The verifiable pre-trade authorization layer for autonomous capital

Already have a trading agent?
Add Profit Engine Governor.
Keep custody. Keep control.

PE Governor evaluates each submitted order intent against your rules, coordinates portfolio capacity across agents, and returns a short-lived signed authorization for the exact permitted amount. Your executor verifies it; PE Governor never takes custody or places the order.

PE Governor by Solarly.

Decision verdicts

Verdict 01ALLOCATE

Authorize new capital, capped at the exact permitted amount.

Verdict 02REDUCE

Cut an existing managed position. Never exceed the returned amount.

Verdict 03REJECT

A hard rule failed. Do not act on this candidate again.

Verdict 04HOLD

Temporary blocker or unselected this cycle. Stand down and re-ask.

01A deterministic decision, rendered live

A deterministic decision, rendered live

This card is produced by the same pure policy the paid endpoint runs, from the example request below. Identical input always yields an identical decision hash.

ALLOCATEpe-governor-policy-1.0.0

Permitted amount

$25,000.00

selected: cand_spot_btc_01

  • cand_spot_btc_01rank 1ALLOCATE
  • cand_eq_msft_02rank 2HOLD
Request hash
request a2a7c6d765b6ef70214374eef0f1ad0fc4276c754b69030219ecdad05ab6e468
Decision hash
decision 855dec83616b3c4363d24707604abf566e092ca8f4e67f7d5bff77007729bd68

Risk checks (observed vs limit)

  • portfolio_state_fresh15 / 120PASS
  • portfolio_state_not_future0 / 5PASS
  • reconciliation_currenttrue / truePASS
  • kill_switch_clearfalse / falsePASS
  • daily_loss_budget400 / 5000PASS
  • max_drawdown1.8 / 8PASS

How it works

Phase 01

1. Propose

Your agents emit up to 50 candidates on a common bus: lane, asset, side, requested notional, caller-supplied maximum loss and expected net edge, evidence status and expiry.

Phase 02

2. Govern

PE Governor applies one pure policy: state freshness, reconciliation, kill switch, evidence, loss budgets, reserve, notional caps and concurrency — then ranks and picks at most one winner.

Phase 03

3. Obey

Capital moves on your terms. Same request in, byte-identical decision out, with SHA-256 hashes of the canonical request and decision for audit.

02Foundational control for autonomous capital

Foundational control for autonomous capital

A deterministic authorization layer that makes agent decisions bounded, auditable, and portable across your execution stack.

Tamper-evident policy receipts

Every response binds the canonical request and decision with SHA-256 hashes, the policy version, timestamp, exact permitted amount, and observed-versus-limit checks. Replays remain byte-identical.

Portfolio-wide governance

Evaluate up to 50 candidates from multiple strategies against one fresh, reconciled portfolio snapshot. Loss, drawdown, reserve, notional, concurrency, and kill-switch rules apply before at most one winner is selected.

Machine-native payment

Pay the published, risk-banded price per decision in USDC on Base through the Coinbase Business checkout flow, or use prepaid credits. Idempotency prevents duplicate logical purchases.

Enforcement starts in your execution adapter

PE Governor returns the authorization; your adapter verifies and obeys it before placing an order. Coinbase does not currently enforce PE decisions at the venue, and payment never changes the verdict.

Read the install policy
03Signed authorizations your executor can verify

Signed authorizations your executor can verify

Every governed allocation carries a short-lived, cryptographically signed authorization bound to its exact intent and the portfolio's latest submitted risk state.

Verifiable policy proofs

The signature covers the canonical proof payload: issuer, key id, verdict, exact permitted amount, candidate, strategy, lane, full scope, request hash, decision hash, portfolio-state hash, the durable price quote and expiry. Fetch the public key once and verify offline.

Atomic cross-agent reservations

Concurrent agents in the same tenant and portfolio contend for one aggregate risk ledger. A winning candidate only becomes executable if the reservation is granted; otherwise the verdict is downgraded to HOLD.

Risk-banded pricing

The price of a decision scales with capital at risk — the largest requested notional or maximum loss in the request. The quote is deterministic and hash-bound. Payment buys evaluation, never a verdict.

Deterministic price per decision

Capital at risk is max(requestedNotionalUsd, maximumLossUsd) across submitted candidates. One credit unit equals 0.05 USDC.

Deterministic price per decision
Capital at riskPrice (USDC on Base)Credit units
up to $1,0000.05 USDC1
up to $10,0000.10 USDC2
up to $100,0001.00 USDC20
up to $500,0005.00 USDC100
above $500,00010.00 USDC200

The same price applies to ALLOCATE, REDUCE, REJECT and HOLD. There is no subscription.

Verify before you execute

Your execution adapter must verify the payload hash, the signature, the issuer and key id, the validity window, the live reservation token, every expected hash, and that the order matches the authorized intent and exact amount. Consume each authorization once in a durable store, and refuse any order not covered by a live authorization.

verify-authorization.ts
import { verifyAuthorizationForOrder } from "./pe-authorization";

// 1. Fetch and cache the published Ed25519 verification key (kid + issuer).
const { issuer, keys } = await (await fetch("/api/pe/v1/keys")).json();

// 2. Gate every order on a live, exactly matching authorization.
const check = await verifyAuthorizationForOrder({
  proof: decision.proof,                   // returned with every 200
  publicKeyBase64Url: keys[0].x,
  order: {
    candidateId, strategyId, assetId, lane, side, reduceOnly,
    amountUsd: decision.allocationAmountUsd, // must equal permittedAmountUsd exactly
    tenantId, portfolioId, agentId, ownerId, accountScope,
  },
  expected: {
    issuer,
    keyId: keys[0].kid,
    policyVersion: decision.policyVersion,
    requestHash: decision.audit.requestHash,
    decisionHash: decision.audit.decisionHash,
    portfolioStateHash: decision.proof.payload.portfolioStateHash,
    quoteHash: decision.priceQuote.quoteHash,
    reservationFencingToken: decision.proof.payload.reservation.fencingToken,
  },
  // Durable single-use store: ONE atomic operation, never has() then add().
  replayStore: {
    consumeIfUnused: async (id) => {
      const { rowCount } = await db.query(
        "INSERT INTO used_authorizations (id) VALUES ($1) ON CONFLICT DO NOTHING",
        [id],
      );
      return rowCount === 1;                 // false => already consumed
    },
  },
});

if (!check.valid) throw new Error(check.reason); // never place the order
placeOrder(decision.allocationAmountUsd);
Verification keys
04Hold portfolio capacity for the whole execution window

Hold portfolio capacity for the whole execution window

Optional

Verifying a signed authorization offline stays sufficient on its own. If you want more, claim it: PE Governor then holds that authorization's share of aggregate capacity until your adapter reports the outcome, so a second agent cannot spend the same room twice.

  1. AUTHORIZED

    Issued with the decision and already holding capacity for its short validity window.

  2. CLAIMED

    Your adapter bound a secret claim key and now owns the outcome. No other caller can transition it.

  3. COMMITTED

    The adapter acted. Capacity stays held, because committed capital is at work until you reconcile.

  4. RELEASED

    The adapter stood down without acting. Capacity returns immediately.

  5. EXPIRED

    Nobody reported back in time. Capacity returns on its own, with no cleanup call needed.

authorization-lifecycle.ts
// Optional. Offline verification of the proof is still sufficient.
const { authorizationId } = decision.lifecycle;
const claimKey = crypto.randomUUID() + crypto.randomUUID(); // >= 32 chars, keep it

const claim = await fetch(`/api/pe/v1/authorizations/${authorizationId}/claim`, {
  method: "POST",
  headers: { "x-pe-claim-key": claimKey },
});
if (!claim.ok) return; // someone else owns this authorization

try {
  await placeOrderWithYourOwnExecutor(intent); // PE Governor never does this
  await fetch(`/api/pe/v1/authorizations/${authorizationId}/commit`, {
    method: "POST",
    headers: { "x-pe-claim-key": claimKey },
  });
} catch {
  // stand down and give the capacity straight back
  await fetch(`/api/pe/v1/authorizations/${authorizationId}/release`, {
    method: "POST",
    headers: { "x-pe-claim-key": claimKey },
  });
}

Lifecycle state is bookkeeping of your own policy. Committing records that your adapter acted; PE Governor still never places, routes, or settles an order.

05Install the policy once

Install the policy once

Wire the call ahead of any allocation at or above the owner threshold. Stop on REJECT or HOLD, and never exceed a REDUCE amount.

install-policy.txt
# Install once, obey always.
BEFORE any allocation >= OWNER_THRESHOLD_USD:
  decision = POST /api/pe/v1/governor          # same-origin; production clients resolve it against https://governor.solarly.ai
  if decision.decision in ("REJECT", "HOLD"):
      stop()                                  # no order, no retry loop
  if decision.decision == "REDUCE":
      size = min(intended_size, decision.allocationAmountUsd)
  if decision.decision == "ALLOCATE":
      size = decision.allocationAmountUsd     # never more
  execute(size)                               # execution is 100% yours

Request and response payloads

06Request — pe-governor-request.v1
request.json
{
  "schema": "pe-governor-request.v1",
  "requestedAt": "2026-08-11T22:30:00.000Z",
  "ownerId": "owner_demo",
  "portfolio": {
    "asOf": "2026-08-11T22:29:45.000Z",
    "reconciliationCurrent": true,
    "killSwitchEngaged": false,
    "equityUsd": 250000,
    "cashAvailableUsd": 90000,
    "grossNotionalUsd": 120000,
    "dailyNotionalUsedUsd": 30000,
    "realizedLossTodayUsd": 400,
    "drawdownPct": 1.8,
    "openPositions": [
      {
        "assetId": "ETH-USD",
        "lane": "SPOT",
        "notionalUsd": 20000,
        "managed": true
      }
    ]
  },
  "constraints": {
    "capitalReserveUsd": 25000,
    "installThresholdUsd": 1000,
    "maxCandidateNotionalUsd": 25000,
    "maxPositionNotionalUsd": 40000,
    "maxPortfolioNotionalUsd": 200000,
    "maxDailyNotionalUsd": 75000,
    "remainingLossBudgetUsd": 3000,
    "maxDailyLossUsd": 5000,
    "maxDrawdownPct": 8,
    "maxConcurrentPositions": 12,
    "maxConcurrentPositionsPerLane": 6,
    "maxPortfolioStalenessSeconds": 120,
    "minimumEdgeBpsByLane": {
      "EQUITIES": 25,
      "SPOT": 30,
      "FUTURES": 40
    }
  },
  "candidates": [
    {
      "candidateId": "cand_spot_btc_01",
      "sourceLane": "SPOT",
      "strategyId": "carry_basis_v3",
      "assetId": "BTC-USD",
      "side": "BUY",
      "reduceOnly": false,
      "requestedNotionalUsd": 30000,
      "maximumLossUsd": 1200,
      "expectedNetEdgeBps": 85,
      "evidenceStatus": "READY",
      "createdAt": "2026-08-11T22:28:00.000Z",
      "expiresAt": "2026-08-11T22:40:00.000Z",
      "metadata": {
        "venue": "primary",
        "confidence": 0.71
      }
    },
    {
      "candidateId": "cand_eq_msft_02",
      "sourceLane": "EQUITIES",
      "strategyId": "gap_fade_v2",
      "assetId": "MSFT",
      "side": "BUY",
      "reduceOnly": false,
      "requestedNotionalUsd": 12000,
      "maximumLossUsd": 900,
      "expectedNetEdgeBps": 40,
      "evidenceStatus": "READY",
      "createdAt": "2026-08-11T22:27:10.000Z",
      "expiresAt": "2026-08-11T22:45:00.000Z"
    }
  ]
}
07Response — pe-governor-decision.v1
decision.json
{
  "schema": "pe-governor-decision.v1",
  "policyVersion": "pe-governor-policy-1.0.0",
  "generatedAt": "2026-08-11T22:30:00.000Z",
  "decision": "ALLOCATE",
  "selectedCandidateId": "cand_spot_btc_01",
  "allocationAmountUsd": 25000,
  "reasons": [
    "ALLOCATION_PERMITTED"
  ],
  "portfolioChecks": [
    {
      "check": "portfolio_state_fresh",
      "status": "PASS",
      "observed": 15,
      "limit": 120
    },
    {
      "check": "portfolio_state_not_future",
      "status": "PASS",
      "observed": 0,
      "limit": 5
    },
    {
      "check": "reconciliation_current",
      "status": "PASS",
      "observed": true,
      "limit": true
    },
    {
      "check": "kill_switch_clear",
      "status": "PASS",
      "observed": false,
      "limit": false
    },
    {
      "check": "daily_loss_budget",
      "status": "PASS",
      "observed": 400,
      "limit": 5000
    },
    {
      "check": "max_drawdown",
      "status": "PASS",
      "observed": 1.8,
      "limit": 8
    }
  ],
  "candidates": [
    {
      "candidateId": "cand_spot_btc_01",
      "decision": "ALLOCATE",
      "allocationAmountUsd": 25000,
      "rank": 1,
      "expectedAfterCostProfitUsd": 212.5,
      "reasons": [
        "SIZE_CONSTRAINED_BY_LIMITS",
        "ALLOCATION_ELIGIBLE"
      ],
      "riskChecks": [
        {
          "check": "evidence_ready",
          "status": "PASS",
          "observed": "READY",
          "limit": "READY"
        },
        {
          "check": "candidate_unexpired",
          "status": "PASS",
          "observed": "2026-08-11T22:40:00.000Z",
          "limit": "2026-08-11T22:30:00.000Z"
        },
        {
          "check": "maximum_loss_bounded",
          "status": "PASS",
          "observed": 1200,
          "limit": 30000
        },
        {
          "check": "remaining_loss_budget",
          "status": "PASS",
          "observed": 1200,
          "limit": 3000
        },
        {
          "check": "install_threshold",
          "status": "PASS",
          "observed": 30000,
          "limit": 1000
        },
        {
          "check": "lane_minimum_edge_bps",
          "status": "PASS",
          "observed": 85,
          "limit": 30
        },
        {
          "check": "capital_reserve",
          "status": "PASS",
          "observed": 65000,
          "limit": 0
        },
        {
          "check": "max_candidate_notional",
          "status": "BLOCKED",
          "observed": 30000,
          "limit": 25000
        },
        {
          "check": "max_position_notional",
          "status": "PASS",
          "observed": 40000,
          "limit": 40000
        },
        {
          "check": "max_portfolio_notional",
          "status": "PASS",
          "observed": 80000,
          "limit": 200000
        },
        {
          "check": "max_daily_notional",
          "status": "PASS",
          "observed": 45000,
          "limit": 75000
        },
        {
          "check": "lane_concurrency",
          "status": "PASS",
          "observed": 1,
          "limit": 6
        },
        {
          "check": "portfolio_concurrency",
          "status": "PASS",
          "observed": 1,
          "limit": 12
        },
        {
          "check": "permitted_size_usd",
          "status": "PASS",
          "observed": 25000,
          "limit": 30000
        }
      ]
    },
    {
      "candidateId": "cand_eq_msft_02",
      "decision": "HOLD",
      "allocationAmountUsd": 0,
      "rank": 2,
      "expectedAfterCostProfitUsd": 48,
      "reasons": [
        "ALLOCATION_ELIGIBLE",
        "NOT_SELECTED_THIS_CYCLE"
      ],
      "riskChecks": [
        {
          "check": "evidence_ready",
          "status": "PASS",
          "observed": "READY",
          "limit": "READY"
        },
        {
          "check": "candidate_unexpired",
          "status": "PASS",
          "observed": "2026-08-11T22:45:00.000Z",
          "limit": "2026-08-11T22:30:00.000Z"
        },
        {
          "check": "maximum_loss_bounded",
          "status": "PASS",
          "observed": 900,
          "limit": 12000
        },
        {
          "check": "remaining_loss_budget",
          "status": "PASS",
          "observed": 900,
          "limit": 3000
        },
        {
          "check": "install_threshold",
          "status": "PASS",
          "observed": 12000,
          "limit": 1000
        },
        {
          "check": "lane_minimum_edge_bps",
          "status": "PASS",
          "observed": 40,
          "limit": 25
        },
        {
          "check": "capital_reserve",
          "status": "PASS",
          "observed": 65000,
          "limit": 0
        },
        {
          "check": "max_candidate_notional",
          "status": "PASS",
          "observed": 12000,
          "limit": 25000
        },
        {
          "check": "max_position_notional",
          "status": "PASS",
          "observed": 40000,
          "limit": 40000
        },
        {
          "check": "max_portfolio_notional",
          "status": "PASS",
          "observed": 80000,
          "limit": 200000
        },
        {
          "check": "max_daily_notional",
          "status": "PASS",
          "observed": 45000,
          "limit": 75000
        },
        {
          "check": "lane_concurrency",
          "status": "PASS",
          "observed": 0,
          "limit": 6
        },
        {
          "check": "portfolio_concurrency",
          "status": "PASS",
          "observed": 1,
          "limit": 12
        },
        {
          "check": "permitted_size_usd",
          "status": "PASS",
          "observed": 12000,
          "limit": 12000
        }
      ]
    }
  ],
  "execution": {
    "performed": false,
    "custody": false,
    "brokerage": false,
    "orderPlacement": false,
    "walletControl": false,
    "note": "PE Governor returns a decision only. It never executes trades, holds custody, controls wallets, or places orders."
  },
  "alpha": {
    "independentReturnForecast": false,
    "proprietaryAlphaClaim": false,
    "expectedEdgeSource": "caller_supplied",
    "maximumLossSource": "caller_supplied"
  },
  "audit": {
    "engine": "pe-governor",
    "deterministic": true,
    "llmUsed": false,
    "policyVersion": "pe-governor-policy-1.0.0",
    "requestHash": "a2a7c6d765b6ef70214374eef0f1ad0fc4276c754b69030219ecdad05ab6e468",
    "generatedAt": "2026-08-11T22:30:00.000Z",
    "decisionHash": "855dec83616b3c4363d24707604abf566e092ca8f4e67f7d5bff77007729bd68"
  }
}
08Payment and settlement

Payment and settlement

Pay per decision in USDC on Base through a Coinbase Business checkout, or draw down prepaid credits. There is no subscription. Authorization is not settlement: only a COMPLETED checkout releases the decision.

  1. Step 01

    POST + idempotency key

    One logical request is reserved atomically.

  2. Step 02

    402 with x402 URL

    Exactly one Coinbase checkout is created.

  3. Step 03

    202 while processing

    Retry with the same key and checkout id.

  4. Step 04

    COMPLETED

    Polling confirms a COMPLETED checkout. Signed webhook confirmation is available when configured.

  5. Step 05

    200 decision

    Stored once; replays are byte-identical.

The status-code state machine

Client retry loop

A minimal integration. Send a UUID v4 idempotency key, read the x402 URL and checkout id from the 402 body, pay it, then poll with the same key and checkout id until the decision is released.

retry-loop.ts
import { randomUUID } from "node:crypto";

const ENDPOINT = "/api/pe/v1/governor"; // same-origin; resolves against https://governor.solarly.ai
const idempotencyKey = randomUUID(); // UUID v4, one per logical decision

// 1. First call: body + idempotency key. No payment yet, so expect 402.
let res = await fetch(ENDPOINT, {
  method: "POST",
  headers: { "content-type": "application/json", "x-idempotency-key": idempotencyKey },
  body: JSON.stringify(governorRequest),
});

if (res.status !== 402) throw new Error(`unexpected status ${res.status}`);

// 2. Read the x402 URL and checkout id straight off the 402 body.
const { payment } = await res.json();
const x402Url: string = payment.x402Url;     // where the client pays
const checkoutId: string = payment.checkoutId; // echo this back on every retry

// 3. Pay with your x402 client. The authorization response is NOT settlement:
//    only a COMPLETED checkout releases the decision.
await x402Client.pay(x402Url, { amount: payment.amount, asset: payment.currency });

// 4. Poll the same request with the same key + checkout id, backing off.
for (let attempt = 0; attempt < 12; attempt++) {
  res = await fetch(ENDPOINT, {
    method: "POST",
    headers: { "x-idempotency-key": idempotencyKey, "x-checkout-id": checkoutId },
  }); // body may be omitted on retries

  if (res.status === 200) {
    const decision = await res.json(); // pe-governor-decision.v1
    console.log(decision.decision, decision.allocationAmountUsd, decision.audit.decisionHash);
    break;
  }
  if (res.status !== 202) throw new Error(await res.text()); // 402/409 are terminal
  await new Promise((r) => setTimeout(r, Math.min(500 * 2 ** attempt, 8000)));
}

Full walkthrough: first purchase guide

09The boundary, stated plainly

The boundary, stated plainly

  1. 01. No trade execution and no order placement
  2. 02. No custody, wallets, or private keys
  3. 03. No brokerage or money transmission
  4. 04. No LLM anywhere in the decision path
  5. 05. No independent return forecast and no proprietary alpha claim
  6. 06. Expected edge and maximum loss are always caller-supplied inputs
  7. 07. No venue-native enforcement is claimed; your adapter enforces every authorization
  8. 08. A signed authorization proves which policy decision was issued. It is not a compliance certificate, underwriting decision, on-chain attestation, or venue approval.