A deterministic multi-harness control plane for AI-assisted development. Functional roles, model intelligence, and commercial harnesses decoupled under strict, auditable governance.
How the control plane operates in production — deterministic gates, independent challenge, fail-closed.
Problem: Port a strategy from Python/Pandas to C++/Rust for low latency without altering a single decimal.
Roles: Planner · Implementer · Operator · Challenger
Deterministic gate: Operator runs a 10-year tick-by-tick backtest and rejects the patch on any difference ≥ 0.0000001.
Fail-closed: Patch rejected; parity must hold through gaps, splits, and dividends injected by the Challenger.
Problem: Generate new signals without overfitting or survivorship bias.
Roles: Researcher · Implementer · Operator · Challenger · Governor
Deterministic gate: Operator runs the walk-forward workflow — Sharpe, maximum drawdown, and real transaction costs.
Fail-closed: Governor merges only if predefined risk thresholds pass; Challenger attacks with noisy synthetic data.
Problem: A code change must not breach regulatory limits (MiFID II, exposure caps) or break the kill switch.
Roles: Implementer · Operator · Reviewer
Deterministic gate: Operator runs mandatory checks — check_max_exposure, check_kill_switch_logic, check_no_lookahead.
Fail-closed: No code reaches production without an Operator-generated compliance certificate.
Problem: Broker rejections, network latency, and partial fills must not hang or duplicate orders.
Roles: Implementer · Challenger · Operator · Governor
Deterministic gate: Operator verifies idempotent handling (no duplicated orders) and automatic reconnection.
Fail-closed: Governor requires human approval if the Challenger finds a lost order state.