22:45:00.000Z",
"limit": "2026-08-11T22:30:00.000Z"
},
{
"check": "maximum_loss_bounded",
"status": "PASS",
"observed": 900,
"limit": 12000
},
{
"check": "remaining_loss_budget",
"status": "PASS",
"observed": 900,
"limit": 3000
},
{
"check": "install_threshold",
"status": "PASS",
"observed": 12000,
"limit": 1000
},
{
"check": "lane_minimum_edge_bps",
"status": "PASS",
"observed": 40,
"limit": 25
},
{
"check": "capital_reserve",
"status": "PASS",
"observed": 65000,
"limit": 0
},
{
"check": "max_candidate_notional",
"status": "PASS",
"observed": 12000,
"limit": 25000
},
{
"check": "max_position_notional",
"status": "PASS",
"observed": 40000,
"limit": 40000
},
{
"check": "max_portfolio_notional",
"status": "PASS",
"observed": 80000,
"limit": 200000
},
{
"check": "max_daily_notional",
"status": "PASS",
"observed": 45000,
"limit": 75000
},
{
"check": "lane_concurrency",
"status": "PASS",
"observed": 0,
"limit": 6
},
{
"check": "portfolio_concurrency",
"status": "PASS",
"observed": 1,
"limit": 12
},
{
"check": "permitted_size_usd",
"status": "PASS",
"observed": 12000,
"limit": 12000
}
]
}
],
"execution": {
"performed": false,
"custody": false,
"brokerage": false,
"orderPlacement": false,
"walletControl": false,
"note": "PE Governor returns a decision only. It never executes trades, holds custody, controls wallets, or places orders."
},
"alpha": {
"independentReturnForecast": false,
"proprietaryAlphaClaim": false,
"expectedEdgeSource": "caller_supplied",
"maximumLossSource": "caller_supplied"
},
"audit": {
"engine": "pe-governor",
"deterministic": true,
"llmUsed": false,
"policyVersion": "pe-governor-policy-1.0.0",
"requestHash": "a2a7c6d765b6ef70214374eef0f1ad0fc4276c754b69030219ecdad05ab6e468",
"generatedAt": "2026-08-11T22:30:00.000Z",
"decisionHash": "855dec83616b3c4363d24707604abf566e092ca8f4e67f7d5bff77007729bd68"
}
}Payment and settlement
Pay per decision in USDC on Base through a Coinbase Business checkout, or draw down prepaid credits. There is no subscription. Authorization is not settlement: only a COMPLETED checkout releases the decision.
- Step 01
POST + idempotency key
One logical request is reserved atomically.
- Step 02
402 with x402 URL
Exactly one Coinbase checkout is created.
- Step 03
202 while processing
Retry with the same key and checkout id.
- Step 04
COMPLETED
Polling confirms a COMPLETED checkout. Signed webhook confirmation is available when configured.
- Step 05
200 decision
Stored once; replays are byte-identical.
The status-code state machine
POST /api/pe/v1/governor (X-Idempotency-Key: uuid-v4)
|
v
402 Payment Required --payment.x402Url--> client pays the checkout
| |
|<---- retry: same key + X-Checkout-Id ------+
v
202 Accepted checkout ACTIVE / PROCESSING --> back off, retry
|
v
checkout COMPLETED (polling; signed webhook when configured)
|
v
200 OK pe-governor-decision.v1, stored once, replays byte-identicalClient retry loop
A minimal integration. Send a UUID v4 idempotency key, read the x402 URL and checkout id from the 402 body, pay it, then poll with the same key and checkout id until the decision is released.
import { randomUUID } from "node:crypto";
const ENDPOINT = "/api/pe/v1/governor"; // same-origin; resolves against https://governor.solarly.ai
const idempotencyKey = randomUUID(); // UUID v4, one per logical decision
// 1. First call: body + idempotency key. No payment yet, so expect 402.
let res = await fetch(ENDPOINT, {
method: "POST",
headers: { "content-type": "application/json", "x-idempotency-key": idempotencyKey },
body: JSON.stringify(governorRequest),
});
if (res.status !== 402) throw new Error(`unexpected status ${res.status}`);
// 2. Read the x402 URL and checkout id straight off the 402 body.
const { payment } = await res.json();
const x402Url: string = payment.x402Url; // where the client pays
const checkoutId: string = payment.checkoutId; // echo this back on every retry
// 3. Pay with your x402 client. The authorization response is NOT settlement:
// only a COMPLETED checkout releases the decision.
await x402Client.pay(x402Url, { amount: payment.amount, asset: payment.currency });
// 4. Poll the same request with the same key + checkout id, backing off.
for (let attempt = 0; attempt < 12; attempt++) {
res = await fetch(ENDPOINT, {
method: "POST",
headers: { "x-idempotency-key": idempotencyKey, "x-checkout-id": checkoutId },
}); // body may be omitted on retries
if (res.status === 200) {
const decision = await res.json(); // pe-governor-decision.v1
console.log(decision.decision, decision.allocationAmountUsd, decision.audit.decisionHash);
break;
}
if (res.status !== 202) throw new Error(await res.text()); // 402/409 are terminal
await new Promise((r) => setTimeout(r, Math.min(500 * 2 ** attempt, 8000)));
}The boundary, stated plainly
- 01. No trade execution and no order placement
- 02. No custody, wallets, or private keys
- 03. No brokerage or money transmission
- 04. No LLM anywhere in the decision path
- 05. No independent return forecast and no proprietary alpha claim
- 06. Expected edge and maximum loss are always caller-supplied inputs
- 07. No venue-native enforcement is claimed; your adapter enforces every authorization
- 08. A signed authorization proves which policy decision was issued. It is not a compliance certificate, underwriting decision, on-chain attestation, or venue approval.