Problem
The current ATS Agent has no live order authority; doctor pins broker_live_ready=false. A paper login, approval, permission preference, or simulated/site paper result must never activate live capital.
Agent deliverable
- Expose a distinct verified LIVE account fingerprint and mode, separate profile/session generation, short-lived live arm, scoped grant, and visible LIVE LOCKED/HOLD state. Arm requires a separate authenticated owner action; it expires on restart, account switch, browser takeover, credential rotation, or adapter change.
- Permit only one qualified site, one account, one equity symbol and one order type initially, with small numerical quantity/notional/daily/open-position caps, current executable pricing and trading-hours checks. Default-deny leverage, short opening, options, transfers, and autonomous mode. Require independent human approve-once for every order.
- Reuse the typed ATSv2 controller and qualified browser adapter with live-specific account/mode checks at preview and commit; prove Stop, site order lookup, cancel, and flatten if supported before enabling submit. If any required action or current limit cannot be verified, remain HOLD.
- Deliver a submit-disabled read-only live account/positions pass and ticket-preparation dry run first. Keep paper and live grants, receipts, UI labels, and histories separate. A release flag off or rollback blocks new commits while preserving reconciliation and operator controls.
- Gate a single minimum-size attended live canary on signed paper evidence, exact-head adversarial review, explicit owner authorization, and a fresh separate operator approval. Reconcile site order ID, fills, open orders, and positions; record exact adapter/host/contract revisions.
Acceptance
Wrong-account or paper-to-live flip, takeover, restart, UI drift, stale quote, closed market, cap breach, unknown outcome, and missing cancel/flatten proof block commit or halt safely. An authorized canary has matching live site history, position, and ATS ledger with no duplicate; any discrepancy returns HOLD. Autonomous live stays disabled pending its own product/policy decision.
Evidence and dependency
src/core/ats_runtime/doctor.ts pins broker_live_ready=false; README.md marks supervised and autonomous live unshipped. See docs/specs/2026-09-23-ats-agent-browser-remaining-gates-v2.md G6 and docs/specs/2026-09-23-ats-paper-live-execution.md G8. Depends on the qualified site paper gate and companion ATSv2/browser-host operator work.
Issue dependencies
Problem
The current ATS Agent has no live order authority; doctor pins broker_live_ready=false. A paper login, approval, permission preference, or simulated/site paper result must never activate live capital.
Agent deliverable
Acceptance
Wrong-account or paper-to-live flip, takeover, restart, UI drift, stale quote, closed market, cap breach, unknown outcome, and missing cancel/flatten proof block commit or halt safely. An authorized canary has matching live site history, position, and ATS ledger with no duplicate; any discrepancy returns HOLD. Autonomous live stays disabled pending its own product/policy decision.
Evidence and dependency
src/core/ats_runtime/doctor.ts pins broker_live_ready=false; README.md marks supervised and autonomous live unshipped. See docs/specs/2026-09-23-ats-agent-browser-remaining-gates-v2.md G6 and docs/specs/2026-09-23-ats-paper-live-execution.md G8. Depends on the qualified site paper gate and companion ATSv2/browser-host operator work.
Issue dependencies